Data Processing Method, Apparatus, Computer Device, and Storage Medium

By generating random data of request status and identity authentication parameters dynamically generate symmetric keys on the data request side, the problem of easy leakage of keys in the prior art is solved, and the security of data transmission is improved.

CN116112268BActive Publication Date: 2025-07-29KINGDEE DEEKING CLOUDCOMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310114140.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-31
Publication Date
2025-07-29
Estimated Expiration
2043-01-31

AI Technical Summary

Technical Problem

The keys used in existing encryption methods remain unchanged for a long time and are prone to leakage, resulting in low data security.

Method used

Generate random data and identity authentication parameters in the request status on the data request side, and dynamically generate symmetric keys. Use this key to encrypt and decrypt the data query parameters to ensure the security of data transmission.

Benefits of technology

By dynamically generating symmetric keys, the security of data query parameters and target data is ensured, and the security of data transmission is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112268B_ABST
    Figure CN116112268B_ABST
Patent Text Reader

Abstract

This application relates to a data processing method, apparatus, and computer device. The method includes: obtaining a data query request sent by a data request end, where the data query request includes encrypted data query parameters and request status random data, and the encrypted data query parameters are obtained by the data request end encrypting the data query parameters using a symmetric key; obtaining identity authentication parameters corresponding to the data request end, and generating a symmetric key based on the identity authentication parameters and the request status random data; using the symmetric key to decrypt the encrypted data query parameters to obtain the data query parameters; searching for target data based on the data query parameters, and encrypting the target data using the symmetric key to obtain encrypted target data; returning the encrypted target data to the data request end so that the data request end can use the symmetric key to decrypt the encrypted target data to obtain the target data. Using this method can improve the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data transmission, and in particular to a data processing method, apparatus, computer equipment, storage medium, and computer program product. Background Art

[0002] With the development of the Internet, a large amount of data is transmitted over the network. However, data is often intercepted or forged during the data transmission process. To ensure the security of data transmission, it is necessary to encrypt core sensitive data. The existing encryption method encrypts the data using a key agreed upon by both parties.

[0003] However, the keys used in existing encryption methods are fixed and do not change for a long time, which makes it easy for the keys to be leaked, resulting in low data security. Summary of the Invention

[0004] Based on this, it is necessary to provide a data processing method, apparatus, computer equipment, computer-readable storage medium and computer program product that can improve data security in response to the above technical problems.

[0005] In a first aspect, the present application provides a data processing method. The method comprises:

[0006] Obtain the data query request sent by the data requester. The data query request includes encrypted data query parameters and request status random data. The encrypted data query parameters are obtained by the data requester using a symmetric key to encrypt the data query parameters. The symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data requester.

[0007] Obtain the identity authentication parameters corresponding to the data request end, and generate a symmetric key based on the identity authentication parameters and the random data of the request status;

[0008] Decrypt the encrypted data query parameter using the symmetric key to obtain the data query parameter;

[0009] Searching for target data based on data query parameters, and encrypting the target data using a symmetric key to obtain encrypted target data;

[0010] The encrypted target data is returned to the data requesting end, so that the data requesting end uses the symmetric key to decrypt the encrypted target data to obtain the target data.

[0011] In a second aspect, the present application further provides a data processing device. The device comprises:

[0012] An acquisition module, configured to acquire a data query request sent by a data request end. The data query request includes encrypted data query parameters and request status random data. The encrypted data query parameters are obtained by the data request end encrypting the data query parameters using a symmetric key, and the symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data request end;

[0013] A key generation module, configured to acquire the identity authentication parameters corresponding to the data request end and generate a symmetric key based on the identity authentication parameters and the request status random data;

[0014] A decryption module, configured to decrypt the encrypted data query parameters using the symmetric key to obtain the data query parameters;

[0015] A data encryption module, configured to search for target data based on the data query parameters and encrypt the target data using the symmetric key to obtain encrypted target data;

[0016] A data sending module, configured to return the encrypted target data to the data request end so that the data request end decrypts the encrypted target data using the symmetric key to obtain the target data.

[0017] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0018] Acquire a data query request sent by a data request end. The data query request includes encrypted data query parameters and request status random data. The encrypted data query parameters are obtained by the data request end encrypting the data query parameters using a symmetric key, and the symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data request end;

[0019] Acquire the identity authentication parameters corresponding to the data request end and generate a symmetric key based on the identity authentication parameters and the request status random data;

[0020] Decrypt the encrypted data query parameters using the symmetric key to obtain the data query parameters;

[0021] Search for target data based on the data query parameters and encrypt the target data using the symmetric key to obtain encrypted target data;

[0022] Return the encrypted target data to the data request end so that the data request end decrypts the encrypted target data using the symmetric key to obtain the target data.

