A Micro-Service-Based Configuration Data Encryption and Desensitization Method and System
By introducing AES encryption algorithm and national secret algorithm in microservice applications and adding decryption keys to the startup script, the problem of low configuration data security for existing microservice applications is solved, and higher configuration data security and timeliness are achieved.
Patent Information
- Application Number
- CN202310306128.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-27
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2043-03-27
AI Technical Summary
The configuration data of existing microservice applications is stored in plain text in the deployed war or jar package, which is easily obtained by criminals. The PBEWithMD5AndDES algorithm used is easily cracked exhaustively, which poses a great security risk.
Introduce jasypt-spring-boot-starter dependency in microservice applications, rewrite the getProperty method of the encryption and decryption processing class, add AES encryption algorithm and national secret algorithm in factory mode, generate encryption keys and decryption keys, encrypt configuration data, and add decryption keys in the startup script to decrypt configuration data.
By using AES encryption algorithm and national secret algorithm instead of traditional algorithms, the keys are avoided from being cracked exhaustively, the security of configuration data is improved, and the timeliness of configuration data is improved through the caching mechanism.
Smart Images

Figure CN116346345B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly to a method and system for encrypting and desensitizing configuration data based on microservices. Background Art
[0002] A microservices system includes multiple business microservices and an API gateway. The business microservices are responsible for processing business requests from terminals, and the API gateway is responsible for forwarding data between terminals and each business microservice. In the process of each business microservice interacting with a terminal, sensitive information (configuration data) such as account numbers, passwords, ID cards, and contact numbers may be involved. To ensure the security of sensitive information during the interaction process, it is necessary to encrypt the sensitive information.
[0003] However, most of the configuration data of existing microservices applications is stored in plain text in yml configuration files or configuration centers. Once the war package or jar package deployed by the microservices application is obtained by criminals and the file is directly opened through a compression tool, it is easy to obtain the configuration data related to the operation of the microservices. Some microservices applications use springboot to integrate the jasypt tool for encryption and decryption of configuration data to achieve data encryption and desensitization processing. Since jasypt uses the PBEWithMD5AndDES algorithm, it is easy to be violently cracked by methods such as brute force enumeration, and there are great security risks.
[0004] After retrieval, a Chinese invention patent with an application date of May 12, 2021 and an application number of CN202110518035.4 discloses a data encryption and desensitization method, device, electronic device, and storage medium. This patent mainly performs encryption and decryption of data stored in a database and requires cooperation with certain physical devices for data encryption and decryption. It belongs to the data security protection after the application runs and does not involve the relevant configuration data loaded during the application startup.
[0005] Therefore, how to provide a method and system for encrypting and desensitizing configuration data based on microservices to improve the security of configuration data has become an urgent technical problem to be solved. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to provide a method and system for encrypting and desensitizing configuration data based on microservices to improve the security of configuration data.
[0007] In a first aspect, the present invention provides a method for encrypting and desensitizing configuration data based on microservices, including the following steps:
[0008] Step S1: Rewrite the getProperty method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern;
[0009] Step S2: Generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, encrypt the configuration data using the encryption key, identify the encrypted configuration data using the preset prefix character and suffix character, and compile and package the microservice application;
[0010] Step S3: Add the decryption key to the startup script of the microservice application;
[0011] Step S4: When the microservice application starts, decrypt the encrypted configuration data using the decryption key and store it in the cache;
[0012] Step S5: During the running of the microservice application, call the decrypted configuration data from the cache, and clear the cache data after the running stops.
[0013] Further, the specific content of step S1 is as follows:
[0014] Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern.
[0015] Further, in step S2, the national cryptography algorithm includes SM2 and SM3.
[0016] Further, the specific content of step S3 is as follows:
[0017] After adding the -Djasypt.encryptor.password configuration item to the startup script of the microservice application, add the decryption key to the startup script.
[0018] Further, the specific content of step S4 is as follows:
[0019] When the microservice application starts, locate the encrypted configuration data based on the prefix character and suffix character, decrypt the configuration data using the decryption key carried by the startup script, and store it in the cache.
