Data security protection method and system for the self-collection process of omni-channel clothing transactions

By performing multi-level encryption on each processing link in the data transmission and storage process of the clothing industry, the problem of insufficient data security is solved, and high security and flexible encryption measures for data in self-pickup orders for clothing transactions are realized.

CN118864053BActive Publication Date: 2025-05-06GUANGZHOU REGENTSOFT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410891527.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-04
Publication Date
2025-05-06
Estimated Expiration
2044-07-04

AI Technical Summary

Technical Problem

The clothing industry lacks effective security measures in data transmission and storage, resulting in data breaches and privacy damage.

Method used

Multi-level encryption of the data of each participant in each processing step is achieved by multi-level encryption of the accessible data in the complete raw data, generating multi-level encrypted data and keys.

Benefits of technology

Improve the security of clothing transaction self-pickup order data during storage and transmission. Even if one layer of encryption is cracked, other layers can still protect the data from being easily accessed, enhancing the flexibility of encryption measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118864053B_ABST
    Figure CN118864053B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data protection technology, and specifically discloses a data security protection method and system for an omni-channel clothing transaction self-pickup process, the method comprising: determining all participants in each processing link in the business flow process of a current clothing transaction self-pickup order; based on the data access rights of each participant in each processing link to the corresponding complete original data, multi-level encryption is performed on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and a multi-level key is generated for each participant; based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained; and the data protection of each processing link in the data flow process of the clothing transaction self-pickup order is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data protection technology, and in particular to a data security protection method and system for an omni-channel clothing transaction self-pickup process. Background Art

[0002] At present, the importance of big data security is becoming more and more prominent in today's digital age, especially in various industries. In the apparel industry, big data is widely used in market research, production management, sales forecasting and other aspects. However, with the widespread application of big data, data security issues are also increasingly attracting attention. The apparel industry not only involves customers' personal information, such as name, address, phone number, etc., but also sensitive data such as payment information and purchase records. If this data is leaked or hacked, it will not only damage consumers' privacy rights, but may also lead to serious consequences such as financial losses and damage to brand reputation. Therefore, the apparel industry must attach importance to big data security and take effective measures to protect the security and privacy of customer data.

[0003] At present, the information system of the clothing industry has no data security protection. In most cases, information is displayed in plain text, lacking necessary security measures. In many cases, data is only encrypted at a certain level (such as the database level), which may cause data to be easily leaked during transmission or at the application level. If the key management is not appropriate, even if the data is encrypted, once the key is leaked, the data security will be threatened.

[0004] Therefore, the present invention proposes a data security protection method and system for the omni-channel clothing transaction self-pickup process. Summary of the invention

[0005] The present invention provides a data security protection method and system for the omni-channel clothing transaction self-pickup process, which is used to obtain the multi-level encrypted data of each participant in each processing link by multi-level encryption of the accessible data in the corresponding complete original data of each participant, and generate a multi-level key for each participant, so as to realize the multi-level encryption of the data of each processing link in the data flow process of the clothing transaction self-pickup order, and effectively improve the security of the current clothing transaction self-pickup order data in the storage and transmission process. Even if the encryption mechanism of one level (layer) is cracked, the encryption mechanism of other layers can still protect the data of the current clothing transaction self-pickup order from being easily accessed, and also improve the flexibility of the encryption measures that can be taken for the current clothing transaction self-pickup order data.

[0006] The present invention provides a data security protection method for the self-collection process of omni-channel clothing transactions, comprising:

[0007] S1: Identify all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel;

[0008] S2: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order;

[0009] S3: Based on the data access rights of each participant in each processing link to the corresponding complete original data, multi-level encryption is performed on the accessible data of each participant in each processing link in the corresponding complete original data to obtain multi-level encrypted data of each participant, and a multi-level key of each participant is generated;

[0010] S4: Based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained.

[0011] Preferably, a data security protection method for the omni-channel clothing transaction self-pickup process, S1: determining all participants in each processing link in the business flow process of the current clothing transaction self-pickup order generated from any channel in the omni-channel, including:

[0012] S101: receiving the clothing transaction self-pickup order generated by each channel in the omni-channel in real time, and treating the clothing transaction self-pickup order generated by any channel in the omni-channel as the current clothing transaction self-pickup order;

[0013] S102: Based on the task allocation mechanism, all participants in each processing link in the business flow of the current clothing transaction self-pickup order are determined.

[0014] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process, S2: based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order, including:

[0015] S201: Based on the system preset data protection requirements, determine the first data protection requirements of each processing link in the business flow process;

[0016] S202: Determine a second data protection requirement for each processing link in the business flow process based on the data protection requirement set by the user;

[0017] S203: Determine the data protection requirement of each processing link in the business flow process based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process;

[0018] S204: Obtaining complete original data of the current clothing transaction self-pickup order;

[0019] S205: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the corresponding complete original data.

[0020] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process, S203: based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process, determining the data protection requirement of each processing link in the business flow process, including:

[0021] Determine the protection scope of the first data protection requirement and the protection scope of the second data protection requirement for all processing links in the business flow process;

[0022] According to the principle of corresponding protection scope from large to small, the first data protection requirements and the second data protection requirements of all processing links in the business flow process are sorted to obtain a data protection requirement sequence;

[0023] The ranking order of the first data protection requirement or the second data protection requirement in the data protection requirement sequence of each processing link in the business flow process shall be regarded as the protection level corresponding to the first data protection requirement or the second data protection requirement;

[0024] The integer range consisting of the smaller value to the larger value of the protection level of the first data protection requirement and the protection level of the second data protection requirement of each processing link in the business flow process is regarded as the protection level range of the corresponding processing link;

[0025] Based on the protection assessment model and the data protection requirements of all processing links in the business flow of all reference users, the protection assessment values ​​of the clothing transaction self-pickup order data of all reference users are obtained, and the data protection requirements of each processing link in the business flow of all reference users whose protection assessment values ​​are not less than the protection assessment threshold are used as reference requirements;

[0026] Based on the data protection requirement sequence, determine the protection level of the data protection requirements for each processing link in the business flow of each reference user in the reference requirements;

[0027] Based on the protection level of the data protection requirements for each processing link in the business flow process of all reference users, the second data protection requirement for each processing link in the business flow process of the current user, and the acceptable range of protection levels for each processing link, the data protection requirements for each processing link in the business flow process are determined.