[0023] Fourthly, the present application also provides a computer-readable storage medium. On the computer-readable storage medium, there is a computer program stored, and when the computer program is executed by a processor, the following steps are implemented:

[0024] Obtain a data query request sent by a data request end, where the data query request includes an encrypted data query parameter and a request status random data. The encrypted data query parameter is obtained by the data request end encrypting the data query parameter using a symmetric key, and the symmetric key is generated based on the request status random data and the identity authentication parameter corresponding to the data request end;

[0025] Obtain the identity authentication parameter corresponding to the data request end, and generate a symmetric key based on the identity authentication parameter and the request status random data;

[0026] Use the symmetric key to decrypt the encrypted data query parameter to obtain the data query parameter;

[0027] Search for target data based on the data query parameter, and use the symmetric key to encrypt the target data to obtain encrypted target data;

[0028] Return the encrypted target data to the data request end so that the data request end can use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0029] Fifthly, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0030] Obtain a data query request sent by a data request end, where the data query request includes an encrypted data query parameter and a request status random data. The encrypted data query parameter is obtained by the data request end encrypting the data query parameter using a symmetric key, and the symmetric key is generated based on the request status random data and the identity authentication parameter corresponding to the data request end;

[0031] Obtain the identity authentication parameter corresponding to the data request end, and generate a symmetric key based on the identity authentication parameter and the request status random data;

[0032] Use the symmetric key to decrypt the encrypted data query parameter to obtain the data query parameter;

[0033] Search for target data based on the data query parameter, and use the symmetric key to encrypt the target data to obtain encrypted target data;

[0034] Return the encrypted target data to the data request end so that the data request end can use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0035] Sixth aspect, the present application provides a data processing method. The method is applied to a data request end, and the method includes:

[0036] Obtain data query parameters and generate request status random data;

[0037] Obtain identity authentication parameters, generate a symmetric key based on the request status random data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0038] Generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to a data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to search for target data and encrypt the target data to obtain encrypted target data;

[0039] Obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0040] Seventh aspect, the present application further provides a data processing device. The device is applied to a data request end, and the device includes:

[0041] A data generation module, configured to obtain data query parameters and generate request status random data;

[0042] An encryption module, configured to obtain identity authentication parameters, generate a symmetric key based on the request status random data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0043] A request sending module, configured to generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to a data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to search for target data and encrypt the target data to obtain encrypted target data;

[0044] A decryption module, configured to obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0045] Eighth aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0046] Obtain data query parameters and generate request status random data;

[0047] Obtain identity authentication parameters, generate a symmetric key based on the request status random data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0048] Generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to the data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to search for target data and encrypt the target data to obtain encrypted target data;

[0049] Obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0050] In a ninth aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the following steps are implemented:

[0051] Obtain data query parameters and generate request status random data;

[0052] Obtain identity authentication parameters, generate a symmetric key based on the request status random data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0053] Generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to the data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to search for target data and encrypt the target data to obtain encrypted target data;

[0054] Obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0055] In a tenth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0056] Obtain data query parameters and generate request status random data;

[0057] Obtain identity authentication parameters, generate a symmetric key based on the request status random data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0058] Generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to the data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to find the target data, and encrypts the target data to obtain the encrypted target data;

[0059] Obtain the encrypted target data returned by the data processing end, and decrypt the encrypted target data using the symmetric key to obtain the target data. The above data processing method, device, computer device, storage medium, and computer program product generate a symmetric key by using the request status random data and the identity authentication parameters at the data request end, and encrypt the data query parameters using the symmetric key to obtain the encrypted data query parameters. Since the request status random data for each data request at the data request end is random data, the symmetric key changes randomly, ensuring the security of the encrypted data query parameters sent by the data request end. Generate a symmetric key using the identity authentication information and the request status random data in the data query request through the identity authentication parameters corresponding to the data request end. Decrypt the encrypted data query parameters using the symmetric key to obtain the data query parameters, so as to obtain the target data required by the data request end according to the data query parameters, and encrypt the target data using the symmetric key to obtain the encrypted target data, and return the encrypted target data to the data request end, ensuring the security of the target data, thereby improving the security of data transmission.

[0060] The above data processing method, device, computer device, storage medium, and computer program product generate request status random data at the data request end, generate a symmetric key using the request status random data and the identity authentication parameters, and encrypt the data query parameters using the symmetric key to obtain the encrypted data query parameters, ensuring the security of the data query parameters. And generate a request signature parameter using the time data, identity identification parameter, identity authentication parameter, and request status random data, generate a data query request through the time data, identity identification parameter, request status random data, request signature parameter, and encrypted data query parameters, send the data query request to the data query end for identity authentication and find the target data, and encrypt the target data, realizing two-way encryption. By receiving the encrypted target data returned by the data query end and decrypting the target encrypted data using the symmetric key, the security of the target data is ensured, thereby improving the security of data transmission. Description of the Drawings

[0061] Figure 1 It is an application environment diagram of the data processing method in an embodiment;

[0062] Figure 2 It is a schematic flowchart of the data processing method in an embodiment;

[0063] Figure 3 It is a schematic flowchart of a data processing method in another embodiment;

[0064] Figure 4 It is a schematic flowchart of a data request in one embodiment;

[0065] Figure 5 It is a structural block diagram of a data processing device in one embodiment;

[0066] Figure 6 It is a structural block diagram of a data processing device in another embodiment;

[0067] Figure 7 It is an internal structure diagram of a computer device in one embodiment;

[0068] Figure 8 It is an internal structure diagram of a computer device in one embodiment. Detailed implementation manners

