Response information determination method, apparatus, electronic device and storage medium

By parsing the request resource identifier information, retrieving the encryption algorithm from the interface information database, and using a temporary key to process the request, the security shortcomings of traditional encryption methods in complex scenarios are solved, achieving higher data transmission security.

CN116405279BActive Publication Date: 2026-03-13AGRICULTURAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Traditional encryption methods are too simplistic and cannot meet the data transmission security requirements of complex scenarios, resulting in insufficient security during data transmission.

Method used

By parsing the request to be responded to, the requested resource identification information is determined, the corresponding encryption algorithm is retrieved from the interface information database, and the request is processed using a temporary key to determine the target request and response information.

Benefits of technology

It improves the security of data transmission and adapts to encryption requirements in complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405279B_ABST
    Figure CN116405279B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, electronic device, and storage medium for determining response information. The method includes: parsing a request to be responded to to determine request resource identifier information corresponding to the request; retrieving a request encryption algorithm corresponding to the request resource identifier information from a pre-set interface information database; wherein the interface information database stores resource identifier information and interface encryption algorithms; processing the request to be responded to based on the request encryption algorithm and temporary key information to determine a target request, and then determining response information based on the target request. Based on the above technical solution, the method achieves the acquisition of the corresponding encryption algorithm based on resource identifier information, and then determines the target request based on the encryption algorithm and temporary key, thereby improving the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for determining response information. Background Technology

[0002] To ensure the security of information and data, confidential processing of request / response data from network interfaces is a crucial data security measure, and in scenarios such as finance and insurance, it is often necessary to perform separate encryption processing on transmitted data.

[0003] However, traditional encryption methods often use a single encryption algorithm to encrypt data transmission, which cannot guarantee the security of data transmission. Their application scenarios are relatively limited and they cannot be applied to complex scenarios. Summary of the Invention

[0004] This invention provides a response information determination method, apparatus, electronic device, and storage medium, which realizes the acquisition of corresponding encryption algorithms based on resource identification information, and then determines the target request based on the encryption algorithm and temporary key, thereby improving the security of data transmission.

[0005] In a first aspect, embodiments of the present invention provide a method for determining response information, including:

[0006] The request to be responded to is parsed to determine the request resource identifier information corresponding to the request to be responded to;

[0007] The request encryption algorithm corresponding to the requested resource identifier information is retrieved from a pre-set interface information database; wherein, the interface information database is used to store resource identifier information and interface encryption algorithms;

[0008] The request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and the response information is determined based on the target request.

[0009] Secondly, embodiments of the present invention also provide a response information determining device, the device comprising:

[0010] The information acquisition module is used to parse the request to be responded to and determine the request resource identifier information corresponding to the request to be responded to.

[0011] The algorithm retrieval module is used to retrieve the request encryption algorithm corresponding to the requested resource identifier information from a pre-set interface information database; wherein, the interface information database is used to store resource identifier information and interface encryption algorithms;

[0012] The target request determination module is used to process the request to be responded to based on the request encryption algorithm and temporary key information, determine the target request, and determine the response information based on the target request.

[0013] Thirdly, embodiments of the present invention also provide an electronic device, the device comprising:

[0014] One or more processors; and

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to implement the response information determination method as described in any embodiment of the present invention.

[0017] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the response information determination method as described in any of the embodiments of the present invention.

[0018] The technical solution of this invention involves parsing a request to be responded to, determining the request resource identifier information corresponding to the request, and then retrieving a request encryption algorithm corresponding to the request resource identifier information from a pre-set interface information database. The interface information database stores resource identifier information and interface encryption algorithms. Finally, the request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and then the response information is determined based on the target request. Based on this technical solution, the corresponding encryption algorithm is obtained based on resource identifier information, and then the target request is determined based on the encryption algorithm and temporary key, thus improving the security of data transmission.

