Data processing method, apparatus, device, medium, and program product

By automatically encrypting sensitive data using a sensitivity detection model and software development kit before interface calls, the problem of sensitive data not being encrypted in a timely manner in existing technologies is solved, achieving real-time, automatic protection and security of sensitive data.

CN118316999BActive Publication Date: 2025-12-05INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410417650.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-08
Publication Date
2025-12-05
Estimated Expiration
2044-04-08

AI Technical Summary

Technical Problem

In existing technologies, it is difficult for applications to fully cover all encryption-related interfaces when performing complex operations, resulting in sensitive data not being encrypted in a timely manner. Furthermore, code repair and version updates are subject to time delays and complexities, making it impossible to effectively protect the security of sensitive data.

Method used

Before issuing a request to the target interface, the interface sequence is analyzed using a pre-trained sensitivity detection model to extract feature vectors, determine whether sensitive data is involved, and automatically encrypt sensitive data when it is not encrypted. The encryption algorithm is encapsulated using a software development kit to achieve automatic encryption repair.

Benefits of technology

It enables real-time, automatic protection of sensitive data, and can automatically identify and encrypt sensitive data when the interface is updated or changed, ensuring data transmission security and reducing manual intervention and delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118316999B_ABST
    Figure CN118316999B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data processing method, relating to the fields of artificial intelligence and information security. The method comprises: in response to a request that an application is about to call a target interface, obtaining an interface sequence called by the application, the interface sequence comprising information of the target interface and called interfaces; extracting a first feature vector of the interface sequence; inputting the first feature vector into a pre-trained sensitive detection model to obtain a sensitive detection result; when the sensitive detection result is sensitive and sensitive data in the request is not encrypted, encrypting the sensitive data, and the application is configured to send the encrypted request to call the target interface. The present disclosure also provides a data processing apparatus, device, storage medium and program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of artificial intelligence and information security, and more specifically, to a data processing method, apparatus, device, medium, and program product. Background Technology

[0002] With increasing emphasis on personal information protection, the security risks of transmitting sensitive user data in plaintext over the network are also drawing growing attention. Related technologies typically involve pre-testing all API calls made by the application to determine if any calls involve sensitive data, thus deciding whether the transmitted data should be encrypted. However, fixing these issues relies on developers modifying code and pushing out version updates to mitigate potential sensitive data leaks.

[0003] In realizing the inventive concept disclosed herein, the inventors discovered that when applications perform complex operations, the interface sequence is large and may involve multiple encryption and decryption operations. During testing, it is difficult to comprehensively cover all encryption-related interfaces, and it is difficult to determine whether all sensitive data involved is encrypted. Furthermore, code modifications and version updates have a certain time delay and are subject to limitations imposed by multiple code repositories, dependencies, and environments. Therefore, related technologies do not provide comprehensive and timely protection for sensitive data. Summary of the Invention

[0004] In view of the above problems, this disclosure provides data processing methods, apparatus, devices, media and program products.

[0005] According to a first aspect of this disclosure, a data processing method is provided, characterized by comprising: in response to a request from an application to call a target interface, obtaining a sequence of interfaces called by the application, the sequence of interfaces including information about the target interface and the interfaces already called; extracting a first feature vector from the sequence of interfaces; inputting the first feature vector into a pre-trained sensitivity detection model to obtain a sensitivity detection result; when the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, encrypting the sensitive data, wherein the application is configured to send the encrypted request to call the target interface.

[0006] According to an embodiment of this disclosure, the application includes a client, which initiates the request in response to a user's operation on its front-end interface. Obtaining the sequence of interfaces called by the application includes: in response to the client's request to call the target interface, extracting a second feature vector of the front-end interface; inputting the second feature vector into the sensitivity detection model to obtain an interface detection result; and when the interface detection result indicates that the front-end interface is related to a sensitive operation, obtaining the sequence of interfaces called by the application.

[0007] According to an embodiment of this disclosure, extracting the second feature vector of the front-end interface includes: extracting the second feature vector based on at least one of the preset sensitive identifiers, interface layout, interface content, and interface code structure of the front-end interface.

[0008] According to an embodiment of this disclosure, extracting the first feature vector of the interface sequence includes: extracting the first feature vector based on at least one of the description information of the target interface, the request message, the description information of each of the invoked interfaces, and the historical request message of each of the invoked interfaces.

[0009] According to embodiments of this disclosure, the client integrates a pre-packaged software development kit, and the sensitivity detection model is encapsulated within the software development kit.

