Personal data decryption and desensitization method and system for omni-channel self-pickup business in the apparel industry
By adopting multi-level verification and dual-encrypted personal data decryption and desensitization methods in the omni-channel self-pickup business of the clothing industry, the data security problems caused by a single encryption method in the existing technology are solved, and higher data privacy and security are achieved.
Patent Information
- Application Number
- CN202411002888.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-07-25
AI Technical Summary
The existing personal data encryption methods have a high probability of cracking due to a single encryption method, which cannot guarantee data privacy and security, and reduces the user experience.
The personal data decryption and desensitization method of omni-channel self-pickup service is adopted. By acquiring user access needs, device-level and user-level verification is carried out, multiple data tables are retrieved from the database based on the verification results for table-level and field-level decryption, and the decryption results are verified at a row-level level to ensure the security of the data.
Through multi-level verification and dual encryption, the user identity and device security can be maximized, and even when the key is cracked, the privacy and security of data can be ensured, improving the security of data.
Smart Images

Figure CN119004526B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data encryption technology, and in particular to a personal data decryption and desensitization method and system for omni-channel self-pickup business in the clothing industry. Background Art
[0002] At present, in today's digital age, data has become one of the indispensable resources in the business field, especially in the clothing industry. Doing a good job in collecting, organizing and managing customer profiles will greatly help analyze and understand customers, help communicate with customers, and consolidate cooperation. However, with the widespread application of data, data privacy and security issues are becoming increasingly prominent. These data often contain personal information such as the customer's name, address, contact information, height, clothing size, and dressing style, so special attention needs to be paid to data and security issues. As part of the company's top secrets, all employees of the company have the responsibility and obligation to strictly abide by the company's confidentiality system, in order to ensure that customer profile management meets relevant laws, regulations, standards, industry specifications and the actual needs of the project, thereby ensuring the security of customer information. The existing personal data encryption methods are all through the setting of specific keys and private keys. The data is encrypted by the key, and the user can obtain the data information by decrypting the data with the private key. However, it has the following problems: a single encryption method will result in a higher probability of cracking, and the data can be read when it is cracked, and the data privacy and security cannot be guaranteed. Reduced user experience. Summary of the invention
[0003] In response to the above-mentioned problems, the present invention provides a personal data decryption and desensitization method for the omni-channel self-pickup business in the clothing industry to solve the problem mentioned in the background technology that the single encryption method will lead to a high probability of cracking, the data can be read when cracked, the data privacy and security cannot be guaranteed, and the user experience is reduced.
[0004] A personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry, comprising the following steps:
[0005] Obtain the user's access requirements, determine the user's expected retrieved data based on the access requirements, confirm whether the expected retrieved data exists, and if so, generate a verification request;
[0006] Perform device-level verification and user-level verification on the user according to the verification request, and obtain the verification result;
[0007] Based on the verification results, multiple data tables are retrieved from the user's database, and table-level and field-level decryption is performed on the data tables to obtain the decryption results;
[0008] The retrieved data is obtained based on the decryption result, and the retrieved data is verified at the row level. Data errors or data display are performed based on the verification content.
[0009] Preferably, obtaining the user's access requirements, determining the user's desired retrieved data according to the access requirements, confirming whether the desired retrieved data exists, and if so, generating a verification request, includes:
[0010] Obtain the user's online data access needs through the blockchain network, analyze the online data access needs to determine the type of data and data subject to be accessed by the user;
[0011] Determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data;
[0012] Generate retrieval condition parameters according to the data description factors, perform retrieval in the secret database according to the retrieval condition parameters, and determine whether there is matching data according to the retrieval results;
[0013] If so, confirm that the expected data exists and generate a device and authentication request for the user; if not, confirm that the expected data does not exist.
[0014] Preferably, performing device-level verification and user-level verification on the user according to the verification request and obtaining the verification result includes:
[0015] Obtaining the device identification and independent key of the user's login device according to the verification request;
[0016] Confirm whether the user's login device is a trusted device based on the device identification. If so, confirm that the device verification is successful; if not, confirm that the device verification fails;
[0017] Use an independent key to log in to the confidential database, determine the user's user level based on the login result, and determine the user's operation permissions and operation interface on the login device based on the user level.
