Data storage and transmission method and device, computer device, medium and product
By deploying off-site business systems in the government cloud and adopting encrypted storage and transmission technology, the problems of low security and availability of government cloud data have been solved, and the secure storage and continuous transmission of government data have been achieved.
Patent Information
- Application Number
- CN202310506587.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-06
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2043-05-06
AI Technical Summary
The current data security and data cluster availability of the government cloud are low, and government data can be easily intercepted during transmission, resulting in insufficient security of government data transmission.
By deploying the first business system and the second business system in different locations, government data is saved in the first business system and the second business system associated with it respectively, and encrypted storage and encrypted transmission are adopted, combined with preset encryption communication protocols and data interfaces, to achieve secure storage and transmission of government data.
Ensure that government data can still be completely preserved in another system when an accident occurs in one system, ensure the security and availability of government data, reduce service interruption time, and achieve continuous data transmission and secure output.
Smart Images

Figure CN116599711B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud technology, and in particular to a data storage and transmission method, apparatus, computer equipment, medium and product. Background Art
[0002] In recent years, with the development of concepts such as smart government and smart cities, governments across the country have actively responded to national calls to build their own government cloud platforms. The construction of government cloud platforms helps governments streamline, optimize, and integrate management and service functions, reducing the workload of decentralized departments, improving resource utilization, lowering construction costs, and reducing administrative expenses. Through information technology, it also significantly improves the efficiency of various business operations.
[0003] However, the inventors discovered that the current way of creating government clouds stores government data in a unified manner in a large data cluster. Once an accident occurs in the data cluster, the relevant parties will be unable to obtain the government data, resulting in the security of the government data and low availability of the data cluster. At the same time, the current government cloud usually sends government data directly to the relevant clients, which makes it easy for the government data to be intercepted during the transmission process, resulting in the problem of reducing the data transmission security of the government data. Summary of the Invention
[0004] The present application provides a data storage and transmission method, apparatus, computer equipment, medium and product to solve the problems of low government data security and data cluster availability caused by the current government cloud, as well as the problem that government data can be easily intercepted during transmission, resulting in reduced data transmission security of government data.
[0005] In a first aspect, the present application provides a data storage and transmission method, comprising:
[0006] Receiving government data output by the first client; and saving the government data to the first business system and the second business system associated with the first business system respectively;
[0007] receiving a service request output by a second client, obtaining government data from the first business system or the second business system according to the service request, and outputting the obtained government data to the second client according to a preset encrypted communication protocol; wherein the service request is used to instruct the first business system or the second business system to output the government data;
[0008] receive a calling request output by the third client, call a preset data interface according to the calling request to obtain calling data, perform desensitization processing on the calling data to obtain desensitized calling data, and output the desensitized calling data to the third client; wherein the calling request is used to instruct the first business system or the second business system to output government affair data belonging to a preset calling range, the calling range defines metadata of government affair data that can be output to the third client, and the data interface is a computer interface used to obtain government affair data from the first business system or the second business system.
[0009] In the above scheme, the government affair data is respectively saved to the first business system and the second business system associated with the first business system, comprising:
[0010] encrypting the government affair data to obtain encrypted storage data, saving the encrypted storage data to the first business system, and calling the first business system to synchronize the encrypted storage data to the second business system associated with the first business system; or
[0011] outputting the government affair data to the first business system, calling the first business system to encrypt the received government affair data to obtain encrypted storage data and save it, and calling the first business system to output the encrypted storage data to the second business system associated with the first business system.
[0012] In the above scheme, the government affair data is encrypted to obtain encrypted storage data, the encrypted storage data is saved to the first business system, and the first business system is called to synchronize the encrypted storage data to the second business system associated with the first business system, comprising:
[0013] calling a preset encryption interface to encrypt the government affair data to obtain encrypted storage data;
[0014] saving the encrypted storage data to a first master database in the first business system, and outputting the encrypted storage data in the first master database to a first backup database in the first business system according to a preset first snapshot period;
[0015] outputting the encrypted storage data in the first master database to a second master database in the second business system, and outputting the encrypted storage data in the second master database to a second backup database in the second business system according to a preset second snapshot period.
[0016] In the above scheme, the encrypted storage data includes first encrypted storage data, second encrypted storage data, third encrypted storage data and fourth encrypted storage data.
[0017] Outputting the government data to the first business system, calling the first business system to encrypt the received government data to obtain encrypted storage data and save the encrypted storage data, and calling the first business system to output the encrypted storage data to a second business system associated with the first business system, including:
[0018] Outputting the government data to a first master database in the first business system, calling the first master database to encrypt the government data received by the first master database to obtain first encrypted storage data, and saving the first encrypted storage data in the first master database;
[0019] calling the first primary database to decrypt the first encrypted stored data according to a preset third snapshot period to obtain first decrypted data, and outputting the first decrypted data to a first backup database in the first business system;
[0020] calling the first backup database to encrypt the first decrypted data to obtain second encrypted storage data, and saving the second encrypted storage data to the first backup database;
[0021] calling the first master database to decrypt the first encrypted stored data according to a preset fourth snapshot period to obtain second decrypted data, and outputting the second decrypted data to a second master database in the second business system;
[0022] calling the second main database to encrypt the second decrypted data to obtain third encrypted storage data, and saving the third encrypted storage data to the second main database;
[0023] calling the second primary database to decrypt the third encrypted stored data according to a preset fifth snapshot period to obtain third decrypted data, and outputting the third decrypted data to a second backup database in the second business system;
[0024] The second backup database is called to encrypt the third decrypted data to obtain fourth encrypted storage data, and the fourth encrypted storage data is saved in the second backup database.