[0020] In the second aspect, the present invention provides a configuration data encryption and desensitization system based on microservices, including the following modules:
[0021] An encryption algorithm update module, which is used to rewrite the getProperty method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern;
[0022] A configuration data encryption module, which is used to generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, encrypt the configuration data using the encryption key, identify the encrypted configuration data using a preset prefix character and suffix character, and compile and package the microservice application;
[0023] A decryption key addition module, which is used to add the decryption key to the microservice application startup script;
[0024] A configuration data demolding module, which is used to decrypt the encrypted configuration data and store it in the cache when the microservice application starts, using the decryption key;
[0025] A configuration data invocation module, which is used to invoke the decrypted configuration data from the cache during the running of the microservice application and clear the cache data after the running stops.
[0026] Further, the encryption algorithm update module is specifically used for:
[0027] Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern.
[0028] Further, in the configuration data encryption module, the national cryptography algorithm includes SM2 and SM3.
[0029] Further, the decryption key addition module is specifically used for:
[0030] After adding the -Djasypt.encryptor.password configuration item to the microservice application startup script, add the decryption key to the startup script.
[0031] Further, the configuration data demolding module is specifically used for:
[0032] When the microservice application starts, locate the encrypted configuration data based on the prefix character and suffix character, and decrypt the configuration data using the decryption key carried by the startup script and store it in the cache.
[0033] The advantages of the present invention are as follows:
[0034] By adding the AES encryption algorithm and the national cryptography algorithm in the microservice application to replace the traditional PBEWithMD5AndDES algorithm, and generating a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, the exhaustion cracking of the encryption key and the decryption key is avoided. The encrypted configuration data is identified by the preset prefix character and suffix character, and the decryption key is added to the startup script of the microservice application. When the microservice application starts, the encrypted configuration data can be located based on the prefix character and the suffix character, and the configuration data decrypted by the decryption key carried by the startup script is stored in the cache, and then the decrypted configuration data is called from the cache, thereby greatly improving the security of the configuration data and greatly improving the timeliness of the configuration data call. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The present invention will be further described below with reference to the accompanying drawings in conjunction with the embodiments.
[0036] Figure 1 FIG. is a flowchart of a method for encrypting and desensitizing configuration data based on microservices according to the present invention.
[0037] Figure 2 FIG. is a schematic structural diagram of a system for encrypting and desensitizing configuration data based on microservices according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] The overall idea of the technical solution in the embodiments of the present application is as follows: By adding the AES encryption algorithm and the national cryptography algorithm in the microservice application to replace the traditional PBEWithMD5AndDES algorithm, and generating a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, the configuration data is encrypted and desensitized by using the encryption key and the decryption key, and the exhaustion cracking of the encryption key and the decryption key is avoided to improve the security of the configuration data.
[0039] Please refer to Figures 1 to 2 As shown in the figure, a preferred embodiment of a method for encrypting and desensitizing configuration data based on microservices according to the present invention includes the following steps:
[0040] Step S1, rewrite the getProperty(String name) method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and use the factory pattern to add the AES encryption algorithm and the national cryptography algorithm to replace the traditional PBEWithMD5AndDES algorithm; the factory pattern supports the rapid upgrade and expansion of the algorithm;
[0041] Step S2: Generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptographic algorithm, use the encryption key to encrypt the configuration data, identify the encrypted configuration data with a preset prefix character and suffix character, and compile and package the microservice application;
[0042] During specific implementation, the encrypted configuration data can be replaced and stored through the prefix character and suffix character without changing the original configuration format; the prefix character and suffix character can be customized or generated through ENC. Through data encryption and desensitization processing with the prefix character and suffix character, the original plaintext configuration data can be directly replaced without changing the original configuration format of the program, making the configuration use simpler and reducing code intrusion;
[0043] Step S3: Add the decryption key to the microservice application startup script;
[0044] Step S4: When the microservice application starts, decrypt the encrypted configuration data with the decryption key and store it in the cache;
[0045] Step S5: During the running process of the microservice application, call the decrypted configuration data from the cache, and clear the cache data after the running stops to further prevent the leakage of the configuration data.
[0046] The specific content of Step S1 is as follows:
[0047] Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptographic algorithm using the factory pattern.
[0048] In Step S2, the national cryptographic algorithms include SM2 and SM3.
[0049] The specific content of Step S3 is as follows:
[0050] After adding the -Djasypt.encryptor.password configuration item to the startup script of the microservice application, add the decryption key to the startup script.