[0010] According to embodiments of this disclosure, encrypting the sensitive data includes: instructing the software development kit to call a pre-packaged encryption algorithm to encrypt the sensitive data.

[0011] According to an embodiment of this disclosure, the request originates in a production environment. Before obtaining the sequence of interfaces called by the application in response to a request from the application to call a target interface, the method further includes: obtaining a business test message of the application in a test environment, wherein the business test message is obtained based on any one of the interfaces in the application call interface set, the interface set including at least one interface called by the application in the production environment; performing sensitive field detection on the business test message; and integrating the software development kit on the client when a sensitive field is detected in the business test message.

[0012] According to an embodiment of this disclosure, the sensitivity detection model is constructed based on a machine learning algorithm. Pre-training the sensitivity detection model includes: determining a training dataset, the training dataset including at least one pair of interface sequence samples and sensitivity labels, the sensitivity labels being used to characterize whether the corresponding interface sequence samples involve sensitive data; and training the sensitivity detection model using the training dataset.

[0013] Another aspect of this disclosure provides a data processing apparatus, characterized in that it includes: an interface sequence module, configured to obtain an interface sequence to be called by the application in response to a request from an application to call a target interface, the interface sequence including information about the target interface and the interfaces already called; a feature vector module, configured to extract a first feature vector from the interface sequence; a sensitivity detection module, configured to input the first feature vector into a pre-trained sensitivity detection model to obtain a sensitivity detection result; and a data encryption module, configured to encrypt the sensitive data when the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, wherein the application is configured to send the encrypted request to call the target interface.

[0014] Another aspect of this disclosure provides an electronic device, including: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the method as described above.

[0015] Another aspect of this disclosure provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, causes the processor to perform the method described above.

[0016] Another aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the method described above.

[0017] The above one or more embodiments have the following beneficial effects: Before issuing a request to call the target interface, the interface sequence is analyzed using a sensitivity detection model to determine whether the target interface involves sensitive data. If the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, encryption repair can be automatically performed without manual intervention. Therefore, it is possible to monitor and protect the security of sensitive data in real time and automatically. Even when the interface is updated or changed, sensitive data can be automatically identified and encrypted through feature vector extraction and intelligent analysis by the sensitivity detection model, ensuring the security of data during transmission. Attached Figure Description

[0018] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0019] Figure 1 This diagram illustrates an application scenario of data processing according to embodiments of the present disclosure.

[0020] Figure 2a and Figure 2b A schematic visualization of a user interaction according to an embodiment of the present disclosure is shown.

[0021] Figure 3 A flowchart illustrating a data processing method according to an embodiment of the present disclosure is shown schematically.

[0022] Figure 4 A flowchart illustrating the process of obtaining an interface sequence of application calls according to an embodiment of this disclosure is shown schematically.

[0023] Figure 5 This schematically illustrates a front-end and back-end architecture diagram integrating software development tools according to an embodiment of the present disclosure;

[0024] Figure 6 A flowchart illustrating a test according to an embodiment of the present disclosure is shown schematically;

[0025] Figure 7 A flowchart illustrating a training process according to an embodiment of the present disclosure is shown schematically;

[0026] Figure 8 A flowchart illustrating a data processing method according to another embodiment of the present disclosure is shown schematically;

[0027] Figure 9 A schematic block diagram of a data processing apparatus according to an embodiment of the present disclosure is shown.

[0028] Figure 10 A block diagram schematically illustrates an electronic device suitable for implementing a data processing method according to an embodiment of the present disclosure. Detailed Implementation

[0029] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0030] In the technical solution of this invention, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0031] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this invention offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0032] In related technologies, one approach to detecting sensitive data in applications is to pre-test the API (Application Programming Interface) sequence for encryption-related API calls to determine if the sensitive data is encrypted. However, during complex operations, the API sequence can be large and may involve multiple encryption / decryption operations, resulting in excessive computation and difficulty in accurately and quickly determining whether sensitive data is encrypted. Therefore, this approach suffers from incomplete testing scope.

[0033] However, relying on developers to modify code and push out version updates to fix issues also has some drawbacks and challenges:

[0034] 1. Fixing issues requires developers to modify code, update versions, and release them, which typically involves a time delay. During this period, sensitive data issues may persist and could lead to potential security risks. Furthermore, interface updates or API sequence changes may occur.

[0035] 2. Version updates and patch pushes may involve coordinating multiple codebases, dependencies, and environments. In complex application and infrastructure environments, version conflicts and deployment complexities can lead to difficulties and delays in the patching process.