[0018] Preferably, the method of retrieving multiple data tables from the user's database based on the verification result, performing table-level decryption and field-level decryption on the data tables, and obtaining the decryption results includes:
[0019] Determine the amount of data in each data table, determine the security level of each data table based on the amount of data, and perform different encryption protections on all data tables based on the security level;
[0020] Determine the relevant business type and data table structure based on the data content of each data table, and determine the verification conditions based on the relevant business type and data table structure;
[0021] Obtain the verification script for each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations;
[0022] Determine the field format of each data table and the validation rules, write a validation function based on the validation rules, and submit the validation function to the confidential database for field-level decryption operations.
[0023] Preferably, the method of obtaining retrieved data according to the decryption result, performing a row-level verification on the retrieved data, and reporting a data error or displaying the data according to the verification content includes:
[0024] Obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value;
[0025] Compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result;
[0026] Determine whether the current hash value is the same as the target hash value based on the comparison result. If so, confirm that the stored encrypted data is consistent with the retrieved data, and display the table-level data and field-level data;
[0027] If not, confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a data tampering reminder.
[0028] A personal data decryption and desensitization system for omni-channel self-pickup business in the clothing industry, the system comprising:
[0029] The confirmation module is used to obtain the user's access requirements, determine the user's expected retrieved data based on the access requirements, and confirm whether the expected retrieved data exists. If so, generate a verification request;
[0030] The verification module is used to perform device-level verification and user-level verification on the user according to the verification request and obtain the verification result;
[0031] The decryption module is used to retrieve multiple data tables from the user's database based on the verification results, perform table-level and field-level decryption on the data tables, and obtain the decryption results;
[0032] The data error reporting and display module is used to obtain the retrieved data according to the decryption result, perform row-level verification on the retrieved data, and report data errors or display data according to the verification content.
[0033] Preferably, the confirmation module includes:
[0034] The first determination submodule is used to obtain the user's online data access requirements through the blockchain network, and parse the online data access requirements to determine the type of data and data subject to be accessed by the user;
[0035] The first acquisition submodule is used to determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data;
[0036] A search submodule is used to generate search condition parameters according to the data description factors, search in the secret database according to the search condition parameters, and determine whether there is matching data according to the search results;
[0037] The first confirmation submodule is used to confirm that the expected retrieved data exists and generate a device and identity authentication request for the user if yes, and if not, confirm that the expected retrieved data does not exist.
[0038] Preferably, the verification module comprises:
[0039] The second acquisition submodule is used to obtain the device identification and independent key of the user login device according to the verification request;
[0040] The second confirmation submodule is used to confirm whether the user login device is a trusted device according to the device identifier, and if so, confirm that the device verification is successful; if not, confirm that the device verification fails;
[0041] The second determination submodule is used to use an independent key to log in to the confidential database, determine the user level of the user according to the login result, and determine the user's operation authority and operation interface on the login device based on the user level.
[0042] Preferably, the decryption module comprises:
[0043] The first encryption submodule is used to determine the data volume of each data table, determine the security level of each data table according to the data volume, and perform encryption protection in different ways on all data tables based on the security level;
[0044] The third determination submodule is used to determine the relevant business type and data table structure according to the data content of each data table, and determine the verification condition according to the relevant business type and data table structure;
[0045] The first decryption submodule is used to obtain the verification script of each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations;
[0046] The second decryption submodule is used to determine the field format of each data table and the verification rules, write a verification function according to the verification rules, and submit the verification function to the secret database for field-level decryption operations.
[0047] Preferably, the data error reporting and display module includes:
[0048] The second encryption submodule is used to obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value;
[0049] A comparison submodule, used to compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result;
[0050] The data display submodule is used to determine whether the current hash value is the same as the target hash value based on the comparison result. If so, it confirms that the stored encrypted data is consistent with the retrieved data, and displays the table-level data and field-level data;
[0051] The data error reporting submodule is used to confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a reminder that the data has been tampered with.
[0052] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.
[0053] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.
