A data security transmission method, device and medium

By deploying interfaces and configuring encryption algorithms on the data receiving system, key pairs and permission set tokens are generated, solving the problems of insufficient capabilities and security risks in data collection methods, and realizing secure data transmission and rapid response.

CN117595989BActive Publication Date: 2025-11-21AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311590557.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-27
Publication Date
2025-11-21
Estimated Expiration
2043-11-27

AI Technical Summary

Technical Problem

Existing data acquisition methods lack diversity and pose high security risks to transmission and storage, necessitating standardized and secure interface methods for data transmission.

Method used

Develop and deploy various interfaces on the data receiving system, adopt the HTTPS transmission protocol, configure data encryption algorithms, generate key pairs and permission set tokens, and achieve secure data transmission through encryption algorithms.

Benefits of technology

This ensures data security and improves response speed after data changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117595989B_ABST
    Figure CN117595989B_ABST
Patent Text Reader

Abstract

The application discloses a data security transmission method and device and medium. The method comprises the following steps: based on the data collection requirement, developing and deploying the docking interface for receiving various data on the data receiving system, and performing interface configuration on the docking interface, wherein the docking interface adopts the HTTPS transmission protocol; configuring the data encryption algorithm for the docking interface, and authorizing the docking interface to the third-party collection system according to the data type collected by the third-party collection system; configuring the application by using the encryption algorithm, generating the related key pair according to the encryption algorithm, synchronously generating the permission set token, and setting the key pair to generate the life cycle; and interacting with the data receiving system according to the key pair and the permission set token, so as to realize the safe transmission of the collected data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, and more specifically, to a data security transmission method, apparatus, and medium. Background Technology

[0002] While traditional data acquisition methods can still provide valuable data to data receiving systems, the rapid development of IoT and AI technologies, along with the increasing complexity of the social and cyberspace environments, has led to problems such as insufficient diversification of acquisition methods and high security risks in transmission and storage. There is an urgent need to receive data collected through internet and AI technologies via standardized and secure interfaces. Summary of the Invention

[0003] To address the shortcomings of existing technologies, this invention provides a data security transmission method, apparatus, and medium.

[0004] According to one aspect of the present invention, a method for secure data transmission is provided, comprising:

[0005] Based on the data collection requirements, various data receiving interfaces were developed and deployed on the data receiving system, and the interfaces were configured. The interfaces use the HTTPS transmission protocol.

[0006] Configure a data encryption algorithm for the interface and authorize the interface to the third-party data collection system according to the data type collected by the third-party data collection system;

[0007] The application is configured using an encryption algorithm, and relevant key pairs are generated based on the encryption algorithm. Permission set tokens are generated simultaneously, and key pairs are set for lifecycle.

[0008] Based on the key pair and permission set token, it interacts with the data receiving system to achieve secure transmission of collected data.

[0009] Optionally, the interface configuration includes any combination of the following: interface name, code, business category, interface URL, and interface status. The interface status includes registered, active, suspended, and deregistered. After an interface is registered, it is in the registered state; when it is officially used, the status is changed to active; when the interface is adjusted for management purposes, it is changed to suspended; if it is determined that the interface will no longer be used, it is changed to deregistered.

[0010] Optionally, a data encryption algorithm can be configured for the interface, including:

[0011] Configure the SM4 symmetric data encryption algorithm for the interface.

[0012] Optionally, it also includes: adding third-party encryption / decryption service configuration to the interface using RESTful, wherein the third-party encryption / decryption service configuration includes service name, service code, HEAD information, BODY information, service description, and validity period.

[0013] Optionally, it also includes: modifying the encryption / decryption source of the interface to the service name and service code of the newly added third-party encryption / decryption service configuration, based on the added third-party encryption / decryption service configuration.

[0014] Optionally, it also includes setting the permission set token to self-renewal.

[0015] According to another aspect of the present invention, a data secure transmission device is provided, comprising:

[0016] The development configuration module is used to develop and deploy various data receiving interfaces on the data receiving system based on the data collection requirements, and to configure the interfaces, which use the HTTPS transmission protocol.

[0017] The authorization configuration module is used to configure the data encryption algorithm for the interface and authorize the interface to the third-party collection system according to the data type collected by the third-party collection system.