[0036] This disclosure proposes a data processing method in some embodiments. Before issuing a request to call a target interface, a sensitivity detection model is used to analyze the interface sequence to determine whether the target interface involves sensitive data. If the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, encryption repair can be automatically performed without manual intervention. Therefore, it can monitor and protect the security of sensitive data in real time and automatically. Even when the interface is updated or changed, sensitive data can be automatically identified and encrypted through feature vector extraction and intelligent analysis by the sensitivity detection model, ensuring data security during transmission.

[0037] Figure 1The diagram illustrates an application scenario of data processing according to embodiments of the present disclosure. It should be noted that... Figure 1 The examples shown are merely examples to illustrate the application of the embodiments of this disclosure, in order to help those skilled in the art understand the technical content of this disclosure. However, they do not mean that the embodiments of this disclosure cannot be used in other devices, systems, environments, or scenarios.

[0038] like Figure 1 As shown, application scenario 100 according to this embodiment may include terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 serves as a medium for providing a communication link between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0039] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0040] Terminal devices 101, 102, and 103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0041] Server 105 can be a server providing various services, such as a backend management server supporting websites browsed by users using terminal devices 101, 102, and 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices. For example, server 105 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud computing, network services, and middleware services.

[0042] In applications such as client applications and web applications (abbreviated as APP), the client (i.e., the front end) and the server (i.e., the back end) can communicate data via network messages. For example, in the APP client, parameters that the server needs to obtain from the client are assembled and sent to the server by calling a network request method. For example, the data processing method disclosed herein can be applied to the protection of sensitive data during the process of a client calling an interface from the server.

[0043] The data processing method provided in this disclosure can generally be executed by at least one of a terminal device or a server. Accordingly, the data processing apparatus provided in this disclosure can generally be disposed in at least one of a terminal device or a server.

[0044] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0045] The following will be based on Figure 1 The scene described is illustrated in Figure 2. Figure 8 The data processing method of the embodiments of this disclosure will be described in detail.

[0046] Figure 2a and Figure 2b A schematic visualization of a user interaction according to an embodiment of the present disclosure is shown. Figure 3 A flowchart illustrating a data processing method according to an embodiment of the present disclosure is shown schematically.

[0047] Figure 3 A flowchart illustrating a data processing method according to an embodiment of the present disclosure is shown schematically.

[0048] like Figure 3 As shown, this embodiment includes:

[0049] In operation S310, in response to a request from the application to call a target interface, the sequence of interfaces to be called by the application is obtained. The sequence of interfaces includes information about the target interface and the interfaces that have been called.

[0050] For example, an interface sequence includes the order and information of a series of interface calls made by an application during execution. For instance, a payment program might first call the login interface, then the verification interface, then the balance query interface, and finally the payment interface. This series of interface calls constitutes an interface sequence. The target interface is the interface to be called, and the already called interfaces are those that precede the target interface and belong to the same call chain. There can be zero or one or more already called interfaces. The behavior of the application calling the target interface can be obtained through bytecode instrumentation, instrumentation, etc., and information about the already called interfaces can be recorded.

[0051] During operation S320, the first feature vector of the interface sequence is extracted;

[0052] The first feature vector comprises a mathematical representation extracted from the interface sequence, which contains explicit or implicit information about the interface sequence for subsequent sensitive detection tasks.

[0053] In some embodiments, extracting the first feature vector of the interface sequence includes: extracting the first feature vector based on at least one of the following: the description information of the target interface, the request message, the description information of each invoked interface, and the historical request message of each invoked interface.

[0054] For example, the description information of the target interface includes information such as the interface name, function, parameters, and usage method. For instance, the description information of a payment interface might include the API URL, required parameter fields such as amount and payee information, and return value. The request message includes the data packet sent to the interface, which may include the request method (such as GET or POST), request headers, and request body. For instance, the HTTP request message might contain the transaction amount and target account that the user wants to send to the payment interface. The description information of the invoked interfaces includes descriptions of the interfaces that have already been invoked, including the function and invocation method of each interface. For instance, in the operation of checking the balance after a user logs in, both the login and balance query interfaces have corresponding description information. The historical request messages of the invoked interfaces include data packets of previous requests to specific interfaces.

[0055] For example, in a payment event, the description information of the payment interface, the submitted payment message, the information and messages of the previously called login interface may be obtained in combination to reflect the usage patterns and behavioral characteristics of the interface from different perspectives. Feature vectors can be extracted from these to be used for subsequent sensitivity detection and to provide data support for the sensitivity detection model.