[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a flowchart illustrating a response information determination method provided in an embodiment of the present invention;

[0022] Figure 2 This is a flowchart of a response information determination method provided in an embodiment of the present invention;

[0023] Figure 3 This is a flowchart of the interface information database construction method provided in the embodiments of the present invention;

[0024] Figure 4 This is a flowchart for determining a request to be responded to, provided in an embodiment of the present invention;

[0025] Figure 5 This is a flowchart of the request decryption and response encryption process provided in an embodiment of the present invention;

[0026] Figure 6 This is a structural block diagram of a response information determination device provided in an embodiment of the present invention;

[0027] Figure 7 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] Example 1

[0031] Figure 1This is a flowchart illustrating a response information determination method provided in an embodiment of the present invention. This embodiment is applicable to situations where the corresponding encryption algorithm is determined based on the resource identifier information corresponding to the request to be responded to, and then the corresponding target request is determined based on the encryption algorithm and the temporary key, and then the response information is determined based on the target request. This method can be executed by a response information determination device, which can be implemented in hardware / software. The device can be configured in an electronic device, such as a PC or a server.

[0032] like Figure 1 As shown, the method includes:

[0033] S110. Parse the request to be responded to and determine the request resource identifier information corresponding to the request to be responded to.

[0034] The request to be responded to can be a request sent from the foreground, such as a request sent by a user by triggering a control in the application. The requested resource identifier can be understood as the resource identifier corresponding to the request to be responded to, such as a Uniform Resource Locator (URL).

[0035] Specifically, the pending response request sent by the user is parsed to determine the request identification information corresponding to the pending response request. For example, when a user needs to log in to the application, the corresponding pending response request can be sent by triggering a control in the application. The pending response request is then parsed to determine the request resource identification information corresponding to the pending response request. This request resource identification information can be included in the header file of the pending response request. After parsing the pending response request, the request resource identification information corresponding to the pending response request can be obtained.

[0036] Based on the above technical solution, before parsing the request to be responded to and determining the request resource identifier information corresponding to the request to be responded to, the method includes: decrypting the request to be applied based on the second key information to determine the identity token information and the first key information corresponding to the request to be applied; storing the first key information in the interface information database, and determining the request to be responded to based on the request to be applied, the first key information and the identity token information.

[0037] The second key information can be a key used to encrypt the application request, and this second key information is a public key generated based on an asymmetric encryption algorithm, such as the SM2 encryption algorithm. The application request can be the initial request information sent by the foreground. The identity token information can be understood as a token used to authenticate the user's identity information. The first key information is generated based on a symmetric encryption algorithm during login, and the symmetric encryption algorithm can be the SM4 encryption algorithm. The interface information database can be a pre-set database used to store information corresponding to each interface.

[0038] Yes, when the front end sends an application request, it decrypts the application request based on the second key information to obtain the identity token information and the first key information corresponding to the application request. The first key information is stored in the interface information database. Then, based on the application request, the first key information, and the identity token information, the response request is determined. For example, when a user needs to send a request, the front end can generate the first key information corresponding to the current application request and obtain the second key information. The original request is encrypted using the second key information. When the back end receives the request information, it needs to decrypt the request based on the second key information to determine the first key information and the identity token information corresponding to the application request. Then, based on the application request, the first key information, and the identity token information, the response request is determined.

[0039] Based on the above technical solution, the step of determining the request to be responded to based on the application request, the first key information, and the identity token information includes: determining whether to encrypt the application request; if the application request is encrypted, obtaining a target encryption algorithm corresponding to the application request; determining target key information based on the target encryption algorithm, encrypting the target key information based on the first key information to determine temporary key information, and determining the request to be responded to based on the temporary key information and the identity token information; if the application request is not encrypted, determining the request to be responded to based on the identity token information.

[0040] The target encryption algorithm can be an algorithm used to perform secondary encryption on the application request. The target key information can be understood as the key information used to decrypt the encrypted target key information. The temporary key information is the key information obtained by encrypting the target key information based on the first key information.

[0041] Specifically, if encryption of the application request is required, the target encryption algorithm corresponding to the application request is obtained, and the target key information is obtained based on the target encryption algorithm. The target key information is then encrypted using the first key information to obtain a temporary key information. The response request is then determined based on the temporary key information and the identity token information. If encryption of the application request is not required, the response request is directly determined based on the identity token information. For example, the temporary key information and the identity token information can be placed in a header file to obtain the response request. It should be noted that to ensure the security of data transmission, the key can be double-encrypted to improve the security of data transmission. That is, if encryption of the application request is required, after the first encryption using the target encryption algorithm, the encrypted target key information is then encrypted a second time using the first key information to obtain the temporary key information.