[0028] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process determines the data protection requirements for each processing link in the business flow process based on the protection level of the data protection requirements for each processing link in the business flow process of all reference users and the protection level of the second data protection requirements for each processing link in the business flow process of the current user and the protection level range of each processing link, including:

[0029] Determine all optional protection level polylines, wherein the protection level of each processing link included in the optional protection level polyline belongs to the protection level range of the corresponding processing link;

[0030] Generate all reference protection level polylines based on the data protection requirements of each processing link in the business flow of all reference users;

[0031] Based on the protection level of the second data protection requirement of each processing link in the current user's business flow process, generate a user-set protection level polyline;

[0032] The difference between the protection level of each processing link in each optional protection level polyline, each reference protection level polyline or user-set protection level polyline and the minimum value of all protection levels in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline is regarded as the correction level of the corresponding processing link in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline;

[0033] Generate all optional correction protection level polylines or all reference correction protection level polylines or user-set correction protection level polylines based on the correction level of each processing link in all optional protection level polylines or all reference protection level polylines or user-set protection level polylines;

[0034] Among all optional correction protection level polylines, the optional correction protection level polyline with the greatest comprehensive similarity to all reference correction protection level polylines and the user-set correction protection level polyline is selected as the final correction protection level polyline;

[0035] The data protection requirements corresponding to the protection level of each processing link in the optional protection level polyline corresponding to the final correction protection level polyline in the data protection requirement sequence shall be regarded as the data protection requirements of the corresponding processing link in the business flow process.

[0036] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process, S3: based on the data access rights of each participant in each processing link to the corresponding complete original data, the accessible data of each participant in each processing link in the corresponding complete original data is multi-level encrypted to obtain the multi-level encrypted data of each participant, and a multi-level key of each participant is generated, including:

[0037] S301: Determine the accessible data in the corresponding complete original data by each participant in each processing link based on the data access rights of each participant in each processing link to the corresponding complete original data;

[0038] S302: Perform multi-level encryption on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate a multi-level key for each participant.

[0039] Preferably, the data security protection method for the omni-channel clothing transaction self-collection process, S302: multi-level encryption of the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate a multi-level key for each participant, including:

[0040] Perform field-level encryption on the accessible data of each participant in each processing link, obtain the first encrypted data of each participant, and generate a field-level key for each participant;

[0041] Perform row-level encryption on the first encrypted data of each participant in each processing link, obtain the second encrypted data of each participant, and generate a row-level key for each participant;

[0042] Performing table-level encryption on the second encrypted data of each participant based on the secret database to obtain the third encrypted data of each participant, and generating a table-level encryption key for each participant;

[0043] Identify all devices involved in each process that can access data for each participant;

[0044] Based on the ECC algorithm and all involved devices of each participant's accessible data, perform device-level encryption on each participant's third encrypted data, obtain each participant's fourth encrypted data, and generate a device-level key for each participant;

[0045] Performing user-level encryption on the fourth encrypted data corresponding to each participant based on the identity information of each participant, obtaining multi-level encrypted data of each participant, and generating a user-level key for each participant;

[0046] The field-level keys, row-level keys, table-level encryption keys, device-level keys, and user-level keys of the accessible data of each participant in each processing link are stored separately as multi-level keys for each participant.

[0047] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process performs row-level encryption on the first encrypted data of each participant in each processing link, obtains the second encrypted data of each participant, and generates a row-level key for each participant, including:

[0048] Generate a hash value for each row of data in the first encrypted data of each participant in each processing link using the signature server, and add the hash value of each row of data to the corresponding row of data in the first encrypted data to obtain a hash column of accessible data;

[0049] The hash column of the first encrypted data is encrypted based on the secret database to obtain the second encrypted data of each participant, and a row-level key of each participant is generated.

[0050] Preferably, the data security protection method for the omni-channel clothing transaction self-pickup process, S4: based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained, including:

[0051] S401: Based on the multi-level encrypted data of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the complete original data of the current clothing transaction self-pickup order, a data flow thread of the business flow process of the current clothing transaction self-pickup order and a corresponding data flow dynamic form are generated;

[0052] S402: triggering the business flow process based on the data flow thread and the corresponding data flow dynamic form, and receiving in real time the key input by each participant in each processing link of the business flow process of the current clothing transaction self-pickup order;

[0053] S403: Based on the real-time reception of the keys input by each participant in each processing link of the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level keys, determine whether the corresponding participant can read the corresponding encrypted data. If so, continue to execute the corresponding business flow process until the corresponding business flow process is traversed to obtain the data security protection result of the current clothing transaction self-pickup order. Otherwise, determine that the corresponding business flow process is abnormal as the abnormal flow monitoring result, and send the abnormal flow monitoring result to the monitoring background in real time as the data security protection result of the current clothing transaction self-pickup order.

[0054] The present invention provides a data security protection system for an omni-channel clothing transaction self-pickup process, which is used to execute the data security protection method for an omni-channel clothing transaction self-pickup process described in any one of Embodiments 1 to 9, including:

[0055] Participant determination module, used to determine all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel;

[0056] The access permission determination module is used to determine the data access permission of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order based on the data protection requirements of each processing link in the business flow process;

[0057] A data encryption processing module is used to perform multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data based on the data access rights of each participant in each processing link to the corresponding complete original data to obtain the multi-level encrypted data of each participant, and generate a multi-level key for each participant;

[0058] The data security protection module is used to obtain the data security protection results of the current clothing transaction self-pickup order based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data.

[0059] The beneficial effects of the present invention compared with the prior art are as follows: by performing multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data, the multi-level encrypted data of each participant is obtained, and a multi-level key of each participant is generated, so as to realize multi-level encryption of the data of each processing link in the data flow process of the clothing transaction self-pickup order, and effectively improve the security of the current clothing transaction self-pickup order data in the storage and transmission process. Even if the encryption mechanism of one level (layer) is cracked, the encryption mechanism of other layers can still protect the data of the current clothing transaction self-pickup order from being easily accessed, and also improve the flexibility of the encryption measures that can be taken for the current clothing transaction self-pickup order data.

[0060] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in this application document.

