A data security access method, system, device and storage medium
By performing identity checksum permission verification on database access, and using encryption and decryption and data mapping processing, the problem of insufficient security of existing database access methods is solved, and high-security data access management is achieved.
Patent Information
- Application Number
- CN202311641039.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2043-12-04
AI Technical Summary
The security of existing database access methods is not high enough, easy to crack, and it is easy to lose important data in the database due to identity information leakage.
By performing identity verification on the data requesting end, determining the permission basic code and recalling the encryption public key to send it to the data requesting end, receiving feedback access verification encrypted data packets for private key decryption, obtaining access request information, permission allocation number and initial verification code, performing permission verification and data mapping processing, and finally using the permission verification code to verify the request verification code to ensure the compliance and security of data access.
It realizes safe and reliable data access management, fully verifies the data access compliance of the data requesting end, improves the security of data access, and prevents non-authorized personnel from stealing important data in the database.
Smart Images

Figure CN117540405B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security technology, and specifically relates to a data security access method, system, device and storage medium. Background Art
[0002] With the development of computer technology, the application of databases has become more and more extensive. Databases usually store some important and private information, such as a large amount of customer data in a bank's database, and a large amount of sales data in a product sales company's database. Therefore, effectively ensuring the security of the corresponding data in the database has become the main work point of database security management. At present, the more common database access supervision method is to verify the identity information of the requester. After the identity authentication is passed, the requester can access the database to obtain the corresponding data. This data access method is not secure enough, easy to crack, and easy to cause important data in the database to be lost due to identity information leakage. Therefore, a more secure and reliable data access implementation method is needed to ensure the security of database data resources. Summary of the invention
[0003] The purpose of the present invention is to provide a data security access method, system, device and storage medium to solve the above problems existing in the prior art.
[0004] In order to achieve the above object, the present invention adopts the following technical solutions:
[0005] In a first aspect, a data security access method is provided, comprising:
[0006] Obtain the identity verification information sent by the data requester;
[0007] Perform identity verification on the data request end according to the identity verification information. After the identity verification passes, retrieve the preset encryption public key and determine the corresponding permission basic code according to the identity verification information;
[0008] Send the encrypted public key to the data request end, and receive the access verification encrypted data packet fed back by the data request end, wherein the access verification encrypted data packet is obtained by the data request end using the encrypted public key to asymmetrically encrypt the access request information, the authority allocation number and the initial verification code;
[0009] Use the preset decryption private key to asymmetrically decrypt the access verification encrypted data packet to obtain the access request information, permission allocation number and initial verification code;
[0010] Determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine the number of fixed digits according to the permission allocation number;
[0011] Extracting numbers corresponding to fixed digits from the initial verification code as additional numbers, and performing data conversion processing on the initial verification code according to a set data conversion rule to obtain a conversion verification code;
[0012] According to the set data mapping rules, data mapping processing is performed on each bit of the conversion verification code to obtain a mapping verification code;
[0013] Add the permission number to the end of the permission basic code to obtain the permission verification code, and add each additional number to the end of the mapping verification code to obtain each request verification code;
[0014] Each request verification code is verified using the permission verification code. If a request verification code is consistent with the permission verification code, the database is accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end.
[0015] In a possible design, the identity verification information includes a user identity number, and the identity verification is performed on the data request end according to the identity verification information. After the identity verification passes, the preset encryption public key is retrieved, and the corresponding permission basic code is determined according to the identity verification information matching, including:
[0016] Substitute the user ID into the preset user registry to search and determine whether the user ID exists in the user registry. If so, the identity authentication is successful, otherwise the identity authentication fails;
[0017] After the identity verification is passed, the preset encryption public key is retrieved, and the permission basic code corresponding to the user identity number is matched and searched in the user registration table, which contains several user identity numbers and the permission basic code corresponding to each user identity number.
[0018] In one possible design, the access verification encrypted data packet is obtained by the data request end using an encrypted public key to asymmetrically encrypt the access request information, the permission allocation number and the initial verification code based on the RSA algorithm, and the access verification encrypted data packet is asymmetrically decrypted using a preset decryption private key to obtain the access request information, the permission allocation number and the initial verification code, including: using a preset decryption private key and asymmetrically decrypting the access verification encrypted data packet based on the RSA algorithm to obtain the access request information, the permission allocation number and the initial verification code.