[0025] In the above solution, obtaining government data from the first business system or the second business system according to the business request, and outputting the obtained government data to the second client according to a preset encryption communication protocol, includes:
[0026] Extracting a request field from the business request, and acquiring government affairs data from a first master database of the first business system according to the request field;
[0027] If the government affairs data cannot be obtained from the first business system according to the request field, obtaining the government affairs data from the second business system;
[0028] Encrypting the government data to obtain encrypted transmission data;
[0029] The encrypted channel between the client and the second client is activated according to the encrypted communication protocol, and the encrypted channel is called to send the encrypted transmission data to the second client.
[0030] In the above solution, encrypting the government data to obtain encrypted transmission data includes:
[0031] Encrypting the government data using a preset transmission encryption algorithm to obtain encrypted data;
[0032] Performing a calculation on the government data using a preset hash function to obtain a hash value;
[0033] Aggregating the encrypted data and the hash value to obtain encrypted transmission data;
[0034] The public key used for decrypting the encrypted data in the transmission confidentiality algorithm is sent to a preset third-party system. The third-party system is used to generate a certificate containing the public key according to the identity information of the second client, and send the certificate to the second client.
[0035] In the above scheme, calling a preset data interface according to the call request to obtain call data, performing desensitization processing on the call data to obtain desensitized call data, and outputting the desensitized call data to the third client, includes:
[0036] If it is determined that the call request contains token information, extracting the call permission in the call request, wherein the token information indicates that the third client has passed the authentication registration, and the call permission defines the range of data that the third client can call;
[0037] If it is determined according to a preset permission rule that the calling permission matches the data interface, extracting a request field in the calling request, and calling the data interface according to the request field to obtain calling data;
[0038] Extracting the sensitive permissions in the call request, determining the sensitive fields in the call data according to the sensitive permissions, and desensitizing the data corresponding to the sensitive fields in the call data to convert the call data into desensitized call data;
[0039] The desensitized call data is output to the third client.
[0040] In the above solution, after outputting the desensitized call data to the third client, the method further includes:
[0041] receiving a full display request output by a third client, performing authority authentication on the third client according to the full display request, and obtaining an authentication result;
[0042] If it is determined that the authentication result is passed, the call data before desensitization corresponding to the call data after desensitization is obtained, and the call data before desensitization is transmitted to the third client.
[0043] In a second aspect, the present application provides a data storage and transmission device, comprising:
[0044] A storage module, configured to receive government data output by the first client; and save the government data to the first business system and a second business system associated with the first business system;
[0045] a transmission module, configured to receive a service request output by a second client, obtain government data from the first business system or the second business system according to the service request, and output the obtained government data to the second client according to a preset encrypted communication protocol; wherein the service request is used to instruct the first business system or the second business system to output the government data;
[0046] A calling module is used to receive a calling request output by a third client, call a preset data interface according to the calling request to obtain calling data, desensitize the calling data to obtain desensitized calling data, and output the desensitized calling data to the third client; wherein, the calling request is used to instruct the first business system or the second business system to output government data belonging to a preset calling range, the calling range defines the metadata of the government data that can be output to the third client, and the data interface is a computer interface for obtaining government data from the first business system or the second business system.
[0047] In a third aspect, the present application provides a computer device, comprising: a processor and a memory communicatively connected to the processor;
[0048] The memory stores computer-executable instructions;
[0049] The processor executes the computer-executable instructions stored in the memory to implement the data storage and transmission method as claimed in claim 1 .
[0050] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the above-mentioned data storage and transmission method.
[0051] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which implements the above-mentioned data storage and transmission method when executed by a processor.
[0052] The present application provides a data storage and transmission method, device, computer equipment, medium and product. By creating a first business system and a second business system in different locations, once an accident occurs in one business system, the other business system can still completely save the government data, thereby ensuring the security of the government data; at the same time, it can also realize the subsequent transmission of government data through the business system where no accident occurs, thereby ensuring the high availability of the business system, reducing or even eliminating the time when the business system cannot provide services, and ensuring the continuous preservation of government data and the subsequent continuous transmission.
[0053] By sending the government data generated according to the business request to the second client according to the encrypted communication protocol, the data security of the government data output to the second client is guaranteed.