[0061] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0063] Figure 1 This is a flow chart of a data security protection method for the omni-channel clothing transaction self-pickup process in an embodiment of the present invention;

[0064] Figure 2 Schematic diagram of a multi-layer key system of a secret database in an embodiment of the present invention;

[0065] Figure 3 Schematic diagram of the system architecture of the signature verification server in an embodiment of the present invention;

[0066] Figure 4 This is a schematic diagram of a row-level encryption process in an embodiment of the present invention;

[0067] Figure 5 Schematic diagram of the internal functional modules of the data security protection system for the omni-channel clothing transaction self-pickup process in an embodiment of the present invention. DETAILED DESCRIPTION

[0068] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0069] Embodiment 1:

[0070] The present invention provides a data security protection method for the self-collection process of omni-channel clothing transactions, referring to Figure 1 ,include:

[0071] S1: Identify all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel;

[0072] S2: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order;

[0073] S3: Based on the data access rights of each participant in each processing link to the corresponding complete original data, multi-level encryption is performed on the accessible data of each participant in each processing link in the corresponding complete original data to obtain multi-level encrypted data of each participant, and a multi-level key of each participant is generated;

[0074] S4: Based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained.

[0075] In this embodiment, omni-channel includes but is not limited to different online shopping platforms and offline stores.

[0076] In this embodiment, the clothing transaction self-pickup order is a clothing transaction order that requires the buyer to pick up the goods at the store.

[0077] In this embodiment, the business flow process includes the business links included in the process of completing the clothing transaction self-pickup order, such as: generating an order, allocating goods, shipping, picking up goods, returning goods, etc.

[0078] In this embodiment, the processing steps include but are not limited to ordering, distribution, delivery, and picking up, and may also include return and exchange steps, etc.

[0079] In this embodiment, all participants in the processing link are staff members who complete the corresponding processing link, such as a picker who completes the pick link.

[0080] In this embodiment, the complete original data of the current clothing transaction self-pickup order is all relevant data required to complete the entire process of the current clothing transaction self-pickup order, for example, including: order table, distribution table, delivery table, pick-up table, return and exchange table, etc.

[0081] In this embodiment, the data access rights of the participants to the complete original data of the current clothing transaction self-pickup order limit the scope of the participants' access to the complete original data of the current clothing transaction self-pickup order. For example, the data range accessible to the picker includes order number, document date, picker channel number, etc., but the data range that the picker cannot access includes inseam, size, chest circumference, shoulder width, quantity, etc.

[0082] In this embodiment, the data accessible to the participant in the corresponding complete original data represents all specific data accessible to the participant in the complete original data.

[0083] In this embodiment, multi-level encryption means performing field-level encryption, row-level encryption, table-level encryption, device-level encryption, and user-level encryption on the data in sequence, and finally obtaining the encrypted data after multiple encryptions and the corresponding keys of the multiple encryption processes.

[0084] In this embodiment, the multi-level key includes multiple keys generated using different encryption methods.

[0085] The beneficial effects of the above technology are: by performing multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data, the multi-level encrypted data of each participant is obtained, and the multi-level key of each participant is generated, so as to realize the multi-level encryption of the data of each processing link in the data flow process of the clothing transaction self-pickup order, and effectively improve the security of the current clothing transaction self-pickup order data in the storage and transmission process. Even if the encryption mechanism of one level (layer) is cracked, the encryption mechanism of other layers can still protect the data of the current clothing transaction self-pickup order from being easily accessed, and also improve the flexibility of the encryption measures that can be taken for the current clothing transaction self-pickup order data.

[0086] Embodiment 2:

[0087] Based on Example 1, a data security protection method for the omni-channel clothing transaction self-pickup process, S1: Determine all participants in each processing link in the business flow process of the current clothing transaction self-pickup order generated from any channel in the omni-channel, including:

[0088] S101: receiving the clothing transaction self-pickup order generated by each channel in the omni-channel in real time, and treating the clothing transaction self-pickup order generated by any channel in the omni-channel as the current clothing transaction self-pickup order;

[0089] S102: Based on the task allocation mechanism, all participants in each processing link in the business flow of the current clothing transaction self-pickup order are determined.

[0090] In this embodiment, the task allocation mechanism is a preset mechanism for allocating staff to specific processing tasks in each processing link in the business flow process of different clothing transaction self-pickup orders. For example, tasks are allocated in sequence according to the preset priority allocation levels of currently idle staff who can handle the specific processing tasks of the corresponding processing links.

[0091] The beneficial effects of the above technology are: completing the receiving process of the clothing transaction self-pickup orders generated by each channel in the omni-channel, and realizing the allocation of all participants in each processing link in the business flow process of the current clothing transaction self-pickup orders according to the task allocation mechanism.

[0092] Embodiment 3:

[0093] Based on Example 1, the data security protection method for the omni-channel clothing transaction self-pickup process, S2: based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order, including:

[0094] S201: Based on the system preset data protection requirements, determine the first data protection requirements of each processing link in the business flow process;

[0095] S202: Determine a second data protection requirement for each processing link in the business flow process based on the data protection requirement set by the user;

[0096] S203: Determine the data protection requirement of each processing link in the business flow process based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process;

[0097] S204: Obtaining complete original data of the current clothing transaction self-pickup order;

[0098] S205: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the corresponding complete original data.

[0099] In this embodiment, the system preset data protection requirements are the data protection requirements for each processing link in the business flow process of the system's original settings (factory settings). When the user does not enter the user-set data protection requirements, the first data protection requirement for each processing link in the business flow process contained in the system preset data protection requirements shall be used as the data protection requirements for each processing link in the business flow process.

[0100] In this embodiment, the first data protection requirement is included in the system preset data protection requirements and is used to limit the content of specific data items that can be accessed by participants in each processing link.

[0101] In this embodiment, the data protection requirements set by the user are input by the user, representing the second data protection requirements for each processing link that the user wants to set.

[0102] In this embodiment, the second data protection requirement is the content contained in the data protection requirement set by the user and is used to limit the specific data items that can be accessed by the participants in each processing link.

[0103] In this embodiment, the data protection requirements of the processing link are determined after the comprehensive system preset data protection requirements and the user set data protection requirements, and are ultimately used to limit the specific data items that can and cannot be accessed by participants in a single processing link.

