Data interaction method and system for hiding real user identification

CN116866049BActive Publication Date: 2026-10-09DINGDANG KUAIYAO TECH GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310890229.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-20
Publication Date
2026-10-09
Estimated Expiration
2043-07-20

AI Technical Summary

Technical Problem

[0004]通过双向加密算法隐藏用户标识的方式,需要对应用服务和终端进行大量改造,并且对旧版本终端无法兼容,导致只能放弃旧版本终端用户

Benefits of technology

[0015] This invention deploys encryption and decryption algorithms in the entry gateway module of a web application service. The entry gateway module unifies the encryption and decryption of user identification information without requiring terminal modifications. This solves the problem of needing to modify numerous terminal applications to hide user identifiers, improving the efficiency of security strategy deployment and implementation, as well as compatibility with older devices, while ensuring information security. It is particularly effective in improving modification efficiency and compatibility with older terminals when updating encryption algorithms or keys. Furthermore, in existing two-way encryption schemes, the decryption program contained on the terminal can still be obtained by malicious actors through decompilation, posing a risk of leakage. In contrast, the entry gateway module in this embodiment is a key device on the service provider side, and its security protection performance far exceeds that of user terminal devices, effectively preventing decryption program leakage and further strengthening information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116866049B_ABST
    Figure CN116866049B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a kind of data interaction method and system for hiding real user identification. Among them, method includes: in response to the login request of terminal, the login module obtains the user identification plaintext of the terminal, and sends the user identification plaintext to entry gateway module;The entry gateway module is fed back to the terminal after the user identification plaintext is encrypted;When the terminal logs in successfully, the entry gateway module responds to the service request of the terminal, and the user identification ciphertext carried in the service request is decrypted into user identification plaintext by the entry gateway module, and is sent to the service module;The service module processes the service request according to the user identification plaintext, and feedback is sent to the terminal by processing result. The embodiment improves the deployment efficiency of security policy and the compatibility of old version equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network services, and in particular to a data interaction method and system for hiding the real user's identity. Background Technology

[0002] User information refers to personal data information saved or generated by users during the use of web application services, such as a user's shipping address and historical transaction orders. User identifier refers to a user's identity number, also known as an ID, which is a relatively unique code within the web application service. In the web application service system, all information data generated by users is associated with user identifiers in the database. During interaction with terminal applications (web pages, apps), web application services frequently need to obtain current user information through user identifiers, and user identifier names are agreed upon (parameter names and field names representing the user identifier during interaction, such as userid, uid, etc.).

[0003] If user identifiers are transmitted to the terminal in plaintext, there is a risk of exposing user information, making it easy to guess the generation pattern of user identifiers, obtain more user identifiers, and cause information leakage. Existing technology uses a two-way encryption algorithm to encrypt user identifiers. When using a user identifier, a decryption algorithm is used to obtain the user identifier, thereby achieving the effect of hiding the user identifier.

[0004] Hiding user identifiers using two-way encryption algorithms requires significant modifications to application services and terminals, and is incompatible with older terminal versions, necessitating the abandonment of users with older terminals. Furthermore, since both application services and terminals need to perform encryption and decryption, it's difficult for terminals to update simultaneously when the encryption algorithm or key needs updating. Summary of the Invention

[0005] This invention provides a data interaction method and system that hides the real user's identity, improving the deployment efficiency of security policies and compatibility with older devices.

[0006] In a first aspect, embodiments of the present invention provide a data interaction method for hiding the real user identifier, applied to a server, the server including a login module, an entry gateway module, and a business module;

[0007] The method includes:

[0008] In response to a login request from a terminal, the login module obtains the plaintext user identifier of the terminal and sends the plaintext user identifier to the ingress gateway module; the ingress gateway module encrypts the plaintext user identifier and sends it back to the terminal.

[0009] When the terminal successfully logs in, the ingress gateway module responds to the terminal's service request by decrypting the encrypted user identifier of the terminal carried in the service request into plaintext user identifier and sending it to the service module; the service module processes the service request according to the plaintext user identifier and feeds back the processing result to the terminal.

[0010] Secondly, embodiments of the present invention provide a data interaction method for hiding the real user identifier, applied to a terminal, comprising:

[0011] The user identifier ciphertext, generated by the server's ingress gateway module and stored in the terminal, is used to initiate a service request to the ingress gateway module.

[0012] Thirdly, embodiments of the present invention provide a data interaction system that hides the real user's identifier, comprising: a terminal and a server, wherein the server includes a login module, an entry gateway module, and a business module; wherein...