[0055] Figure 1 This is a workflow diagram of a personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry provided by the present invention;
[0056] Figure 2 Another workflow diagram of a personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry provided by the present invention;
[0057] Figure 3 This is a structural schematic diagram of a personal data decryption and desensitization system for omni-channel self-pickup business in the clothing industry provided by the present invention;
[0058] Figure 4 This is a structural schematic diagram of a confirmation module in a personal data decryption and desensitization system for omni-channel self-pickup business in the clothing industry provided by the present invention. DETAILED DESCRIPTION
[0059] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0060] At present, in today's digital age, data has become one of the indispensable resources in the business field, especially in the clothing industry. Doing a good job in collecting, organizing and managing customer profiles will greatly help analyze and understand customers, help communicate customer sentiment, and stabilize cooperation. However, with the widespread application of data, data privacy and security issues are becoming increasingly prominent. These data often contain personal information such as the customer's name, address, contact information, height, clothing size, and dressing style, so special attention needs to be paid to data and security issues. As part of the company's top secrets, all employees of the company have the responsibility and obligation to strictly abide by the company's confidentiality system, in order to ensure that customer profile management meets relevant laws, regulations, standards, industry specifications, and the actual needs of the project, thereby ensuring the security of customer information. Existing personal data encryption methods are all through setting specific keys and private keys. The data is encrypted by the key, and the user can obtain data information by decrypting the data with the private key. However, it has the following problems: a single encryption method will result in a high probability of cracking, and the data can be read when it is cracked, and data privacy and security cannot be guaranteed. Reduced user experience. In order to solve the above problems, this embodiment discloses a personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry.
[0061] A personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry, such as Figure 1 As shown, the following steps are included:
[0062] Step S101, obtaining the user's access requirements, determining the user's desired retrieved data according to the access requirements, confirming whether the desired retrieved data exists, and if so, generating a verification request;
[0063] Step S102: Perform device-level verification and user-level verification on the user according to the verification request, and obtain the verification result;
[0064] Step S103: retrieve multiple data tables from the user's database based on the verification result, perform table-level decryption and field-level decryption on the data tables, and obtain decryption results;
[0065] Step S104: Obtain retrieved data according to the decryption result, perform row-level verification on the retrieved data, and report data errors or display data according to the verification content.
[0066] In this embodiment, the access demand is represented by an online data access demand issued by a user;
[0067] In this embodiment, device-level verification refers to trust verification of the user's device, and user-level verification refers to verification of the user's identity attributes;
[0068] In this embodiment, the row-level verification is represented by performing a hash value comparison verification on the retrieved data to determine whether the retrieved data has been tampered with or maliciously modified.
[0069] The working principle of the above technical solution is: obtain the user's access requirements, determine the user's expected retrieved data based on the access requirements, confirm whether the expected retrieved data exists, and if so, generate a verification request; perform device-level verification and user-level verification on the user according to the verification request, and obtain the verification results; based on the verification results, retrieve multiple data tables from the user's database, perform table-level decryption and field-level decryption on the data tables, and obtain the decryption results; obtain the retrieved data based on the decryption results, perform row-level verification on the retrieved data, and report data errors or display data based on the verification content.
[0070] The beneficial effects of the above technical solution are: by performing device-level and user-level verification on users accessing data, the user's identity security and device security can be maximized to avoid malicious access to data. Furthermore, by performing table-level encryption and field-level double encryption on the data table, the privacy and security of the data can be guaranteed even when the key is cracked, which is more secure and solves the problem mentioned in the prior art that the single encryption method will lead to a high probability of cracking, and the data can be read when it is cracked, and the privacy and security of the data cannot be guaranteed. The user experience is reduced.
[0071] In one embodiment, Figure 2 As shown, the obtaining of the user's access requirements, determining the user's expected retrieved data according to the access requirements, confirming whether the expected retrieved data exists, and if so, generating a verification request, including:
[0072] Step S201: obtaining the user's online data access requirements through the blockchain network, parsing the online data access requirements to determine the type of data and data subject to be accessed by the user;
[0073] Step S202: Determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data;
[0074] Step S203, generating search condition parameters according to the data description factors, searching in the secret database according to the search condition parameters, and determining whether there is matching data according to the search results;
[0075] Step S204: If yes, confirm that the expected data exists and generate a device and identity authentication request for the user; if no, confirm that the expected data does not exist.