[0019] In a possible design, determining the corresponding permission type according to the access request information, matching the corresponding permission number according to the permission type, and determining each fixed digit according to the permission allocation number include:
[0020] Extracting the request type number from the access request information, substituting the request type number into a preset permission classification table, matching and determining the permission type corresponding to the request type number, and determining the corresponding permission number according to the matched permission type, wherein the permission classification table includes a plurality of permission types, each permission type is associated with a corresponding request type number and a permission number;
[0021] The permission allocation number is segmented according to the set segmentation digits to obtain the segmented fixed digits.
[0022] In a possible design, performing data conversion processing on the initial verification code according to a set data conversion rule to obtain a converted verification code includes:
[0023] Extract the first digit of the initial verification code as the first parameter, extract the last digit of the initial verification code as the second parameter, and use the remaining part of the initial verification code after removing the first digit and the last digit as the secondary verification code;
[0024] Add the first parameter to each odd-digit number of the secondary verification code, and obtain the corresponding addition result as the converted odd-digit number. If the addition result is a two-digit number, take the unit digit of the addition result as the converted odd-digit number. Subtract the second parameter from each even-digit number of the secondary verification code, and obtain the corresponding subtraction result as the converted even-digit number. If an even-digit number is less than the second parameter, add 10 to the even-digit number and then subtract the second parameter to obtain the corresponding subtraction result as the converted even-digit number.
[0025] Combine the converted odd-digit numbers and the converted even-digit numbers in sequence to obtain a conversion verification code.
[0026] In a possible design, performing data conversion processing on the initial verification code according to a set data conversion rule to obtain a converted verification code includes:
[0027] Extract the first digit of the initial verification code as the first parameter, extract the last digit of the initial verification code as the second parameter, and use the remaining part of the initial verification code after removing the first digit and the last digit as the secondary verification code;
[0028] Add the first parameter to each odd-digit number of the secondary verification code, and obtain the corresponding addition result as the converted odd-digit number. If the addition result is a two-digit number, take the unit digit of the addition result as the converted odd-digit number, and subtract the second parameter from each even-digit number of the secondary verification code, and obtain the absolute value of the corresponding subtraction result as the converted even-digit number;
[0029] Combine the converted odd-digit numbers and the converted even-digit numbers in sequence to obtain a conversion verification code.
[0030] In a possible design, performing data mapping processing on each bit of data in the conversion verification code according to a set data mapping rule to obtain a mapping verification code includes:
[0031] Each bit of data in the conversion verification code is substituted into a preset data mapping table for association matching, the mapping data corresponding to each bit of data in the conversion verification code is determined, and the mapping data corresponding to each bit of data in the conversion verification code is extracted and sequentially combined to obtain a mapping verification code. The data mapping table contains a number of conversion verification code data, and each conversion verification code data is associated with corresponding mapping data.
[0032] In a second aspect, a data security access system is provided, including an acquisition unit, a verification unit, a transceiver unit, a decryption unit, a determination unit, a conversion unit, a mapping unit, a combination unit and an execution unit, wherein:
[0033] An acquisition unit, used to acquire identity verification information sent by a data requesting end;
[0034] The verification unit is used to perform identity verification on the data request end according to the identity verification information. After the identity verification is passed, the preset encryption public key is retrieved and the corresponding permission basic code is determined according to the identity verification information matching;
[0035] A transceiver unit is used to send the encrypted public key to the data request end, and receive the access verification encrypted data packet fed back by the data request end, wherein the access verification encrypted data packet is obtained by the data request end using the encrypted public key to asymmetrically encrypt the access request information, the authority allocation number and the initial verification code;
[0036] A decryption unit, used to perform asymmetric decryption processing on the access verification encrypted data packet using a preset decryption private key to obtain access request information, permission allocation number and initial verification code;
[0037] A determination unit, used to determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine each fixed digit according to the permission allocation number;
[0038] The conversion unit is used to extract the numbers corresponding to the fixed digits from the initial verification code as the additional numbers, and perform data conversion processing on the initial verification code according to the set data conversion rules to obtain the conversion verification code;
[0039] A mapping unit, used to perform data mapping processing on each bit of data in the conversion verification code according to a set data mapping rule to obtain a mapping verification code;
[0040] A combination unit, used for adding the permission number to the end of the permission basic code to obtain the permission verification code, and adding each additional number to the end of the mapping verification code to obtain each request verification code;
[0041] The execution unit is used to verify each request verification code using the permission verification code. If a request verification code is consistent with the permission verification code, the database is accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end.