[0018] The generation module is used to configure the application using encryption algorithms, generate relevant key pairs according to the encryption algorithms, and simultaneously generate permission set tokens and set the lifecycle of key pairs;

[0019] The transmission module is used to interact with the data receiving system based on the key pair and the permission set token to achieve secure transmission of the collected data.

[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, the storage medium storing a computer program for performing the methods described in any of the above aspects of the present invention.

[0021] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: a processor; a memory for storing executable instructions of the processor; the processor being configured to read the executable instructions from the memory and execute the instructions to implement the method described in any of the preceding aspects of the present invention.

[0022] Therefore, this invention uses a configurable domestic cryptographic encryption method and a periodic key update mechanism to ensure data security. It employs unified interface management and authorization to improve the response speed when the required data changes. Attached Figure Description

[0023] Exemplary embodiments of the present invention can be more fully understood by referring to the following figures:

[0024] Figure 1 This is a flowchart illustrating a data security transmission method provided in an exemplary embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram of the structure of a data security transmission device provided in an exemplary embodiment of the present invention;

[0026] Figure 3 This is the structure of an electronic device provided in an exemplary embodiment of the present invention. Detailed Implementation

[0027] Hereinafter, exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments described herein.

[0028] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps described in these embodiments do not limit the scope of the invention.

[0029] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of the present invention are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.

[0030] It should also be understood that in the embodiments of the present invention, "multiple" can refer to two or more, and "at least one" can refer to one, two or more.

[0031] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more unless explicitly defined or given contrary instructions in the context.

[0032] Furthermore, the term "and / or" in this invention is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this invention generally indicates that the preceding and following related objects have an "or" relationship.

[0033] It should also be understood that the description of the various embodiments in this invention emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.

[0034] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.

[0035] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.

[0036] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the specification.

[0037] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.

[0038] The embodiments of this invention can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate together with a wide range of other general-purpose or special-purpose computing system environments or configurations. Well-known examples of terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, and servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems, etc.

[0039] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in distributed cloud computing environments, where tasks are executed by remote processing devices linked through communication networks. In distributed cloud computing environments, program modules can reside on local or remote computing system storage media, including storage devices.

[0040] Exemplary methods

[0041] Figure 1 This is a schematic flowchart of a data security transmission method provided in an exemplary embodiment of the present invention. This embodiment can be applied to electronic devices, such as... Figure 1 As shown, the data secure transmission method 100 includes the following steps:

[0042] Step 101: Based on the data collection requirements, develop and deploy various data receiving interfaces on the data receiving system, and configure the interfaces, which use the HTTPS transmission protocol.

[0043] Optionally, the interface configuration includes any combination of the following: interface name, code, business category, interface URL, and interface status. The interface status includes registered, active, suspended, and deregistered. After an interface is registered, it is in the registered state; when it is officially used, the status is changed to active; when the interface is adjusted for management purposes, it is changed to suspended; if it is determined that the interface will no longer be used, it is changed to deregistered.

[0044] Specifically, this application provides a method for secure data transmission, which can facilitate the access of a third-party data acquisition system to a data receiving system, while ensuring the security of information transmission between the access system and the data acquisition and receiving system based on domestic encryption algorithms.

[0045] Furthermore, the interface management system standardizes and unifies the management of interfaces for data collection. It allows for the configuration and management of various data receiving interfaces developed and deployed based on data collection requirements. This includes the interface name, code, business category, URL, and status (registered, active, suspended, deregistered). After registration, the interface defaults to "registered." When it needs to be used formally, the status can be changed to "active." If the interface needs to be adjusted for management purposes, it can be changed to "suspended." If it is determined that it will no longer be used, it can be changed to "deregistered." To ensure the security of the interface integration process, the interface must use the HTTPS protocol.

[0046] Step 102: Configure a data encryption algorithm for the interface and authorize the interface to the third-party data collection system according to the data type collected by the third-party data collection system.

[0047] Optionally, a data encryption algorithm can be configured for the interface, including:

[0048] Configure the SM4 symmetric data encryption algorithm for the interface.

[0049] Optionally, it also includes: adding third-party encryption / decryption service configuration to the interface using RESTful, wherein the third-party encryption / decryption service configuration includes service name, service code, HEAD information, BODY information, service description, and validity period.

[0050] Optionally, it also includes: modifying the encryption / decryption source of the interface to the service name and service code of the newly added third-party encryption / decryption service configuration, based on the added third-party encryption / decryption service configuration.