[0054] For a third client that obtains call data by calling a data interface, the method of desensitizing the call data to obtain desensitized call data and outputting the desensitized call data to the third client ensures that the third client can obtain the call data it needs while also ensuring the data security of the call data itself. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0056] Figure 1 A schematic diagram of an application scenario provided in an embodiment of the present application;
[0057] Figure 2 This is a flowchart of Example 1 of a data storage and transmission method provided in an embodiment of the present application;
[0058] Figure 3 A schematic diagram of a program module of Example 2 of a data storage and transmission device provided by the present invention;
[0059] Figure 4 Schematic diagram of the hardware structure of the computer device in the computer device of the present invention.
[0060] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0061] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0062] See also Figure 1 , the specific application scenarios of this application are:
[0063] A server 11 running a data storage and transmission method is connected to a first business system 12 and a second business system 13 . The server 11 is also connected to a first client 14 , a second client 15 and a third client 16 .
[0064] The server 11 receives the government data output by the first client 14, and saves the government data to the first business system 12 and the second business system 13 associated with the first business system; the server 11 receives the business request output by the second client 15, obtains the government data from the first business system 12 or the second business system 13 according to the business request, and outputs the government data to the second client 15 according to the preset encryption communication protocol; the server 11 receives the call request output by the third client 16, calls the preset data interface according to the call request to obtain the call data, desensitizes the call data to obtain the desensitized call data, and outputs the desensitized call data to the third client 16, wherein the data interface is a computer interface for obtaining government data from the first business system or the second business system.
[0065] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0066] Example 1:
[0067] See also Figure 2 , the present application provides a data storage and transmission method, including:
[0068] S201: Receive government data output by a first client; and save the government data to a first business system and a second business system associated with the first business system.
[0069] In this step, the government data is data for data storage and subsequent data transmission, and the government business includes: natural person ID number, mobile phone number, electronic license, social security data, tax data, etc.
[0070] The first business system is a database or database cluster for saving government data, and the second business system is a database or database cluster associated with the first government data. The second business system is associated with the first business system by establishing a communication connection between the first business system.
[0071] By creating the first business system and the second business system in different places, if one business system encounters an accident (such as earthquake, fire, power failure, etc.), the other business system can still save the government data completely. At the same time, the subsequent transmission of government data can be realized through the business system that does not encounter the accident, ensuring the high availability of the business system, reducing or even eliminating the time when the business system cannot provide services, ensuring the continuous saving of government data and the subsequent continuous transmission.
[0072] In this embodiment, the first client is a management terminal for auditing, modifying, and processing government data, or a user terminal for uploading personal information.
[0073] In a preferred embodiment, saving the government data to the first business system and the second business system associated with the first business system includes:
[0074] Encrypting the government data to obtain encrypted storage data, saving the encrypted storage data to the first business system, and calling the first business system to synchronize the encrypted storage data to the second business system associated with the first business system; or
[0075] Outputting the government data to the first business system, calling the first business system to encrypt the received government data to obtain encrypted storage data and save it, and calling the first business system to output the encrypted storage data to the second business system associated with the first business system.
[0076] Illustratively, the method of encrypting the government data includes: PBKDF2 algorithm. PBKDF2 algorithm is to increase random salt value on the basis of hash algorithm and multiple hash operations, so that the table building and cracking difficulty of rainbow table are greatly increased. When using PBKDF2 algorithm, the hash algorithm is recommended to use sha1 or sha256, the length of random salt value generally cannot be less than 8 bytes, and the hash number is at least 1000 times. 1000 times of hash operation may only need less than 1 ms for the server, but for the cracker, the calculation is increased by 1000 times, and the random salt of at least 8 bytes increases the rainbow table building difficulty by N orders of magnitude, making it almost impossible to crack in large quantities.
[0077] Other methods for encrypting government data include symmetric encryption algorithms or one-way hashing algorithms. Symmetric encryption algorithms use the same key for both encryption and decryption. Common symmetric encryption algorithms include DES, AES, RC4, and RC5. This encryption method allows the original password to be restored through decryption. Of course, this precondition requires the key to be available, so the key and data are generally stored and managed separately. However, fully protecting the key is a complex task. One-way hashing algorithms, such as MD5 and SHA1, cannot be used to restore the original password through calculation after encryption.
[0078] Specifically, encrypting the government data to obtain encrypted storage data, saving the encrypted storage data to a first business system, and calling the first business system to synchronize the encrypted storage data to a second business system associated with the first business system include:
[0079] Call the preset encryption interface to encrypt the government data to obtain encrypted storage data;
[0080] The encrypted stored data is saved in a first primary database in the first business system, and the encrypted stored data in the first primary database is output to a first backup database in the first business system according to a preset first snapshot period;
[0081] The encrypted stored data in the first master database is output to a second master database in the second business system, and the encrypted stored data in the second master database is output to a second backup database in the second business system according to a preset second snapshot period.