[0042] In a third aspect, a data security access device is provided, comprising:
[0043] A memory for storing instructions;
[0044] A processor is used to read the instructions stored in the memory and execute any one of the methods described in the first aspect according to the instructions.
[0045] In a fourth aspect, a computer-readable storage medium is provided, wherein instructions are stored on the computer-readable storage medium, and when the instructions are executed on a computer, the computer is caused to execute any one of the methods described in the first aspect. In addition, a computer program product containing instructions is provided, and when the instructions are executed on a computer, the computer is caused to execute any one of the methods described in the first aspect.
[0046] Beneficial effect: The present invention verifies the identity of the data request end, determines the authority base code, retrieves the encrypted public key and sends it to the data request end, then receives the access verification encrypted data packet fed back by the data request end and decrypts it with the private key, obtains the access request information, the authority allocation number and the initial verification code, and then determines the authority number according to the access request information, uses the authority allocation number and the initial verification code to obtain the mapping verification code and each additional number, combines the authority number with the authority base code to obtain the authority verification code, combines each additional number with the mapping verification code to obtain each request verification code, and finally verifies each request verification code using the authority verification code. If the verification is successful, the database is accessed according to the access request information to retrieve the corresponding access data and transmit it to the data request end, so as to achieve safe and reliable data access management. The present invention can fully verify the data access compliance of the data request end through the associated identity verification and authority verification dual verification method, as well as the encryption, decryption, conversion and mapping of the corresponding authority verification data, effectively improve the security of data access, ensure the security of the accessed data in the database, and prevent it from being stolen by unauthorized personnel. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0048] Figure 1 This is a schematic diagram of the steps of the method in Example 1 of the present invention;
[0049] Figure 2 This is a schematic diagram of the structure of the system in Example 2 of the present invention;
[0050] Figure 3 This is a schematic diagram of the structure of the device in Example 3 of the present invention. DETAILED DESCRIPTION
[0051] It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention. The specific structures and functional details disclosed herein are only used to describe the exemplary embodiments of the present invention. However, the present invention can be embodied in many alternative forms, and it should not be understood that the present invention is limited to the embodiments set forth herein.
[0052] It should be understood that, unless otherwise clearly specified and limited, the term "connection" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the embodiments can be understood according to specific circumstances.
[0053] In the following description, certain details are provided to facilitate a complete understanding of the example embodiments. However, it will be appreciated by those of ordinary skill in the art that the example embodiments may be implemented without these certain details. For example, the system may be shown in a block diagram to avoid obscuring the example with unnecessary details. In other embodiments, well-known processes, structures, and techniques may not be shown in unnecessary detail to avoid obscuring the embodiments.
[0054] Embodiment 1:
[0055] This embodiment provides a data security access method, which can be applied to a corresponding data security access server, such as Figure 1 As shown, the method comprises the following steps:
[0056] S1. Obtain the identity verification information sent by the data requester.
[0057] In specific implementation, if a user wants to access corresponding data in the database, he must first send identity verification information to the server through the data request end. The identity verification information includes the user identity number. After the server obtains the identity verification information sent by the data request end, it performs subsequent identity verification.
[0058] S2. Perform identity verification on the data request end according to the identity verification information. After the identity verification passes, retrieve the preset encryption public key, and determine the corresponding permission basic code according to the identity verification information.