[0104] The first data protection requirement, the second data protection requirement, and the data protection requirement in this embodiment all represent the specific data items that are accessible to the participants in the corresponding processing links (such as order number, document date, distribution channel number, etc.) and the specific data items that are not accessible (such as inseam, size, chest circumference, shoulder width, quantity, etc.).

[0105] The beneficial effects of the above technology are: by comprehensively considering the system preset data protection requirements and the user set data protection requirements, the data protection requirements for each processing link in the business flow process are reasonably determined, and default data protection requirements and data protection requirements for users to set can be provided, thereby improving the flexibility of the encryption scope in the data protection process.

[0106] Embodiment 4:

[0107] Based on Example 1, the data security protection method for the omni-channel clothing transaction self-pickup process, S203: based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process, determine the data protection requirement of each processing link in the business flow process, including:

[0108] Determine the protection scope of the first data protection requirement and the protection scope of the second data protection requirement for all processing links in the business flow process;

[0109] According to the principle of corresponding protection scope from large to small, the first data protection requirements and the second data protection requirements of all processing links in the business flow process are sorted to obtain a data protection requirement sequence;

[0110] The ranking order of the first data protection requirement or the second data protection requirement in the data protection requirement sequence of each processing link in the business flow process shall be regarded as the protection level corresponding to the first data protection requirement or the second data protection requirement;

[0111] The integer range consisting of the smaller value to the larger value of the protection level of the first data protection requirement and the protection level of the second data protection requirement of each processing link in the business flow process is regarded as the protection level range of the corresponding processing link;

[0112] Based on the protection assessment model and the data protection requirements of all processing links in the business flow of all reference users, the protection assessment values ​​of the clothing transaction self-pickup order data of all reference users are obtained, and the data protection requirements of each processing link in the business flow of all reference users whose protection assessment values ​​are not less than the protection assessment threshold are used as reference requirements;

[0113] Based on the data protection requirement sequence, determine the protection level of the data protection requirements for each processing link in the business flow of each reference user in the reference requirements;

[0114] Based on the protection level of the data protection requirements for each processing link in the business flow process of all reference users, the second data protection requirement for each processing link in the business flow process of the current user, and the acceptable range of protection levels for each processing link, the data protection requirements for each processing link in the business flow process are determined.

[0115] In this embodiment, the protection scope of the first data protection requirement or the second data protection requirement refers to the content contained in the first data protection requirement or the second data protection requirement and is used to limit specific data items that are inaccessible.

[0116] In this embodiment, the protection assessment model is a model obtained by training a neural network model using the data protection requirements of each processing link in the business flow of a large number of clothing transaction self-pickup orders as model input, and using the protection assessment values ​​of the corresponding data protection requirements manually assessed as model input.

[0117] In this embodiment, the data protection requirements for each processing link in the user's business flow process may be determined based on the system preset data protection requirements, or may be determined based on the comprehensive system preset data protection requirements and the user set data protection requirements.

[0118] In this embodiment, based on the protection evaluation model and the data protection requirements of all processing links in the business flow of all reference users, the protection evaluation values ​​of the clothing transaction self-pickup order data of all reference users are obtained, including:

[0119] The data protection requirements of all processing links in the reference user's business flow are input into the protection assessment model to obtain the protection assessment value of the reference user's clothing transaction self-pickup order data.

[0120] In this embodiment, the protection evaluation value indicates the quality of the data protection effect obtained after data protection is performed on the corresponding reference user's clothing transaction self-pickup order in accordance with the data protection requirements of each processing link in the reference user's business flow process. The larger the protection evaluation value, the better the corresponding data protection effect, and vice versa.

[0121] In this embodiment, the protection assessment threshold is a preset value that the corresponding protection assessment value cannot be less than when the data protection requirements of each processing link in the business flow of the reference user are taken as reference requirements.

[0122] In this embodiment, based on the data protection requirement sequence, the protection level of the data protection requirement of each processing link in the business flow process of each reference user in the reference requirement is determined, that is,

[0123] The sorting ordinal numbers of the data protection requirements contained in the data protection requirements sequence that are the same as the data protection requirements for each processing link in the business flow process of each reference user in the reference requirements shall be regarded as the protection level of the data protection requirements for each processing link in the business flow process of each reference user in the reference requirements.

[0124] The beneficial effects of the above technology are: a data protection requirement sequence is constructed based on the first data protection requirements and the second data protection requirements of all processing links in the business flow process, which can achieve a unified representation of the protection level of the first data protection requirement or the second data protection requirement and the data protection requirements of each processing link in the business flow process of each reference user in the reference requirements, and based on the limitation of the protection level of the first data protection requirement and the protection level of the second data protection requirement of each processing link in the business flow process, the possible range of protection levels of each processing link is reasonably determined, and the data protection requirements of each processing link in the business flow process of each reference user in the reference requirements with better protection performance are screened out through the protection evaluation model as a reference, and combined with the protection level of the second data protection requirement of each processing link in the business flow process of the current user and the possible range of protection levels of each processing link, the data protection requirements for each processing link in the business flow process that are finally adopted are reasonably determined.

[0125] Embodiment 5:

[0126] On the basis of Example 4, the data security protection method for the self-pickup process of omni-channel clothing transactions determines the data protection requirements of each processing link in the business flow process based on the protection level of the data protection requirements of each processing link in the business flow process of all reference users and the protection level of the second data protection requirements of each processing link in the business flow process of the current user and the protection level range of each processing link, including:

[0127] Determine all optional protection level polylines, wherein the protection level of each processing link included in the optional protection level polyline belongs to the protection level range of the corresponding processing link;

[0128] Generate all reference protection level polylines based on the data protection requirements of each processing link in the business flow of all reference users;

[0129] Based on the protection level of the second data protection requirement of each processing link in the current user's business flow process, generate a user-set protection level polyline;

[0130] The difference between the protection level of each processing link in each optional protection level polyline, each reference protection level polyline or user-set protection level polyline and the minimum value of all protection levels in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline is regarded as the correction level of the corresponding processing link in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline;

[0131] Generate all optional correction protection level polylines or all reference correction protection level polylines or user-set correction protection level polylines based on the correction level of each processing link in all optional protection level polylines or all reference protection level polylines or user-set protection level polylines;

[0132] Among all optional correction protection level polylines, the optional correction protection level polyline with the greatest comprehensive similarity to all reference correction protection level polylines and the user-set correction protection level polyline is selected as the final correction protection level polyline;

[0133] The data protection requirements corresponding to the protection level of each processing link in the optional protection level polyline corresponding to the final correction protection level polyline in the data protection requirement sequence shall be regarded as the data protection requirements of the corresponding processing link in the business flow process.