[0069] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0070] The data processing method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed on the cloud or other network servers. The data processing end can be a server, and the data request end can be a terminal. The server 104 obtains the data query request sent by the data request end 102. The data query request includes encrypted data query parameters and request status random data. The encrypted data query parameters are obtained by the data request end 102 encrypting the data query parameters using a symmetric key. The symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data request end; the server 104 obtains the identity authentication parameters corresponding to the data request end, and generates a symmetric key based on the identity authentication parameters and the request status random data; the server 104 uses the symmetric key to decrypt the encrypted data query parameters to obtain the data query parameters; the server 104 searches for the target data based on the data query parameters, and encrypts the target data using the symmetric key to obtain the encrypted target data; the server 104 returns the encrypted target data to the data request end 102, so that the data request end 102 uses the symmetric key to decrypt the encrypted target data to obtain the target data. The data request end 102 obtains the data query parameters and generates request status random data; the data request end 102 obtains the identity authentication parameters, generates a symmetric key based on the request status random data and the identity authentication parameters, and encrypts the data query parameters using the symmetric key to obtain the encrypted data query parameters; the data request end 102 generates a data query request based on the request status random data and the encrypted data query parameters, and sends the data query request to the data processing end, that is, the server 104, so that the data processing end uses the request status random data and the encrypted data query parameters to search for the target data and encrypts the target data to obtain the encrypted target data; the data request end 102 obtains the encrypted target data returned by the data processing end and decrypts the encrypted target data using the symmetric key to obtain the target data. Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0071] In one embodiment, as Figure 2 shown, a data processing method is provided. Taking the server in Figure 1 as an example for illustration, the method includes the following steps:

[0072] Step 202: Obtain the data query request sent by the data requester. The data query request includes encrypted data query parameters and request status random data. The encrypted data query parameters are obtained by the data requester encrypting the data query parameters using a symmetric key. The symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data requester.

[0073] Among them, the data requester refers to the device that requests to obtain data. The encrypted data query parameters refer to the parameters used to query data after encryption. The request status random data refers to the random data generated by the data requester in the state of requesting data, which is dynamically changing. The identity authentication parameters refer to the identity information corresponding to the data requester. The identity authentication parameters are used for the data requester to perform information verification during data transmission, and the identity authentication parameters are also used to generate the symmetric key.

[0074] Specifically, the server receives the identity authentication request sent by the data requester, generates the identity identification parameters and identity authentication parameters corresponding to the data requester, and sends the identity identification parameters and identity authentication parameters to the data requester. The identity identification parameters represent the identity information of the data requester and are used for the data requester to perform information verification during data transmission.

[0075] The data requester obtains the data query parameters through the human-computer interaction interface and randomly generates request status random data in response to the data acquisition operation. The data requester uses the request status random data and the identity authentication parameters to generate a symmetric key, and uses the symmetric key to encrypt the data query parameters to obtain the encrypted data query parameters. Then the data requester generates a data query request based on the request status random data, the encrypted data query parameters, and the identity identification parameters. The server obtains the data query request sent by the data requester.

[0076] Step 204: Obtain the identity authentication parameters corresponding to the data requester, and generate a symmetric key based on the identity authentication parameters and the request status random data.

[0077] Step 206: Use the symmetric key to decrypt the encrypted data query parameters to obtain the data query parameters.

[0078] Specifically, the server obtains the identity identification parameters and the request status random data in the data query request. The server determines the identity authentication parameters corresponding to the data requester according to the identity identification parameters. Then the server uses the identity authentication parameters and the request status random data to perform information verification on the data requester. When it is detected that the information verification passes, the server uses the identity authentication information and the request status random data to perform calculations according to the preset encryption algorithm to obtain the symmetric key. Then the server uses the symmetric key to decrypt the encrypted data query parameters to obtain the data query parameters.

[0079] Step 208: Search for target data based on the data query parameters, and encrypt the target data using the symmetric key to obtain the encrypted target data.

[0080] Step 210: Return the encrypted target data to the data request side, so that the data request side can decrypt the encrypted target data using the symmetric key to obtain the target data.

[0081] Among them, the target data refers to the data that the data request side needs to obtain.

[0082] Specifically, the server searches for and obtains the target data in the data storage system according to the data query parameters. The server can convert the format of the target data according to a preset format to obtain the converted target data. The server encrypts the target data using the symmetric key to obtain the encrypted target data, and returns the encrypted target data to the data request side. After receiving the encrypted target data, the data request side decrypts the encrypted target data using the symmetric key to obtain the target data.

[0083] The data query parameters may further include data operation parameters. The data operations include data addition, data deletion, data update, etc. The server performs data operations on the target data according to the data operation parameters to obtain a data operation result. The server can return the data operation result to the data request side. The server can also obtain the target data after the data operation, encrypt the target data after the data operation using the symmetric key to obtain the encrypted target data, and return the encrypted target data to the data request side.

[0084] In the above data processing method, by using the request status random data and the identity authentication parameters at the data request side to generate a symmetric key, and encrypting the data query parameters using the symmetric key to obtain the encrypted data query parameters. Since the request status random data when the data request side requests data each time is random data, the symmetric key changes randomly, ensuring the security of the encrypted data query parameters sent by the data request side. By using the identity authentication parameters corresponding to the data request side, a symmetric key is generated using the identity authentication information and the request status random data in the data query request. The encrypted data query parameters are decrypted using the symmetric key to obtain the data query parameters, so as to obtain the target data required by the data request side according to the data query parameters, and encrypt the target data using the symmetric key to obtain the encrypted target data, and return the encrypted target data to the data request side, ensuring the security of the target data, thereby improving the security of data transmission.

[0085] In one embodiment, the data query request further includes an identity identification parameter; Step 204: Obtain the identity authentication parameters corresponding to the data request side, including:

[0086] Obtain the identity authentication parameter corresponding to the identity identification parameter based on the preset parameter correspondence.