[0042] Based on the above technical solution, before parsing the request to be responded to and determining the request resource identifier information corresponding to the request to be responded to, the method includes: obtaining the interface information to be applied and determining whether there is preset identifier information in the interface information to be applied; if the preset identifier information matches the first preset identifier information, then storing the resource identifier information corresponding to the interface to be applied and the request encryption algorithm in the request decryption hash table; if the preset identifier information matches the second preset identifier information, then storing the resource identifier information corresponding to the interface to be applied and the request encryption algorithm in the response encryption hash table; storing the request decryption hash table and the response encryption hash table in the interface information database to determine the encryption algorithm based on the interface information database and the resource identifier information.

[0043] The application interface information can be the relevant information for all interfaces under the current service. Preset identifier information can be understood as identifier information used to determine whether an interface needs encryption. The first preset identifier information can indicate that the current interface requires request decryption, and correspondingly, the second preset identifier information can indicate that the current interface requires response encryption. The request encryption algorithm can be the encryption algorithm corresponding to the current interface. The request decryption hash table can be understood as a hash table storing the relevant information of all interfaces that need decryption, and correspondingly, the response encryption hash table can be a hash table storing the relevant information of all interfaces that require corresponding encryption.

[0044] Specifically, the process involves acquiring the interface information to be applied and determining whether preset identifier information exists within it. If the preset identifier information matches the first preset identifier information, the resource identifier information and request encryption algorithm corresponding to the interface to be applied are stored in a request decryption hash table. If the preset identifier information matches the second preset identifier information, the resource identifier information and request encryption algorithm corresponding to the interface to be applied are stored in a response encryption hash table. The request decryption hash table and the response encryption hash table are then stored in the interface information database to determine the encryption algorithm based on the interface information database and the resource identifier information. For example, preset identifier information can be used to mark whether a request needs decryption, whether a response needs encryption, and the encryption algorithm used. The same identifier information is used to modify the interfaces of the middleware module providing the service and the interfaces of each backend module that receive and process forwarded requests through the middleware module. A Bean scanner that runs with the project startup is defined in each module to count all interfaces containing preset identifier information. After scanning, each backend module concatenates the scanned interface URLs and stores them in the same Redis in Ky-Value format.

[0045] S120. Retrieve the request encryption algorithm corresponding to the requested resource identifier information from the pre-set interface information database.

[0046] The interface information database is used to store resource identification information and interface encryption algorithms.

[0047] Specifically, the request encryption algorithm corresponding to the requested resource identifier information is retrieved from the pre-set interface information database. For example, it can be based on the requested resource identifier information to match from the pre-set interface information database, and the successfully matched encryption algorithm is used as the request encryption algorithm.

[0048] Based on the above technical solution, the step of determining the request encryption algorithm corresponding to the resource identification information from a preset database based on the resource identification information includes: obtaining a request decryption hash table from the interface information database; and determining the request encryption algorithm corresponding to the resource identification information based on the request resource identification information and the request decryption hash table.

[0049] Specifically, the request decryption hash table is obtained from the interface information database. Based on the request resource identifier information and the request decryption hash table, the request encryption algorithm corresponding to the resource identifier information is determined. For example, after the middle platform module receives the request, it first verifies the correctness of the identity token information in the interceptor, and then queries the database for the corresponding SM4 key based on the key value in the identity token information to decrypt the temporary key information in the request header. It also queries the request decryption hash table in the database. If the request resource identifier information is in the decryption hash table, the corresponding request encryption algorithm is determined.

[0050] S130. Process the request to be responded to based on the request encryption algorithm and temporary key information, determine the target request, and determine the response information based on the target request.

[0051] The target request can be the request information obtained by decrypting the request to be responded to based on the request encryption algorithm and temporary key information. The response information can be understood as the response corresponding to the target request.

[0052] Specifically, the request to be responded to can be processed based on the request encryption algorithm and temporary key information to determine the target request information, and then the corresponding response information can be determined based on the target request information. For example, the target key information can be determined by decrypting the temporary key information, and then the target key information can be decrypted according to the request encryption algorithm to obtain the original target request.

[0053] Based on the above technical solution, the step of processing the request to be responded to based on the request encryption algorithm and the temporary key information includes: obtaining identity token information corresponding to the request to be responded to, and determining first key information corresponding to the request to be responded to based on the identity token information; if the request to be responded to has a target temporary key, then decrypting the target temporary key based on the first key information to obtain the temporary key information, so as to decrypt the request to be responded to based on the temporary key information.

