Information interaction method and system, device and electronic equipment for test environment
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-16
- Publication Date
- 2026-08-11
AI Technical Summary
[0005]本发明实施例提供了一种用于测试环境的信息交互方法及系统、装置、电子设备,以至少解决相关技术中跨机构系统在测试环境中进行信息交互时安全机制不够完备,导致数据安全性较低的技术问题
[0015]本发明中,提出一套用于测试环境信息交互的安全性验证和备份机制,由信息交互的上游系统根据参与交互的目标信息的信息类型,将目标信息经过加密后得到的加密信息传输至数据湖中,并借由数据湖中的指定消息集群向下游系统推送消息提取通知,相比于现有技术,通过数据湖可以实现在信息交互的过程中对加密数据进行数据保管和数据备份。
Smart Images

Figure CN118316685B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology or other related fields. Specifically, it relates to an information interaction method, system, device, and electronic device for a testing environment. Background Technology
[0002] Systems that interact with a financial institution's information system (interface call messages, file exchanges) are collectively referred to as third-party institutions. There is a significant amount of information exchange between the financial institution's information system and third-party institutions, as well as various heterogeneous systems. These "cross-institutional systems" also have multiple "basic systems" responsible for information transmission, distribution, and conversion between them and the financial institution's information system.
[0003] In related technologies, the delivery testing environment of financial institution information systems is subject to various limitations and influences. Information interaction with cross-institutional systems is often affected by the underlying system, making it inaccurate and untimely. Furthermore, delivery testing environments typically require simulation verification using sensitive data from the production environment; however, this data may involve sensitive information such as personal identification and financial data, and the data may be threatened by eavesdropping or tampering during transmission. The security of the delivery testing environment is also affected by internal and external threats. Therefore, to ensure the security of the delivery testing environment, financial institutions need to take a series of measures to ensure the security and confidentiality requirements of the information interaction chain.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This invention provides an information interaction method, system, device, and electronic device for a testing environment, to at least solve the technical problem in the related art where the security mechanism is not complete when cross-organizational systems interact in a testing environment, resulting in low data security.
[0006] According to one aspect of the present invention, an information interaction method for a test environment is provided, applied to an upstream system for information interaction, wherein an interaction relationship has been pre-established between the upstream system and a downstream system, and the downstream system is a cross-institutional system of the upstream system. The method includes: determining the information type of target information participating in the current interaction process, wherein the information type includes: interface call message, contract file, and non-contract file; encrypting the target information using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship; transmitting the encrypted information to a data lake based on the information type, and sending an information extraction notification to the downstream system based on a designated message cluster in the data lake, wherein the information extraction notification includes at least the information type; the downstream system obtains the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using an encryption private key to obtain decrypted information, thereby completing the information interaction.
[0007] According to another aspect of the present invention, an information interaction method for a test environment is also provided, applied to a downstream system for information interaction, wherein the downstream system and the upstream system have a pre-established interaction relationship, and the upstream system is a cross-organizational system of the downstream system. The method includes: obtaining an information extraction notification based on a specified message cluster, wherein the information extraction notification contains at least the information type of the target information involved in the current interaction process, and the information type includes: interface call message, contract file, and non-contract file; accessing a data lake based on the information extraction notification, and obtaining encrypted information corresponding to the target information from the data lake based on the information type, wherein the encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system; decrypting the encrypted information using the encryption private key of the downstream system to obtain decrypted information, thereby completing the information interaction.
[0008] According to another aspect of the present invention, an information interaction device for a test environment is also provided, applied to an upstream system for information interaction, wherein an interaction relationship has been pre-established between the upstream system and a downstream system, and the downstream system is a cross-institutional system of the upstream system. The device includes: a determining unit, used to determine the information type of target information participating in the current interaction process, wherein the information type includes: interface call message, contract file, and non-contract file; an encryption unit, used to encrypt the target information using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship; and a transmission unit, used to transmit the encrypted information to a data lake based on the information type, and send an information extraction notification to the downstream system based on a designated message cluster in the data lake, wherein the information extraction notification includes at least the information type, and the downstream system obtains the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using an encryption private key to obtain decrypted information, thus completing the information interaction.
[0009] According to another aspect of the present invention, an information interaction device for a test environment is also provided, applied to a downstream system for information interaction, wherein the downstream system and the upstream system have a pre-established interaction relationship, and the upstream system is a cross-institutional system of the downstream system. The device includes: an acquisition unit, configured to acquire an information extraction notification based on a specified message cluster, wherein the information extraction notification includes at least the information type of the target information involved in the current interaction process, the information type including: interface call message, contract file, and non-contract file; an access unit, configured to access a data lake based on the information extraction notification, and acquire encrypted information corresponding to the target information from the data lake based on the information type, wherein the encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system; and a decryption unit, configured to decrypt the encrypted information using the encryption private key of the downstream system to obtain decrypted information, thereby completing the information interaction.
[0010] According to another aspect of the present invention, an information interaction system for a test environment is also provided, comprising: an upstream system and a downstream system, wherein an interaction relationship has been pre-established between the upstream system and the downstream system, and the downstream system is a cross-institutional system of the upstream system; a designated message cluster for running N topic message containers, where N is a positive integer, each topic message container for providing a one-to-one message push service to the upstream and downstream systems involved in the interaction process; and a data lake for backing up and storing all interaction data involved in the interaction process, wherein the data lake includes at least a rule execution module and a file interaction module, wherein the rule execution module is connected to a rule base, the rule execution module is used to impose rule restrictions on the upstream and downstream systems in the interaction process, the rule base is used to store the restriction rules established by the upstream and downstream systems in the interaction process, and the file interaction module is used to temporarily store encrypted information transmitted by the upstream system in the interaction process and transmit the encrypted information to the downstream system within the scope allowed by the restriction rules.
[0011] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the information interaction method for a test environment described in any one of the above embodiments.
[0012] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the information interaction method for a test environment described in any one of the preceding embodiments.
[0013] This invention proposes an information interaction method for a test environment. First, the information type of the target information participating in the interaction process is determined. The information type includes: interface call messages, contract files, and non-contract files. Then, the target information is encrypted using the encryption public key of the downstream system to obtain encrypted information. The encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship. Finally, the encrypted information is transmitted to a data lake based on the information type, and an information retrieval notification is sent to the downstream system based on a designated message cluster in the data lake. The information retrieval notification contains at least the information type. The downstream system retrieves the encrypted information from the data lake based on the information retrieval notification and decrypts the encrypted information using its encryption private key to obtain decrypted information, thus completing the information interaction.
[0014] This invention also proposes another information interaction method for a test environment. First, an information extraction notification is obtained based on a specified message cluster. The information extraction notification contains at least the information type of the target information involved in this interaction process. The information type includes: interface call message, contract file, and non-contract file. Then, the data lake is accessed based on the information extraction notification, and the encrypted information corresponding to the target information is obtained from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system. Finally, the encrypted information is decrypted using the encryption private key of the downstream system to obtain the decrypted information, thus completing the information interaction.
[0015] This invention proposes a security verification and backup mechanism for information interaction in a testing environment. The upstream system of the information interaction transmits encrypted information obtained by encrypting the target information to a data lake according to the information type of the target information involved in the interaction. The downstream system then pushes a message retrieval notification through a designated message cluster in the data lake. Compared with the prior art, the data lake enables data storage and backup of encrypted data during the information interaction process.
[0016] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the encryption public key of the downstream system in the upstream system's database. Before being transmitted to the data lake, the target information is encrypted using the encryption public key. After the downstream system extracts the encrypted information through the security verification of the data lake, it decrypts it using the encryption private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information.