[0082] For example, government data is encrypted through an encryption interface to achieve in-application encryption of government data and obtain encrypted storage data. In-application encryption means realizing encryption and decryption requirements through an encryption interface at the business code level (such as developing a custom mybatis interface, or directly writing an interface for operating jdbc, etc.). It can be flexibly processed according to business characteristics, and sensitive data fields are encrypted at the application layer and stored in ciphertext form. The benefits of encryption at the application layer are: first, it can prevent DBAs and database super-administrators from obtaining plaintext data (because the encryption logic is at the application code layer and cannot be decrypted at the database level); second, there is no need to rely on third-party vendor support, and customized development can be combined with business characteristics. The application system can solve most encryption and decryption problems on its own.
[0083] The snapshot period is the time period used to synchronize the primary and backup databases in the business system (e.g., every 5 minutes, every 10 minutes). While ensuring comprehensive data synchronization between the primary and backup databases, it also avoids frequent synchronization of the primary and backup databases, which would waste data synchronization computing resources.
[0084] Optionally, the encrypted storage data in the first master database is output to a first backup database in the first business system according to a preset first snapshot period, including:
[0085] The first incremental data in the first master database is identified, the first incremental data being the encrypted storage data changed in the first master database in the current first snapshot period;
[0086] The first incremental data is output to the first backup database in the first business system.
[0087] Therefore, the incremental synchronization between the first master database and the first backup database is performed to reduce the resources consumed during data synchronization.
[0088] Optionally, the encrypted storage data in the second master database is output to a second backup database in the second business system according to a preset second snapshot period, including:
[0089] The second incremental data in the second master database is identified, the second incremental data being the encrypted storage data changed in the second master database in the current second snapshot period;
[0090] The second incremental data is output to the second backup database in the second business system.
[0091] Therefore, the incremental synchronization between the second master database and the second backup database is performed to reduce the resources consumed during data synchronization.
[0092] Specifically, the encrypted storage data includes first encrypted storage data, second encrypted storage data, third encrypted storage data and fourth encrypted storage data;
[0093] The government affair data is output to the first business system, the first business system is called to encrypt the received government affair data to obtain encrypted storage data and save, and the first business system is called to output the encrypted storage data to a second business system associated with the first business system, including:
[0094] The government affair data is output to a first master database in the first business system, the first master database is called to encrypt the government affair data received by the first master database to obtain first encrypted storage data, and the first encrypted storage data is saved to the first master database;
[0095] The first master database is called to decrypt the first encrypted storage data according to a preset third snapshot period to obtain first decrypted data, and the first decrypted data is output to a first backup database in the first business system;
[0096] Calling the first backup database to encrypt the first decrypted data to obtain second encrypted storage data, and saving the second encrypted storage data to the first backup database;
[0097] calling the first master database to decrypt the first encrypted stored data according to a preset fourth snapshot period to process second decrypted data, and outputting the second decrypted data to a second master database in the second business system;
[0098] calling the second main database to encrypt the second decrypted data to obtain third encrypted storage data, and saving the third encrypted storage data to the second main database;
[0099] calling the second primary database to decrypt the third encrypted stored data according to a preset fifth snapshot period, and outputting the third decrypted data to a second backup database in the second business system;
[0100] The second backup database is called to encrypt the third decrypted data to obtain fourth encrypted storage data, and the fourth encrypted storage data is saved in the second backup database.
[0101] Exemplarily, through the TDE transparent data encryption method or UDF user-defined function encryption, the first main database encrypts the government data and decrypts the first encrypted storage data; the first backup database encrypts the first decrypted data and decrypts the second encrypted storage data; the second main database encrypts the second decrypted data and decrypts the third encrypted storage data; the second backup database encrypts the third decrypted data and decrypts the fourth encrypted storage data.
[0102] TDE (Transparent Data Encryption) refers to a technology that transparently implements data storage encryption and access decryption within the database without modifying the application. Common databases on the market, such as Oracle, MySQL, and SQL Server, all have this feature built in by default. Data is written to disk (in memory) in plaintext and is encrypted upon writing. After encryption, even if others have access to the database file, they cannot read the data without the key, thus effectively protecting the data in the database. The following is a brief description of MySQL TDE encryption (supported since MySQL 5.7): MySQL's InnoDB uses a two-tiered encryption key architecture, consisting of a master encryption key and tablespace encryption keys. The master encryption key is used to encrypt and decrypt tablespace keys, while the tablespace encryption and decryption keys remain unchanged and are stored in the tablespace file header. This allows for periodic rotation of the master encryption key, providing higher security. Encryption keys are managed through a keyring, which is implemented using plugins and components.
[0103] UDF user-defined function encryption expands business needs based on existing database functions. That is, in the form supported by the database, customized processing logic is implemented by defining the function name and execution process, and data encryption and decryption in the database are realized through the UDF interface.
[0104] S202: Receive a business request output by the second client, obtain government data from the first business system or the second business system according to the business request, and output the obtained government data to the second client according to a preset encryption communication protocol; wherein the business request is used to instruct the first business system or the second business system to output the government data.
[0105] In this step, the government data generated according to the business request is sent to the second client according to the encrypted communication protocol, thereby ensuring the data security of the government data output to the second client. In this embodiment, the second client is usually a management terminal for reviewing, modifying, and processing government data.