[0059] In specific implementation, the server can substitute the user identity number into the preset user registration table for search, and determine whether the user identity number exists in the user registration table. If it exists, the identity authentication is passed, otherwise the identity authentication fails. After the identity verification is passed, the server retrieves the preset encryption public key and matches and searches for the permission basic code corresponding to the user identity number in the user registration table. The user registration table contains several user identity numbers and the permission basic code corresponding to each user identity number.
[0060] S3. Send the encrypted public key to the data request end, and receive the access verification encrypted data packet fed back by the data request end, wherein the access verification encrypted data packet is obtained by the data request end using the encrypted public key to asymmetrically encrypt the access request information, the authority allocation number and the initial verification code.
[0061] In specific implementation, the server sends the encrypted public key to the data request end. After receiving the encrypted public key, the data request end uses the encrypted public key to perform asymmetric encryption based on the RSA algorithm on the access request information, the authority allocation number and the initial verification code to obtain the access verification encrypted data packet, and then feeds the access verification encrypted data packet back to the server. The access request information includes the database address to be accessed, the request type number, the identifier of the requested data, etc. The authority allocation number and the initial verification code are saved by the user of the data request end and are assigned to the user by the server when the user is initially registered and the authority is configured.
[0062] S4. Use the preset decryption private key to asymmetrically decrypt the access verification encrypted data packet to obtain the access request information, the authority allocation number and the initial verification code.
[0063] In specific implementation, after obtaining the access verification encrypted data packet, the server uses a preset decryption private key and performs asymmetric decryption processing on the access verification encrypted data packet based on the RSA algorithm to obtain access request information, permission allocation number and initial verification code.
[0064] S5. Determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine the number of fixed digits according to the permission allocation number.
[0065] In specific implementation, the server extracts the request type number from the access request information. The request type number corresponds to the data request type, such as read data, read data after modification, etc. The request type number is substituted into the preset permission classification table, and the permission type corresponding to the request type number is matched and determined. The corresponding permission number is determined according to the matched permission type. The permission classification table contains several permission types, and each permission type is associated with a corresponding request type number and permission number. At the same time, the permission allocation number is segmented according to the set segmentation digits to obtain the segmented fixed digits.
[0066] S6. Extract the numbers corresponding to the fixed digits from the initial verification code as the additional numbers, and perform data conversion processing on the initial verification code according to the set data conversion rule to obtain the converted verification code.
[0067] In specific implementation, after determining each fixed digit, the server extracts the numbers corresponding to each fixed digit from the initial verification code as additional numbers. For example, if the fixed digit is the 7th digit and the 7th digit in the initial verification code is 1, 1 is extracted as an additional number, and so on.
[0068] When performing data conversion processing on the initial verification code, the first digit of the initial verification code can be extracted as the first parameter, the last digit of the initial verification code can be extracted as the second parameter, and the remaining part of the initial verification code after removing the first digit and the last digit is used as the secondary verification code; each odd digit of the secondary verification code is added to the first parameter respectively, and the corresponding addition result is obtained as the converted odd digit. If the addition result is a two-digit number, the unit digit of the addition result is taken as the converted odd digit. For example, if the odd digit is 7, the first parameter is 7, and the addition result is 14, 4 is taken as the converted odd digit. , and so on; subtract the second parameter from each even-digit digit of the secondary verification code, and obtain the corresponding subtraction result as the converted even-digit digit. If an even-digit digit is less than the second parameter, add 10 to the even-digit digit and then subtract the second parameter to obtain the corresponding subtraction result as the converted even-digit digit. For example, if the even-digit digit is 2 and the second parameter is 9, and 2 is less than 9, then add 2 to 10 to obtain 12, and then subtract 9 from 12 to obtain the subtraction result 3 as the converted even-digit digit, and so on; combine each converted odd-digit digit and each converted even-digit digit in sequence to obtain a conversion verification code.
[0069] Alternatively, extract the first digit of the initial verification code as the first parameter, extract the last digit of the initial verification code as the second parameter, and use the remaining part of the initial verification code after removing the first digit and the last digit as the secondary verification code; add the first parameter to each odd digit of the secondary verification code, and obtain the corresponding addition result as the converted odd digit. If the addition result is a two-digit number, take the unit digit of the addition result as the converted odd digit; subtract the second parameter from each even digit of the secondary verification code, and obtain the absolute value of the corresponding subtraction result as the converted even digit; combine each converted odd digit and each converted even digit in sequence to obtain a conversion verification code. The two data conversion processing methods can be selected according to actual needs.