[0017] The data lake in this invention can also perform security verification on downstream systems when they extract encrypted information. Compared with the shortcomings of insufficient security mechanisms in the test environment in the prior art, this invention can provide a supplementary security mechanism for information interaction between cross-institutional systems in the test environment, further ensuring the data security of interactive information in the test environment. This solves the technical problem in related technologies where the security mechanism is not complete when cross-institutional systems interact with information in the test environment, resulting in low data security. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0019] Figure 1 This is a flowchart of an optional information interaction method for a test environment according to an embodiment of the present invention;
[0020] Figure 2This is a flowchart of another optional information interaction method for a test environment according to an embodiment of the present invention;
[0021] Figure 3 This is a schematic diagram of an optional data lake-based verification and backup mechanism according to an embodiment of the present invention;
[0022] Figure 4 This is a flowchart of an optional information interaction method based on a verification backup mechanism according to an embodiment of the present invention;
[0023] Figure 5 This is a schematic diagram of an optional information interaction system for a testing environment according to an embodiment of the present invention;
[0024] Figure 6 This is a schematic diagram of an optional information interaction device for a testing environment according to an embodiment of the present invention;
[0025] Figure 7 This is a schematic diagram of another optional information interaction device for a testing environment according to an embodiment of the present invention;
[0026] Figure 8 This is a hardware structure block diagram of an electronic device (or mobile device) for an information interaction method in a testing environment according to an embodiment of the present invention. Detailed Implementation
[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0029] To facilitate understanding of the present invention by those skilled in the art, some terms or nouns involved in the various embodiments of the present invention are explained below:
[0030] AOP, or Aspect-Oriented Programming, refers to a programming approach where, when a method is executed, additional functionalities are dynamically performed by the program to enhance the original method without modifying its original execution logic.
[0031] Kafka is a high-performance, low-latency, high-throughput distributed messaging system.
[0032] A Topic is a logical concept in Kafka that can be used to differentiate business systems. It typically adopts a multi-subscriber pattern, where a topic can have one or more consumers subscribing to the producer's data.
[0033] Contractual relationships, also known as information dependencies between cross-institutional systems in a test environment, refer to information exchanges between two systems, A and B, based on specified rules. System A transmits information 1 to system B, and system B also needs to provide information 2 to system A within the specified rules to ensure the privacy and non-repudiation of the interaction process.
[0034] The delivery test environment is the final step before production deployment. At this point, the program is basically stable and performance testing will begin in the delivery test environment.
[0035] Information fingerprints are unique identifiers used to identify and verify data. They are generated by processing data using a specific algorithm to produce a fixed-length string or number, which is called an information fingerprint. They are usually calculated based on the content of the data and have three characteristics: uniqueness, irreversibility, and fixed length.
[0036] A distributed service invocation platform is a platform that provides the functionality and services of distributed service invocation. It can help developers quickly and easily develop and deploy distributed services, and typically provides the following functions: service registration and discovery, service invocation, load balancing, fault tolerance and failover, security authentication and authorization, and service governance.
[0037] It should be noted that the information interaction method and apparatus for testing environments in this invention can be used in the field of information security technology when interacting with cross-organizational systems in a testing environment, and can also be used in any field other than information security when interacting with cross-organizational systems in a testing environment. This invention does not limit the application field of the information interaction method and apparatus for testing environments.
[0038] It should be noted that all relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data) involved in this invention are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, processing, transmission, provision, disclosure, use, and handling of such data must comply with the laws, regulations, and standards of the relevant regions, necessary confidentiality measures have been taken, and it does not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse. For example, this system has an interface with relevant users or organizations. Before obtaining relevant information, a request to obtain the information needs to be sent to the aforementioned user or organization through the interface, and the relevant information is obtained only after receiving consent from the aforementioned user or organization.
[0039] The information collection (e.g., user voice, video, and text collection) and analysis operations involved in this invention have provided users with corresponding operation entry points during execution, allowing users to choose to agree to or reject the automated decision results; if the user chooses to reject, the process enters the expert decision-making process.
[0040] The following embodiments of the present invention can be applied to various systems / applications / devices that need to interact with cross-institutional systems in a test environment, enabling data storage and backup of encrypted data during information interaction through a data lake. The present invention involves the upstream system transmitting encrypted information (after encrypting the target information) to the data lake based on the information type of the target information involved in the interaction. A designated message cluster in the data lake then pushes a message retrieval notification to the downstream system. When the downstream system retrieves the encrypted information, it performs security verification on the downstream system. This provides a supplementary security mechanism for cross-institutional system information interaction in the test environment, further ensuring the data security of the interacting information in the test environment.
[0041] The present invention will now be described in detail with reference to various embodiments.
[0042] Example 1
[0043] According to an embodiment of the present invention, an embodiment of an information interaction method for a test environment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0044] Figure 1 This is a flowchart of an optional information interaction method for a test environment according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0045] Step S101: Determine the information type of the target information participating in this interaction process.
[0046] Step S102: Encrypt the target information using the encryption public key of the downstream system to obtain encrypted information.
[0047] Step S103: Based on the information type, transmit the encrypted information to the data lake, and send an information extraction notification to the downstream system based on the specified message cluster in the data lake, wherein the information extraction notification contains at least the information type.
[0048] Through the above steps, the information type of the target information participating in this interaction process can be determined first. The information type includes: interface call message, contract file and non-contract file. Then, the target information is encrypted using the encryption public key of the downstream system to obtain encrypted information. The encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship. Finally, the encrypted information is transmitted to the data lake based on the information type, and an information retrieval notification is sent to the downstream system based on the designated message cluster in the data lake. The information retrieval notification contains at least the information type. The downstream system retrieves the encrypted information from the data lake based on the information retrieval notification and decrypts the encrypted information using the encryption private key to obtain decrypted information, thus completing the information interaction.
[0049] In this embodiment of the invention, a security verification and backup mechanism for information interaction in a test environment is proposed. The upstream system of the information interaction transmits the encrypted information obtained by encrypting the target information to the data lake according to the information type of the target information involved in the interaction. The designated message cluster in the data lake pushes the message retrieval notification to the downstream system. Compared with the prior art, the data lake can realize data storage and data backup of encrypted data during the information interaction process.
[0050] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the downstream system's encrypted public key in its database. Before being transmitted to the data lake, the target information is encrypted using the encrypted public key. After the downstream system extracts the encrypted information through the data lake's security verification, it decrypts it using the encrypted private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information, thereby solving the technical problem in related technologies where the security mechanism is not complete enough when cross-institutional systems exchange information in the test environment, resulting in low data security.
[0051] The embodiments of the present invention will now be described in detail with reference to the steps described above.
[0052] The implementing entity of this invention can be a financial information system or an information interaction system within a financial system. As an upstream system for information interaction, it combines a data lake and a designated message cluster within the data lake to achieve the storage and backup of encrypted information and the targeted push of information extraction notifications to downstream systems for information interaction, thereby ensuring data security when interacting with cross-institutional systems in a test environment.
[0053] It should be noted that the downstream system is a cross-organizational system of the upstream system, and an interaction relationship has been established between the upstream and downstream systems. The upstream and downstream systems with the interaction relationship use dedicated topic message containers to push messages in the designated message cluster of this embodiment of the invention.
[0054] For example, when using the Kafka distributed messaging system as the designated message cluster, the Topic logic in Kafka can be used as a dedicated topic message cluster. By utilizing the subscriber pattern, the upstream system acts as the producer, and the downstream system acts as the consumer to subscribe to the message notifications of the upstream system. In the security verification mechanism provided in this embodiment of the invention, the upstream and downstream systems need to subscribe to each other's message notifications in order to perform more rigorous interactive verification.
[0055] Step S101: Determine the information type of the target information participating in this interaction process.
[0056] It should be noted that the information types include: interface call messages, contract files, and non-contract files. Interface call messages are data packets transmitted between cross-organizational systems for communication and interaction. They contain information and parameters required to perform specific functions or operations. Interface call messages typically include the requested operation, input parameters, and return results. This data is usually encoded in a structured format (such as XML or JSON) so that the system can understand and process it. For testing and verifying interface call messages, the following aspects should be considered: verifying the completeness and correctness of input parameters, testing boundary conditions, and simulating various possible response scenarios to ensure the system can process them correctly.
[0057] Another point to note is that the contract file is a crucial document shared across systems within the testing environment. It defines interfaces and interaction specifications, including but not limited to API documentation, WSDL files, and Swagger documentation. The contract file contains information required for interaction between systems, such as operations, parameters, data formats, and protocols. Upstream and downstream systems in the testing environment must adhere to the dependencies defined in the contract file to ensure correct and consistent interaction.
[0058] In a testing environment, the extraction and management of contract files are crucial. The testing team needs to ensure version consistency of contract files and collaborate with the development team to update and adjust them promptly to reflect changes across systems. Additionally, the testing team can utilize automated tools to verify the consistency between contract files and the actual implementation, thereby reducing potential errors and inconsistencies.