[0106] In a preferred embodiment, obtaining government data from the first business system or the second business system according to a business request, and outputting the obtained government data to the second client according to a preset encryption communication protocol, includes:
[0107] Extracting a request field in the business request, and acquiring government affairs data from a first master database of the first business system according to the request field;
[0108] If the government data cannot be obtained from the first business system according to the request field, then the government data is obtained from the second business system;
[0109] Encrypting government data to obtain encrypted transmission data;
[0110] The encrypted channel between the client and the second client is activated according to the encrypted communication protocol, and the encrypted channel is called to send the encrypted transmission data to the second client.
[0111] For example, https is used as an encrypted communication protocol. https is a transmission protocol that adds the SSL / TLS protocol to http. Above the transport layer is the session layer, where the SSL / TLS protocol is transmitted, while http is at the application layer. Using the SSL / TLS protocol, data transmitted by https is encrypted and cannot be decrypted even if intercepted. After installing an SSL certificate on a website, accessing it using the https encryption protocol activates the 'SSL encrypted channel' (SSL protocol) between the client and the server, achieving high-strength two-way encrypted transmission, identifying the website's true identity, and preventing the leakage or tampering of transmitted data. The encrypted channel is a transmission channel based on the SSL protocol.
[0112] Furthermore, the government data is encrypted to obtain encrypted transmission data, including:
[0113] Encrypting government data using a preset transmission encryption algorithm to obtain encrypted data;
[0114] The government data is operated by a preset hash function to obtain a hash value;
[0115] Aggregate the encrypted data and hash value to obtain encrypted transmission data;
[0116] The public key used for decrypting the encrypted data in the transmission confidentiality algorithm is sent to a preset third-party system. The third-party system is used to generate a certificate recording the public key according to the identity information of the second client and send the certificate to the second client.
[0117] Exemplarily, the transmission encryption algorithm includes: a symmetric encryption algorithm, an asymmetric encryption algorithm or a hash algorithm;
[0118] Symmetric encryption algorithms use the same key for both the encryptor and decryptor. Common examples include DES, AES, RC4, and RC5. These algorithms are characterized by their openness, minimal computational complexity, and high encryption speed and efficiency. However, their disadvantage is that both parties in a transaction use the same key, which compromises security.
[0119] Asymmetric encryption algorithms use two different keys for encryption and decryption: a public key and a private key. The sender encrypts data with the public key, and the receiver decrypts the data with the private key. These algorithms are characterized by their complexity and security, eliminating the need for end users to transmit keys. Common asymmetric encryption algorithms include RSA and ECC.
[0120] A hash algorithm is a one-way function characterized by being easy to calculate in the forward direction but extremely difficult to calculate in the reverse direction. It is irreversible and fast to calculate. A hash algorithm maps data of any length into a fixed-length hash value. Different data will produce different hash values after hashing. Comparing these values can determine whether the data has been modified. Common hash algorithms include MD5 and SHA.
[0121] The hash algorithm is the MD5 message digest algorithm. The MD5 message digest algorithm (MD5 Message-DigestAlgorithm) is a widely used cryptographic hash function that can generate a 128-bit (16-byte) hash value to ensure the integrity and consistency of information transmission. Before the sender encrypts the plaintext data, it takes the MD5 value of the plaintext to obtain the "digest" of its information (Note: the digest must be irreversible and the plaintext data cannot be deduced in reverse). Then, the public key is used to encrypt the plaintext and the plaintext digest respectively and send them to the data receiver. After receiving the data, the data receiver uses the private key to decrypt the ciphertext and the ciphertext digest, and then takes the MD5 digest of the decrypted plaintext and compares the decrypted plaintext digest with the plaintext digest sent to see if they are consistent; if they are consistent, it proves that the data is original and has not been tampered with.
[0122] In the various encryption and signature verification schemes mentioned above, we have always assumed that the public key held by the receiver or sender is always correct. However, unless the other party personally hands over the public key to us, if no measures are taken, the public key between the two parties in the network may be tampered with.
[0123] The third-party system runs a certificate authentication algorithm. This algorithm involves the following steps: When a second client wants to publish its public key, it sends its identity information to the third-party system, which verifies the identity. If the third-party system confirms the identity is the client's true identity, it packages the identity information and public key into a certificate, commonly known as a CA certificate. To obtain the public key, we simply obtain the certificate and extract the public key from it.
[0124] S203: Receive a call request output by the third client, call a preset data interface according to the call request to obtain call data, desensitize the call data to obtain desensitized call data, and output the desensitized call data to the third client; wherein, the call request is used to instruct the first business system or the second business system to output government data belonging to a preset call range, the call range defines the metadata of the government data that can be output to the third client, and the data interface is a computer interface for obtaining government data from the first business system or the second business system.
[0125] In this step, for the third client that obtains the call data by calling the data interface, the call data is desensitized to obtain the desensitized call data, and the desensitized call data is output to the third client. This ensures that the third client can obtain the call data it needs while also ensuring the data security of the call data itself.