[0013] The terminal is used to send a login request; in response to the login request of the terminal, the login module is used to obtain the user identifier plaintext of the terminal and send the user identifier plaintext to the ingress gateway module; the ingress gateway module is used to encrypt the user identifier plaintext and then send it back to the terminal.

[0014] When the terminal successfully logs in, the terminal initiates a service request to the ingress gateway module based on the encrypted user identifier. The ingress gateway module responds to the service request by decrypting the encrypted user identifier carried in the service request into plaintext user identifier and sending it to the service module. The service module processes the service request based on the plaintext user identifier and feeds back the processing result to the terminal.

[0015] This invention deploys encryption and decryption algorithms in the entry gateway module of a web application service. The entry gateway module unifies the encryption and decryption of user identification information without requiring terminal modifications. This solves the problem of needing to modify numerous terminal applications to hide user identifiers, improving the efficiency of security strategy deployment and implementation, as well as compatibility with older devices, while ensuring information security. It is particularly effective in improving modification efficiency and compatibility with older terminals when updating encryption algorithms or keys. Furthermore, in existing two-way encryption schemes, the decryption program contained on the terminal can still be obtained by malicious actors through decompilation, posing a risk of leakage. In contrast, the entry gateway module in this embodiment is a key device on the service provider side, and its security protection performance far exceeds that of user terminal devices, effectively preventing decryption program leakage and further strengthening information security. Attached Figure Description

[0016] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0017] Figure 1 This is a schematic diagram of a data interaction system that hides the real user's identifier, provided in an embodiment of the present invention.

[0018] Figure 2 This is a flowchart of a data interaction method for hiding the real user identifier provided in an embodiment of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0020] In the description of this invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0021] In the description of this invention, it should also be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0022] This invention provides a data interaction method for hiding the real user's identifier. To illustrate this method, a system architecture supporting its implementation will be introduced first. Figure 1 This is a schematic diagram of a data interaction method system for hiding the real user identifier provided in an embodiment of the present invention, such as... Figure 1 As shown, the system includes a server and a terminal. The server includes a login module, an entry gateway module, and a service module. The login module provides login services to the terminal, completing login through account and password verification. The service module provides business services to successfully logged-in terminals, processing business data to provide the necessary services. The entry gateway module serves as the unified request entry point for the server, performing routing, load balancing, protocol conversion (HTTP --> RPC), security protection, rate limiting, and circuit breaking on terminal requests and service data. User terminals request services from the login module and service module through the entry gateway module, and the login module and service module provide services to the terminal through the entry gateway. Furthermore, the login module, entry gateway module, and service module can be deployed in different electronic devices or integrated within the same electronic device; this embodiment does not impose specific limitations.

[0023] Based on the above data interaction system, Figure 2 This is a flowchart illustrating a data interaction method for hiding the real user identifier provided in an embodiment of the present invention. This method achieves the purpose of hiding the user identifier without modifying the terminal; it only requires modification of the entry gateway module. Figure 2 As shown, when a user terminal initiates a login request, the method specifically includes the following steps:

[0024] S110. The user terminal initiates a login request to the ingress gateway module. The login request information may include the login username and password.

[0025] S120. In response to the login request from the terminal, the entry gateway module forwards the login request to the login module.

[0026] S130, The login module sends the user identifier plaintext of the terminal back to the entry gateway.

[0027] The login module's login service verifies the account and password information in the login request. If the verification succeeds, the login module creates a plaintext user identifier for the terminal, encapsulates it in the response result of the login request (the response body of an HTTP request), and sends the response result back to the ingress gateway module. If the verification fails, the login module returns a login information error. The user identifier is a unique identifier generated in the application service during the user creation process and stored in the login module.

[0028] S140. The entry gateway module encrypts the user identifier in plaintext and then sends it back to the terminal.

[0029] The entry gateway module extracts the plaintext of the user identifier from the response result according to the agreed user identifier name, encrypts it into ciphertext of the user identifier, modifies the plaintext of the user identifier in the response result into the ciphertext of the user identifier, and feeds back the modified response result to the terminal.