[0134] In this embodiment, the optional protection level broken line is a broken line obtained by connecting the protection levels of all processing links whose corresponding protection levels belong to the protection level range of the corresponding processing link in sequence according to the sequence of the processing links.

[0135] In this embodiment, based on the protection level of data protection requirements of each processing link in the business flow process of all reference users, all reference protection level polylines are generated:

[0136] The protection level of the data protection requirements of each processing link in the business flow of all reference users is connected into a broken line in the order of the processing links to obtain all reference protection level broken lines.

[0137] In this embodiment, based on the protection level of the second data protection requirement of each processing link in the current user's business flow process, a user-set protection level polyline is generated:

[0138] The protection level of the second data protection requirement of each processing link in the current user's business flow process is connected into a broken line in the order of the processing links to obtain the user-set protection level broken line.

[0139] In this embodiment, based on the correction level of each processing link in all optional protection level broken lines or all reference protection level broken lines or user-set protection level broken lines, all optional correction protection level broken lines or all reference correction protection level broken lines or user-set correction protection level broken lines are generated as follows:

[0140] Connect the correction level of each processing link in each optional protection level polyline into a polyline in sequence according to the order of the processing links to obtain a corresponding optional correction protection level polyline;

[0141] Connect the correction level of each processing link in each reference protection level polyline into a polyline in sequence according to the order of the processing links to obtain a corresponding reference correction protection level polyline;

[0142] The correction level of each processing link in the user-set protection level polyline is sequentially connected into a polyline according to the sequence of the processing links to obtain the corresponding user-set correction protection level polyline.

[0143] In this embodiment, the comprehensive similarity between each optional correction protection level polyline and all reference correction protection level polylines and the user-set correction protection level polyline is calculated as follows:

[0144] The square root of the sum of the differences between all two protection levels with the same ordinal number in each optional correction protection level polyline and a single reference correction protection level polyline or a user-set correction protection level polyline is taken as the deviation value between the corresponding optional correction protection level polyline and the corresponding single reference correction protection level polyline or the user-set correction protection level polyline;

[0145] 1 and the deviation value are regarded as the similarity between the corresponding optional correction protection level polyline and the corresponding single reference correction protection level polyline or the user-set correction protection level polyline;

[0146] The average of the similarities between each optional correction protection level polyline and all reference correction protection level polylines and the user-set correction protection level polylines is taken as the comprehensive similarity between the optional correction protection level polyline and all reference correction protection level polylines and the user-set correction protection level polylines;

[0147] The comprehensive similarity represents the comprehensive similarity between the optional correction protection level polyline and all reference correction protection level polylines and the user-set correction protection level polyline.

[0148] The beneficial effect of the above technology is: after unifying the optional protection level polyline whose protection level of each processing link belongs to the acceptable range of protection level of the corresponding processing link, all reference protection level polylines and user-set protection level polylines, among all optional correction protection level polylines, the optional correction protection level polyline with the greatest comprehensive similarity with all reference correction protection level polylines and user-set correction protection level polylines is screened out as the final correction protection level polyline, thereby realizing the reasonable determination of the data protection requirements for each processing link in the business flow process, and ensuring that the data protection requirements for each processing link finally adopted combine the two goals of "maximizing the degree of closeness to the protection requirements set by the user" and "maximizing the protection effect".

[0149] Embodiment 6:

[0150] Based on Example 1, the data security protection method for the omni-channel clothing transaction self-pickup process, S3: based on the data access rights of each participant in each processing link to the corresponding complete original data, the accessible data of each participant in each processing link in the corresponding complete original data is multi-level encrypted to obtain the multi-level encrypted data of each participant, and a multi-level key of each participant is generated, including:

[0151] S301: Determine the accessible data in the corresponding complete original data by each participant in each processing link based on the data access rights of each participant in each processing link to the corresponding complete original data;

[0152] S302: Perform multi-level encryption on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate a multi-level key for each participant.

[0153] The beneficial effects of the above technology are: to determine the accessible data of each participant in each processing link in the corresponding complete original data, and to perform multi-level encryption on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and to generate corresponding multi-level keys.

[0154] Embodiment 7:

[0155] Based on Example 6, the data security protection method for the omni-channel clothing transaction self-collection process, S302: multi-level encryption of the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate multi-level keys for each participant, refer to Figure 2 ,include:

[0156] Perform field-level encryption on the accessible data of each participant in each processing link, obtain the first encrypted data of each participant, and generate a field-level key for each participant;

[0157] Perform row-level encryption on the first encrypted data of each participant in each processing link, obtain the second encrypted data of each participant, and generate a row-level key for each participant;

[0158] Performing table-level encryption on the second encrypted data of each participant based on the secret database to obtain the third encrypted data of each participant, and generating a table-level encryption key for each participant;

[0159] Identify all devices involved in each process that can access data for each participant;

[0160] Based on the ECC algorithm and all involved devices of each participant's accessible data, perform device-level encryption on each participant's third encrypted data, obtain each participant's fourth encrypted data, and generate a device-level key for each participant;

[0161] Performing user-level encryption on the fourth encrypted data corresponding to each participant based on the identity information of each participant, obtaining multi-level encrypted data of each participant, and generating a user-level key for each participant;

[0162] The field-level keys, row-level keys, table-level encryption keys, device-level keys, and user-level keys of the accessible data of each participant in each processing link are stored separately (that is, these keys are transmitted to the corresponding participants via different encrypted transmission channels, or stored in different storage files readable by the participants) as multi-level keys for each participant.

[0163] In this embodiment, reference Figure 2 The secret database implements a three-layer key system, allowing each layer of keys to perform their respective functions, truly achieving high-intensity key security protection. The secret database has a three-layer high-intensity key system. The first layer of data keys can use different keys for different fields; the second layer of user keys realizes encryption isolation between users. User keys will never leave the user's trusted environment, so other users including administrators cannot decrypt plaintext data; the third layer of device keys realizes encryption isolation between devices, greatly improving overall security.