[0059] Another point to note is that uncontractual files refer to unstructured or semi-structured files transmitted during the interaction process, such as images, videos, and PDF documents. These can contain various types of data, such as reports, pictures, and audio. For testing and verifying uncontractual files, the following aspects should be considered: ensuring file integrity and usability, verifying file format compatibility, and testing the performance of file parsing and processing. Optionally, before executing step S101, the method further includes: determining the system aspect status of the upstream system and the downstream system, wherein the system aspect status is used to indicate whether the cross-cutting concerns embedded in the system can be called normally, and the cross-cutting concerns are used to execute cross-cutting code and start the interaction process when a specified call signal is received without affecting the original system logic; if the system aspect status of both the upstream system and the downstream system is in the open state, the step of determining the information type of the target information participating in this interaction process continues to be executed; or, if the system aspect status of the upstream system is in the closed state, the system aspect status is changed to the open state; if the system aspect status of the downstream system is in the closed state, a status change notification is pushed to the downstream system through the topic message container in the specified message cluster, wherein the status change notification is used to notify the upstream system to change the system aspect status to the open state.
[0060] This invention employs Aspect-Oriented Programming (AOP) to focus on and separate the state of cross-cutting concerns embedded in the system, thereby obtaining the system's aspect state. These cross-cutting concerns (such as logging, security, and transaction management) span the entire application, while an aspect is the unit in AOP used to encapsulate these cross-cutting concerns. An aspect contains cross-cutting code executed at a specific point (e.g., when a specific call signal is received). Other specific points can include before and after a method call, when an exception is thrown, etc.
[0061] This invention provides another optional method for classifying system aspect states, including: aspect activation state, indicating whether the aspect is currently active; aspect loading state, indicating whether the aspect has been successfully loaded into the system; aspect execution state, indicating whether the cross-cutting code of the aspect has been successfully executed. If the aspect's notification execution fails, it may cause functions related to the cross-cutting concern to malfunction; and aspect exception state, indicating whether an exception occurred during the execution of the aspect's notification. If an exception occurs during the execution of the aspect's notification, it may affect the stability and reliability of the system. By monitoring and managing the state of aspects, it can be ensured that cross-cutting concerns can be called and executed normally, thereby achieving better code structure and maintainability.
[0062] Step S102: Encrypt the target information using the encryption public key of the downstream system to obtain encrypted information.
[0063] It should be noted that the downstream system's public encryption key is pre-stored in the upstream system's database based on the interaction relationship. Upstream and downstream systems with an interaction relationship exchange certificates, obtain each other's public encryption keys, and store them in their respective databases. This allows them to encrypt the target information using the other party's public encryption key before transmitting it to the other party. Upon receiving the encrypted information, the receiving party can decrypt it using its own private encryption key. Successful decryption indicates successful interaction and information exchange; failure to decrypt indicates interaction failure but no information leakage, thus maximizing data security during information exchange.
[0064] Optionally, step S102 includes: when the information type is a non-contract file, transmitting the encrypted information to the file interaction module in the data lake; obtaining the file index of the non-contract file indicated by the encrypted information based on the file interaction module, wherein the file index is used to identify the upstream and downstream systems involved in the interaction process of the encrypted information; calling the first cross-cutting concern pre-embedded in the upstream system and executing the cross-cutting code corresponding to the first cross-cutting concern to start the second interaction process; adding the file index to the information extraction notification based on the second interaction process and transmitting the information extraction notification to the designated message cluster in the data lake; and pushing the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
[0065] It should be noted that the file index is used to identify the source and destination systems of specific encrypted information in the interaction process. For example, system A represents the source system (i.e., the upstream system) of the encrypted information, and system B represents the destination system (i.e., the downstream system). These two systems may be located in different networks, organizations, or departments, or they may be cross-organizational systems. In the embodiments of this invention, the file index can take the form of: sender + receiver. That is, in the example above, the file index is: A+B, and the index "A+B" indicates that the encrypted information is transmitted from system A to system B. This index may be an identifier, a string, or other form of symbol used to uniquely identify this specific interaction process.
[0066] By using file indexes, the system can track and manage the transmission of encrypted information from system A to system B, enabling it to trace the flow of specific encrypted information and its transmission path within the interaction process. The file index may also contain metadata about the interaction process, such as transmission time, encryption algorithm, and encryption key, allowing the system to better manage and understand the transmission of encrypted information.
[0067] Another point to note is that the second interaction process refers to the execution process in which the upstream and downstream systems interact with non-contract documents based on their interaction relationship.
[0068] Optionally, step S102 further includes: when the information type is a contract file, generating a file key for the contract file indicated by the encrypted information; calculating an information fingerprint of the encrypted information based on the file key and a preset irreversible algorithm, wherein the information fingerprint is used to uniquely identify the encrypted information through a fixed-length sequence; establishing a first binding relationship between the information fingerprint and the encrypted information, and establishing a first restriction rule based on the information fingerprint, the first binding relationship, and a first specified duration; transmitting the encrypted information to the file interaction module in the data lake, and transmitting the first restriction rule to the rule execution module in the data lake; calling a first cross-cutting concern pre-embedded in the upstream system, and executing the cross-cutting code corresponding to the first cross-cutting concern to start a third interaction process; adding the first restriction rule to the information extraction notification based on the third interaction process, and transmitting the information extraction notification to a designated message cluster in the data lake; and pushing the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
[0069] It should be noted that the third interaction process refers to the execution process in which the upstream and downstream systems interact with each other on the contract documents based on their interaction relationship.
[0070] It's important to note that the file key here differs from the public and private keys mentioned above. When generating the file key for the contract file, a random number generator can be used to generate a random and unique key, typically a binary string of sufficient length to provide security. The information fingerprint, on the other hand, is calculated based on this random and unique key and an irreversible algorithm. For example, a hash function can be used to generate a fixed-length hash value, but it's impossible to deduce the random and unique key from this fixed-length hash value.
[0071] Another point to note is that in the steps of establishing the first binding relationship between the information fingerprint and the encrypted information, and establishing the first restriction rule based on the information fingerprint, the first binding relationship, and the first specified duration, this embodiment of the invention provides an exemplary first restriction rule: if the downstream system can provide the file key within the first specified duration, then the downstream system is allowed to extract the encrypted information in the file interaction module; if the downstream system cannot provide the file key within the first specified duration, then the encrypted information is automatically destroyed. The component that executes the above rule determination is the rule execution module in the data lake. Optionally, after pushing the information extraction notification to the downstream system, the method further includes: receiving a key request notification pushed by the topic message container, wherein the key request notification is used to notify the upstream system to provide the file key of the contract document to the downstream system within a second specified duration according to the second restriction rule, the second specified duration being less than the first specified duration.
[0072] It should be noted that, according to the contractual relationship, if the downstream system wants to extract the encrypted information corresponding to the contract file, it also needs to provide a response contract file to the upstream system. Similarly, the response contract file is encrypted using the upstream system's public key, and the second restriction rule is executed to establish a second binding relationship between the information fingerprint and the encrypted response information. The second restriction rule is then established based on the information fingerprint, the second binding relationship, and the second specified duration. The encrypted response information is transmitted to the file interaction module in the data lake, and the second restriction rule is transmitted to the rule execution module in the data lake. The second restriction rule is added to the key request notification, and the key request notification is transmitted to the designated message cluster in the data lake. The information extraction notification is pushed to the upstream system using the interaction relationship and the topic message container in the designated message cluster.
[0073] An exemplary second limiting rule provided in this embodiment of the invention is as follows: if the upstream system can provide the file key within a second specified time period, the upstream system is allowed to extract the encrypted response information from the file interaction module; if the downstream system cannot provide the file key within the second specified time period, the encrypted response information is automatically destroyed. The component that executes the above rule determination is the rule execution module in the data lake.
[0074] Step S103: Based on the information type, transmit the encrypted information to the data lake, and send an information extraction notification to the downstream system based on the specified message cluster in the data lake, wherein the information extraction notification contains at least the information type.
[0075] It should be noted that the downstream system retrieves encrypted information from the data lake based on the information extraction notification, and uses the encryption private key to decrypt the encrypted information to obtain the decrypted information, thus completing the information exchange.
[0076] Optionally, step S103 includes: when the information type is an interface call message, calling the first cross-cutting concern pre-embedded in the upstream system; executing the cross-cutting code corresponding to the first cross-cutting concern to start the first interaction process; based on the first interaction process, adding encrypted information to the information extraction notification and transmitting the information extraction notification to the designated message cluster of the data lake; and using the interaction relationship and the topic message container in the designated message cluster to push the information extraction notification to the downstream system.