[0030] Furthermore, the process of encrypting the user identifier in plaintext by the ingress gateway module includes two optional implementation methods:

[0031] In a first optional implementation, the ingress gateway module performs an irreversible encryption algorithm on the plaintext user identifier and the timestamp to generate ciphertext user identifier, and stores the correspondence between the plaintext and ciphertext user identifiers for decryption. For example, the irreversible encryption algorithm is MD5. The ingress gateway module generates a string as the ciphertext user identifier based on the MD5 operation of the user identifier and timestamp, and stores the correspondence between the user identifier and the ciphertext user identifier in a Redis cache service (keeping one copy of the user identifier and one copy of the ciphertext user identifier as key and value respectively). Encryption is performed by retrieving the user identifier and the encrypted user identifier from the cache. The irreversible encryption algorithm may also include SHA1, HMAC, etc., but this embodiment does not impose specific limitations.

[0032] In a second optional implementation, the ingress gateway module performs a reversible encryption algorithm on the plaintext user identifier to generate ciphertext user identifier and stores the encryption key for decrypting the ciphertext user identifier. For example, the reversible encryption algorithm includes the DES algorithm. The ingress gateway module uses the DES encryption algorithm to encrypt the user identifier, and the DES encryption key is stored in the ingress gateway service. When a user logs in, the DES encryption algorithm is used to generate an encrypted user identifier. The reversible encryption algorithm may also include AES, 3DES, etc., but this embodiment does not impose specific limitations.

[0033] The various encryption strategies described above can be adjusted using Java's SPI (Service Provider Interface) mechanism. When an encryption strategy needs to be updated (e.g., due to key leakage or the need to upgrade the encryption scheme), the specific implementation of the encryption strategy is selected by modifying the backend configuration information of the gateway service. Optionally, each encryption strategy is stored in the encryption strategy library of the ingress gateway module, with different encryption strategies corresponding to different implementation classes. When an encryption strategy needs to be updated, the encryption strategy name configured in the gateway service backend is modified, and a corresponding implementation class is added to the encryption strategy library. The class name of the implementation class is the same as the modified encryption strategy name, and the content of the implementation class is the implementation steps of the modified encryption strategy. After addition, during the encryption strategy execution phase, the ingress gateway module automatically searches for the implementation class name in the encryption strategy library based on the modified encryption strategy name. When a class name matching the modified encryption strategy name is found, the implementation class is called, and the encryption operation in the class is automatically executed, completing the automatic switching of the encryption strategy. Furthermore, the access log statistics of the ingress gateway module can be used to determine whether the key has been leaked or needs to be updated. When the number of interface accesses increases significantly, or when the calls to related interfaces are disproportionate, it indicates that the key has been leaked or needs to be updated.

[0034] In one specific implementation, the current encryption policy configured in the ingress gateway module is the DES encryption algorithm. When the access volume of the gateway interface increases significantly, it is assumed that the DES key has been leaked, and the encryption policy needs to be updated. At this time, the ingress gateway module changes the name of the encryption policy in the background to AES (the policy to be updated can be set according to needs; AES is used as an example here), and adds an implementation class named AES to the encryption policy library. The class contains the implementation steps of the AES encryption algorithm. After the addition is completed, when the ingress gateway module receives the response result from the login module to the terminal, it extracts the user identifier plaintext from the response result, searches for an implementation class with the name AES in the encryption policy library, and calls the class to automatically execute the encryption steps within the class, completing the AES encryption operation on the user identifier plaintext, thereby realizing the update from the DES encryption policy to the AES encryption policy. S150, the user terminal stores the user identifier ciphertext locally, and the terminal login is successful.

[0035] Optionally, after the terminal successfully logs in for the first time, the ingress gateway module can cache the plaintext user identifier of the terminal; then S120 includes: in response to the terminal's login request, the ingress gateway module searches for the encrypted user identifier of the terminal in the cache; if found, it is directly fed back to the terminal without forwarding the login request to the login module. If not found, the login request is forwarded to the login module.

[0036] After successful login, when the user terminal initiates a service request, the method specifically includes the following steps:

[0037] S210. The terminal that has completed the login sends a service request to the ingress gateway module. The service request carries the encrypted user identifier of the terminal.

[0038] Specifically, the http-request parameter can include encrypted user identifiers, replacing plaintext user identifiers in unencrypted interactions, and using a pre-defined user identifier name as the parameter name.

[0039] S220. In response to the service request from the terminal, the ingress gateway module decrypts the encrypted user identifier into plaintext and sends it to the service module.

[0040] The ingress gateway module extracts the ciphertext of the user identifier of the terminal from the service request of the terminal; decrypts the ciphertext of the user identifier into plaintext of the user identifier using the decryption policy set in the network management system, modifies the ciphertext of the user identifier in the service request into the plaintext of the user identifier, and sends the modified service request to the backend service module.