[0164] In this embodiment, field-level encryption can ensure that even if the table-level encryption is cracked, the data of a single field cannot be directly obtained. The signature server is called, and the signature verification server is developed in accordance with the relevant cryptographic algorithm specifications of the national secrets. The SM2, SM3, and SM4 algorithms are used for field-level encryption, which has good scalability.

[0165] In this embodiment, performing table-level encryption on the accessible data of the corresponding participants based on the secret database means that all data tables in the accessible data of the corresponding participants are transmitted and stored in the form of table encryption by the secret database.

[0166] In this embodiment, all devices involved in the data accessible to the participants are data access devices that the participants need to use when processing tasks in the corresponding processing links.

[0167] In this embodiment, the ECC algorithm is elliptic curve cryptography.

[0168] In this embodiment, based on the ECC algorithm and all devices involved in the accessible data of each participant, the accessible data of each participant is encrypted at the device level, including:

[0169] Generate a pair of points on the EC curve and the corresponding private key pair and public key pair, which is called ECC parameter generation;

[0170] Use the public and private keys on the device to encrypt and decrypt the data to be protected;

[0171] On the device side where data needs to be protected, install an Eccoshell server, which contains an ECC key pair generated by the device side and the public key of the device side; all data that needs to be encrypted is first encrypted by the ECC key pair in the Eccoshell server; then, the server encrypts the data with the public key generated by the ECC key pair to obtain the final result;

[0172] The decryption process is the opposite. The data is first decrypted with the public key on the device, and then decrypted with the private key on the device.

[0173] In this embodiment, user-level encryption generates a unique encryption key for each user based on user identity authentication and identification authority. When a user accesses data, the data is encrypted and decrypted using their personal key. This layer of encryption can achieve fine-grained access control and personal privacy protection. This process is implemented using a secret database.

[0174] The beneficial effects of the above technologies are: by encrypting at different levels such as devices, users, tables, and fields, the security of data during storage and transmission can be effectively improved. Device-level encryption ensures that data is reliably protected in the first step of collection, eliminating the risk of device theft, copying, or illegal access. User-level encryption can achieve fine-grained access control and personal privacy protection. Table-level encryption can ensure that data is encrypted during transmission and storage, improving overall security. Field-level encryption and row-level encryption can ensure that even if the table-level encryption is cracked, the data of a single field cannot be directly obtained.

[0175] Embodiment 8:

[0176] Based on Example 7, the data security protection method for the omni-channel clothing transaction self-collection process performs row-level encryption on the first encrypted data of each participant in each processing link, obtains the second encrypted data of each participant, and generates a row-level key for each participant, referring to Figure 3 and 4 ,include:

[0177] Generate a hash value for each row of data in the first encrypted data of each participant in each processing link by using the signature server, and add the hash value of each row of data to the corresponding row of data in the first encrypted data to obtain a hash column of accessible data;

[0178] The hash column of the first encrypted data is encrypted based on the secret database to obtain the second encrypted data of each participant, and a row-level key of each participant is generated.

[0179] In this embodiment, reference Figure 3 The signature server is the signature verification server (DSVS for short), which is a server with multiple security functions, high stability, and high performance that provides digital signature and verification services for application systems. It is also a cross-platform, scalable, and rapidly deployable hardware and software integrated security device that uses the SM3 algorithm to sign row data and obtain the hash value of the row data.

[0180] In this embodiment, the hash column of the first encrypted data is column data containing hash values ​​of all row data in the first encrypted data.

[0181] The beneficial effects of the above technology are: Storing the hash value of each row in the latter field can ensure the consistency and integrity of the data during the collection and processing process, prevent unauthorized modification and serialization problems, and achieve stronger encryption of accessible data.

[0182] Embodiment 9:

[0183] Based on Example 1, the data security protection method for the omni-channel clothing transaction self-pickup process, S4: based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained, including:

[0184] S401: Based on the multi-level encrypted data of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the complete original data of the current clothing transaction self-pickup order, a data flow thread of the business flow process of the current clothing transaction self-pickup order and a corresponding data flow dynamic form are generated;

[0185] S402: triggering the business flow process based on the data flow thread and the corresponding data flow dynamic form, and receiving in real time the key input by each participant in each processing link of the business flow process of the current clothing transaction self-pickup order;

[0186] S403: Based on the real-time reception of the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key, determine whether the corresponding participant can read the corresponding encrypted data. If so, continue to execute the corresponding business flow process (i.e., decrypt the multi-level encrypted data based on the key input by the participant to provide the corresponding participant with access to the accessible data) until the corresponding business flow process is traversed to obtain the data security protection result of the current clothing transaction self-pickup order. Otherwise, determine that the corresponding business flow process is abnormal as the abnormal flow monitoring result, and send the abnormal flow monitoring result to the monitoring background in real time as the data security protection result of the current clothing transaction self-pickup order.

[0187] In this embodiment, the data flow thread of the business flow process of the current clothing transaction self-pickup order is a recording thread containing all encrypted and unencrypted data in different processing links in the business flow process.

[0188] In this embodiment, the dynamic form of data flow includes the flow of data in different processing links during the business process and the form of data when it is accessed (that is, whether it is encrypted and the form of the encrypted data).

[0189] In this embodiment, the business flow process is triggered based on the data flow thread and the corresponding data flow dynamic form:

[0190] When a trigger instruction is received from a participant in the first processing link in the business flow process, the accessible data in the data form of the corresponding processing link in the corresponding data flow dynamic form will be transmitted or stored to the corresponding device or user end, so as to achieve the purpose of triggering the data flow thread, and trigger the change of data form and the normal operation of the business flow process based on the trigger mechanism of the corresponding processing link.

[0191] In this embodiment, based on the key input by each participant in each processing link and the corresponding multi-level key in the business flow process of the current clothing transaction self-pickup order received in real time, it is determined whether the corresponding participant can read the corresponding encrypted data, including:

[0192] Determine whether the key input by each participant in each processing link in the business flow of the current clothing transaction self-pickup order received in real time corresponds to the key of the same level in the corresponding multi-level key. If so, it is determined that the corresponding participant can read the corresponding encrypted data. Otherwise, it is determined that the corresponding participant cannot read the corresponding encrypted data.