[0054] Specifically, the system obtains the identity token information corresponding to the request to be responded to, determines the first key information corresponding to the request based on the identity token information, and if the request to be responded to has a target temporary key, decrypts the target temporary key based on the first key information to obtain temporary key information, which is then used to decrypt the request to be responded to. For example, after receiving the request, the middleware module can first verify the correctness of the identity token information in the interceptor, then query the corresponding SM4 key from the database based on the key value in the identity token information, decrypt the temporary key information in the request header, and query the request decryption hash table in the database. If the request resource identifier information is in the decryption hash table, the corresponding request encryption algorithm is determined.

[0055] Based on the above technical solution, after determining the target request and determining the response information based on the target request, the method includes: obtaining the response resource identifier information of the response information and obtaining the response encryption hash table from a pre-set interface information database; determining the response encryption algorithm corresponding to the response information based on the response resource identifier information and the response encryption hash table, and encrypting the response information based on the response encryption algorithm.

[0056] Specifically, after obtaining the response information, it is necessary to determine whether the response information needs to be encrypted. This involves obtaining the response resource identifier information corresponding to the current response information and retrieving the response encryption hash table from the preset database. Then, based on the response resource identifier information and the response encryption hash table, the response encryption algorithm corresponding to the response information is determined, and the response information is encrypted based on the response encryption algorithm. That is, after the request is processed, the response encryption hash table is queried in the response enhancer. If the response resource identifier information is in the response encryption hash table, the key is used to encrypt the response body.

[0057] The technical solution of this invention involves parsing a request to be responded to, determining the request resource identifier information corresponding to the request, and then retrieving a request encryption algorithm corresponding to the request resource identifier information from a pre-set interface information database. The interface information database stores resource identifier information and interface encryption algorithms. Finally, the request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and then the response information is determined based on the target request. Based on this technical solution, the corresponding encryption algorithm is obtained based on resource identifier information, and then the target request is determined based on the encryption algorithm and temporary key, thus improving the security of data transmission.

[0058] Example 2

[0059] Figure 2 This is a flowchart of a response information determination method provided by an embodiment of the present invention. This embodiment further optimizes the above-described response information determination method based on the previous embodiments. Specific implementation details can be found in the technical solution of this embodiment. Technical terms that are the same as or corresponding to those in the previous embodiments will not be repeated here.

[0060] Building the Interface Information Database: Specifically, custom annotations are used to mark whether requests require decryption, responses require encryption, and the encryption algorithm used. The same annotations are used on the interfaces of the middle platform module providing the service and the interfaces of each backend module that receive and process requests from the middle platform module. Each module defines a Bean scanner that runs with the project at startup to collect data on all interfaces containing custom annotations. After scanning, each backend module concatenates the URLs of the scanned interfaces and stores them in the same Redis instance as a Ky-Value pair. The specific steps for building the interface information database are as follows: Figure 3As shown,

[101] Create a custom annotation `Secret` to describe whether the request needs to be decrypted, whether the response needs to be encrypted, and the encryption algorithm used;

[102] Use the `@Secret` annotation to decorate the requests that need to be encrypted in each module;

[103] Create a new class `AnnoListener` that implements Spring's interface `ApplicationListener`, and decorate it with the `@Component` annotation so that it runs automatically when the project starts;

[104] Override the `onApplicationEvent` method in the `AnnoListener` class to obtain the Bean object that provides the interface service through the Spring context, such as the Bean object decorated with `@RestController`;

[105] Define a Map variable.<String,String> reqEncMap is used to store the URL of the interface that needs to be decrypted and the corresponding encryption algorithm.

[0061]

[106] Define Map variables<String,String> `resEncMap` is used to store the URL of the interface that needs to be encrypted and the corresponding encryption algorithm.

[107] Iterate through the methods in the object and determine if they contain the `@Secret` annotation.

[108] If determined by

[107] to contain the annotation, extract the `reqEnc` variable from the annotation. If true, extract the encryption algorithm marked by the annotation and the URL of the current interface, and add them to the `reqEncMap` variable in

[105] .

[109] If determined by

[107] to contain the annotation, extract the `resEnc` variable from the annotation. If true, extract the encryption algorithm marked by the annotation and the URL of the current interface, and add them to the `resEncMap` variable in

[106] .