[0051] Specifically, in terms of encryption algorithm configuration and application, the data encryption and decryption of this invention uses the built-in SM4 symmetric encryption algorithm by default. It can also reference symmetric encryption and decryption services provided by third parties, such as cryptographic machines, through configuration. It is only necessary to add the third-party encryption and decryption service configuration in accordance with the RESTful method, which mainly includes the service name, service code, HEAD information, BODY information, service description, validity period, etc. After adding the configuration, the encryption and decryption source is modified to the newly added service name and service code to be used.

[0052] Step 103: Configure the application using an encryption algorithm, generate relevant key pairs according to the encryption algorithm, and simultaneously generate permission set tokens and set the lifecycle of key pairs.

[0053] Optionally, it also includes setting the permission set token to self-renewal.

[0054] Step 104: Based on the key pair and the permission set token, interact with the data receiving system to achieve secure transmission of the collected data.

[0055] Specifically, the interface authorization and key management system authorizes third-party systems to use interfaces and manages the lifecycle of keys. During authorization, the system selects the corresponding authorized interface based on the data type collected by the third-party system, generates a key pair using a domestic encryption algorithm configured in the application settings, and simultaneously generates a token containing the permission set. The third-party system subsequently needs to interact with the main system based on the generated key pair and token, and the system supports autonomous token renewal.

[0056] The key technical point of this invention is:

[0057] 1. By using configurable domestic cryptographic encryption methods and a periodic key update mechanism, the collected and connected data is encrypted and decrypted as a whole, ensuring data security.

[0058] 2. Improve the response speed of data collection after changes occur by using unified interface management and interface authorization.

[0059] Therefore, this invention uses a configurable domestic cryptographic encryption method and a periodic key update mechanism to ensure data security. It employs unified interface management and authorization to improve the response speed when the required data changes.

[0060] Exemplary device

[0061] Figure 2 This is a schematic diagram of the structure of a data security transmission device provided in an exemplary embodiment of the present invention. Figure 2 As shown, the device 200 includes:

[0062] The development configuration module 210 is used to develop and deploy various data receiving interfaces on the data receiving system based on the data collection requirements, and to configure the interfaces, wherein the interfaces adopt the HTTPS transmission protocol.

[0063] The authorization configuration module 220 is used to configure the data encryption algorithm for the interface and authorize the interface to the third-party collection system according to the data type collected by the third-party collection system.

[0064] The generation module 230 is used to configure the application using an encryption algorithm, generate relevant key pairs according to the encryption algorithm, and synchronously generate permission set tokens and set the lifecycle of key pairs;

[0065] The transmission module 240 is used to interact with the data receiving system based on the key pair and the permission set token to achieve secure transmission of the collected data.

[0066] Optionally, the interface configuration includes any combination of the following: interface name, code, business category, interface URL, and interface status. The interface status includes registered, active, suspended, and deregistered. After an interface is registered, it is in the registered state; when it is officially used, the status is changed to active; when the interface is adjusted for management purposes, it is changed to suspended; if it is determined that the interface will no longer be used, it is changed to deregistered.

[0067] Optionally, the authorization configuration module 220 configures a data encryption algorithm for the interface, including:

[0068] The configuration submodule is used to configure the SM4 symmetric data encryption algorithm for the interface.

[0069] Optionally, the device 200 further includes: an addition module for adding third-party encryption / decryption service configuration to the interface using RESTful methods, wherein the third-party encryption / decryption service configuration includes service name, service code, HEAD information, BODY information, service description, and validity period.

[0070] Optionally, the device 200 further includes a modification module, used to modify the encryption / decryption source of the interface to the service name and service code of the newly added third-party encryption / decryption service configuration according to the added third-party encryption / decryption service configuration.

[0071] Optionally, the device 200 further includes a setting module for setting the permission set token to self-renewal.

[0072] Exemplary electronic devices

[0073] Figure 3 This is the structure of an electronic device provided in an exemplary embodiment of the present invention. For example... Figure 3As shown, the electronic device 30 includes one or more processors 31 and memory 32.

[0074] The processor 31 may be a central processing unit (CPU) or other form of processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.

[0075] The memory 32 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 31 may execute the program instructions to implement the methods of the software programs of the various embodiments of the present invention described above, and / or other desired functions. In one example, the electronic device may also include an input device 33 and an output device 34, these components being interconnected via a bus system and / or other forms of connection mechanisms (not shown).