[0041] In existing technologies, the data streams for login request messages, response messages, and business request messages are all read only once, and the corresponding data space is released immediately after reading. This embodiment, to deploy encryption and decryption strategies in the ingress gateway module, sets the business request messages as a repeatedly readable data stream and identifies the user through a specific field. This allows the ingress gateway module to automatically recognize the content of the user identifier field, perform encryption and decryption operations on that content, reread the original message, replace the original content of the user identifier field, and then send it again. This method modifies the original data stream reading and storage method, ensuring the implementation of gateway encryption and decryption.

[0042] Furthermore, the decryption strategy is relative to the gateway's decryption strategy during the user login process.

[0043] Depending on the encryption and decryption strategies configured in the gateway system, the process of the ingress gateway decrypting the ciphertext of the user identifier includes the following two optional implementation methods:

[0044] In the first optional implementation, the encryption and decryption strategy set by the ingress gateway module is based on an irreversible encryption algorithm. That is, the ciphertext of the user identifier carried in the service request of the terminal is generated using an irreversible encryption algorithm. In this case, the ingress gateway module decrypts the ciphertext of the user identifier back into the plaintext user identifier of the terminal according to the stored correspondence between plaintext and ciphertext user identifiers.

[0045] In the second optional implementation, the encryption and decryption strategy set by the ingress gateway module is based on a reversible encryption algorithm. That is, the ciphertext of the user identifier carried in the service request of the terminal is generated using a reversible encryption algorithm. In this case, the ingress gateway module decrypts the ciphertext of the user identifier into the plaintext of the user identifier of the terminal according to the stored encryption key.

[0046] Similar to encryption strategies, the various decryption strategies described above can also be adjusted using Java's SPI mechanism. The name of the encryption strategy should match the name of the decryption strategy. Optionally, each decryption strategy is stored in the decryption strategy library of the entry gateway module, with different implementation classes corresponding to different decryption strategies. When an encryption strategy is updated, a corresponding implementation class can be added to the decryption strategy library. The class name of this implementation class is the same as the name of the modified encryption strategy (i.e., the same as the name of the corresponding decryption strategy), and the content of the implementation class contains the implementation steps of the decryption strategy. After addition, during the execution phase of the decryption strategy, the entry gateway module automatically searches for the implementation class name in the decryption strategy library based on the modified encryption strategy name. When a class name matching the modified encryption strategy name is found, the implementation class is called, and the decryption operation within the class is automatically executed to complete the decryption strategy.

[0047] Automatic switching.

[0048] For ease of understanding, the specific implementation method of updating the DES encryption policy to the AES policy will still be used for explanation. In this specific implementation, after the ingress gateway module changes the encryption policy name from DES to AES, it can add another implementation class named AES to the decryption policy library. This class contains the implementation steps of the AES decryption algorithm. After adding this class, when the ingress gateway module receives a service request from the terminal, it extracts the user identifier ciphertext from the service request, searches for an implementation class with the name AES in the decryption policy library, and calls that class to automatically execute the decryption steps within the class, completing the AES decryption operation on the user identifier ciphertext. This also realizes the update from the DES decryption policy to the AES decryption policy.

[0049] In the prior art, when the encryption / decryption strategy needs to be updated, a new software version needs to be released to update all terminals. This embodiment replaces the terminal version update by switching the encryption / decryption strategy of the entry gateway module, which is beneficial to take into account different types of user terminals, reduce terminal operations, and improve user experience.

[0050] S230. The service module processes the service request in plaintext according to the user identifier and feeds back the processing result to the ingress gateway module.

[0051] The business module obtains the required user data based on the user identifier in plaintext, processes the business request based on the user data, and feeds back the processing result to the ingress gateway module.

[0052] S240, The ingress gateway module forwards the processing result to the terminal.

[0053] This embodiment deploys encryption and decryption algorithms in the entry gateway module of the web application service. User identification information is uniformly encrypted and decrypted through the entry gateway module without requiring terminal modifications. This solves the problem of needing to modify numerous terminal applications to hide user identifiers, while ensuring...