[110] After the iteration of

[107] is completed, the scan results of the current module are respectively...<REQ_ENC_URL,reqEncMap> and<RES_ENC_URL,resEncMap> The data is stored in Redis in the form of [database name], thus completing the database construction.

[0062] It's important to note that Java is a backend language for providing internet services. Spring is an open-source J2EE application framework. Redis is a high-speed, in-memory key-value database. Header is the header of an HTTP request. Token is a temporary authentication token. HTTP stands for Hypertext Transfer Protocol. SM2 is an asymmetric encryption algorithm released by the State Cryptography Administration. SM4 is a symmetric encryption algorithm released by the State Cryptography Administration. ThreadLocal is a local variable of the current Java thread. HandlerInterceptor is the handler interceptor interface of the Spring MVC framework; its implementation classes automatically execute upon receiving a request. RequestBodyAdviceAdapter is an abstract adapter class that implements the RequestBodyAdvice interface; Spring processes input objects annotated with @RequestBody through its subclasses. ResponseBodyAdvice is a Spring aspect interface; Spring processes output objects annotated with @ResponseBody through its implementation classes. An aspect is a class defined in Spring AOP used to enhance target classes or methods. Annotations are markings used in Java code.

[0063] Determining the pending response request: Specifically, when the front-end initiates a login request, it synchronously sends the SM4 algorithm key generated on the front-end. After the middleware module verifies the login information and it passes the verification, it stores the SM4 key in Redis and returns an authentication token to the front-end. Subsequent front-end requests generate corresponding keys according to the agreement and encrypt the request body. Simultaneously, it uses the SM4 key generated during login to encrypt the temporarily generated key, and passes the token and the encrypted temporary key into the header. The specific steps for determining the pending response request are as follows: Figure 4As shown,

[201] the login interface `login` is defined in the middleware module.

[202] The front-end generates the SM4 key `KeyLogin` for this login call and obtains the SM2 public key `KeyPub` from the back-end.

[203] The `KeyLogin` generated in

[202] is passed into the login interface, and the login request body is encrypted using the `KeyPub` obtained in

[202] .

[204] The login request is sent, the middleware decrypts it using the corresponding SM2 key, verifies it, generates the token for this login, and stores the `KeyLogin` generated in

[202] in Redis.

[205] After receiving the response to the login request, the front-end temporarily stores the token locally.

[206] When the front-end sends other interface requests, if the interface needs encryption, it generates `KeyTemp` according to the agreed encryption algorithm.

[207] The `KeyLogin` generated in

[202] is used to encrypt `KeyTemp` to obtain `KeyTempEnc`.

[208] The request header contains the token received in

[205] and the `KeyTempEnc` obtained in

[207] .

[0064] Request decryption and response encryption: Specifically, after receiving a request, the middleware module first verifies the token's correctness in the interceptor. Then, based on the key value in the token, it retrieves the corresponding SM4 key from Redis, decrypts the temporary key in the request header, and stores it in threadLocal. In the aspect defined before the request handler, it queries the concatenated URL of the request interface in Redis. If the request path is found there, it uses the key in threadLocal to decrypt the request body before continuing subsequent processing. Simultaneously, it queries the concatenated URL of the response interface stored in Redis and stores it in threadLocal. After request processing is complete, the response enhancer queries the concatenated URL of the response interface stored in threadLocal. If the request path is found there, it uses the key in threadLocal to encrypt the response body. Finally, it releases the threadLocal resources uniformly. The specific steps of request decryption and response encryption are as follows: Figure 5As shown,

[301] a new class `AuthInterceptor` implementing the `HandlerInterceptor` interface is created in the middleware module, and managed by Spring using the `@Component` annotation.

[302] The `preHandle` method of the `AuthInterceptor` class in

[301] is overridden to extract and parse the token object in the request header.

[303] Based on the parsing result in

[302] , the SM4 key `KeyLogin` for this login is retrieved from Redis.

[304] An attempt is made to obtain the encrypted temporary key in the request header. If it exists, the `KeyLogin` obtained in

[303] is used to decrypt it to obtain the plaintext key.

[305] If the plaintext temporary key is obtained in step

[304] , it is stored in `threadLocal`; otherwise, the `KeyLogin` obtained in

[303] is stored in `threadLocal`.

[306] The `afterCompletion` method of the `AuthInterceptor` class in

[301] is overridden to release the `threadLocal` resource.