[0051] The specific content of Step S4 is as follows:
[0052] When the microservice application starts, locate the encrypted configuration data based on the prefix character and suffix character, decrypt the configuration data with the decryption key carried by the startup script, and store it in the cache to ensure the running efficiency.
[0053] A preferred embodiment of a configuration data encryption and desensitization system based on microservices according to the present invention includes the following modules:
[0054] An encryption algorithm update module, which is used to rewrite the getProperty(String name) method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and use the factory pattern to add the AES encryption algorithm and the national cryptography algorithm to replace the traditional PBEWithMD5AndDES algorithm; the factory pattern supports the rapid upgrade and expansion of algorithms;
[0055] A configuration data encryption module, which is used to generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, encrypt the configuration data using the encryption key, identify the encrypted configuration data using preset prefix characters and suffix characters, and compile and package the microservice application;
[0056] Specifically, during implementation, the encrypted configuration data can be replaced and stored through the prefix characters and suffix characters without changing the original configuration format; the prefix characters and suffix characters can be customized or generated through ENC. Through the prefix characters and suffix characters for data encryption and desensitization processing, the original plaintext configuration data can be directly replaced without changing the original configuration format of the program, making the configuration use simpler and having less code intrusion;
[0057] A decryption key addition module, which is used to add the decryption key to the microservice application startup script;
[0058] A configuration data demolding module, which is used to decrypt the encrypted configuration data and store it in the cache when the microservice application starts;
[0059] A configuration data call module, which is used to call the decrypted configuration data from the cache during the operation of the microservice application and clear the cache data after the operation stops to further prevent the leakage of the configuration data.
[0060] Specifically, the encryption algorithm update module is used for:
[0061] Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and use the factory pattern to add the AES encryption algorithm and the national cryptography algorithm.
[0062] In the configuration data encryption module, the national cryptography algorithm includes SM2 and SM3.
[0063] The decryption key addition module is specifically used for:
[0064] After adding the -Djasypt.encryptor.password configuration item to the startup script of the microservice application, add the decryption key to the startup script.
[0065] The configuration data demolding module is specifically used for:
[0066] When the microservice application starts, locate the encrypted configuration data based on the prefix character and the suffix character, and decrypt the configuration data carried by the startup script and store it in the cache to ensure the running efficiency.
[0067] To facilitate the understanding of the present invention, the following examples are further described:
[0068] Step 1: Add the jasypt running dependency to the pom.xml configuration file in the springboot application <dependency> <groupid>com.github.ulisesbocchio< / groupid>
[0069] <artifactid>jasypt-spring-boot-starter< / artifactid> <version> 2.1.0< / version> < / dependency> , create the EncryptablePropertySourceWrapper class, and override the getProperty(String name) method;
[0070] Step 2: Use the encryption tool to encrypt the database connection address, account, and password in the example application, and add the custom prefix ABC and suffix curly braces to obtain the new configuration characters as follows:
[0071] Spring:
[0072] datasource:
[0073] type: com.alibaba.druid.pool.DruidDataSource
[0074] Url: ABC{NwvvAr49WV9kfW6uWsrMw7T70v / J3dEk}
[0075] username: ABC{Bxz6CGM24feTtXkETnI5YA==}
[0076] Pasword: ABC{V+VqOiO4IU8a3ODMgXb9NA9DDNRRNnMH}
[0077] Replace the corresponding configuration data in the application.yml configuration file, then compile and package, check the generated jar package, and the compiled yml configuration is the replaced configuration string, and there is no plaintext storage of important data and sensitive information;
[0078] Step 3: Use the command "java -Djasypt.encryptor.password=51fd8366ea45d32a6d0c94d588 - jardemo.jar" to directly start the sample application, or use a startup script written in.bat (for Windows systems) or.sh (for Linux systems) to start the application. If the program starts and runs normally, it indicates that the encrypted and desensitized configuration passes the check;
[0079] Step 4: Use the sample application to call the database and perform operations such as adding, deleting, modifying, and querying data in the database. If successful, it indicates that the encrypted and desensitized configuration information is correctly decrypted and called, and the program functions can be used normally. Use the system memory tool to view the program running memory data (system permissions are required) and view the configuration data after the interface;
[0080] Step 5: Shut down the sample application, check the system running memory, and the configuration data memory is recycled, and the program stops normally.