[0126] In this embodiment, the third client is a terminal of a partner for obtaining government data from the first business system or the second business system, or a terminal of a government data owner for viewing his own information and performing business processing operations.
[0127] In a preferred embodiment, calling a preset data interface according to a call request to obtain call data, desensitizing the call data to obtain desensitized call data, and outputting the desensitized call data to a third client includes:
[0128] If it is determined that the call request contains token information, extracting the call permission in the call request, wherein the token information indicates that the third client has passed the authentication registration, and the call permission defines the scope of data that the third client can call;
[0129] If the call permission is determined to match the data interface according to the preset permission rules, the request field in the call request is extracted, and the data interface is called according to the request field to obtain the call data;
[0130] Extract sensitive permissions from the call request, determine sensitive fields in the call data based on the sensitive permissions, desensitize the data corresponding to the sensitive fields in the call data, and convert the call data into desensitized call data;
[0131] The desensitized call data is output to the third client.
[0132] For example, a third-party client is authenticated and registered through an authentication center, and token information (e.g., a token) is sent to the authenticated and registered third-party client to indicate that the client is a terminal authorized to call the data interface. Spring Cloud OAuth2 and JWT can be used as the authentication center. Spring Cloud OAuth2 is an open-source OAuth2 authentication and authorization framework based on SpringCloud. It provides a unified authentication and authorization solution to help developers implement single sign-on and authorization management in distributed systems. JWT stands for JSON Web Token, which, if taken literally, suggests a token based on the JSON format for network transmission. In reality, JWT is a compact claims format designed for transmission in space-constrained environments, such as HTTP authorization request header parameters and URI query parameters. JWT converts claims into JSON format, and this JSON content is applied as a payload in a JWS structure or as an (encrypted) raw string in a JWE structure. Claims are digitally signed or integrity-protected using a message authentication code (MAC) and / or encryption operations.
[0133] Permission rules document the process by which an identified object is confirmed to possess certain permissions, or whether it possesses certain permissions. For example, a certain interface allows viewing a list of all user data. This functionality is typically restricted to super administrators, not ordinary users. Therefore, the interface must perform a permission check on the user. Each user's permissions are typically maintained through a backend configuration table. During interface authentication, the interface checks the current user's permission list. If the user is a super administrator, access is successful; otherwise, an error message is returned.
[0134] The desensitized permission reflects the part that the third client does not have the right to view. By obtaining the sensitive field corresponding to the desensitized permission, the data corresponding to the sensitive field is the part that the third client does not have the right to view.
[0135] Sensitive fields such as natural person user name, ID number, mobile phone number, account password, electronic certificate, human resources and social security, tax, etc., need to be desensitized when displayed on the system.
[0136] The data corresponding to the sensitive fields in the call data is overwritten (for example, smeared or mosaiced), or replaced with specified characters (for example, "Zhang Laosan" is changed to "Zhang**"), so that the call data is converted into desensitized call data.
[0137] Furthermore, after outputting the desensitized call data to the third client, the method further includes:
[0138] receiving a full display request output by a third client, performing authority authentication on the third client according to the full display request, and obtaining an authentication result;
[0139] If it is determined that the authentication result is passed, the call data before desensitization corresponding to the call data after desensitization is obtained, and the call data before desensitization is output to the third client.
[0140] For example, if an authorized user needs to view the specific information of sensitive data, he or she needs to authenticate again before the original data can be displayed, for example:
[0141] A service hall system displays the user's ID card information, which is desensitized and displayed with asterisks in the middle 8 digits. If a third-party client user attempts to view the desensitized portion of the desensitized call data, a full authentication request is sent.
[0142] Obtain the standard password corresponding to the account information in the full authentication request from the preset password library. If the password information in the full authentication request is consistent with the standard password, a passed authentication result is generated; if the password information in the full authentication request is inconsistent with the standard password, a failed authentication result is generated.
[0143] Obtain the standard facial information corresponding to the identity information in the full authentication request from the preset face library. If the collected facial information in the full authentication request is consistent with the standard facial information, a passed authentication result is generated; if the collected facial information in the full authentication request is inconsistent with the standard facial information, a failed authentication result is generated.
[0144] Obtain the standard fingerprint information corresponding to the identity information in the full authentication request from the preset fingerprint library. If the collected fingerprint information in the full authentication request is consistent with the standard fingerprint information, a passed authentication result is generated; if the collected fingerprint information in the full authentication request is inconsistent with the standard fingerprint information, a failed authentication result is generated.
[0145] In the technical solution of this application, the collection, storage, use, processing, transmission, provision and disclosure of information such as financial data or user data involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0146] Example 2:
[0147] See also Figure 3 , the present application provides a data storage and transmission device 3, comprising:
[0148] The storage module 31 is configured to receive the government data output by the first client and store the government data in the first business system and the second business system associated with the first business system.