[401] Define a class EncAspect, mark it as an aspect class using the @Aspect annotation, and manage it with Spring using the @Component annotation.

[402] Define a method with no return value in the EncAspect class in

[401] , and mark the pointcut of this aspect class using the @Pointcut annotation.

[403] Define an around method in the EncAspect class in

[401] , and decorate the around method marked as an aspect using the @Around annotation.

[404] In the around method defined in

[403] , determine the module to be accessed based on the request URL, and read the

[110] value of the corresponding module stored in Redis.<REQ_ENC_URL,reqEncMap> Value: reqMap.

[0065]

[405] Read the `reqMap` variable from

[404] , iterate through its values ​​to determine if the request URL is in a certain `reqEncMap` value.

[406] Obtain the encryption algorithm for the key value corresponding to the `reqEncMap` obtained from

[405] .

[407] Based on the encryption algorithm obtained from

[406] and the key stored in `threadLocal` in

[305] , call the corresponding method to decrypt the request body.

[408] Read the

[110] value of the corresponding module stored in Redis.<RES_ENC_URL,resEncMap> Value resMap.

[409] Read the resMap variable in

[408] , iterate through its value to determine whether the request URL is in a certain resEncMap value.

[0066]

[410] Obtain the encryption algorithm for the key value corresponding to resEncMap obtained in

[409] , and store it in threadLocal.

[409] Use the decrypted data obtained in

[407] to complete subsequent processing.

[501] Define a class EncAdapter that implements the interface ResponseBodyAdvice. <object>

[502] Override the `supports` method of the `EncAdapter` class in

[501] to determine if the response encryption algorithm stored in `threadLocal` is present in `410`. If present, return `true` and execute the `beforeBodyWrite` method.

[503] Override the `beforeBodyWrite` method of the `EncAdapter` class in

[501] and call the corresponding method to encrypt the response body based on the encryption algorithm stored in `threadLocal` in `410` and the key stored in `threadLocal` in `305`.

[504] Wrap the encrypted body from

[503] into a JSON object or an XML object and return it to the front end to complete the processing.

[0067] It should be noted that the technical solution of this invention addresses the need for request and response encryption in complex situations involving multiple module combinations, multiple algorithm requirements, and varying request-response encryption needs in Java Web applications. It utilizes a middleware module as the request gateway. In the backend module, custom annotations mark whether requests and responses are encrypted and the algorithms used. An annotation scanning class unifies the two requirements and corresponding algorithms and stores them in Redis. The middleware module uses a login interface to store a base key in Redis. Subsequent frontend requests include a token and a temporary key encrypted with the base key in the header (if the interface uses an additional encryption algorithm). The middleware module defines a HandlerInterceptor implementation class to parse the token, request the base key from Redis, and parse the plaintext of the obtained temporary key. Then, an aspect-based around-the-resource method queries Redis before the interface class processes the request to determine if decryption is required and retrieves the decryption algorithm, completing the request decryption. Finally, ResponseBodyAdvice is used. <object>The implementation class performs the response encryption in the corresponding method.

[0068] The technical solution of this invention involves parsing a request to be responded to, determining the request resource identifier information corresponding to the request, and then retrieving a request encryption algorithm corresponding to the request resource identifier information from a pre-set interface information database. The interface information database stores resource identifier information and interface encryption algorithms. Finally, the request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and then the response information is determined based on the target request. Based on this technical solution, the corresponding encryption algorithm is obtained based on resource identifier information, and then the target request is determined based on the encryption algorithm and temporary key, thus improving the security of data transmission.

[0069] Example 3

[0070] Figure 6 This is a structural block diagram of a response information determination device provided in an embodiment of the present invention. The device includes: an information acquisition module 610, an algorithm retrieval module 620, and a target request determination module 630.

[0071] Information acquisition module 610 is used to parse the request to be responded to and determine the request resource identification information corresponding to the request to be responded to;

[0072] The algorithm retrieval module 620 is used to retrieve the request encryption algorithm corresponding to the requested resource identifier information from a pre-set interface information database; wherein, the interface information database is used to store resource identifier information and interface encryption algorithms;

[0073] The target request determination module 630 is used to process the request to be responded to based on the request encryption algorithm and temporary key information, determine the target request, and determine the response information based on the target request.