[0056] According to embodiments of this disclosure, by combining information from the target interface and the invoked interfaces, feature vectors can be comprehensively extracted, which helps the model to more accurately identify and prevent potential risks of sensitive data leakage.

[0057] In operation S330, the first feature vector is input into the pre-trained sensitive detection model to obtain the sensitive detection result;

[0058] Sensitivity detection models include pre-trained artificial intelligence models designed to identify whether an interface involves sensitive data. For example, machine learning models are trained to detect and identify whether an interface whose input parameters include fields of personal identification information (such as ID card numbers, phone numbers, etc.) involves sensitive data. The sensitivity detection result refers to the output generated by the sensitivity detection model after processing the first feature vector, indicating whether the interface involves sensitive data.

[0059] Sensitive data can include sensitive personal information, personal information, or privacy information. This refers to personal information that, if leaked or illegally used, could easily infringe upon the personal dignity of a natural person or endanger their personal or property safety. This includes biometric information, religious beliefs, specific identity, medical and health information, financial accounts, location tracking, and the personal information of minors under the age of fourteen. Sensitive data refers to information that requires protection, such as login credentials, personally identifiable information, and payment information. (See reference...) Figure 2a and Figure 2b The account numbers and passwords that users enter in mobile banking applications are sensitive data.

[0060] When operating S340, if the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, the sensitive data is encrypted, and the application is configured to send the encrypted request to call the target interface.

[0061] For example, in banking systems, users' personal and financial information is highly sensitive. Suppose a user conducts various financial transactions through a mobile banking app. After entering the app, the user might perform a transfer. After filling in the transfer information and clicking the "transfer" button, the mobile banking app can obtain the sequence of API calls, including login, account balance check, and transfer request initiation APIs. Next, the app extracts feature vectors from these API calls, which may include the call time, order, and relationships between the APIs. This first feature vector is then input into a pre-trained sensitivity detection model. If the sensitivity detection result is sensitive, the request contains unencrypted sensitive data such as the user's biometric information. The mobile banking app automatically encrypts this data before sending the request. Even if new APIs are added to the banking system, or new data fields are added to existing APIs, the automated sensitivity detection and encryption process ensures the security of user information.

[0062] According to embodiments of this disclosure, before issuing a request to call a target interface, a sensitivity detection model is used to analyze the interface sequence to determine whether the target interface involves sensitive data. If the sensitivity detection result indicates sensitivity, and the sensitive data in the request is not encrypted, encryption and repair can be automatically performed without manual intervention. Therefore, it is possible to monitor and protect the security of sensitive data in real time and automatically. Even when the interface is updated or changed, sensitive data can be automatically identified and encrypted through feature vector extraction and intelligent analysis by the sensitivity detection model, ensuring data security during transmission.

[0063] Figure 4 A flowchart illustrating the process of obtaining an interface sequence of application calls according to an embodiment of this disclosure is shown.

[0064] The application includes a client, which responds to user actions on its front-end interface by initiating requests, such as... Figure 4 As shown, this embodiment is one example of operation S210, including:

[0065] When operating S410, in response to a client's request to call the target interface, the second feature vector of the front-end interface is extracted;

[0066] The front-end interface includes the part of the screen that users can see and interact with using the client, and typically includes elements such as buttons, text boxes, and images. For example, Figure 2b The login page for the online banking application is where users enter their account number and password.

[0067] In some embodiments, extracting the second feature vector of the front-end interface includes: extracting the second feature vector based on at least one of the preset sensitivity identifiers, interface layout, interface content, and interface code structure of the front-end interface.

[0068] For example, preset sensitive identifiers include predefined identifiers used to mark interfaces that may involve sensitive information interactions. For instance, components containing password input fields or payment information forms are pre-marked with sensitive identifiers. Preset sensitive identifiers can include insensitive identifiers, pending identifiers, and sensitive identifiers. If an interface has a sensitive identifier, feature vector extraction can be skipped, and the interface sequence can be obtained directly. For insensitive identifiers and pending identifiers, for example, the second feature vector can be extracted only from the front-end interface with the pending identifier.

[0069] For example, the interface layout includes the arrangement and structure of front-end interface elements, such as the positional relationships of buttons, images, text boxes, etc. For instance, in a login page, the username input box is positioned above the password input box. Interface content includes one or more pieces of information displayed on the front-end interface, including text, images, links, etc. For example, a payment page displays the total amount, a list of products, and a confirm payment button. The interface code structure includes how the HTML, CSS, and JavaScript code that constitute the front-end interface are organized.