[0077] Optionally, a designated message cluster in the data lake is used to run N topic message containers, where N is a positive integer. Each topic message container corresponds to an interaction relationship and, based on the interaction relationship, provides point-to-point message push services to the upstream and downstream systems involved in that interaction relationship.
[0078] In this embodiment of the invention, a security verification and information backup mechanism for information interaction in the delivery test environment is provided. When problems occur in the basic system and cross-organizational system connectivity verification cannot be performed, cross-organizational system interaction security verification can be performed through a designated message cluster and rule execution module in the data lake, thereby supplementing the security mechanism of the delivery test environment. It can also rely on the data caching performance of the data lake to achieve interactive data backup function, which facilitates information traceability.
[0079] Example 2
[0080] According to an embodiment of the present invention, another embodiment of an information interaction method for a test environment is also provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0081] Figure 2 This is a flowchart of another optional information interaction method for a test environment according to an embodiment of the present invention, such as... Figure 2 As shown, the method includes the following steps:
[0082] Step S201: Obtain information extraction notification based on the specified message cluster, wherein the information extraction notification contains at least the information type of the target information involved in this interaction process.
[0083] Step S202: Access the data lake based on the information extraction notification, and obtain the encrypted information corresponding to the target information from the data lake based on the information type.
[0084] Step S203: Use the encryption private key of the downstream system to decrypt the encrypted information to obtain the decrypted information and complete the information exchange.
[0085] Through the above steps, information extraction notifications can be obtained first based on a specified message cluster. The information extraction notifications must contain at least the information type of the target information involved in this interaction process. The information types include: interface call messages, contract files, and non-contract files. Then, the data lake is accessed based on the information extraction notifications, and the encrypted information corresponding to the target information is obtained from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system. Finally, the encrypted information is decrypted using the encryption private key of the downstream system to obtain the decrypted information, thus completing the information interaction.
[0086] This invention proposes a security verification and backup mechanism for information interaction in a test environment. It receives message extraction notifications pushed from a designated message cluster in a data lake to downstream systems. The data lake also enables security verification of downstream systems when they extract encrypted information. Furthermore, it allows for data storage and backup of encrypted data during information interaction. Compared to the shortcomings of inadequate security mechanisms in existing technologies for test environments, this invention provides a supplementary security mechanism for information interaction between cross-organizational systems in test environments, further ensuring the data security of interactive information. This solves the technical problem of low data security caused by inadequate security mechanisms when cross-organizational systems interact in test environments in related technologies.
[0087] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the downstream system's encryption public key in its database. Before being transmitted to the data lake, the target information is encrypted using the encryption public key. After the downstream system extracts the encrypted information through the data lake's security verification, it decrypts it using the encryption private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information. The embodiments of this invention will be described in detail below with reference to the above steps.
[0088] The implementing entity of this invention can be a financial information system or an information interaction system within a financial system. As a downstream system for information interaction, it combines a data lake and a designated message cluster within the data lake to realize the storage and backup of encrypted information and receive targeted information extraction notifications pushed by the upstream system for information interaction, thereby ensuring data security when interacting with cross-institutional systems in a test environment.
[0089] It should be noted that the downstream system is a cross-organizational system of the upstream system, and an interaction relationship has been established between the upstream and downstream systems. The upstream and downstream systems with the interaction relationship use dedicated topic message containers to push messages in the designated message cluster of this embodiment of the invention.
[0090] For example, when using the Kafka distributed messaging system as the designated message cluster, the Topic logic in Kafka can be used as a dedicated topic message cluster. By utilizing the subscriber pattern, the upstream system acts as the producer, and the downstream system acts as the consumer to subscribe to the message notifications of the upstream system. In the security verification mechanism provided in this embodiment of the invention, the upstream and downstream systems need to subscribe to each other's message notifications in order to perform more rigorous interactive verification.
[0091] Step S201: Obtain information extraction notification based on the specified message cluster, wherein the information extraction notification contains at least the information type of the target information involved in this interaction process.
[0092] It should be noted that the information types include: interface call messages, contract files, and non-contract files.
[0093] Interface call messages are data packets transmitted between systems across organizations for communication and interaction. They contain information and parameters required to perform specific functions or operations. Interface call messages typically include the requested operation, input parameters, and return results. This data is usually encoded in a structured format (such as XML or JSON) so that the system can understand and process it. Testing and verifying interface call messages can focus on the following aspects: verifying the completeness and correctness of input parameters, testing boundary conditions, and simulating various possible response scenarios to ensure the system can handle them correctly.
[0094] Another point to note is that the contract file is a crucial document shared across systems within the testing environment. It defines interfaces and interaction specifications, including but not limited to API documentation, WSDL files, and Swagger documentation. The contract file contains information required for interaction between systems, such as operations, parameters, data formats, and protocols. Upstream and downstream systems in the testing environment must adhere to the dependencies defined in the contract file to ensure correct and consistent interaction.
[0095] In a testing environment, the extraction and management of contract files are crucial. The testing team needs to ensure version consistency of contract files and collaborate with the development team to update and adjust them promptly to reflect changes across systems. Additionally, the testing team can utilize automated tools to verify the consistency between contract files and the actual implementation, thereby reducing potential errors and inconsistencies.
[0096] Another point to note is that uncontractual files refer to unstructured or semi-structured files transmitted during the interaction process, such as images, videos, and PDF documents. These can contain various types of data, such as reports, pictures, and audio. For testing and verifying uncontractual files, the following aspects should be considered: ensuring file integrity and usability, verifying file format compatibility, and testing the performance of file parsing and processing.
[0097] Step S202: Access the data lake based on the information extraction notification, and obtain the encrypted information corresponding to the target information from the data lake based on the information type.
[0098] It should be noted that the encrypted information is obtained by the upstream system encrypting the target information using the downstream system's public key. Upstream and downstream systems with an interactive relationship exchange certificates, obtain each other's public keys, and store them in their respective databases. This allows them to pre-encrypt the target information using the other party's public key before transmitting it to the other party. Upon receiving the encrypted information, the receiving party can decrypt it using its own private key. Successful decryption indicates successful interaction and information exchange; failure to decrypt indicates interaction failure but no information leakage, thus maximizing data security during information exchange.
[0099] Optionally, step S202 includes: if the information type is a non-contract file, executing the cross-cutting code corresponding to the second cross-cutting concern to initiate the second interaction process; based on the second interaction process, extracting the file index from the information extraction notification, and accessing the rule execution module in the data lake based on the file index, wherein the rule execution module extracts the encrypted information corresponding to the non-contract file in the file interaction module based on the file index.
[0100] It should be noted that the file index is used to identify the source and destination systems of specific encrypted information in the interaction process. For example, system A represents the source system (i.e., the upstream system) of the encrypted information, and system B represents the destination system (i.e., the downstream system). These two systems may be located in different networks, organizations, or departments, or they may be cross-organizational systems. In the embodiments of this invention, the file index can take the form of: sender + receiver. That is, in the example above, the file index is: A+B, and the index "A+B" indicates that the encrypted information is transmitted from system A to system B. This index may be an identifier, a string, or other form of symbol used to uniquely identify this specific interaction process.
[0101] By using file indexes, the system can track and manage the transmission of encrypted information from system A to system B, enabling it to trace the flow of specific encrypted information and its transmission path within the interaction process. The file index may also contain metadata about the interaction process, such as transmission time, encryption algorithm, and encryption key, allowing the system to better manage and understand the transmission of encrypted information.
[0102] Another point to note is that the second interaction process refers to the execution process in which the upstream and downstream systems interact with non-contract documents based on their interaction relationship.
[0103] Optionally, step S202 further includes: if the information type is a contract file, executing the cross-cutting code corresponding to the second cross-cutting concern to initiate the third interaction process; parsing the first restriction rule in the information extraction notification to obtain the information fingerprint, and establishing a second restriction rule based on the information fingerprint and the second specified duration; pushing a key request notification to the upstream system based on the third interaction process, the second restriction rule, and the specified message cluster in the data lake, wherein the key request notification is used to notify the upstream system to provide the file key of the contract file within the second specified duration according to the second restriction rule; accessing the rule execution module in the data lake based on the file key, wherein the rule execution module extracts the encrypted information corresponding to the contract file in the file interaction module based on the file key.