[0070] S7. Perform data mapping processing on each bit of data in the conversion verification code according to the set data mapping rule to obtain a mapping verification code.
[0071] In specific implementation, the server substitutes each bit of data in the conversion verification code into a preset data mapping table for association matching, determines the mapping data corresponding to each bit of data in the conversion verification code, extracts the mapping data corresponding to each bit of data in the conversion verification code, and sequentially combines them to obtain the mapping verification code. The data mapping table contains a number of conversion verification code data, and each conversion verification code data is associated with corresponding mapping data. For example, if the first bit of the conversion verification code is 1, in the data mapping table, the mapping data associated with data 1 is A, then the first bit of the obtained mapping verification code is A, and so on.
[0072] S8. Add the permission number to the end of the permission basic code to obtain the permission verification code, and add each additional number to the end of the mapping verification code to obtain each request verification code.
[0073] In specific implementation, after determining the basic permission code, permission number, mapping verification code and additional numbers, the server adds the permission number to the end of the basic permission code to obtain the permission verification code. At the same time, the server adds each additional number to the end of the mapping verification code to obtain each request verification code.
[0074] S9. Use the permission verification code to verify each request verification code. If a request verification code is consistent with the permission verification code, access the database according to the access request information, and retrieve the corresponding access data in the database and transmit it to the data request end.
[0075] During specific implementation, the server compares each request verification code with the permission verification code one by one. If there is a request verification code that is verified to be consistent with the permission verification code, it is determined that the permission verification passes. At this time, the database can be accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end to achieve a closed-loop data access operation for the data request end.
[0076] The method of this embodiment can fully verify the compliance of data access of the data request end through a dual verification method of associative identity verification and permission verification, as well as processing such as encryption, decryption, conversion, and mapping of corresponding permission verification data, effectively improve the security of data access, ensure the security of the data accessed in the database, and prevent it from being stolen by unauthorized personnel.
[0077] Embodiment 2:
[0078] This embodiment provides a data security access system, as Figure 2 shown, including an acquisition unit, a verification unit, a transceiver unit, a decryption unit, a determination unit, a conversion unit, a mapping unit, a combination unit, and an execution unit, where:
[0079] The acquisition unit is used to acquire the identity verification information sent by the data request end;
[0080] The verification unit is used to perform identity verification on the data request end according to the identity verification information. After the identity verification passes, the preset encryption public key is retrieved, and the corresponding permission base code is matched and determined according to the identity verification information;
[0081] The transceiver unit is used to send the encryption public key to the data request end and receive the access verification encrypted data packet fed back by the data request end. The access verification encrypted data packet is obtained by the data request end performing asymmetric encryption on the access request information, the permission allocation number, and the initial verification code using the encryption public key;
[0082] The decryption unit is used to perform asymmetric decryption processing on the access verification encrypted data packet using the preset decryption private key to obtain the access request information, the permission allocation number, and the initial verification code;
[0083] The determination unit is used to determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine each fixed number of digits according to the permission allocation number;
[0084] The conversion unit is used to extract the numbers corresponding to each fixed number of digits from the initial verification code as each additional number, and perform data conversion processing on the initial verification code according to the set data conversion rule to obtain the conversion verification code;
[0085] A mapping unit, used to perform data mapping processing on each bit of data in the conversion verification code according to a set data mapping rule to obtain a mapping verification code;
[0086] A combination unit, used for adding the permission number to the end of the permission basic code to obtain the permission verification code, and adding each additional number to the end of the mapping verification code to obtain each request verification code;
[0087] The execution unit is used to verify each request verification code using the permission verification code. If a request verification code is consistent with the permission verification code, the database is accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end.
[0088] Embodiment 3:
[0089] This embodiment provides a data security access device, such as Figure 3 As shown, at the hardware level, it includes:
[0090] Data interface, used to establish data connection between the processor and the data request end and the database;
[0091] A memory for storing instructions;
[0092] The processor is used to read the instructions stored in the memory and execute the data security access method in Example 1 according to the instructions.