[0087] Among them, the identity identification parameter refers to the identity information corresponding to the data request end. The identity identification information and the identity authentication information can be information representing the identity of the data request end. The identity identification information and the identity authentication information are in one-to-one correspondence.

[0088] Specifically, the server can pre-allocate corresponding identity identification parameters and identity authentication parameters to multiple data request ends, and pre-send the identity identification parameters and identity authentication parameters to each data request end. The server establishes the parameter correspondence between the identity identification parameter and the identity authentication parameter to obtain the preset parameter correspondence. The server obtains the identity identification parameter and the request status random data in the data query request, and determines the identity authentication information corresponding to the identity identification parameter according to the preset parameter correspondence.

[0089] Then the server can use the identity authentication parameter and the request status random data for calculation to obtain the symmetric key. The server and the data request end pre-set a common custom encryption algorithm, for example, the hash algorithm. The data request end and the server perform hash calculation using the identity authentication parameter and the request status random data to obtain the symmetric key. The calculation expression of the symmetric key can be:

[0090] Aeskey = Substr(HASH(AppSecret + State), 32), indicating that the symmetric key Aeskey is a new string generated by the identity authentication parameter AppSecret and the request status random data State through the common hash algorithm, and the first 32 characters of the new string are intercepted. "+" is the string concatenation operator. State can be the request end status value, for example, a 32-bit random string composed of uppercase and lowercase characters and numbers, which is a unique value that cannot be repeated.

[0091] In this embodiment, by obtaining the identity authentication parameter corresponding to the identity identification parameter according to the preset parameter correspondence, the consistency of the identity authentication parameters in the request end and the service end is ensured, thereby ensuring the consistency of the symmetric keys generated by the request end and the service end, so that the service end and the request end can successfully perform data encryption and data decryption using the symmetric key.

[0092] In one embodiment, the data query request further includes time data; step 204, obtaining the identity authentication parameter corresponding to the data request end, and generating a symmetric key based on the identity authentication parameter and the request status random data, includes:

[0093] Obtain the current time data, and calculate the time difference between the time data and the current time data;

[0094] When it is detected that the time difference does not exceed the preset time difference threshold, obtain the identity authentication parameters corresponding to the data request end, and generate a symmetric key based on the identity authentication parameters and the request status random data.

[0095] Among them, the time data refers to the time when the data request end sends the target data query request. The time data can represent a timestamp, with the unit of seconds, and is used for request expiration control.

[0096] Specifically, the data query request also includes time data. After obtaining the data query request, the server can perform parameter integrity verification on the data query request to verify whether the parameters in the data query request are complete. For example, verify whether there is time data, request status random data, encrypted data query parameters, etc. in the data query request.

[0097] After the server detects that the parameter integrity verification of the data query request passes, it performs time interval verification on the time data. The server obtains the current time data, calculates the time difference between the time data and the current time data, and when it is detected that the time difference does not exceed the preset time difference threshold, it determines that the time interval verification passes. The preset time difference threshold can be two minutes.

[0098] Then the server obtains the identity identification parameters in the data query request, obtains the corresponding identity authentication parameters according to the identity identification parameters, and generates a symmetric key using the identity authentication parameters and the request status random data.

[0099] In this embodiment, by using the time data for time interval verification, the legitimacy of the data request end is ensured, thereby improving the security of data transmission.

[0100] In one embodiment, the data query request further includes a request signature parameter, and the request signature parameter is generated by the data request end based on the identity authentication parameter and the request status random data. Step 204, generating a symmetric key based on the identity authentication parameter and the request status random data, includes:

[0101] Generate a target signature parameter based on the identity authentication parameter and the request status random data;

[0102] When it is detected that the target signature parameter is consistent with the request signature parameter, generate a symmetric key based on the identity authentication parameter and the request status random data.

[0103] Among them, the target signature parameter refers to the signature parameter generated on the server side. The request signature parameter refers to the parameter generated by the data request end for information verification.

[0104] Specifically, the data query request further includes a request signature parameter. After the server obtains the data query request and detects that the parameter integrity check and the time interval check pass, it performs identity authentication on the request signature parameter.

[0105] The server obtains the identity authentication parameter corresponding to the identity identification parameter according to the preset parameter correspondence, and then uses the request status random data and the identity authentication parameter to perform signature calculation to obtain the target signature parameter.

[0106] When the server detects that the target signature parameter is consistent with the request signature, it determines that the identity authentication passes, and generates a symmetric key using the identity authentication parameter and the request status random data.

[0107] In one embodiment, the data query request further includes time data and an identity identification parameter, and the request signature parameter is obtained by performing signature calculation using the request status random data, time data, identity identification parameter, and identity authentication parameter;

[0108] Obtaining the identity authentication parameter corresponding to the data request end includes:

[0109] Obtaining the identity authentication parameter corresponding to the identity identification parameter based on the preset parameter correspondence;

[0110] Generating the target signature parameter based on the identity authentication parameter and the request status random data includes:

[0111] Performing signature calculation using the request status random data, time data, identity identification parameter, and identity authentication parameter to obtain the target signature parameter.

[0112] Specifically, the server obtains the data query request sent by the data request end. The data query request may include request status random data, time data, identity identification parameter, request signature parameter, and encrypted data query parameter. The request signature parameter is obtained by the data request end performing signature calculation using the request status random data, time data, identity identification parameter, and identity authentication parameter.