[0070] According to embodiments of this disclosure, by comprehensively considering multiple features, the sensitivity detection model can more accurately identify which front-end operations may involve sensitive data.

[0071] In other embodiments, a second feature vector can also be extracted based on the user's operation behavior on the front-end interface. For example, the user's click pattern, page dwell time, search keywords, etc., may be extracted as part or all of the second feature vector.

[0072] Machine learning methods, such as decision trees, support vector machines, clustering algorithms, or deep learning models, can be used to extract the first or second feature vector.

[0073] In operation S420, the second feature vector is input into the sensitive detection model to obtain the interface detection result;

[0074] The interface detection result is obtained by applying the second feature vector to a sensitivity detection model, indicating whether the front-end interface is related to sensitive operations. For example, detecting whether a user is attempting to enter credit card information on a payment page.

[0075] In some embodiments, in addition to the client's front-end interface, information about redirection from the client's front-end interface to other applications may also be included. For example, information about the redirection interface may be obtained in advance through the redirection link, feature vectors may be extracted to determine whether sensitive operations are involved, and the user may be promptly alerted or prevented from redirecting. Alternatively, the redirection interface may be opened in the client's built-in browser, and encryption operations may be performed.

[0076] Sensitive operations include user actions that may involve the processing of sensitive data. For example, a user uploading a photo of their personal ID card on the front-end interface is a sensitive operation.

[0077] When operating the S430, if the interface detection result indicates that the front-end interface is related to sensitive operations, obtain the sequence of interfaces called by the application.

[0078] Taking a user's experience redeeming points in a bank's application as an example, they might enter their name and phone number. The client extracts the second feature vector from the points redemption interface. This feature vector is then fed into a sensitivity detection model, which determines that the user is interacting with an interface related to a sensitive operation. The client then begins to acquire the sequence of API calls, including login, checking points balance, points addition / deduction, and initiating a redemption request. If the user enters sensitive data during this process and no encryption code is deployed, this data will be automatically encrypted, and a secure points redemption request will be sent.

[0079] According to embodiments of this disclosure, the interface sequence is only further recorded when a user's operation on the front-end interface is determined to be related to a sensitive operation, thereby specifically protecting the security of sensitive data and reducing unnecessary data processing and storage.

[0080] Figure 5 The diagram illustrates a front-end and back-end architecture diagram integrating software development tools according to an embodiment of the present disclosure.

[0081] In some embodiments, the client integrates a pre-packaged software development kit (SDK), within which the sensitivity detection model is encapsulated.

[0082] like Figure 5As shown, for example, a mobile banking app integrates an SDK, which includes a parser, a sensitivity detection model, and an encryptor, to facilitate the quick integration and use of the SDK's functions in mobile banking.

[0083] For example, a sensitivity detection model can use a Long Short-Term Memory (LSTM) neural network model to analyze and process API sequences. It takes the API sequence as input and performs sequence modeling and feature extraction through LSTM layers. An LSTM model can include one or more LSTM layers to perform deep learning modeling on sequence data. It can learn patterns and associations in the API sequence and determine whether it contains the transmission or storage of sensitive information.

[0084] In some embodiments, the software development kit may include an encryptor for encrypting sensitive data, which includes instructing the software development kit to call a pre-packaged encryption algorithm to encrypt the sensitive data.

[0085] For example, the encryptor is used to automatically encrypt and repair sensitive information. When the LSTM model detects sensitive information in an API sequence, the encryptor encrypts the sensitive information according to predefined encryption algorithms and rules to ensure its secure transmission and storage. Encrypting sensitive data on the client side increases the difficulty of unauthorized access or leakage.

[0086] The SDK can perform encryption within the trusted execution environment of the terminal device. Encryption algorithms can include AES (Advanced Encryption Standard) or RSA encryption methods.

[0087] Reference Figure 5 When a user applies for a credit card, sensitive credit card application details are transmitted between the user's device and the server. The SDK can call a pre-packaged encryption algorithm to encrypt this data, ensuring that even if the data is intercepted during transmission to the credit card system on the server, it cannot be interpreted by an unauthorized third party.

[0088] In some embodiments, the software development kit may also encapsulate a parser to interact with the application, parse the application's UI elements and interaction flow, and obtain the application's user interface (UI) information. Simultaneously, it is also responsible for capturing and recording the application's API call sequences for subsequent analysis and processing.