[0093] Optionally, the device also includes an internal bus. The processor, the memory and the data interface can be interconnected through the internal bus, and the internal bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0094] The memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) and / or first in last out (FILO), etc. The processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
[0095] Embodiment 4:
[0096] This embodiment provides a computer-readable storage medium, on which instructions are stored, and when the instructions are executed on a computer, the computer executes the data security access method in Embodiment 1. The computer-readable storage medium refers to a carrier for storing data, which may include but is not limited to a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash drive, and / or a memory stick, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems.
[0097] This embodiment also provides a computer program product including instructions, which, when executed on a computer, enables the computer to execute the data security access method in Embodiment 1. The computer may be a general-purpose computer, a special-purpose computer, a computer network or other programmable systems.
[0098] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A data security access method, It is characterized in that include: Obtain the identity verification information sent by the data requester; Perform identity verification on the data request end according to the identity verification information. After the identity verification passes, retrieve the preset encryption public key and determine the corresponding permission basic code according to the identity verification information; Send the encrypted public key to the data request end, and receive the access verification encrypted data packet fed back by the data request end, wherein the access verification encrypted data packet is obtained by the data request end using the encrypted public key to asymmetrically encrypt the access request information, the authority allocation number and the initial verification code; Use the preset decryption private key to asymmetrically decrypt the access verification encrypted data packet to obtain the access request information, permission allocation number and initial verification code; Determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine the number of fixed digits according to the permission allocation number; Extracting numbers corresponding to fixed digits from the initial verification code as additional numbers, and performing data conversion processing on the initial verification code according to a set data conversion rule to obtain a conversion verification code; According to the set data mapping rules, data mapping processing is performed on each bit of the conversion verification code to obtain a mapping verification code; Add the permission number to the end of the permission basic code to obtain the permission verification code, and add each additional number to the end of the mapping verification code to obtain each request verification code; Each request verification code is verified using the permission verification code. If a request verification code is consistent with the permission verification code, the database is accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end.
2. A data security access method according to claim 1, It is characterized in that The identity verification information includes a user identity number, and the identity verification is performed on the data request end according to the identity verification information. After the identity verification passes, the preset encryption public key is retrieved, and the corresponding permission basic code is determined according to the identity verification information matching, including: Substitute the user ID into the preset user registry to search and determine whether the user ID exists in the user registry. If so, the identity authentication is successful, otherwise the identity authentication fails; After the identity verification is passed, the preset encryption public key is retrieved, and the permission basic code corresponding to the user identity number is matched and searched in the user registration table, which contains several user identity numbers and the permission basic code corresponding to each user identity number.
3. A data security access method according to claim 1, It is characterized in that The access verification encrypted data packet is obtained by the data request end using the encryption public key to asymmetrically encrypt the access request information, the permission allocation number and the initial verification code based on the RSA algorithm, and the access verification encrypted data packet is asymmetric decrypted using a preset decryption private key to obtain the access request information, the permission allocation number and the initial verification code, including: using a preset decryption private key and asymmetric decrypting the access verification encrypted data packet based on the RSA algorithm to obtain the access request information, the permission allocation number and the initial verification code.
4. A data security access method according to claim 1, It is characterized in that The method of determining the corresponding permission type according to the access request information, matching the corresponding permission number according to the permission type, and determining the number of fixed digits according to the permission allocation number includes: Extracting the request type number from the access request information, substituting the request type number into a preset permission classification table, matching and determining the permission type corresponding to the request type number, and determining the corresponding permission number according to the matched permission type, wherein the permission classification table includes a plurality of permission types, each permission type is associated with a corresponding request type number and a permission number; The permission allocation number is segmented according to the set segmentation digits to obtain the segmented fixed digits.