[0113] After the server obtains the data query request and detects that the parameter integrity check and the time interval check pass, it obtains the identity identification parameter in the data query request. The server obtains the identity authentication parameter corresponding to the identity identification parameter according to the preset parameter correspondence, and then uses the request status random data, time data, identity identification parameter in the data query request, and the obtained identity authentication parameter to perform signature calculation to obtain the target signature parameter.

[0114] In a specific embodiment, the data request end obtains data query parameters in response to a data query instruction, generates request status random data and time data, and then obtains an identity identification parameter and an identity authentication parameter previously received from the server. The data request end uses the request status random data, time data, identity identification parameter, and identity authentication parameter to perform signature calculation to obtain a request signature parameter. The signature calculation expressions for the request signature parameter and the target signature parameter can be:

[0115] Sign = SHA256(Timestamp + AppId + AppSecret + State), which means a string generated by the SHA256 algorithm using a string combined with the time data Timestamp, identity identification parameter AppId, identity authentication parameter AppSecret, and request status random data State to obtain the signature parameter Sign. The SHA256 algorithm: is a commonly used and very secure Hash algorithm, and the length of the hash value used is 256 bits.

[0116] Then the data request end uses the identity authentication parameter and the request status random data to perform encryption calculation according to a preset algorithm to obtain a symmetric key. The data request end uses the symmetric key to perform encryption calculation on the data query parameters to obtain encrypted data query parameters.

[0117] The expression for the data request end to perform encryption calculation on the data query parameters is:

[0118] Cipher = AESEncrypt(Parameter, Aeskey), which means using the symmetric key Aeskey to perform encryption calculation on the data query parameter Parameter using the AES256 encryption algorithm to obtain the encrypted data query parameter Cipher. The data format of the data query parameter can be in json format (JavaScript Object Notation, a lightweight data exchange format). The AES256 algorithm (Advanced Encryption Standard) is an algorithm for data encryption and decryption using a 256-bit symmetric block cipher.

[0119] The data request end uses the request status random data, time data, identity identification parameter, request signature parameter, and encrypted data query parameters to generate a data query request.

[0120] In this embodiment, by generating a request signature parameter and a symmetric key at the data request end and using the symmetric key to encrypt the data query parameters, the security of the data query parameters is ensured, and subsequent identity authentication of the request signature parameter by the server end avoids parameter tampering, thereby improving the security of data transmission.

[0121] In a specific embodiment, after the server detects that the target signature parameter is consistent with the request signature parameter, it uses the identity authentication parameter and the request status random data to perform a hash calculation to obtain a symmetric key. Then the server uses the symmetric key to decrypt the encrypted data query parameter, and the decryption expression is:

[0122] Parameter = AESDecrypt(Cipher, Aeskey), which means using the symmetric key Aeskey to decrypt the encrypted data query parameter Cipher encrypted using the AES algorithm to obtain the data query parameter. Then the server can obtain the target data according to the data query parameter and uniformly convert the data format of the target data into a preset format. For example, each data in the target data is assembled into a json string, and the target data in the preset format is encrypted using the symmetric key. The server can use the AES algorithm to encrypt the json string to obtain the encrypted target data.

[0123] The encryption expression of the target data is:

[0124] EncryptedResponse = AESEncrypt(JsonData, Aeskey), which means the encrypted target data EncryptedResponse is AES encrypted for the target data JsonData using the symmetric key Aeskey.

[0125] The server returns the encrypted target data to the data request side. After the data request side obtains the encrypted target data, it uses the symmetric key in the data request side to decrypt it to obtain the target data.

[0126] The decryption expression corresponding to the data request side is:

[0127] JsonData = AESDecrypt(EncryptedResponse, Aeskey), which means the data request side uses the symmetric key Aeskey to decrypt the encrypted target data EncryptedResponse using the AES algorithm to obtain the target data JsonData.

[0128] In this embodiment, the server calculates the target signature parameter and uses the target signature parameter to authenticate the request signature parameter, ensuring that the parameters AppSecret and State are not tampered with, and ensuring the consistency of the symmetric keys generated by the server side and the request side. And the data query parameter is encrypted on the request side, the target data is encrypted on the server side, and then the encrypted target data is returned to the request side, realizing two-way encryption of data transmission, thereby improving the security of data transmission.

[0129] In one embodiment, after obtaining the data query request sent by the data request side in step 202, the following steps are further included:

[0130] When the identity authentication parameter corresponding to the data request side is not obtained, generate a data acquisition failure message and send the data acquisition failure message to the data request side;

[0131] Obtain the updated data query request sent by the data request side. The updated data query request includes updated encrypted data query parameters and updated request status random data.

[0132] Among them, the updated data query request refers to the data query request regenerated by the data request side. The updated encrypted data query parameter refers to the parameter obtained by re-encrypting the data query parameter. The updated request status random data refers to the regenerated data.

[0133] Specifically, when the server detects that the identity authentication parameter corresponding to the data request side is not obtained, it determines that the data acquisition of the data request side fails. The server can also determine that the data acquisition of the data request side fails when, after obtaining the target data query request, it detects a failure result in the parameter integrity verification result, time interval verification result, identity authentication result, and decryption result of the encrypted data query parameter. Generate a data acquisition failure message and send the data acquisition failure message to the data request side.