[0074] Based on the above technical solution, the device includes a request-to-respond module, used to decrypt the application request based on the second key information before parsing the request-to-respond and determining the request resource identifier information corresponding to the request-to-respond, and to determine the identity token information and the first key information corresponding to the application request; wherein, the first key information is generated based on a symmetric encryption algorithm during login; the second key information is a public key generated based on an asymmetric encryption algorithm; the first key information is stored in an interface information database, and the request-to-respond is determined based on the application request, the first key information, and the identity token information.

[0075] Based on the above technical solution, the pending response request determination module is used to determine whether to encrypt the pending application request. If the pending application request is encrypted, a target encryption algorithm corresponding to the pending application request is obtained; target key information is determined based on the target encryption algorithm; the target key information is encrypted based on the first key information to determine temporary key information; and a pending response request is determined based on the temporary key information and the identity token information. The temporary key information is obtained by encrypting the temporary key information based on the first key information. If the pending application request is not encrypted, a pending response request is determined based on the identity token information.

[0076] Based on the above technical solution, the device includes a database determination module, used to obtain application interface information and determine whether preset identification information exists in the application interface information before parsing the application request and determining the request resource identification information corresponding to the application request; if the preset identification information matches the first preset identification information, the resource identification information corresponding to the application interface and the request encryption algorithm are stored in a request decryption hash table; if the preset identification information matches the second preset identification information, the resource identification information corresponding to the application interface and the request encryption algorithm are stored in a response encryption hash table; the request decryption hash table and the response encryption hash table are stored in an interface information database to determine the encryption algorithm based on the interface information database and the resource identification information.

[0077] Based on the above technical solution, the target request determination module is used to obtain identity token information corresponding to the request to be responded to, and determine first key information corresponding to the request to be responded to based on the identity token information; if the request to be responded to has a target temporary key, the target temporary key is decrypted based on the first key information to obtain the temporary key information, so as to decrypt the request to be responded to based on the temporary key information.

[0078] Based on the above technical solution, the algorithm retrieval module is used to obtain the request decryption hash table from the interface information database; and to determine the request encryption algorithm corresponding to the resource identifier information based on the request resource identifier information and the request decryption hash table.

[0079] Based on the above technical solution, the target request determination module includes a response encryption unit, used to obtain response resource identification information of the response information and obtain a response encryption hash table from a pre-set interface information database; determine a response encryption algorithm corresponding to the response information based on the response resource identification information and the response encryption hash table, and encrypt the response information based on the response encryption algorithm.

[0080] The technical solution of this invention involves parsing a request to be responded to, determining the request resource identifier information corresponding to the request, and then retrieving a request encryption algorithm corresponding to the request resource identifier information from a pre-set interface information database. The interface information database stores resource identifier information and interface encryption algorithms. Finally, the request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and then the response information is determined based on the target request. Based on this technical solution, the corresponding encryption algorithm is obtained based on resource identifier information, and then the target request is determined based on the encryption algorithm and temporary key, thus improving the security of data transmission.

[0081] The response information determination device provided in the embodiments of the present invention can execute the response information determination method provided in any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method.

[0082] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of this disclosure.

[0083] Example 4

[0084] Figure 7 A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0085] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0086] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0087] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as response information determination methods.

[0088] In some embodiments, the response information determination method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the response information determination method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the response information determination method by any other suitable means (e.g., by means of firmware).

[0089] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0090] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0091] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0092] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0093] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0094] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0095] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0096] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.< / object> < / object>

Claims

1. A method for determining response information, characterized in that, include: The request to be responded to is parsed to determine the request resource identifier information corresponding to the request to be responded to; The request encryption algorithm corresponding to the requested resource identifier information is retrieved from a pre-set interface information database; wherein, the interface information database is used to store resource identifier information and interface encryption algorithms; The request to be responded to is processed based on the request encryption algorithm and temporary key information to determine the target request, and the response information is determined based on the target request. The target request is the request information obtained after decrypting the request to be responded to based on the request encryption algorithm and temporary key information. Before parsing the request to be responded to and determining the request resource identifier information corresponding to the request to be responded to, the process includes: The application request is decrypted based on the second key information to determine the identity token information and the first key information corresponding to the application request; wherein, the first key information is generated based on a symmetric encryption algorithm during login; and the second key information is the decryption key corresponding to the public key generated based on an asymmetric encryption algorithm. The first key information is stored in the interface information database, and the request to be responded to is determined based on the application request, the first key information, and the identity token information. The step of determining the request to be responded to based on the application request, the first key information, and the identity token information includes: Determine whether to encrypt the application request; if so, obtain the target encryption algorithm corresponding to the application request. The target key information is determined based on the target encryption algorithm, and the target key information is encrypted based on the first key information to determine temporary key information. The request to be responded to is determined based on the temporary key information and the identity token information. The temporary key information is the key obtained by encrypting the target key information based on the first key information. If the application request is not encrypted, the response request is determined based on the identity token information; The process of processing the pending request based on the request encryption algorithm and temporary key information includes: Obtain the identity token information corresponding to the request to be responded to, and determine the first key information corresponding to the request to be responded to based on the identity token information; If the pending request has a target temporary key, then the target temporary key is decrypted based on the first key information to obtain the temporary key information, and the pending request is decrypted based on the temporary key information.