[0089] According to embodiments of this disclosure, the pre-packaged SDK simplifies the development of client-side parsing, sensitivity detection, and encryption functions. Furthermore, by integrating the SDK into the client to implement parsing, sensitivity detection, and encryption functions, sensitive data can be processed locally, improving data security and preventing potential data leakage issues arising from third-party processing.

[0090] Figure 6 A flowchart illustrating a test according to an embodiment of this disclosure is shown schematically.

[0091] The request originates in the production environment and occurs before retrieving the sequence of API calls the application will make in response to a request from the application to call the target API. Figure 6 As shown, this embodiment includes:

[0092] When operating S610, the application's business test messages are obtained in the test environment. The business test messages are obtained based on any one of the interfaces in the application call interface set, which includes at least one interface called by the application in the production environment.

[0093] The production environment includes the environment where applications actually process user business logic. Business test messages include virtual data packets or data structures generated during testing in the test environment based on interfaces in the application's call interface set. The purpose is to simulate real-world operations before the actual application calls the interfaces, in order to evaluate and verify behavior involving sensitive data. For example, in the test environment of an e-commerce platform, this might involve simulating an order detail data packet generated by a user placing an order.

[0094] When operating the S620, perform sensitive field detection on business test messages;

[0095] For example, information such as request headers and parameters can be extracted from the message. All extracted text data is then compared with a sensitive field table. For instance, in fields like healthcare, finance, or personal identification information, fields containing identity information, credit card numbers, and medical records are typically considered sensitive. After defining the sensitive fields, methods such as pattern matching, regular expressions, and natural language processing can be used to locate these fields in the data. Alternatively, the extracted text data can be fed into a support vector machine model for detection. If sensitive information is found in the request message, the sensitive fields, level, category, and business request details are obtained.

[0096] Taking the Support Vector Machine (SVM) model as an example, firstly, the normal business test message of the target APP is obtained, and the input message information is segmented into words. Then, the word list is converted into the corresponding word vector representation using a pre-trained Word2Vec model, and then the word vector representation is converted into feature vectors. Next, the feature vectors are input into the trained SVM model, and the model is used to make predictions. The model will output a prediction result indicating whether the request message contains sensitive information and the field where the sensitive information is located.

[0097] When operating the S630, if a sensitive field is detected in a business test message, the software development kit is integrated on the client side.

[0098] According to embodiments of this disclosure, simulating production environment operations in a test environment can identify risks and issues related to sensitive data processing in advance. For deficiencies involving sensitive data that may not be fully covered, integrating a software development kit can effectively fill these gaps.

[0099] Figure 7 A flowchart illustrating a training process according to an embodiment of this disclosure is shown schematically.

[0100] The sensitivity detection model is built based on machine learning algorithms, and the sensitivity detection model is pre-trained as follows: Figure 7 As shown, this embodiment includes:

[0101] When operating S710, determine the training dataset. The training dataset includes at least one pair of interface sequence samples and sensitive labels. The sensitive labels are used to characterize whether the corresponding interface sequence sample involves sensitive data.

[0102] Interface sequence samples can be API sequences that applications actually call in historical data.

[0103] When operating the S720, a sensitive detection model is trained using the training dataset.

[0104] For example, by employing machine learning algorithms, a sensitivity detection model can be trained using a training dataset. For instance, supervised learning algorithms, such as logistic regression, random forests, or neural networks, can be used to teach the model how to predict sensitive outcomes based on the features of a sample.

[0105] Following steps S710-S720, first, collect datasets of API sequence samples and corresponding sensitive information labels, ensuring a match between the API sequences and the sensitive information labels. Preprocess the data, and then use the Word2Vec model trainer to convert the API sequences into word vectors. Next, design the structure of the LSTM neural network model, compile the model, and select an appropriate loss function and optimizer. Train the model using the training set, updating the model's weights and biases by inputting API sequences and comparing them with the corresponding sensitive information labels. Finally, evaluate the model's performance using the validation set and adjust it based on the validation results; adjust the model's hyperparameters, network structure, or data preprocessing methods to improve performance; evaluate the final model using the test set, calculating metrics such as accuracy, recall, and F1 score to measure the model's effectiveness.

[0106] According to embodiments of this disclosure, a sensitivity detection model built based on machine learning algorithms can be trained using a large amount of sample data, thereby improving the accuracy of identifying sensitive data involved in the interface.

[0107] Figure 8A flowchart illustrating a data processing method according to another embodiment of the present disclosure is shown.