[0134] After receiving the data acquisition failure message, the data request side updates the request status random data, or can also regenerate the request status random data to obtain the updated request status random data. Then the data request side uses the updated request status random data and the identity authentication information to generate an updated symmetric key. Use the updated symmetric key to perform an encryption calculation on the data query parameter again to obtain the updated encrypted data query parameter. Then the data request side generates an updated data query request according to the updated encrypted data query parameter and the updated request status random data, and sends the updated data query request to the server for another data acquisition request.

[0135] In this embodiment, after the data request side detects the data acquisition failure, it generates the updated request status random data, uses the updated request status random data to generate the updated symmetric key, and re-encrypts the data query parameter to obtain the updated encrypted data query parameter. Since the request status random data generated each time is variable and unique, the security of the updated symmetric key and the updated encrypted data query parameter is ensured, thereby improving the security of data transmission.

[0136] In one embodiment, as Figure 3 shown, a data processing method is provided. Taking the method applied to the Figure 1 data request side as an example for illustration, the method includes the following steps:

[0137] Step 302, obtain data query parameters and generate random request status data;

[0138] Step 304, obtain identity authentication parameters, generate a symmetric key based on the random request status data and the identity authentication parameters, and use the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters;

[0139] Step 306, generate a data query request based on the random request status data and the encrypted data query parameters, and send the data query request to the data processing end, so that the data processing end uses the random request status data and the encrypted data query parameters to search for target data and encrypt the target data to obtain encrypted target data;

[0140] Step 308, obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

[0141] Specifically, the user sends a data query instruction to the data request end through the human-computer interaction interface. The data request end obtains the data query parameters in response to the data query instruction and generates random request status data. Then the data request end obtains the pre-stored identity authentication parameters, performs a hash calculation using the random request status data and the identity authentication parameters to obtain the symmetric key corresponding to the data request end, and then uses the symmetric key to encrypt the data query parameters to obtain encrypted data query parameters, and then saves the symmetric key.

[0142] The data request end can generate a data query request according to the random request status data and the encrypted data query parameters, and send the data query request to the data processing end, that is, the server. The data processing end uses the random request status data and the encrypted data query parameters to search for target data, encrypts the target data to obtain encrypted target data, and sends the encrypted target data to the data request end.

[0143] The data request end receives the encrypted target data and uses the symmetric key to decrypt the encrypted target data to obtain the target data.

[0144] The above data processing method generates request status random data at the data request end, uses the request status random data and the identity authentication parameter to generate a symmetric key, and uses the symmetric key to encrypt the data query parameter to obtain an encrypted data query parameter, ensuring the security of the data query parameter. The request signature parameter is generated using the time data, the identity identification parameter, the identity authentication parameter, and the request status random data. The data query request is generated through the time data, the identity identification parameter, the request status random data, the request signature parameter, and the encrypted data query parameter, and the data query request is sent to the data query end for identity authentication and searching for the target data, and the target data is encrypted, realizing two-way encryption. By receiving the encrypted target data returned by the data query end and using the symmetric key to decrypt the target encrypted data, the security of the target data is ensured, thereby improving the security of data transmission. In a specific embodiment, as Figure 4 shown, a schematic diagram of a data request process is provided. The data request end includes a network application, and the network application corresponding to the network application can be developed by an ISV (Independent Software Vendors, which specifically refers to an individual or enterprise specializing in software development, production, sales, and services) using RESTFUL (a design style and development method of a network application). The network application in the data request end performs data transmission with the server through the application programming interface API according to a pre-set communication protocol, and the communication protocol is, for example, HTTPS (Hypertext Transfer Protocol Secure, an HTTP channel with security as the goal). The network application in the data request end calls the application programming interface to send a target data query request to the server. After the server detects that the data request end passes the identity authentication, it obtains the encrypted target data according to the target data query request and returns the encrypted target data to the data request end through the application programming interface. The specific process is as follows:

[0145] The data request end obtains data query parameters and constructs common parameters. The common parameters include request status random data, time data, and identity identification parameters, and the data query parameters are obtained. The data request end uses the common parameters and identity authentication parameters to generate request signature parameters, and uses the request status random data and identity authentication parameters to generate a dynamic symmetric key. The data request end uses the dynamic key to perform AES encryption on the data query parameters to obtain encrypted data query parameters. The data request end generates a target data query request based on the common parameters, request signature parameters, and encrypted data query parameters, and sends the target data query request to the server to initiate an API request, indicating an application to call the API and obtain data. The identity identification parameter Appid can be the identity ID pre-authorized by the server for the ISV to call the API, and the identity authentication parameter Appsecret can be the identity Secret pre-authorized by the server for the ISV to call the API. The identity ID and identity Secret are equivalent to the account and account password for identity authentication.

[0146] The server performs parameter integrity verification to check whether the parameters in the request are missing. If a parameter is missing, the process is stopped. If no parameter is missing, the server performs time interval verification to check whether the time data Timestamp is within a legal interval. If it is not within the legal interval, the process is stopped. If it is within the legal interval, the server checks whether the identity authentication parameter Appsecret exists according to the identity identification parameter Appid. If it does not exist, the process is stopped. If it exists, the server performs identity authentication to check whether the target signature parameter and the request signature parameter are consistent. If they are not consistent, the process is stopped. If they are consistent, the server uses the symmetric key to decrypt the encrypted data query parameters and checks whether the decryption is successful. If the decryption fails, the process is stopped. If the decryption is successful, the server obtains the target data according to the data query parameters, assembles it into a JSON string, encrypts the JSON string using the symmetric key to obtain encrypted target data, and returns the encrypted target data to the data request end through the API.