[0104] It should be noted that, according to the contractual relationship, if the downstream system wants to extract the encrypted information corresponding to the contract file, it also needs to provide a response contract file to the upstream system. Similarly, the response contract file is encrypted using the upstream system's public key, and the second restriction rule is executed to establish a second binding relationship between the information fingerprint and the encrypted response information. The second restriction rule is then established based on the information fingerprint, the second binding relationship, and the second specified duration. The encrypted response information is transmitted to the file interaction module in the data lake, and the second restriction rule is transmitted to the rule execution module in the data lake. The second restriction rule is added to the key request notification, and the key request notification is transmitted to the designated message cluster in the data lake. The information extraction notification is pushed to the upstream system using the interaction relationship and the topic message container in the designated message cluster.
[0105] An exemplary second limiting rule provided in this embodiment of the invention is as follows: if the upstream system can provide the file key within a second specified time period, the upstream system is allowed to extract the encrypted response information from the file interaction module; if the downstream system cannot provide the file key within the second specified time period, the encrypted response information is automatically destroyed. The component that executes the above rule determination is the rule execution module in the data lake.
[0106] Step S203: Use the encryption private key of the downstream system to decrypt the encrypted information to obtain the decrypted information and complete the information exchange.
[0107] Optionally, step S203 includes: when the information type is an interface call message, calling the second cross-cutting concern pre-embedded in the downstream system; executing the cross-cutting code corresponding to the second cross-cutting concern, using the private key of the downstream system to decrypt the encrypted information to obtain message parameter information; assembling the message parameter information with the message template of the downstream database to obtain the interface call message; determining the interface call message as decrypted information, and sending the interface call message as target information to the service call platform.
[0108] In this embodiment of the invention, a security verification and information backup mechanism for information interaction in the delivery test environment is provided. When problems occur in the basic system and cross-organizational system connectivity verification cannot be performed, cross-organizational system interaction security verification can be performed through a designated message cluster and rule execution module in the data lake, thereby supplementing the security mechanism of the delivery test environment. It can also rely on the data caching performance of the data lake to achieve interactive data backup function, which facilitates information traceability.
[0109] The present invention will now be described in conjunction with another specific embodiment.
[0110] The present invention provides an exemplary implementation scenario in which the security mechanism in the delivery test environment is not as complete as that in the production environment, which makes it easy for certain confidential and private data to be leaked.
[0111] This invention provides a verification and backup mechanism for the delivery testing environment. It ensures stable operation even when inter-organizational system communication is disrupted or a bug in a module (collectively referred to as "basic system problems") prevents connectivity verification, thereby improving the data security of the testing environment across organizational systems. Furthermore, it guarantees a high level of security for testing environments with contractual relationships between inter-organizational systems.
[0112] Figure 3 This is a schematic diagram of an optional data lake-based verification and backup mechanism according to an embodiment of the present invention, such as... Figure 3 As shown, the data lake includes at least: a rule execution module and a file interaction module. The rule execution module contains a rule base. Outside the data lake, there exists at least information system A, cross-organizational system B, and a Kafka message cluster. Figure 3 In the provided test environment, A is the upstream system, B is the downstream system, and Kafka message cluster is the designated message cluster. Both A and B have pre-embedded cross-cutting concerns. Based on the pre-established interaction relationship between A and B, a Topic runs in the Kafka message cluster to provide one-to-one message push service for A and B.
[0113] exist Figure 3 Based on the provided verification and backup mechanism, this invention provides a complete information exchange method and information backup method for delivering the test environment. These are described in detail below.
[0114] Figure 4 This is a flowchart of an optional information interaction method based on a verification backup mechanism according to an embodiment of the present invention, such as... Figure 4 As shown, the method includes at least the following steps:
[0115] Step S401: Check the switching status between systems to ensure that the switching status between upstream and downstream systems meets the preset requirements.
[0116] It should be noted that the system switch status here has a similar meaning to the system cross-section status mentioned in Embodiments 1 and 2 above, both of which are used to indicate whether the pre-embedded cross-sectional interest points can be called normally.
[0117] Step S402: Execute the cross-cutting code corresponding to the cross-cutting concern through the upstream system, and encrypt the target information using the encryption public key of the downstream system to obtain encrypted information.
[0118] Step S403: Select different information interaction strategies according to the information type of the target information. The information types include: interface call messages, contract files, and non-contract files.
[0119] In step S404, when the information type is an interface call message, the first interaction strategy is selected. The encrypted information is transmitted to the designated message cluster through the upstream system, and the encrypted information is pushed to the downstream system through the designated message cluster. The downstream system uses the encryption private key to decrypt the encrypted information to obtain the target information and complete the information interaction.
[0120] In step S405, if the information type is not a contract document, the second interaction strategy is selected. The encrypted information is transmitted to the file interaction module through the upstream system, and a file index is generated. The file index is pushed to the downstream system through the specified message cluster. The downstream system accesses the file index, executes the rules, extracts the encrypted information, and decrypts the information to obtain the target information, thus completing the information interaction.
[0121] In step S406, when the information type is a contract document, the third interaction strategy is selected to generate a file key, an information fingerprint, and a first restriction rule. The encrypted information is transmitted to the file interaction module, and the first restriction rule is transmitted to the rule execution module. The information fingerprint is pushed to the downstream system through the execution message cluster. The downstream system requests the file key based on the information fingerprint, extracts the encrypted information, and decrypts the information to obtain the target information, thus completing the information interaction.
[0122] In this embodiment of the invention, a security verification and information backup mechanism for information interaction in the delivery test environment is provided. When problems occur in the basic system and cross-organizational system connectivity verification cannot be performed, cross-organizational system interaction security verification can be performed through a designated message cluster and rule execution module in the data lake, thereby supplementing the security mechanism of the delivery test environment. It can also rely on the data caching performance of the data lake to achieve interactive data backup function, which facilitates information traceability.
[0123] The invention will now be described in conjunction with another alternative embodiment.
[0124] Example 3
[0125] This embodiment provides an information interaction system for a testing environment, which includes multiple implementation components for executing the various implementation steps in Embodiment 1 or Embodiment 2 described above.
[0126] Figure 5 This is a schematic diagram of an optional information interaction system for a testing environment according to an embodiment of the present invention, such as... Figure 5 As shown, the system may include: an upstream system 51, a downstream system 52, a designated message cluster 53, and a data lake 54.
[0127] Among them, there are upstream system 51 and downstream system 52. The upstream system and the downstream system have established an interaction relationship in advance, and the downstream system is a cross-organizational system of the upstream system.
[0128] Specify message cluster 53 to run N topic message containers, where N is a positive integer. Each topic message container is used to provide one-to-one message push service to the upstream and downstream systems involved in the interaction process.
[0129] Data Lake 54 is used to back up and store the interactive data involved in all interactive processes. The data lake contains at least a rule execution module and a file interaction module. The rule execution module is connected to the rule base and is used to impose rule restrictions on upstream and downstream systems in the interactive process. The rule base is used to store the restriction rules established by upstream and downstream systems in the interactive process. The file interaction module is used to temporarily store encrypted information transmitted by upstream systems in the interactive process and transmit the encrypted information to downstream systems within the scope allowed by the restriction rules.
[0130] The aforementioned information interaction system for the test environment can provide one-to-one message push services to upstream and downstream systems involved in the interaction process through a topic message container running in a designated message cluster 53. An interaction relationship has been pre-established between the upstream system 51 and the downstream system 52, with the downstream system 52 being a cross-organizational system of the upstream system 51. All interaction data involved in the interaction process is backed up and stored through a data lake 54. The data lake 54 includes at least a rule execution module and a file interaction module. The rule execution module connects to a rule base and is used to impose rule restrictions on upstream and downstream systems during the interaction process. The rule base stores the restriction rules established by upstream and downstream systems during the interaction process. The file interaction module temporarily stores encrypted information transmitted by the upstream system 51 during the interaction process and transmits the encrypted information to the downstream system 52 within the limits allowed by the restriction rules.
[0131] The information interaction system for the testing environment provided in this embodiment of the invention is at least used to perform the following implementation steps in Embodiment 1 above:
[0132] Step S101: Determine the information type of the target information participating in this interaction process. The information type includes: interface call message, contract file and non-contract file.
[0133] Step S102: Encrypt the target information using the encryption public key of the downstream system to obtain encrypted information. The encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship.
[0134] Step S103: Based on the information type, the encrypted information is transmitted to the data lake, and an information extraction notification is sent to the downstream system based on the specified message cluster in the data lake. The information extraction notification contains at least the information type. The downstream system retrieves the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using the encryption private key to obtain the decrypted information, thus completing the information exchange.