[0108] The data processing method in this embodiment intercepts each API call by the application through code injection technology and records relevant information to obtain the API sequence. It encapsulates the LSTM neural network model into an SDK. Whenever the APP's UI contains sensitive information operations such as login, the corresponding API sequence before sending the network request or storing it is passed to the SDK for analysis. If the analysis finds no sensitive information in the business request, the network request is processed normally. If the business request parameters contain sensitive user information, the SDK will encrypt the network request before proceeding.

[0109] Specifically, such as Figure 8 As shown, this embodiment includes:

[0110] Step S1: Obtain the UI interface of the target APP at runtime;

[0111] Step S2: Determine whether the UI interface is related to operations involving sensitive information;

[0112] In step S3: If it is determined in step S2 that the current UI interface is unrelated to the operation of sensitive information, then proceed normally;

[0113] In step S4: If it is determined in step S2 that the current UI interface is related to the operation of sensitive information, then obtain the relevant API sequence and convert the API sequence into word vectors using Word2Vec;

[0114] In step S5: The word vectors generated in step S4 are fed into the previously trained LSTM neural network model to determine whether the sensitive information has been encrypted;

[0115] In step S6: If it is determined in step S5 that the sensitive information has been encrypted, then proceed normally;

[0116] In step S7: If it is determined in step S5 that the sensitive information is not encrypted, then the sensitive information is encrypted in accordance with the agreement reached with the server, and an encryption flag is added to the request message.

[0117] According to embodiments of this disclosure, combining API sequence analysis and front-end UI analysis enables a more comprehensive understanding of application behavior and data flow, thereby improving the reliability of sensitive information detection and encryption remediation. It allows for real-time monitoring and protection of sensitive information security after the application is launched, effectively addressing potential security threats. This contributes to improving the overall security of the application and user trust.

[0118] Based on the above data processing method, this disclosure also provides a data processing apparatus. The following will be combined with... Figure 9 The device is described in detail.

[0119] Figure 9 A schematic block diagram of a data processing apparatus according to an embodiment of the present disclosure is shown.

[0120] like Figure 9 The data processing device 900 mainly includes an interface sequence module 910, a feature vector module 920, a sensitivity detection module 930, and a data encryption module 940.

[0121] The interface sequence module 910 can perform operation S310, in response to a request from an application to call a target interface, to obtain the interface sequence to be called by the application, wherein the interface sequence includes information about the target interface and the interfaces that have been called.

[0122] In some embodiments, the interface sequence module 910 can perform operations S410 to S430, which will not be described in detail here.

[0123] The feature vector module 920 can perform operation S320 to extract the first feature vector of the interface sequence.

[0124] The sensitivity detection module 930 can perform operation S330, inputting the first feature vector into the pre-trained sensitivity detection model to obtain the sensitivity detection result.

[0125] The data encryption module 940 can perform operation S340, which encrypts the sensitive data when the sensitivity detection result is sensitive and the sensitive data in the request is not encrypted, so that the application can send an encrypted request to call the target interface.

[0126] In some embodiments, the data processing apparatus 900 may further include a testing and integration module for performing operations S610 to S630, which will not be described in detail here.

[0127] In some embodiments, the data processing apparatus 900 may further include a model training module for performing operations S710 to S720, which will not be described in detail here.

[0128] For any parts not mentioned in the apparatus section, please refer to the various embodiments of the above method for understanding. That is, the apparatus section includes modules for performing each step of any of the method embodiments described above. Furthermore, the implementation methods, technical problems solved, functions achieved, and technical effects of each module / unit / subunit in the apparatus section embodiments are the same as or similar to the implementation methods, technical problems solved, functions achieved, and technical effects of the corresponding steps in the method section embodiments, and will not be repeated here.

[0129] According to embodiments of this disclosure, any multiple modules among the interface sequence module 910, feature vector module 920, sensitivity detection module 930, and data encryption module 940 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functionality of one or more of these modules can be combined with at least some of the functionality of other modules and implemented in one module.

[0130] According to embodiments of this disclosure, at least one of the interface sequence module 910, feature vector module 920, sensitivity detection module 930, and data encryption module 940 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), programmable logic array (PLA), system-on-a-chip, system-on-a-substrate, system-on-package, application-specific integrated circuit (ASIC), or any other reasonable method of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three methods. Alternatively, at least one of the interface sequence module 910, feature vector module 920, sensitivity detection module 930, and data encryption module 940 can be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0131] Figure 10 A block diagram schematically illustrates an electronic device suitable for implementing a data processing method according to an embodiment of the present disclosure.