[0147] The data request end obtains the encrypted target data returned after the API response and decrypts the encrypted target data using the symmetric key. When the data request end detects that the decryption fails, the process is stopped and the data acquisition fails. When the data request end detects that the decryption is successful, it obtains the JSON string and the data acquisition is successful.

[0148] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0149] Based on the same inventive concept, an embodiment of the present application further provides a data processing device for implementing the data processing method described above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the data processing device provided below can refer to the limitations on the data processing method in the above text, and will not be repeated here.

[0150] In one embodiment, as Figure 5 shown, a data processing device 500 is provided, including: an acquisition module 502, a key generation module 504, a decryption module 506, a data encryption module 508, and a data sending module 510, where:

[0151] The acquisition module 502 is configured to acquire a data query request sent by a data request end. The data query request includes an encrypted data query parameter and a request status random data. The encrypted data query parameter is obtained by the data request end encrypting the data query parameter using a symmetric key. The symmetric key is generated based on the request status random data and the identity authentication parameter corresponding to the data request end;

[0152] The key generation module 504 is configured to acquire the identity authentication parameter corresponding to the data request end and generate a symmetric key based on the identity authentication parameter and the request status random data;

[0153] The decryption module 506 is configured to decrypt the encrypted data query parameter using the symmetric key to obtain the data query parameter;

[0154] The data encryption module 508 is configured to find target data based on the data query parameter and encrypt the target data using the symmetric key to obtain encrypted target data;

[0155] The data sending module 510 is configured to return the encrypted target data to the data request end so that the data request end decrypts the encrypted target data using the symmetric key to obtain the target data.

[0156] In one embodiment, the key generation module 504 includes:

[0157] A parameter acquisition unit, configured to acquire an identity authentication parameter corresponding to an identity identification parameter based on a preset parameter correspondence.

[0158] In one embodiment, the key generation module 504 includes:

[0159] A time interval verification unit, configured to acquire current time data, calculate a time difference between the time data and the current time data; when it is detected that the time difference does not exceed a preset time difference threshold, acquire the identity authentication parameter corresponding to the data request end, and generate a symmetric key based on the identity authentication parameter and the request status random data.

[0160] In one embodiment, the key generation module 504 includes:

[0161] An identity authentication unit, configured to generate a target signature parameter based on the identity authentication parameter and the request status random data; when it is detected that the target signature parameter is consistent with the request signature parameter, generate a symmetric key based on the identity authentication parameter and the request status random data.

[0162] In one embodiment, the key generation module 504 includes:

[0163] A signature parameter calculation unit, configured to acquire an identity authentication parameter corresponding to a data request end, including: acquiring an identity authentication parameter corresponding to an identity identification parameter based on a preset parameter correspondence; generating a target signature parameter based on the identity authentication parameter and the request status random data, including: performing signature calculation based on the request status random data, the time data, the identity identification parameter, and the identity authentication parameter to obtain the target signature parameter.

[0164] In one embodiment, the data processing device 500 further includes:

[0165] An update request acquisition unit, configured to generate a data acquisition failure message and send the data acquisition failure message to the data request end when the identity authentication parameter corresponding to the data request end is not acquired; acquire an update data query request sent by the data request end, where the update data query request includes an update encrypted data query parameter and an update request status random data.

[0166] In another embodiment, as Figure 6 shown, a data processing device 600 is provided, including: a data generation module 602, an encryption module 604, a request sending module 606, and a decryption module 608, where:

[0167] The data generation module 602 is configured to acquire data query parameters and generate request status random data;

[0168] An encryption module 604, configured to obtain identity authentication parameters, generate a symmetric key based on request status random data and the identity authentication parameters, and encrypt data query parameters using the symmetric key to obtain encrypted data query parameters;

[0169] A request sending module 606, configured to generate a data query request based on the request status random data and the encrypted data query parameters, and send the data query request to a data processing end, so that the data processing end uses the request status random data and the encrypted data query parameters to search for target data, and encrypts the target data to obtain encrypted target data;

[0170] A decryption module 608, configured to obtain the encrypted target data returned by the data processing end, and decrypt the encrypted target data using the symmetric key to obtain the target data.

[0171] Each module in the above data processing device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in a processor in a computer device in a hardware form or be independent of the processor, or can be stored in a memory in the computer device in a software form, so that the processor can call and execute operations corresponding to each of the above modules.

[0172] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store identity authentication parameters, symmetric keys, target data, etc. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communicating with an external terminal through a network connection. When the computer program is executed by the processor, a data processing method is implemented.

[0173] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 8As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data processing method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0174] Those skilled in the art can understand that Figures 7 - 8 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0175] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0176] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0177] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0178] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0179] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0180] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0181] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A data processing method, characterized in that, The method includes: Obtaining a data query request sent by a data request side, where the data query request includes encrypted data query parameters, request status random data, time data, and a request signature parameter. The encrypted data query parameters are obtained by the data request side encrypting the data query parameters using a symmetric key. The symmetric key is generated based on the request status random data and the identity authentication parameters corresponding to the data request side. The request signature parameter is generated by the data request side based on the identity authentication parameters and the request status random data. The time data is the time when the data request side sends the data query request, and is used to participate in integrity verification and perform time interval verification on the data query request; Obtaining the identity authentication parameters corresponding to the data request side, and generating the symmetric key based on the identity authentication parameters and the request status random data, including: after passing the parameter integrity verification for the data query request and passing the time interval verification based on the time data, generating a target signature parameter based on the identity authentication parameters and the request status random data; when it is detected that the target signature parameter is consistent with the request signature parameter, generating the symmetric key based on the identity authentication parameters and the request status random data; Using the symmetric key to decrypt the encrypted data query parameters to obtain the data query parameters; Searching for target data based on the data query parameters, and encrypting the target data using the symmetric key to obtain encrypted target data; Returning the encrypted target data to the data request side so that the data request side can use the symmetric key to decrypt the encrypted target data to obtain the target data.