[0149] The transmission module 32 is configured to receive a service request from the second client, obtain government data from the first business system or the second business system according to the service request, and output the obtained government data to the second client according to a preset encrypted communication protocol; wherein the service request is used to instruct the first business system or the second business system to output the government data;
[0150] The calling module 33 is used to receive the calling request output by the third client, call the preset data interface according to the calling request to obtain the calling data, desensitize the calling data to obtain the desensitized calling data, and output the desensitized calling data to the third client; wherein, the calling request is used to instruct the first business system or the second business system to output the government data belonging to the preset calling range, the calling range defines the metadata of the government data that can be output to the third client, and the data interface is a computer interface for obtaining the government data from the first business system or the second business system.
[0151] Example 3:
[0152] To achieve the above-mentioned purpose, the present application further provides a computer device 4, comprising: a processor and a memory in communication with the processor; the memory storing computer-executable instructions;
[0153] The processor executes the computer-executable instructions stored in the memory to implement the above-mentioned data storage and transmission method, wherein the components of the data storage and transmission device can be dispersed in different computer devices. The computer device 4 can be a smart phone, tablet computer, laptop computer, desktop computer, rack server, blade server, tower server or cabinet server (including an independent server or a server cluster composed of multiple application servers) that executes the program. The computer device of this embodiment includes at least but is not limited to: a memory 41 and a processor 42 that can be interconnected through a system bus, such as Figure 4 It should be pointed out that Figure 4Only a computer device with components is shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead. In this embodiment, the memory 41 (i.e., readable storage medium) includes flash memory, a hard disk, a multimedia card, a card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic storage, a magnetic disk, an optical disk, etc. In some embodiments, the memory 41 can be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. In other embodiments, the memory 41 can also be an external storage device of the computer device, such as a plug-in hard disk equipped with the computer device, a smart memory card (SMC), a secure digital (SD) card, a flash card, etc. Of course, the memory 41 can also include both the internal storage unit of the computer device and its external storage device. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed on the computer device, such as the program code of the data storage and transmission device of Example 3. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or will be output. In some embodiments, the processor 42 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 42 is generally used to control the overall operation of the computer device. In this embodiment, the processor 42 is used to run the program code stored in the memory 41 or process data, such as running the data storage and transmission device to implement the data storage and transmission method of the above embodiment.
[0154] The above-mentioned integrated module implemented in the form of a software function module can be stored in a computer-readable storage medium. The above-mentioned software function module is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform some steps of the methods of each embodiment of the present application. It should be understood that the above-mentioned processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the application can be directly embodied as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor. The memory may include high-speed RAM memory, and may also include non-volatile storage NVM, such as at least one disk memory, or may be a USB flash drive, a mobile hard disk, a read-only memory, a disk or an optical disk, etc.
[0155] To achieve the above objectives, the present application also provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App application store, etc., on which computer-executable instructions are stored, and when the program is executed by the processor 42, the corresponding function is realized. The computer-readable storage medium of this embodiment is used to store computer-executable instructions that implement the data storage and transmission method, and when executed by the processor 42, the data storage and transmission method of the above embodiment is realized.
[0156] The storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0157] An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application-specific integrated circuit (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a main control device.
[0158] The present application provides a computer program product, including a computer program, which implements the above-mentioned data storage and transmission method when executed by a processor.
[0159] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0160] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0161] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A data storage and transmission method, characterized in that: include: receiving government affairs data output by the first client; and saving the government affairs data to a first business system and a second business system associated with the first business system respectively; receiving a service request output by a second client, obtaining government data from the first business system or the second business system according to the service request, and outputting the obtained government data to the second client according to a preset encrypted communication protocol; wherein the service request is used to instruct the first business system or the second business system to output the government data; Receive a call request output by a third client, call a preset data interface according to the call request to obtain call data, desensitize the call data to obtain desensitized call data, and output the desensitized call data to the third client; wherein, the call request is used to instruct the first business system or the second business system to output government data within a preset call range, the call range defines the metadata of the government data that can be output to the third client, and the data interface is a computer interface for obtaining government data from the first business system or the second business system.
2. The data storage and transmission method according to claim 1, wherein: Saving the government data to a first business system and a second business system associated with the first business system, respectively, includes: Encrypting the government data to obtain encrypted storage data, saving the encrypted storage data to a first business system, and calling the first business system to synchronize the encrypted storage data to a second business system associated with the first business system; or Output the government data to the first business system, call the first business system to encrypt the received government data to obtain encrypted storage data and save it, and call the first business system to output the encrypted storage data to a second business system associated with the first business system.
3. The data storage and transmission method according to claim 2, wherein: Encrypting the government data to obtain encrypted storage data, saving the encrypted storage data to a first business system, and calling the first business system to synchronize the encrypted storage data to a second business system associated with the first business system, including: Calling a preset encryption interface to encrypt the government data to obtain encrypted storage data; Saving the encrypted stored data to a first primary database in the first business system, and outputting the encrypted stored data in the first primary database to a first backup database in the first business system according to a preset first snapshot period; The encrypted stored data in the first master database is output to a second master database in a second business system, and the encrypted stored data in the second master database is output to a second backup database in the second business system according to a preset second snapshot period.