[0135] The information interaction system for the testing environment provided in this embodiment of the invention is also used to perform at least the following implementation steps in Embodiment 2 above:
[0136] Step S201: Obtain information extraction notification based on the specified message cluster. The information extraction notification shall contain at least the information type of the target information involved in this interaction process. The information type includes: interface call message, contract file and non-contract file.
[0137] Step S202: Access the data lake based on the information extraction notification, and obtain the encrypted information corresponding to the target information from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system.
[0138] Step S203: Use the encryption private key of the downstream system to decrypt the encrypted information to obtain the decrypted information and complete the information exchange.
[0139] In this embodiment of the invention, a security verification and backup mechanism for information interaction in a test environment is proposed. The upstream system of the information interaction transmits the encrypted information obtained by encrypting the target information to the data lake according to the information type of the target information involved in the interaction. The designated message cluster in the data lake pushes the message retrieval notification to the downstream system. Compared with the prior art, the data lake can realize data storage and data backup of encrypted data during the information interaction process.
[0140] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the encryption public key of the downstream system in the upstream system's database. Before being transmitted to the data lake, the target information is encrypted using the encryption public key. After the downstream system extracts the encrypted information through the security verification of the data lake, it decrypts it using the encryption private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information.
[0141] The data lake in this invention can also perform security verification on downstream systems when they extract encrypted information. Compared with the shortcomings of insufficient security mechanisms in the test environment in the prior art, this invention can provide a supplementary security mechanism for information interaction between cross-institutional systems in the test environment, further ensuring the data security of interactive information in the test environment. This solves the technical problem in related technologies where the security mechanism is not complete when cross-institutional systems interact with information in the test environment, resulting in low data security.
[0142] Example 4
[0143] This embodiment provides an information interaction device for a testing environment, which includes multiple implementation units, each of which corresponds to a specific implementation step in Embodiment 1 above.
[0144] Figure 6 This is a schematic diagram of an optional information interaction device for a testing environment according to an embodiment of the present invention, such as... Figure 6 As shown, the device may include: a determining unit 61, an encryption unit 62, and a transmission unit 63.
[0145] The determining unit 61 is used to determine the information type of the target information participating in this interaction process. The information type includes: interface call message, contract file and non-contract file.
[0146] The encryption unit 62 is used to encrypt the target information using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship;
[0147] The transmission unit 63 is used to transmit encrypted information to the data lake based on the information type, and send an information extraction notification to the downstream system based on the specified message cluster in the data lake. The information extraction notification contains at least the information type. The downstream system obtains the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using the encryption private key to obtain the decrypted information, thus completing the information exchange.
[0148] The aforementioned information interaction device for the testing environment can first determine the information type of the target information participating in this interaction process through the determining unit 61. The information type includes: interface call message, contract file and non-contract file. Then, the encryption unit 62 uses the encryption public key of the downstream system to encrypt the target information to obtain encrypted information. The encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship. Finally, the transmission unit 63 transmits the encrypted information to the data lake based on the information type and sends an information extraction notification to the downstream system based on the designated message cluster in the data lake. The information extraction notification contains at least the information type. The downstream system retrieves the encrypted information from the data lake based on the information extraction notification and decrypts the encrypted information using the encryption private key to obtain decrypted information, thus completing the information interaction.
[0149] In this embodiment of the invention, a security verification and backup mechanism for information interaction in a test environment is proposed. The upstream system of the information interaction transmits the encrypted information obtained by encrypting the target information to the data lake according to the information type of the target information involved in the interaction. The designated message cluster in the data lake pushes the message retrieval notification to the downstream system. Compared with the prior art, the data lake can realize data storage and data backup of encrypted data during the information interaction process.
[0150] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the downstream system's encrypted public key in its database. Before being transmitted to the data lake, the target information is encrypted using the encrypted public key. After the downstream system extracts the encrypted information through the data lake's security verification, it decrypts it using the encrypted private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information, thereby solving the technical problem in related technologies where the security mechanism is not complete enough when cross-institutional systems exchange information in the test environment, resulting in low data security.
[0151] Optionally, a designated message cluster in the data lake is used to run N topic message containers, where N is a positive integer. Each topic message container corresponds to an interaction relationship and, based on the interaction relationship, provides point-to-point message push services to the upstream and downstream systems involved in that interaction relationship.
[0152] Optionally, the information interaction device for the test environment further includes: a first determining module, used to determine the system aspect status of the upstream system and the downstream system, wherein the system aspect status is used to indicate whether the cross-cutting concerns embedded in the system can be called normally, and the cross-cutting concerns are used to execute cross-cutting code and start the interaction process when a specified call signal is received without affecting the original system logic; a first execution module, used to continue executing the step of determining the information type of the target information participating in this interaction process when the system aspect status of both the upstream system and the downstream system is in the open state; a changing module, used to change the system aspect status to the open state when the system aspect status of the upstream system is in the closed state; and a first push module, used to push a status change notification to the downstream system through a topic message container in a specified message cluster when the system aspect status of the downstream system is in the closed state, wherein the status change notification is used to notify the upstream system to change the system aspect status to the open state.
[0153] Optionally, the transmission unit includes: a first invocation module, used to invoke a first cross-cutting concern pre-embedded in the upstream system when the information type is an interface invocation message; a second execution module, used to execute the cross-cutting code corresponding to the first cross-cutting concern and initiate a first interaction process; a first addition module, used to add encrypted information to the information extraction notification based on the first interaction process and transmit the information extraction notification to a designated message cluster in the data lake; and a second push module, used to push the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
[0154] Optionally, the transmission unit further includes: a first transmission module, used to transmit encrypted information to a file interaction module in the data lake when the information type is a non-contract file; an acquisition module, used to acquire the file index of the non-contract file indicated by the encrypted information based on the file interaction module, wherein the file index is used to identify the upstream and downstream systems involved in the interaction process of the encrypted information; a second invocation module, used to invoke a first cross-cutting concern pre-embedded in the upstream system and execute the cross-cutting code corresponding to the first cross-cutting concern to start the second interaction process; a second addition module, used to add the file index to the information extraction notification based on the second interaction process and transmit the information extraction notification to a designated message cluster in the data lake; and a third push module, used to push the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
[0155] Optionally, the transmission unit further includes: a generation module, used to generate a file key for the contract file indicated by the encrypted information when the information type is a contract file; a calculation module, used to calculate an information fingerprint of the encrypted information based on the file key and a preset irreversible algorithm, wherein the information fingerprint is used to uniquely identify the encrypted information through a fixed-length sequence; an establishment module, used to establish a first binding relationship between the information fingerprint and the encrypted information, and establish a first restriction rule based on the information fingerprint, the first binding relationship, and a first specified duration; a second transmission module, used to transmit the encrypted information to the file interaction module in the data lake, and transmit the first restriction rule to the rule execution module in the data lake; a third invocation module, used to invoke a first cross-cutting concern pre-embedded in the upstream system, execute the cross-cutting code corresponding to the first cross-cutting concern, and initiate a third interaction process; a third addition module, used to add the first restriction rule to the information extraction notification based on the third interaction process, and transmit the information extraction notification to a designated message cluster in the data lake; and a fourth push module, used to push the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
[0156] Optionally, the transmission unit further includes a receiving module, configured to receive a key request notification pushed by the topic message container, wherein the key request notification is used to notify the upstream system to provide the file key of the contract document to the downstream system within a second specified time period according to the second restriction rule, the second specified time period being less than the first specified time period.
[0157] The aforementioned information interaction device for the testing environment may also include a processor and a memory. The aforementioned determining unit 61, encryption unit 62, transmission unit 63, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0158] The aforementioned processor contains a kernel, which retrieves the corresponding program unit from memory. One or more kernels can be configured, and by adjusting kernel parameters, the target information can be encrypted using the downstream system's public key. The encrypted information is then transmitted to the data lake based on the information type, and an information retrieval notification is sent to the downstream system based on a specified message cluster within the data lake.
[0159] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0160] Example 5
[0161] This embodiment provides an information interaction device for a testing environment, which includes multiple implementation units, each of which corresponds to a specific implementation step in Embodiment 2 above.
[0162] Figure 7 This is a schematic diagram of another optional information interaction device for a testing environment according to an embodiment of the present invention, such as... Figure 7 As shown, the device may include: an acquisition unit 71, an access unit 72, and a decryption unit 73.