[0054] Under the premise of information security, this embodiment improves the efficiency of security protection strategy deployment and implementation, as well as compatibility with older devices. Especially when updating encryption algorithms or keys, it further enhances transformation efficiency and compatibility with older terminals. Specifically, to deploy the encryption / decryption process within the entry gateway module, this embodiment changes the traditional data reading strategy for request and response messages. Each message is set as a repeatedly readable data stream, and specific fields are defined to identify the user identifier. This allows the entry gateway module to automatically extract and modify the user identifier data before sending the message. Simultaneously, to update encryption / decryption strategies within the entry gateway module, different encryption / decryption strategy implementation classes are deployed on the entry gateway using the SPI mechanism. The strategy name is automatically searched and matched with the corresponding implementation class name, automatically switching between encryption / decryption strategies. This replaces the traditional method of ensuring information security by releasing new terminal versions, reducing terminal operations and improving user experience. Furthermore, in existing two-way encryption schemes, since the terminal contains decryption programs, they can still be obtained by criminals through decompilation, and there is still a risk of leakage. In contrast, the entry gateway module in this embodiment is a key device on the service provider side, and its security protection performance far exceeds that of the user terminal device. It can better prevent the leakage of decryption programs and further enhance information security.

[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention.

Claims

1. A data interaction method for hiding the real user's identifier, characterized in that, Applied to the server side, the server side includes a login module, an entry gateway module, and a business module; The method includes: In response to a login request from a terminal, the login module obtains the plaintext user identifier of the terminal and sends the plaintext user identifier to the ingress gateway module; the ingress gateway module encrypts the plaintext user identifier and sends it back to the terminal. When the terminal successfully logs in, the ingress gateway module responds to the terminal's service request by decrypting the encrypted user identifier of the terminal carried in the service request into plaintext user identifier and sending it to the service module; the service module processes the service request according to the plaintext user identifier and feeds back the processing result to the terminal. Among them, when judging whether the key has been leaked or needs to be updated based on the access log statistics of the ingress gateway module, when the number of interface accesses increases significantly or the calls to related interfaces are disproportionate, it indicates that the key has been leaked or needs to be updated. The specific implementation of the encryption strategy is selected by modifying the backend configuration information of the gateway service. Each encryption strategy is stored in the encryption strategy library of the ingress gateway module, and different encryption strategies correspond to different implementation classes. When an encryption strategy needs to be updated, the encryption strategy name configured in the gateway service backend is modified, and a corresponding implementation class is added to the encryption strategy library. The class name of the implementation class is the same as the modified encryption strategy name, and the content of the implementation class is the implementation steps of the modified encryption strategy. After the addition is completed, in the execution phase of the encryption strategy, the ingress gateway module automatically searches for the implementation class name in the encryption strategy library based on the modified encryption strategy name. When a class name that matches the modified encryption strategy name is found, the implementation class is called, and the encryption operation in the class is automatically executed, thus completing the automatic switching of the encryption strategy. Each decryption strategy is stored in the decryption strategy library of the ingress gateway module, and different decryption strategies correspond to different implementation classes. When an encryption strategy is updated, the corresponding implementation class of the decryption strategy is added to the decryption strategy library. The class name of the implementation class is the same as the name of the modified encryption strategy, and the content of the implementation class is the implementation steps of the decryption strategy. After the addition is completed, in the execution phase of the decryption strategy, the ingress gateway module automatically searches for the implementation class name in the decryption strategy library based on the name of the modified encryption strategy. When a class name that matches the name of the modified encryption strategy is found, the implementation class is called, and the decryption operation within the class is automatically executed, thus completing the automatic switching of the decryption strategy.

2. The data interaction method according to claim 1, characterized in that, In response to a login request from a terminal, the login module obtains the plaintext user identifier of the terminal and sends the plaintext user identifier to the ingress gateway module, including: The entry gateway module responds to the terminal's login request by forwarding the login request to the login module; The login module verifies the username and password in the login request; If the verification is successful, the login module sends the user identifier plaintext of the terminal to the entry gateway.

3. The data interaction method according to claim 1, characterized in that, The login module obtains the user identifier plaintext of the terminal and sends the user identifier plaintext to the ingress gateway module, including: The login module creates a plaintext user identifier for the terminal, encapsulates it in the response to the login request, and feeds the response back to the ingress gateway module.

4. The data interaction method according to claim 3, characterized in that, The ingress gateway module encrypts the plaintext user identifier and sends it back to the terminal, including: the ingress gateway module extracts the plaintext user identifier from the response result, encrypts it into ciphertext user identifier, modifies the plaintext user identifier in the response result into the ciphertext user identifier, and sends the modified response result back to the terminal.