2. The method according to claim 1, characterized in that, Before parsing the request to be responded to and determining the request resource identifier information corresponding to the request to be responded to, the process includes: Obtain the application interface information and determine whether there is preset identification information in the application interface information; If the preset identification information matches the first preset identification information, then the resource identification information corresponding to the interface to be applied and the request encryption algorithm are stored in the request decryption hash table; If the preset identification information matches the second preset identification information, then the resource identification information and request encryption algorithm corresponding to the interface to be applied are stored in the response encryption hash table; The request decryption hash table and the response encryption hash table are stored in the interface information database to determine the encryption algorithm based on the interface information database and the resource identification information.

3. The method according to claim 1, characterized in that, The step of retrieving the request encryption algorithm corresponding to the requested resource identifier information from a pre-set interface information database includes: Retrieve the request decryption hash table from the interface information database; The request encryption algorithm corresponding to the resource identifier information is determined based on the request resource identifier information and the request decryption hash table.

4. The method according to claim 1, characterized in that, After determining the target request and determining response information based on the target request, the process includes: Obtain the response resource identifier information from the response information, and retrieve the response encrypted hash table from the pre-set interface information database; Based on the response resource identifier information and the response encryption hash table, a response encryption algorithm corresponding to the response information is determined, and the response information is encrypted based on the response encryption algorithm.

5. A response information determining device, characterized in that, include: The information acquisition module is used to parse the request to be responded to and determine the request resource identifier information corresponding to the request to be responded to. The algorithm retrieval module is used to retrieve the request encryption algorithm corresponding to the requested resource identifier information from a pre-set interface information database; wherein, the interface information database is used to store resource identifier information and interface encryption algorithms; The target request determination module is used to process the request to be responded to based on the request encryption algorithm and temporary key information, determine the target request, and determine the response information based on the target request. The target request is the request information obtained after decrypting the request to be responded to based on the request encryption algorithm and temporary key information. The pending response request determination module is used to, before parsing the pending response request and determining the request resource identifier information corresponding to the pending response request, decrypt the pending application request based on the second key information to determine the identity token information and the first key information corresponding to the pending application request; wherein, the first key information is generated based on a symmetric encryption algorithm during login; the second key information is the decryption key corresponding to the public key generated based on an asymmetric encryption algorithm; the first key information is stored in the interface information database, and the pending response request is determined based on the pending application request, the first key information, and the identity token information; The pending request determination module is further configured to determine whether to encrypt the pending application request. If the pending application request is encrypted, a target encryption algorithm corresponding to the pending application request is obtained; target key information is determined based on the target encryption algorithm; the target key information is encrypted based on the first key information to determine temporary key information; and a pending response request is determined based on the temporary key information and the identity token information. The temporary key information is a key obtained by encrypting the target key information based on the first key information. If the pending application request is not encrypted, a pending response request is determined based on the identity token information. The target request determination module is used to obtain identity token information corresponding to the request to be responded to, and determine first key information corresponding to the request to be responded to based on the identity token information; if the request to be responded to has a target temporary key, the target temporary key is decrypted based on the first key information to obtain the temporary key information, and the request to be responded to is decrypted based on the temporary key information.

6. An electronic device, characterized in that, The electronic device includes: One or more processors; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the response information determination method according to any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the response information determination method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Service request processing method and device, computer equipment and storage medium

    CN112367164A

  • block chain-based data hierarchical encryption method

    CN113190859A

  • Client and server data encryption transmission method and device and storage medium

    CN115442132A