[0132] like Figure 10 As shown, an electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage portion 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0133] RAM 1003 stores various programs and data required for the operation of electronic device 1000. Processor 1001, ROM 1002, and RAM 1003 are interconnected via bus 1004. Processor 1001 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 1002 and / or RAM 1003. It should be noted that programs may also be stored in one or more memories other than ROM 1002 and RAM 1003. Processor 1001 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in one or more memories.

[0134] According to embodiments of this disclosure, the electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to a bus 1004. The electronic device 1000 may also include one or more of the following components connected to the I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1010 as needed so that computer programs read from it can be installed into the storage section 1008 as needed.

[0135] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0136] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 1002 and / or RAM 1003 and / or one or more memories other than ROM 1002 and RAM 1003 described above.

[0137] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the methods provided in the embodiments of this disclosure.

[0138] When the computer program is executed by the processor 1001, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0139] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1009, and / or installed from the removable medium 1011. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0140] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 1009, and / or installed from removable medium 1011. When the computer program is executed by processor 1001, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0141] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0142] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0143] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0144] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A data processing method, characterized by, The method comprises: obtaining an interface sequence called by the application in response to a request that the application is about to call a target interface, the interface sequence comprising information of the target interface and called interfaces; extracting a first feature vector of the interface sequence; inputting the first feature vector into a pre-trained sensitive detection model to obtain a sensitive detection result; encrypting sensitive data in the request when the sensitive detection result is sensitive and the sensitive data is not encrypted, the application being configured to send the encrypted request to call the target interface.

2. The method of claim 1, wherein, The application comprises a client, and the client initiates the request in response to a user operation on a front-end interface thereof, and the obtaining of the interface sequence called by the application comprises: extracting a second feature vector of the front-end interface in response to a request that the client is about to call the target interface; inputting the second feature vector into the sensitive detection model to obtain an interface detection result; obtaining the interface sequence called by the application when the interface detection result indicates that the front-end interface is related to a sensitive operation.

3. The method of claim 2, wherein, The extracting of the second feature vector of the front-end interface comprises: extracting the second feature vector according to at least one of a preset sensitive identifier, an interface layout, interface content and an interface code structure of the front-end interface.

4. The method according to claim 1 or 2, characterized in that, The extracting of the first feature vector of the interface sequence comprises: extracting the first feature vector according to at least one of description information of the target interface, a message of the request, description information of each called interface and a historical request message of each called interface.

5. The method of claim 2, wherein, The client integrates a pre-packaged software development kit, and the sensitive detection model is packaged in the software development kit.

6. The method of claim 5, wherein, The encrypting of the sensitive data comprises: calling a pre-packaged encryption algorithm by the software development kit to encrypt the sensitive data.

7. The method of claim 5, wherein, The request is generated in a production environment, and before the obtaining of the interface sequence called by the application in response to the request that the application is about to call the target interface, the method further comprises: obtaining a business test message of the application in a test environment, wherein the business test message is obtained according to any interface in an interface set called by the application, and the interface set comprises at least one interface called by the application in the production environment; performing sensitive field detection on the business test message; integrating the software development kit in the client when it is detected that the business test message contains a sensitive field.

8. The method of claim 1, wherein, The sensitive detection model is constructed based on a machine learning algorithm, and the pre-training of the sensitive detection model comprises: determining a training data set comprising at least one pair of interface sequence samples and a sensitive label, the sensitive label being used to represent whether the corresponding interface sequence sample involves sensitive data; training the sensitive detection model by using the training data set.

9. A data processing apparatus, characterized by, The method comprises: an interface sequence module, configured to obtain an interface sequence called by an application in response to a request that the application is about to call a target interface, the interface sequence comprising information of the target interface and called interfaces; a feature vector module, configured to extract a first feature vector of the interface sequence; The sensitive detection module is configured to input the first feature vector into a pre-trained sensitive detection model to obtain a sensitive detection result. The data encryption module is configured to encrypt the sensitive data when the sensitive detection result is sensitive and the sensitive data in the request is not encrypted, and the application is configured to send the encrypted request to call the target interface. 10.An electronic device comprising: one or more processors; memory storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-8.

11. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-8.

12. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-8. The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Sensitive data leakage detection method and system of API

    CN113157854A

  • API (Application Program Interface) abnormal access detection method and device, equipment and medium

    CN117112395A