[0163] The acquisition unit 71 is used to acquire information extraction notification based on a specified message cluster. The information extraction notification contains at least the information type of the target information involved in this interaction process. The information type includes: interface call message, contract file and non-contract file.
[0164] Access unit 72 is used to access the data lake based on information extraction notification and to obtain the encrypted information corresponding to the target information from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system.
[0165] The decryption unit 73 is used to decrypt the encrypted information using the encryption private key of the downstream system, obtain the decrypted information, and complete the information exchange.
[0166] The aforementioned information interaction device for the testing environment can first obtain an information extraction notification based on a specified message cluster through the acquisition unit 71. The information extraction notification contains at least the information type of the target information involved in this interaction process. The information type includes: interface call message, contract file, and non-contract file. Then, the access unit 72 accesses the data lake based on the information extraction notification and obtains the encrypted information corresponding to the target information from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system. Finally, the decryption unit 73 decrypts the encrypted information using the encryption private key of the downstream system to obtain the decrypted information, thus completing the information interaction.
[0167] In this embodiment of the invention, a security verification and backup mechanism for information interaction in a test environment is proposed. It receives message extraction notifications pushed from a designated message cluster in a data lake to downstream systems. Through the data lake, security verification can be performed on downstream systems when they extract encrypted information. Furthermore, it enables data storage and backup of encrypted data during information interaction. Compared to the shortcomings of incomplete security mechanisms in existing technologies for test environments, this invention provides a supplementary security mechanism for information interaction between cross-organizational systems in test environments, further ensuring the data security of interactive information in the test environment. This solves the technical problem of low data security caused by incomplete security mechanisms when cross-organizational systems interact in test environments in related technologies.
[0168] In this invention, the upstream system, which has a pre-established interactive relationship with the downstream system, also pre-stores the encryption public key of the downstream system in the upstream system's database. Before being transmitted to the data lake, the target information is encrypted using the encryption public key. After the downstream system extracts the encrypted information through the security verification of the data lake, it decrypts it using the encryption private key to obtain the target information and complete the information exchange. The above encryption and decryption mechanism further ensures the data security of the target information.
[0169] Optionally, the decryption unit includes: a fourth invocation module, used to invoke a second cross-cutting concern pre-embedded in the downstream system when the information type is an interface call message; a decryption module, used to execute the cross-cutting code corresponding to the second cross-cutting concern, and use the private key of the downstream system to decrypt the encrypted information to obtain message parameter information; an assembly module, used to assemble the message parameter information with the message template of the downstream database to obtain the interface call message; and a second determination module, used to determine the interface call message as decrypted information and send the interface call message as target information to the service invocation platform.
[0170] Optionally, the access unit includes: a third execution module, used to execute the cross-cutting code corresponding to the second cross-cutting concern and initiate the second interaction process when the information type is not a contract file; and an extraction module, used to extract the file index in the information extraction notification based on the second interaction process, and access the rule execution module in the data lake based on the file index, wherein the rule execution module extracts the encrypted information corresponding to the non-contract file in the file interaction module based on the file index.
[0171] Optionally, the access unit further includes: a fourth execution module, used to execute the cross-cutting code corresponding to the second cross-cutting concern and initiate the third interaction process when the information type is a contract file; a parsing module, used to parse the first restriction rule in the information extraction notification, obtain the information fingerprint, and establish a second restriction rule based on the information fingerprint and the second specified duration; a fifth push module, used to push a key request notification to the upstream system based on the third interaction process, the second restriction rule, and the specified message cluster in the data lake, wherein the key request notification is used to notify the upstream system to provide the file key of the contract file within the second specified duration according to the second restriction rule; and an access module, used to access the rule execution module in the data lake based on the file key, wherein the rule execution module extracts the encrypted information corresponding to the contract file in the file interaction module based on the file key.
[0172] The aforementioned information interaction device for the testing environment may also include a processor and a memory. The aforementioned acquisition unit 71, access unit 72, decryption unit 73, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0173] The aforementioned processor contains a kernel, which retrieves the corresponding program unit from memory. One or more kernels can be configured, and by adjusting kernel parameters, the target information can be encrypted using the downstream system's public key. The encrypted information is then transmitted to the data lake based on the information type, and an information retrieval notification is sent to the downstream system based on a specified message cluster within the data lake.
[0174] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0175] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program with the following method steps: determining the information type of the target information participating in this interaction process, wherein the information type includes: interface call message, contract file, and non-contract file; encrypting the target information using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship; transmitting the encrypted information to the data lake based on the information type, and sending an information extraction notification to the downstream system based on a specified message cluster in the data lake, wherein the information extraction notification contains at least the information type; the downstream system retrieves the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using the encryption private key to obtain decrypted information, thus completing the information interaction.
[0176] Alternatively, information extraction notifications can be obtained based on a specified message cluster. These notifications must contain at least the information type of the target information involved in this interaction process. The information type includes: interface call messages, contract files, and non-contract files. The data lake is accessed based on the information extraction notifications, and the encrypted information corresponding to the target information is retrieved from the data lake based on the information type. The encrypted information is obtained by encrypting the target information using the encryption public key of the downstream system. The encrypted information is then decrypted using the encryption private key of the downstream system to obtain the decrypted information, thus completing the information interaction.
[0177] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the information interaction method for a test environment described in either Embodiment 1 or Embodiment 2 above.
[0178] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the information interaction method for a test environment as described in either Embodiment 1 or Embodiment 2 above.
[0179] Figure 8 This is a hardware structure block diagram of an electronic device (or mobile device) for an information interaction method in a testing environment according to an embodiment of the present invention. Figure 8 As shown, an electronic device may include one or more ( Figure 8The processor 802 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 804 for storing data may also be included. In addition, it may include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 8 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, the electronic device may also include components that are more... Figure 8 The more or fewer components shown, or having the same Figure 8 The different configurations shown.
[0180] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0181] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0182] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.
[0183] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0184] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0185] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0186] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for information interaction in a test environment, characterized in that, An upstream system applied to information exchange, wherein an interaction relationship has been pre-established between the upstream system and a downstream system, and the downstream system is a cross-institutional system of the upstream system, the method includes: The information types of the target information participating in this interaction process are determined, wherein the information types include: interface call messages, contract files, and non-contract files; The target information is encrypted using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship; The encrypted information is transmitted to the data lake based on the information type, and an information extraction notification is sent to the downstream system based on the designated message cluster in the data lake. The information extraction notification contains at least the information type. The downstream system obtains the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using the encryption private key to obtain decrypted information, thus completing the information interaction. The steps of transmitting the encrypted information to the data lake based on the information type and sending an information retrieval notification to the downstream system based on the designated message cluster in the data lake further include: In the case where the information type is the non-contract file, the encrypted information is transmitted to the file interaction module in the data lake; The file index of the non-contract file indicated by the encrypted information is obtained based on the file interaction module, wherein the file index is used to identify the upstream and downstream systems of the interaction process involved in the encrypted information; Invoke the first cross-cutting concern pre-embedded in the upstream system, execute the cross-cutting code corresponding to the first cross-cutting concern, and start the second interaction process; Based on the second interaction process, the file index is added to the information extraction notification, and the information extraction notification is transmitted to the designated message cluster of the data lake; Using the interaction relationship and the topic message container in the specified message cluster, the information extraction notification is pushed to the downstream system.
2. The information interaction method according to claim 1, characterized in that, The designated message cluster in the data lake is used to run N topic message containers, where N is a positive integer. Each topic message container corresponds to one of the interaction relationships, and based on the interaction relationship, it provides point-to-point message push services to the upstream and downstream systems involved in the interaction relationship.
3. The information interaction method according to claim 1, wherein, Before determining the type of information being used in this interaction, the following steps are also included: Determine the system aspect status of the upstream system and the downstream system, wherein the system aspect status is used to indicate whether the cross-cutting concerns embedded in the system can be called normally, and the cross-cutting concerns are used to execute cross-cutting code and start the interaction process when a specified call signal is noticed without affecting the original system logic; If both the upstream and downstream systems are in the enabled state, continue executing the step of determining the information type of the target information participating in this interaction process; or, When the system aspect state of the upstream system is in the closed state, the system aspect state is changed to the open state; When the system aspect status of the downstream system is in the closed state, a status change notification is pushed to the downstream system through the topic message container in the designated message cluster, wherein the status change notification is used to notify the upstream system to change the system aspect status to the open state.