5. The data interaction method according to claim 1, characterized in that, The ingress gateway module encrypts the user identifier in plaintext and then sends it back to the terminal, including: The ingress gateway module performs an irreversible encryption algorithm on the plaintext user identifier and the timestamp to generate ciphertext user identifier, and stores the correspondence between the plaintext and ciphertext user identifiers for use in decrypting the ciphertext user identifier; or The ingress gateway module performs a reversible encryption algorithm on the plaintext user identifier to generate ciphertext for identification and stores the encryption key for decrypting the ciphertext user identifier.

6. The data interaction method according to claim 1, characterized in that, In response to a service request from the terminal, the ingress gateway module decrypts the encrypted user identifier of the terminal carried in the service request into plaintext user identifier and sends it to the service module, including: The ingress gateway module extracts the terminal's ciphertext user identifier from the terminal's service request, decrypts it into plaintext user identifier, modifies the ciphertext user identifier in the service request into the plaintext user identifier, and sends the modified service request to the service module.

7. The data interaction method according to claim 1, characterized in that, The service module processes the service request in plaintext based on the user identifier and returns the processing result to the terminal, including: The business module obtains user data based on the user identifier in plaintext, processes the business request based on the user data, and feeds back the processing result to the ingress gateway module. The ingress gateway module forwards the processing result to the terminal.

8. The data interaction method according to claim 1, characterized in that, In response to a service request from the terminal, the ingress gateway module decrypts the encrypted user identifier of the terminal carried in the service request into plaintext user identifier, including: When the user identifier ciphertext carried in the service request of the terminal is generated using an irreversible encryption algorithm, the ingress gateway module decrypts the user identifier ciphertext into the user identifier plaintext of the terminal according to the stored correspondence between user identifier plaintext and user identifier ciphertext. If the user identifier ciphertext carried in the service request of the terminal is generated using a reversible encryption algorithm, the ingress gateway module decrypts the user identifier ciphertext into the user identifier plaintext of the terminal based on the stored encryption key.

9. A data interaction system that hides the real user's identifier, characterized in that, include: The terminal and server are described, with the server including a login module, an entry gateway module, and a business module; wherein, The terminal is used to send a login request; in response to the login request of the terminal, the login module is used to obtain the user identifier plaintext of the terminal and send the user identifier plaintext to the ingress gateway module; the ingress gateway module is used to encrypt the user identifier plaintext and then send it back to the terminal. When the terminal successfully logs in, the terminal initiates a service request to the ingress gateway module based on the encrypted user identifier. The ingress gateway module responds to the service request by decrypting the encrypted user identifier carried in the service request into plaintext user identifier and sending it to the service module. The service module processes the service request based on the plaintext user identifier and feeds back the processing result to the terminal. Among them, when judging whether the key has been leaked or needs to be updated based on the access log statistics of the ingress gateway module, when the number of interface accesses increases significantly or the calls to related interfaces are disproportionate, it indicates that the key has been leaked or needs to be updated. The specific implementation of the encryption strategy is selected by modifying the backend configuration information of the gateway service. Each encryption strategy is stored in the encryption strategy library of the ingress gateway module, and different encryption strategies correspond to different implementation classes. When an encryption strategy needs to be updated, the encryption strategy name configured in the gateway service backend is modified, and a corresponding implementation class is added to the encryption strategy library. The class name of the implementation class is the same as the modified encryption strategy name, and the content of the implementation class is the implementation steps of the modified encryption strategy. After the addition is completed, in the execution phase of the encryption strategy, the ingress gateway module automatically searches for the implementation class name in the encryption strategy library based on the modified encryption strategy name. When a class name that matches the modified encryption strategy name is found, the implementation class is called, and the encryption operation in the class is automatically executed, thus completing the automatic switching of the encryption strategy. Each decryption strategy is stored in the decryption strategy library of the ingress gateway module, and different decryption strategies correspond to different implementation classes. When an encryption strategy is updated, the corresponding implementation class of the decryption strategy is added to the decryption strategy library. The class name of the implementation class is the same as the name of the modified encryption strategy, and the content of the implementation class is the implementation steps of the decryption strategy. After the addition is completed, in the execution phase of the decryption strategy, the ingress gateway module automatically searches for the implementation class name in the decryption strategy library based on the name of the modified encryption strategy. When a class name that matches the name of the modified encryption strategy is found, the implementation class is called, and the decryption operation within the class is automatically executed, thus completing the automatic switching of the decryption strategy.

Citation Information

Patent Citations

  • Hidden user identifier processing method and device

    CN111431839A

  • System access method, computer device and computer program product

    CN116389063A