[0076] In addition, the input device 33 may also include, for example, a keyboard, a mouse, etc.

[0077] The output device 34 can output various information to the outside. The output device 34 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0078] Of course, for the sake of simplicity, Figure 3 Only some of the components of this electronic device relevant to the present invention are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device may include any other suitable components depending on the specific application.

[0079] Exemplary computer program products and computer-readable storage media

[0080] In addition to the methods and apparatus described above, embodiments of the present invention may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps in the methods according to various embodiments of the present invention described in the "Exemplary Methods" section above.

[0081] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of the present invention. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0082] Furthermore, embodiments of the present invention may also be computer-readable storage media storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the steps of the methods according to various embodiments of the present invention described in the "Exemplary Methods" section above.

[0083] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.

[0084] The basic principles of the present invention have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in the present invention are merely examples and not limitations, and should not be considered as essential features of each embodiment of the present invention. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the present invention to the necessity of employing the aforementioned specific details.

[0085] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0086] The block diagrams of devices, systems, devices, and systems involved in this invention are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, systems, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0087] The methods and systems of the present invention may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of the present invention are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, the present invention may also be implemented as a program recorded on a recording medium, the program comprising machine-readable instructions for implementing the methods according to the present invention. Thus, the present invention also covers recording media storing programs for performing the methods according to the present invention.

[0088] It should also be noted that in the systems, apparatus, and methods of the present invention, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered equivalents of the present invention. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the invention. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the invention. Therefore, the invention is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0089] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the invention to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A method for secure data transmission, characterized in that, include: Based on the data collection requirements, various data receiving interfaces are developed and deployed on the data receiving system, and the interfaces are configured. The interfaces use the HTTPS transmission protocol. Configure a data encryption algorithm for the interface and authorize the interface to the third-party data collection system according to the data type collected by the third-party data collection system; The application is configured using an encryption algorithm, and relevant key pairs are generated according to the encryption algorithm. Permission set tokens are generated synchronously, and the lifecycle of the key pairs is set. Based on the key pair and the permission set token, the system interacts with the data receiving system to achieve secure transmission of the collected data.

2. The method according to claim 1, characterized in that, The interface configuration includes any combination of the following: interface name, code, business category, interface URL, and interface status, including registered, active, suspended, and deregistered.

3. The method according to claim 1, characterized in that, Configure a data encryption algorithm for the interface, including: Configure the SM4 symmetric data encryption algorithm for the docking interface.

4. The method according to claim 1 or 3, characterized in that, Also includes: The interface is configured with a third-party encryption / decryption service using RESTful methods. This third-party encryption / decryption service configuration includes the service name, service code, HEAD information, BODY information, service description, and validity period.

5. The method according to claim 4, characterized in that, Also includes: Based on the added third-party encryption / decryption service configuration, the encryption / decryption source of the interface is modified to the service name and service code of the newly added third-party encryption / decryption service configuration.

6. The method according to claim 1, characterized in that, Also includes: Set the permission set token to self-renewal.

7. A data security transmission device, characterized in that, include: A development configuration module is used to develop and deploy various data receiving interfaces on the data receiving system based on the data collection requirements, and to configure the interfaces, wherein the interfaces adopt the HTTPS transmission protocol. The authorization configuration module is used to configure a data encryption algorithm for the interface and authorize the interface to the third-party collection system according to the data type collected by the third-party collection system. The generation module is used to configure the application using an encryption algorithm, generate relevant key pairs according to the encryption algorithm, and synchronously generate permission set tokens and set the lifecycle of the key pairs; The transmission module is used to interact with the data receiving system based on the key pair and the permission set token to achieve secure transmission of the collected data.

8. The apparatus according to claim 7, characterized in that, The interface configuration includes any combination of the following: interface name, code, business category, interface URL, and interface status. The interface status includes registered, active, suspended, and deregistered. After the interface is registered, it is in the registered state; when it is officially used, the status is changed to active; when the interface is adjusted for management purposes, it is changed to suspended. If it has been determined that the interface is no longer in use, then the status will be changed to the "deregistered" status.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program for performing the method described in any one of claims 1-6.

10. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Data interface integration configuration method convenient for docking with external system

    CN114281500A

  • Mobile communication multimedia information source interface system and method

    CN1630243A