[0193] In this embodiment, the abnormal flow monitoring result is a monitoring result that an abnormal flow is detected in the business flow process.

[0194] In this embodiment, the monitoring background is a remote server background for monitoring the data flow process of the omni-channel clothing transaction self-pickup process.

[0195] The beneficial effects of the above technology are: based on the keys input by each participant in each processing link in the current business flow of clothing transaction self-pickup orders and the corresponding multi-level keys and corresponding multi-level encrypted data, multi-level key comparison of data is achieved to ensure that the omni-channel clothing transaction self-pickup order data can only be accessed by the participants in the corresponding processing link in a preset form, which greatly improves the data protection effect of omni-channel clothing transaction self-pickup orders.

[0196] Embodiment 10:

[0197] The present invention provides a data security protection system for the self-collection process of omni-channel clothing transactions, which is used to execute the data security protection method for the self-collection process of omni-channel clothing transactions described in any one of embodiments 1 to 9, referring to Figure 5 ,include:

[0198] Participant determination module, used to determine all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel;

[0199] The access permission determination module is used to determine the data access permission of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order based on the data protection requirements of each processing link in the business flow process;

[0200] A data encryption processing module is used to perform multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data based on the data access rights of each participant in each processing link to the corresponding complete original data to obtain the multi-level encrypted data of each participant, and generate a multi-level key for each participant;

[0201] The data security protection module is used to obtain the data security protection results of the current clothing transaction self-pickup order based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data.

[0202] The beneficial effects of the above technology are: by performing multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data, the multi-level encrypted data of each participant is obtained, and the multi-level key of each participant is generated, so as to realize the multi-level encryption of the data of each processing link in the data flow process of the clothing transaction self-pickup order, and effectively improve the security of the current clothing transaction self-pickup order data in the storage and transmission process. Even if the encryption mechanism of one level (layer) is cracked, the encryption mechanism of other layers can still protect the data of the current clothing transaction self-pickup order from being easily accessed, and also improve the flexibility of the encryption measures that can be taken for the current clothing transaction self-pickup order data.

[0203] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A data security protection method for the self-collection process of omni-channel clothing transactions, characterized in that: include: S1: Identify all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel; S2: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order; S3: Based on the data access rights of each participant in each processing link to the corresponding complete original data, multi-level encryption is performed on the accessible data of each participant in each processing link in the corresponding complete original data to obtain multi-level encrypted data of each participant, and a multi-level key of each participant is generated; S4: Based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained; S2: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order, including: S201: Based on the system preset data protection requirements, determine the first data protection requirements of each processing link in the business flow process; S202: Determine a second data protection requirement for each processing link in the business flow process based on the data protection requirement set by the user; S203: Determine the data protection requirement of each processing link in the business flow process based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process; S204: Obtaining complete original data of the current clothing transaction self-pickup order; S205: Based on the data protection requirements of each processing link in the business flow process, determine the data access rights of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the corresponding complete original data; S203: Based on the first data protection requirement and the second data protection requirement of each processing link in the business flow process, determine the data protection requirement of each processing link in the business flow process, including: Determine the protection scope of the first data protection requirement and the protection scope of the second data protection requirement for all processing links in the business flow process; According to the principle of corresponding protection scope from large to small, the first data protection requirements and the second data protection requirements of all processing links in the business flow process are sorted to obtain a data protection requirement sequence; The ranking order of the first data protection requirement or the second data protection requirement in the data protection requirement sequence of each processing link in the business flow process shall be regarded as the protection level corresponding to the first data protection requirement or the second data protection requirement; The integer range consisting of the smaller value to the larger value of the protection level of the first data protection requirement and the protection level of the second data protection requirement of each processing link in the business flow process is regarded as the protection level range of the corresponding processing link; Based on the protection evaluation model and the data protection requirements of all processing links in the business flow process of all reference users, the protection evaluation values ​​of the clothing transaction self-pickup order data of all reference users are obtained, and the data protection requirements of each processing link in the business flow process of all reference users whose protection evaluation values ​​are not less than the protection evaluation threshold are used as reference requirements; the data protection requirements of all processing links in the business flow process of the reference users are input into the protection evaluation model to obtain the protection evaluation values ​​of the clothing transaction self-pickup order data of the reference users; the protection evaluation value indicates the degree of excellence of the data protection effect obtained after data protection is performed on the clothing transaction self-pickup order of the corresponding reference user according to the data protection requirements of each processing link in the business flow process of the reference user; Based on the data protection requirement sequence, determine the protection level of the data protection requirements for each processing link in the business flow of each reference user in the reference requirements; Based on the protection level of the data protection requirements of each processing link in the business flow process of all reference users and the protection level of the second data protection requirements of each processing link in the business flow process of the current user and the range of protection levels of each processing link, determine the data protection requirements of each processing link in the business flow process; Based on the data protection requirement sequence, determine the protection level of the data protection requirements for each processing link in the business flow of each reference user in the reference requirements, which is: The sorting ordinal numbers of the data protection requirements contained in the data protection requirements sequence that are the same as the data protection requirements for each processing link in the business flow process of each reference user in the reference requirements shall be regarded as the protection level of the data protection requirements for each processing link in the business flow process of each reference user in the reference requirements.

2. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 1 is characterized in that: S1: Identify all participants in each processing link of the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel, including: S101: receiving the clothing transaction self-pickup order generated by each channel in the omni-channel in real time, and treating the clothing transaction self-pickup order generated by any channel in the omni-channel as the current clothing transaction self-pickup order; S102: Based on the task allocation mechanism, all participants in each processing link in the business flow of the current clothing transaction self-pickup order are determined.

3. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 1 is characterized in that: Based on the protection level of the data protection requirements of each processing link in the business flow process of all reference users and the protection level of the second data protection requirements of each processing link in the business flow process of the current user and the range of protection levels for each processing link, the data protection requirements for each processing link in the business flow process are determined, including: Determine all optional protection level polylines, wherein the protection level of each processing link included in the optional protection level polyline belongs to the protection level range of the corresponding processing link; Generate all reference protection level polylines based on the data protection requirements of each processing link in the business flow of all reference users; Based on the protection level of the second data protection requirement of each processing link in the current user's business flow process, generate a user-set protection level polyline; The difference between the protection level of each processing link in each optional protection level polyline, each reference protection level polyline or user-set protection level polyline and the minimum value of all protection levels in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline is regarded as the correction level of the corresponding processing link in the corresponding optional protection level polyline, reference protection level polyline or user-set protection level polyline; Generate all optional correction protection level polylines or all reference correction protection level polylines or user-set correction protection level polylines based on the correction level of each processing link in all optional protection level polylines or all reference protection level polylines or user-set protection level polylines; Among all optional correction protection level polylines, the optional correction protection level polyline with the greatest comprehensive similarity to all reference correction protection level polylines and the user-set correction protection level polyline is selected as the final correction protection level polyline; The protection level of each processing link in the optional protection level polyline corresponding to the final correction protection level polyline in the data protection requirement sequence is regarded as the data protection requirement of the corresponding processing link in the business flow process; Based on the correction level of each processing link in all optional protection level polylines, all reference protection level polylines, or user-set protection level polylines, all optional correction protection level polylines, all reference correction protection level polylines, or user-set correction protection level polylines are generated as follows: Connect the correction level of each processing link in each optional protection level polyline into a polyline in sequence according to the order of the processing links to obtain a corresponding optional correction protection level polyline; Connect the correction level of each processing link in each reference protection level polyline into a polyline in sequence according to the order of the processing links to obtain a corresponding reference correction protection level polyline; The correction level of each processing link in the user-set protection level polyline is sequentially connected into a polyline according to the sequence of the processing links to obtain the corresponding user-set correction protection level polyline.

4. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 1 is characterized in that: S3: Based on the data access rights of each participant in each processing link to the corresponding complete original data, multi-level encryption is performed on the accessible data of each participant in each processing link in the corresponding complete original data to obtain multi-level encrypted data of each participant, and a multi-level key of each participant is generated, including: S301: Determine the accessible data in the corresponding complete original data by each participant in each processing link based on the data access rights of each participant in each processing link to the corresponding complete original data; S302: Perform multi-level encryption on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate a multi-level key for each participant.

5. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 4 is characterized in that: S302: Perform multi-level encryption on the accessible data of each participant in each processing link to obtain multi-level encrypted data of each participant, and generate a multi-level key for each participant, including: Perform field-level encryption on the accessible data of each participant in each processing link, obtain the first encrypted data of each participant, and generate a field-level key for each participant; Perform row-level encryption on the first encrypted data of each participant in each processing link, obtain the second encrypted data of each participant, and generate a row-level key for each participant; Performing table-level encryption on the second encrypted data of each participant based on the secret database to obtain the third encrypted data of each participant, and generating a table-level encryption key for each participant; Identify all devices involved in each process that can access data for each participant; Based on the ECC algorithm and all involved devices of each participant's accessible data, perform device-level encryption on each participant's third encrypted data, obtain each participant's fourth encrypted data, and generate a device-level key for each participant; Performing user-level encryption on the fourth encrypted data corresponding to each participant based on the identity information of each participant, obtaining multi-level encrypted data of each participant, and generating a user-level key for each participant; The field-level keys, row-level keys, table-level encryption keys, device-level keys, and user-level keys of the accessible data of each participant in each processing link are stored separately as multi-level keys for each participant.

6. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 5 is characterized in that: Perform row-level encryption on the first encrypted data of each participant in each processing link, obtain the second encrypted data of each participant, and generate a row-level key for each participant, including: Generate a hash value for each row of data in the first encrypted data of each participant in each processing link using the signature server, and add the hash value of each row of data to the corresponding row of data in the first encrypted data to obtain a hash column of accessible data; The hash column of the first encrypted data is encrypted based on the secret database to obtain the second encrypted data of each participant, and a row-level key of each participant is generated.

7. The data security protection method for the omni-channel clothing transaction self-collection process according to claim 1 is characterized in that: S4: Based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data, the data security protection result of the current clothing transaction self-pickup order is obtained, including: S401: Based on the multi-level encrypted data of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the complete original data of the current clothing transaction self-pickup order, a data flow thread of the business flow process of the current clothing transaction self-pickup order and a corresponding data flow dynamic form are generated; S402: triggering the business flow process based on the data flow thread and the corresponding data flow dynamic form, and receiving in real time the key input by each participant in each processing link of the business flow process of the current clothing transaction self-pickup order; S403: Based on the real-time reception of the keys input by each participant in each processing link of the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level keys, determine whether the corresponding participant can read the corresponding encrypted data. If so, continue to execute the corresponding business flow process until the corresponding business flow process is traversed to obtain the data security protection result of the current clothing transaction self-pickup order. Otherwise, determine that the corresponding business flow process is abnormal as the abnormal flow monitoring result, and send the abnormal flow monitoring result to the monitoring background in real time as the data security protection result of the current clothing transaction self-pickup order.

8. The data security protection system for the omni-channel clothing transaction self-collection process is characterized by: A data security protection method for executing the omni-channel clothing transaction self-pickup process described in any one of claims 1 to 7, comprising: Participant determination module, used to determine all participants in each processing link in the business flow of the current clothing transaction self-pickup order generated from any channel in the omni-channel; The access permission determination module is used to determine the data access permission of each participant in each processing link in the business flow process of the current clothing transaction self-pickup order to the complete original data of the current clothing transaction self-pickup order based on the data protection requirements of each processing link in the business flow process; A data encryption processing module is used to perform multi-level encryption on the accessible data of each participant in each processing link in the corresponding complete original data based on the data access rights of each participant in each processing link to the corresponding complete original data to obtain the multi-level encrypted data of each participant, and generate a multi-level key for each participant; The data security protection module is used to obtain the data security protection results of the current clothing transaction self-pickup order based on the key input by each participant in each processing link in the business flow process of the current clothing transaction self-pickup order and the corresponding multi-level key and the corresponding multi-level encrypted data.

Citation Information

Patent Citations

  • Data processing method, device, equipment and medium

    CN111639938A

  • Method, system and device for processing chained data on block chain and electronic equipment

    CN116781400A