2. The method according to claim 1, characterized in that The data query request further includes an identity identification parameter; the obtaining of the identity authentication parameters corresponding to the data request side includes: Obtaining the identity authentication parameters corresponding to the identity identification parameter based on a preset parameter correspondence.

3. The method according to claim 1, characterized in that The data query request further includes time data; the obtaining of the identity authentication parameters corresponding to the data request side and generating the symmetric key based on the identity authentication parameters and the request status random data includes: Obtaining the current time data and calculating the time difference between the time data and the current time data; When it is detected that the time difference does not exceed a preset time difference threshold, obtaining the identity authentication parameters corresponding to the data request side and generating the symmetric key based on the identity authentication parameters and the request status random data.

4. The method according to claim 1, wherein The data query request further includes time data and an identity identification parameter, and the request signature parameter is obtained by performing signature calculation using the request status random data, the time data, the identity identification parameter, and the identity authentication parameters; The obtaining of the identity authentication parameters corresponding to the data request side includes: Obtaining the identity authentication parameters corresponding to the identity identification parameter based on a preset parameter correspondence; The generating of the target signature parameter based on the identity authentication parameters and the request status random data includes: Perform signature calculation based on the requested status random data, the time data, the identity identification parameter, and the identity authentication parameter to obtain the target signature parameter.

5. The method according to claim 1, wherein After the data query request sent by the data request end, it further includes: When the identity authentication parameter corresponding to the data request end is not obtained, generate a data acquisition failure message and send the data acquisition failure message to the data request end; Obtain the updated data query request sent by the data request end, where the updated data query request includes updated encrypted data query parameters and updated request status random data.

6. A data processing method, characterized in that, The method is applied to the data request end, and the method includes: Obtain data query parameters and generate requested status random data; Obtain the identity authentication parameter, generate a symmetric key based on the requested status random data and the identity authentication parameter, use the symmetric key to encrypt the data query parameter to obtain the encrypted data query parameter, and generate a request signature parameter based on the identity authentication parameter and the requested status random data; Generate a data query request based on the requested status random data, the encrypted data query parameter, the request signature parameter, and the time data, and send the data query request to the data processing end, so that the data processing end uses the requested status random data and the encrypted data query parameter to find the target data and encrypt the target data to obtain the encrypted target data; the time data is the time when the data query request is sent, and is used to participate in integrity verification and perform time interval verification on the data query request; Obtain the encrypted target data returned by the data processing end, and use the symmetric key to decrypt the encrypted target data to obtain the target data.

7. A data processing device, characterized in that, The device includes: An acquisition module, configured to acquire a data query request sent by a data request end, where the data query request includes encrypted data query parameters, requested status random data, time data, and request signature parameters, the encrypted data query parameters are obtained by the data request end encrypting the data query parameters using a symmetric key, the symmetric key is generated based on the requested status random data and the identity authentication parameter corresponding to the data request end, the request signature parameters are generated by the data request end based on the identity authentication parameter and the requested status random data, and the time data is the time when the data request end sends the data query request, and is used to participate in integrity verification and perform time interval verification on the data query request; A key generation module, configured to obtain the identity authentication parameter corresponding to the data request end and generate the symmetric key based on the identity authentication parameter and the requested status random data, including: after passing the parameter integrity verification for the data query request and passing the time interval verification based on the time data, generating a target signature parameter based on the identity authentication parameter and the requested status random data; when it is detected that the target signature parameter is consistent with the request signature parameter, generating the symmetric key based on the identity authentication parameter and the requested status random data; A decryption module, configured to decrypt the encrypted data query parameter using the symmetric key to obtain the data query parameter; A data encryption module, configured to find target data based on the data query parameter, and encrypt the target data using the symmetric key to obtain encrypted target data; A data sending module, configured to return the encrypted target data to the data request end, so that the data request end decrypts the encrypted target data using the symmetric key to obtain the target data.

8. A data processing device, characterized in that, The device is applied to a data request end, and the device includes: A data generation module, configured to obtain a data query parameter and generate request status random data; An encryption module, configured to obtain an identity authentication parameter, generate a symmetric key based on the request status random data and the identity authentication parameter, encrypt the data query parameter using the symmetric key to obtain an encrypted data query parameter, and generate a request signature parameter based on the identity authentication parameter and the request status random data; A request sending module, configured to generate a data query request based on the request status random data, the encrypted data query parameter, the request signature parameter, and time data, and send the data query request to a data processing end, so that the data processing end uses the request status random data and the encrypted data query parameter to find target data, and encrypts the target data to obtain encrypted target data; the time data is the time when the data query request is sent, and is used to participate in integrity verification and perform time interval verification on the data query request; A decryption module, configured to obtain the encrypted target data returned by the data processing end, and decrypt the encrypted target data using the symmetric key to obtain the target data.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Identity information acquisition method and related device

    CN111181909A

  • User identity authentication method, device and equipment and storage medium

    CN112637131A