4. The information interaction method according to claim 1, characterized in that, The steps of transmitting the encrypted information to the data lake based on the information type, and sending an information retrieval notification to the downstream system based on the designated message cluster in the data lake, include: When the information type is the interface call message, the first cross-cutting concern pre-embedded in the upstream system is invoked. Execute the cross-cutting code corresponding to the first cross-cutting concern to initiate the first interaction process; Based on the first interaction process, the encrypted information is added to the information extraction notification, and the information extraction notification is transmitted to the designated message cluster of the data lake; Using the interaction relationship and the topic message container in the specified message cluster, the information extraction notification is pushed to the downstream system.
5. The information interaction method according to claim 1, wherein, The steps of transmitting the encrypted information to the data lake based on the information type and sending an information retrieval notification to the downstream system based on the designated message cluster in the data lake further include: In the case where the information type is the contract file, generate the file key of the contract file indicated by the encrypted information; The information fingerprint of the encrypted information is calculated based on the file key and a preset irreversible algorithm, wherein the information fingerprint is used to uniquely identify the encrypted information through a fixed-length sequence of numbers; Establish a first binding relationship between the information fingerprint and the encrypted information, and establish a first restriction rule based on the information fingerprint, the first binding relationship, and a first specified duration; The encrypted information is transmitted to the file interaction module in the data lake, and the first restriction rule is transmitted to the rule execution module in the data lake; Invoke the first cross-cutting concern pre-embedded in the upstream system, execute the cross-cutting code corresponding to the first cross-cutting concern, and start the third interaction process; Based on the third interaction process, the first restriction rule is added to the information extraction notification, and the information extraction notification is transmitted to the designated message cluster of the data lake; Using the interaction relationship and the topic message container in the specified message cluster, the information extraction notification is pushed to the downstream system.
6. The information interaction method according to claim 5, characterized in that, After pushing the information extraction notification to the downstream system, the process also includes: Receive a key request notification pushed by the topic message container, wherein the key request notification is used to notify the upstream system to provide the file key of the contract file to the downstream system within a second specified time period according to a second restriction rule, wherein the second specified time period is less than the first specified time period.
7. A method of information interaction for a test environment, characterized by, A downstream system applied to information interaction, wherein the downstream system and the upstream system have a pre-established interaction relationship, and the upstream system is a cross-institutional system of the downstream system, the method includes: Information extraction notifications are obtained based on a specified message cluster, wherein the information extraction notifications contain at least the information types of the target information involved in this interaction process, and the information types include: interface call messages, contract files, and non-contract files; Access the data lake based on the information extraction notification, and obtain the encrypted information corresponding to the target information from the data lake based on the information type. The encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system. The encrypted information is decrypted using the encryption private key of the downstream system to obtain the decrypted information, thus completing the information exchange. The step of obtaining the encrypted information corresponding to the target information from the data lake based on the information type includes: If the information type is a non-contract file, execute the cross-cutting code corresponding to the second cross-cutting concern to initiate the second interaction process; Based on the second interaction process, the file index in the information extraction notification is extracted, and the rule execution module in the data lake is accessed based on the file index. The rule execution module extracts the encrypted information corresponding to the non-contract file in the file interaction module based on the file index.
8. The information interaction method according to claim 7, characterized in that, The steps of decrypting the encrypted information using the encryption private key of the downstream system to obtain decrypted information include: When the information type is the interface call message, the second cross-cutting concern pre-embedded in the downstream system is invoked; Execute the cross-cutting code corresponding to the second cross-cutting concern, and use the private key of the downstream system to decrypt the encrypted information to obtain message parameter information; The message parameter information is combined with the message template of the downstream database to obtain the interface call message; The interface call message is identified as the decryption information, and the interface call message is sent to the service call platform as the target information.
9. The information interaction method according to claim 7, characterized in that, The step of obtaining the encrypted information corresponding to the target information from the data lake based on the information type further includes: If the information type is the contract file, execute the cross-cutting code corresponding to the second cross-cutting concern and initiate the third interaction process; The first restriction rule in the information extraction notification is parsed to obtain the information fingerprint, and a second restriction rule is established based on the information fingerprint and the second specified duration. Based on the third interaction process, the second restriction rule, and the designated message cluster in the data lake, a key request notification is pushed to the upstream system, wherein the key request notification is used to notify the upstream system to provide the file key of the contract file within a second specified time period according to the second restriction rule; Access the rule execution module in the data lake based on the file key, wherein the rule execution module extracts the encrypted information corresponding to the contract file in the file interaction module based on the file key.
10. An information interaction system for a testing environment, characterized in that, The system comprising the information interaction method for a test environment according to any one of claims 1 to 6 or 7 to 9, wherein the system includes: Upstream system and downstream system, wherein an interaction relationship has been established between the upstream system and the downstream system in advance, and the downstream system is a cross-organizational system of the upstream system; A designated message cluster is used to run N topic message containers, where N is a positive integer. Each topic message container is used to provide one-to-one message push service to the upstream and downstream systems involved in the interaction process. A data lake is used to back up and store the interaction data involved in all the aforementioned interaction processes. The data lake includes at least a rule execution module and a file interaction module. The rule execution module is connected to a rule base and is used to impose rule restrictions on upstream and downstream systems during the interaction process. The rule base is used to store the restriction rules established by the upstream and downstream systems during the interaction process. The file interaction module is used to temporarily store encrypted information transmitted by the upstream system during the interaction process, and to transmit the encrypted information to the downstream system within the scope permitted by the restriction rules.
11. An information interaction device for a testing environment, characterized in that, An upstream system for information interaction, wherein an interaction relationship has been pre-established between the upstream system and a downstream system, and the downstream system is a cross-institutional system of the upstream system, the device comprising: The determining unit is used to determine the information type of the target information participating in this interaction process, wherein the information type includes: interface call message, contract file and non-contract file; An encryption unit is used to encrypt the target information using the encryption public key of the downstream system to obtain encrypted information, wherein the encryption public key of the downstream system is pre-stored in the database of the upstream system based on the interaction relationship; A transmission unit is configured to transmit the encrypted information to the data lake based on the information type, and send an information extraction notification to the downstream system based on a designated message cluster in the data lake. The information extraction notification includes at least the information type. The downstream system obtains the encrypted information from the data lake based on the information extraction notification, and decrypts the encrypted information using an encryption private key to obtain decrypted information, thus completing the information interaction. The transmission unit further includes: a first transmission module, used to transmit encrypted information to a file interaction module in the data lake when the information type is a non-contract file; an acquisition module, used to acquire the file index of the non-contract file indicated by the encrypted information based on the file interaction module, wherein the file index is used to identify the upstream and downstream systems involved in the interaction process of the encrypted information; a second invocation module, used to invoke a first cross-cutting concern pre-embedded in the upstream system and execute the cross-cutting code corresponding to the first cross-cutting concern to start the second interaction process; a second addition module, used to add the file index to the information extraction notification based on the second interaction process and transmit the information extraction notification to a designated message cluster in the data lake; and a third push module, used to push the information extraction notification to the downstream system using the interaction relationship and the topic message container in the designated message cluster.
12. An information interaction device for a testing environment, characterized in that, A downstream system for information interaction, wherein the downstream system and the upstream system have a pre-established interaction relationship, and the upstream system is a cross-institutional system of the downstream system, the device comprising: The acquisition unit is used to acquire information extraction notifications based on a specified message cluster. The information extraction notifications contain at least the information types of the target information involved in the current interaction process. The information types include: interface call messages, contract files, and non-contract files. An access unit is configured to access the data lake based on the information extraction notification, and to obtain encrypted information corresponding to the target information from the data lake based on the information type, wherein the encrypted information is obtained by the upstream system encrypting the target information based on the encryption public key of the downstream system; The decryption unit is used to decrypt the encrypted information using the encryption private key of the downstream system to obtain decrypted information and complete the information exchange. The access unit includes: a third execution module, used to execute the cross-cutting code corresponding to the second cross-cutting concern and initiate the second interaction process when the information type is a non-contract file; and an extraction module, used to extract the file index in the information extraction notification based on the second interaction process, and access the rule execution module in the data lake based on the file index, wherein the rule execution module extracts the encrypted information corresponding to the non-contract file in the file interaction module based on the file index.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the information interaction method for a test environment as described in any one of claims 1 to 6 or claims 7 to 9.
14. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the information interaction method for a test environment as described in any one of claims 1 to 6 or 7 to 9.
Citation Information
Patent Citations
Enterprise operation data management method and device, computer equipment and storage medium
CN116628088A