4. The data storage and transmission method according to claim 2, wherein: The encrypted stored data includes first encrypted stored data, second encrypted stored data, third encrypted stored data and fourth encrypted stored data; Outputting the government data to the first business system, calling the first business system to encrypt the received government data to obtain encrypted storage data and save the encrypted storage data, and calling the first business system to output the encrypted storage data to a second business system associated with the first business system, including: Outputting the government data to a first master database in the first business system, calling the first master database to encrypt the government data received by the first master database to obtain first encrypted storage data, and saving the first encrypted storage data in the first master database; calling the first primary database to decrypt the first encrypted stored data according to a preset third snapshot period to obtain first decrypted data, and outputting the first decrypted data to a first backup database in the first business system; calling the first backup database to encrypt the first decrypted data to obtain second encrypted storage data, and saving the second encrypted storage data to the first backup database; calling the first master database to decrypt the first encrypted stored data according to a preset fourth snapshot period to obtain second decrypted data, and outputting the second decrypted data to a second master database in the second business system; calling the second main database to encrypt the second decrypted data to obtain third encrypted storage data, and saving the third encrypted storage data to the second main database; calling the second primary database to decrypt the third encrypted stored data according to a preset fifth snapshot period to obtain third decrypted data, and outputting the third decrypted data to a second backup database in the second business system; The second backup database is called to encrypt the third decrypted data to obtain fourth encrypted storage data, and the fourth encrypted storage data is saved in the second backup database.
5. The data storage and transmission method according to claim 1, wherein: Acquiring government data from the first business system or the second business system according to the business request, and outputting the acquired government data to the second client according to a preset encryption communication protocol, including: Extracting a request field from the business request, and acquiring government affairs data from a first master database of the first business system according to the request field; If the government affairs data cannot be obtained from the first business system according to the request field, obtaining the government affairs data from the second business system; Encrypting the government data to obtain encrypted transmission data; The encrypted channel between the client and the second client is activated according to the encrypted communication protocol, and the encrypted channel is called to send the encrypted transmission data to the second client.
6. The data storage and transmission method according to claim 5, characterized in that: Encrypting the government data to obtain encrypted transmission data includes: Encrypting the government data using a preset transmission encryption algorithm to obtain encrypted data; Performing a calculation on the government data using a preset hash function to obtain a hash value; Aggregating the encrypted data and the hash value to obtain encrypted transmission data; The public key used for decrypting the encrypted data in the transmission confidentiality algorithm is sent to a preset third-party system. The third-party system is used to generate a certificate recording the public key according to the identity information of the second client, and send the certificate to the second client.
7. The data storage and transmission method according to claim 1, wherein: Calling a preset data interface according to the call request to obtain call data, performing desensitization processing on the call data to obtain desensitized call data, and outputting the desensitized call data to the third client, including: If it is determined that the call request contains token information, extracting the call permission in the call request, wherein the token information indicates that the third client has passed the authentication registration, and the call permission defines the range of data that the third client can call; If it is determined according to a preset permission rule that the calling permission matches the data interface, extracting a request field in the calling request, and calling the data interface according to the request field to obtain calling data; Extracting the sensitive permissions in the call request, determining the sensitive fields in the call data according to the sensitive permissions, and desensitizing the data corresponding to the sensitive fields in the call data to convert the call data into desensitized call data; The desensitized call data is output to the third client.
8. The data storage and transmission method according to claim 7, characterized in that: After outputting the desensitized call data to the third client, the method further includes: receiving a full display request output by a third client, performing authority authentication on the third client according to the full display request, and obtaining an authentication result; If it is determined that the authentication result is passed, the call data before desensitization corresponding to the call data after desensitization is obtained, and the call data before desensitization is transmitted to the third client.
9. A data storage and transmission device, characterized in that: include: A storage module, configured to receive government data output by the first client; and saving the government affairs data to a first business system and a second business system associated with the first business system respectively; a transmission module, configured to receive a service request output by a second client, obtain government data from the first business system or the second business system according to the service request, and output the obtained government data to the second client according to a preset encrypted communication protocol; wherein the service request is used to instruct the first business system or the second business system to output the government data; A calling module is used to receive a calling request output by a third client, call a preset data interface according to the calling request to obtain calling data, desensitize the calling data to obtain desensitized calling data, and output the desensitized calling data to the third client; wherein, the calling request is used to instruct the first business system or the second business system to output government data belonging to a preset calling range, the calling range defines the metadata of the government data that can be output to the third client, and the data interface is a computer interface for obtaining government data from the first business system or the second business system.
10. A computer device, characterized in that: include: a processor and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the data storage and transmission method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the data storage and transmission method according to any one of claims 1 to 8.
12. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the data storage and transmission method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Government affair data processing method and system based on block chain platform
CN114240399A
Predictive Model Data Stream Prioritization
US20230123322A1