5. A data security access method according to claim 1, It is characterized in that The step of performing data conversion processing on the initial verification code according to the set data conversion rule to obtain a converted verification code includes: Extract the first digit of the initial verification code as the first parameter, extract the last digit of the initial verification code as the second parameter, and use the remaining part of the initial verification code after removing the first digit and the last digit as the secondary verification code; Add the first parameter to each odd-digit number of the secondary verification code, and obtain the corresponding addition result as the converted odd-digit number. If the addition result is a two-digit number, take the unit digit of the addition result as the converted odd-digit number. Subtract the second parameter from each even-digit number of the secondary verification code, and obtain the corresponding subtraction result as the converted even-digit number. If an even-digit number is less than the second parameter, add 10 to the even-digit number and then subtract the second parameter to obtain the corresponding subtraction result as the converted even-digit number. Combine the converted odd-digit numbers and the converted even-digit numbers in sequence to obtain a conversion verification code.
6. A data security access method according to claim 1, It is characterized in that The step of performing data conversion processing on the initial verification code according to the set data conversion rule to obtain a converted verification code includes: Extract the first digit of the initial verification code as the first parameter, extract the last digit of the initial verification code as the second parameter, and use the remaining part of the initial verification code after removing the first digit and the last digit as the secondary verification code; Add the first parameter to each odd-digit number of the secondary verification code, and obtain the corresponding addition result as the converted odd-digit number. If the addition result is a two-digit number, take the unit digit of the addition result as the converted odd-digit number, and subtract the second parameter from each even-digit number of the secondary verification code, and obtain the absolute value of the corresponding subtraction result as the converted even-digit number; Combine the converted odd-digit numbers and the converted even-digit numbers in sequence to obtain a conversion verification code.
7. A data security access method according to claim 1, It is characterized in that The step of performing data mapping processing on each bit of the conversion verification code according to the set data mapping rule to obtain the mapping verification code includes: Each bit of data in the conversion verification code is substituted into a preset data mapping table for association matching, the mapping data corresponding to each bit of data in the conversion verification code is determined, and the mapping data corresponding to each bit of data in the conversion verification code is extracted and sequentially combined to obtain a mapping verification code. The data mapping table contains a number of conversion verification code data, and each conversion verification code data is associated with corresponding mapping data.
8. A data security access system, It is characterized in that It includes an acquisition unit, a verification unit, a transceiver unit, a decryption unit, a determination unit, a conversion unit, a mapping unit, a combination unit and an execution unit, wherein: An acquisition unit, used to acquire identity verification information sent by a data requesting end; The verification unit is used to perform identity verification on the data request end according to the identity verification information. After the identity verification is passed, the preset encryption public key is retrieved and the corresponding permission basic code is determined according to the identity verification information matching; A transceiver unit is used to send the encrypted public key to the data request end, and receive the access verification encrypted data packet fed back by the data request end, wherein the access verification encrypted data packet is obtained by the data request end using the encrypted public key to asymmetrically encrypt the access request information, the authority allocation number and the initial verification code; A decryption unit, used to perform asymmetric decryption processing on the access verification encrypted data packet using a preset decryption private key to obtain access request information, permission allocation number and initial verification code; A determination unit, used to determine the corresponding permission type according to the access request information, match the corresponding permission number according to the permission type, and determine each fixed digit according to the permission allocation number; The conversion unit is used to extract the numbers corresponding to the fixed digits from the initial verification code as the additional numbers, and perform data conversion processing on the initial verification code according to the set data conversion rules to obtain the conversion verification code; A mapping unit, used to perform data mapping processing on each bit of data in the conversion verification code according to a set data mapping rule to obtain a mapping verification code; A combination unit, used for adding the permission number to the end of the permission basic code to obtain the permission verification code, and adding each additional number to the end of the mapping verification code to obtain each request verification code; The execution unit is used to verify each request verification code using the permission verification code. If a request verification code is consistent with the permission verification code, the database is accessed according to the access request information, and the corresponding access data in the database is retrieved and transmitted to the data request end.
9. A data security access device, It is characterized in that include: A memory for storing instructions; A processor is used to read the instructions stored in the memory and execute the data security access method described in any one of claims 1 to 7 according to the instructions.
10. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on a computer, the computer executes the data security access method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Identity authentication method and device, and related equipment
CN111177686A
Equipment method and device, electronic equipment and readable storage medium
CN114553445A