[0081] In summary, the advantages of the present invention are as follows:
[0082] By adding the AES encryption algorithm and the national encryption algorithm in the microservice application to replace the traditional PBEWithMD5AndDES algorithm, and generating a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national encryption algorithm, it avoids the brute-force cracking of the encryption key and the decryption key. The encrypted configuration data is identified by the preset prefix character and suffix character, and the decryption key is added to the startup script of the microservice application. When the microservice application starts, it can locate the encrypted configuration data based on the prefix character and suffix character, decrypt the configuration data stored in the cache through the decryption key carried by the startup script, and then call the decrypted configuration data from the cache, thereby greatly improving the security of the configuration data and greatly improving the timeliness of the configuration data call.
[0083] Although the specific implementation manners of the present invention have been described above, those skilled in the art of this technology should understand that the specific embodiments we described are illustrative rather than used to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should be covered by the scope protected by the claims of the present invention.
Claims
1. A method for encrypting and desensitizing configuration data based on microservices, characterized in that: It includes the following steps: Step S1: Rewrite the getProperty method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern; Step S2: Generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, encrypt the configuration data using the encryption key, identify the encrypted configuration data using the preset prefix character and suffix character, and compile and package the microservice application; Step S3: Add the decryption key to the startup script of the microservice application; Step S4: When the microservice application starts, decrypt the encrypted configuration data through the decryption key and store it in the cache; when the microservice application starts, locate the encrypted configuration data based on the prefix character and suffix character, and decrypt the configuration data through the decryption key carried by the startup script and store it in the cache; Step S5: During the running of the microservice application, call the decrypted configuration data from the cache, and clear the cache data after the running stops.
2. The method for encrypting and desensitizing configuration data based on microservices according to claim 1, characterized in that: The specific content of Step S1 is as follows: Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern.
3. The method for encrypting and desensitizing configuration data based on microservices according to claim 1, characterized in that: In Step S2, the national cryptography algorithm includes SM2 and SM3.
4. The method for encrypting and desensitizing configuration data based on microservices according to claim 1, characterized in that: The specific content of Step S3 is as follows: After adding the -Djasypt.encryptor.password configuration item to the startup script of the microservice application, add the decryption key to the startup script.
5. A system for encrypting and desensitizing configuration data based on microservices, characterized in that: It includes the following modules: The encryption algorithm update module is used to rewrite the getProperty method of the encryption and decryption processing class in the microservice application based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national cryptography algorithm using the factory pattern; The configuration data encryption module is used to generate a pair of encryption keys and decryption keys based on the AES encryption algorithm and the national cryptography algorithm, encrypt the configuration data using the encryption key, identify the encrypted configuration data using the preset prefix character and suffix character, and compile and package the microservice application; The decryption key addition module is used to add the decryption key to the startup script of the microservice application; The configuration data demolding module is used to decrypt the encrypted configuration data through the decryption key and store it in the cache when the microservice application starts; The specific function of the configuration data demolding module is as follows: When the microservice application starts, locate the encrypted configuration data based on the prefix character and suffix character, and decrypt the configuration data through the decryption key carried by the startup script and store it in the cache; A configuration data calling module, which is used to call the decrypted configuration data from the cache during the operation of the microservice application and clear the cache data after the operation stops.
6. The system for encrypting and desensitizing configuration data based on microservices according to claim 5, characterized in that: Specifically, the encryption algorithm update module is used for: Introduce the jasypt-spring-boot-starter dependency in the microservice application, rewrite the getProperty method of the EncryptablePropertySourceWrapper class for encryption and decryption processing based on the jasypt-spring-boot-starter dependency, and add the AES encryption algorithm and the national encryption algorithm using the factory pattern.
7. The system for encrypting and desensitizing configuration data based on microservices according to claim 5, characterized in that: In the configuration data encryption module, the national encryption algorithms include SM2 and SM3.
8. The system for encrypting and desensitizing configuration data based on microservices according to claim 5, characterized in that: Specifically, the decryption key adding module is used for: After adding the -Djasypt.encryptor.password configuration item to the startup script of the microservice application, add the decryption key to the startup script.
Citation Information
Patent Citations
Data encryption desensitization method and device, electronic equipment and storage medium
CN113127915A
Aconfiguration file encryption and decryption device and method
CN109670325A
Configuration file processing method and device
CN112784292A
Cited By
Method and system for calling encryption and decryption between micro-service and database
CN120710742A