[0076] In this embodiment, the data description factor is represented by a data macro description state factor of the desired retrieved data;
[0077] In this embodiment, the search condition parameter is represented by a keyword parameter for the user to perform data search.
[0078] The beneficial effects of the above technical solution are: determining the type of data and data subject to be accessed by the user according to the user's access needs, obtaining the data description factor of the desired data, generating retrieval condition parameters, searching in the confidential database, and determining whether there is matching data based on the retrieval results. This can provide more precise and fine-grained data retrieval, making the retrieval results more accurate and efficient, avoiding fuzzy matching and unnecessary time and space consumption, and ensuring data retrieval efficiency.
[0079] In one embodiment, performing device-level verification and user-level verification on the user according to the verification request and obtaining the verification result includes:
[0080] Obtaining the device identification and independent key of the user's login device according to the verification request;
[0081] Confirm whether the user's login device is a trusted device based on the device identification. If so, confirm that the device verification is successful; if not, confirm that the device verification fails;
[0082] Use an independent key to log in to the confidential database, determine the user's user level based on the login result, and determine the user's operation permissions and operation interface on the login device based on the user level.
[0083] In this embodiment, the independent key is represented by the private key of the user logging into the secret database;
[0084] In this embodiment, the user level is represented by the user's current role level in the set role level table.
[0085] The beneficial effects of the above technical solution are: determining whether the user's login device is a trusted device based on the device identification can ensure the security of data and avoid the hidden dangers caused by unauthorized access operations. At the same time, the database is logged in according to an independent key, and the user level of the user is determined according to the login result, thereby determining the user's operating permissions and operating interface on the device. Different operating permissions are allocated according to the user's role and responsibilities, which can also avoid unnecessary losses caused by abuse of permissions.
[0086] In one embodiment, the method of retrieving multiple data tables from the user's database based on the verification result, performing table-level decryption and field-level decryption on the data tables, and obtaining the decryption results includes:
[0087] Determine the amount of data in each data table, determine the security level of each data table based on the amount of data, and perform different encryption protections on all data tables based on the security level;
[0088] Determine the relevant business type and data table structure based on the data content of each data table, and determine the verification conditions based on the relevant business type and data table structure;
[0089] Obtain the verification script for each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations;
[0090] Determine the field format of each data table and the validation rules, write a validation function based on the validation rules, and submit the validation function to the confidential database for field-level decryption operations.
[0091] In this embodiment, the verification condition is expressed as a reference condition for verifying data tables of different business types and different data structures.
[0092] The beneficial effects of the above technical solution are: determining the verification conditions according to the relevant business type and data table structure of each data table, thereby obtaining the verification script of each data table, submitting the verification script to the confidential database to perform table-level decryption operations, making the decryption process more efficient and reusable, determining the verification rules of the data table, writing the verification function, performing field-level decryption, and submitting the verification function to the confidential database for field-level decryption operations, which can ensure the security and reliability of the code and avoid errors and vulnerabilities. At the same time, separating the decryption logic from the data also helps reduce potential attack risks.
[0093] In this embodiment, the verification script of each data table is obtained based on the verification conditions, including:
[0094] Obtain the formal description factor for verifying each data table according to the verification conditions, and call the underlying verification function based on the formal description factor;
[0095] Solve the underlying verification function, write the script code for verifying each data table according to the solution parameters, and generate the verification script;
[0096] Determine the function attribute identifier of the verification script, and call the adapted test component from the component library according to the function attribute identifier;
[0097] Get the verification logic of the underlying verification function and build a test framework based on the verification logic;
[0098] Get the same format data of each data table and use it as a test case. Based on the test case, use the test framework and test components to test the verification script.
[0099] Determine the qualification of the verification script for each data sheet based on the test results and correct and adjust the unqualified verification scripts.
[0100] The beneficial effect of the above technical solution is: by testing the verification script of each data table to ensure that the script is qualified, the data quality and data integrity of each data table can be fully verified, thereby improving the verification accuracy and verification reliability.
[0101] In one embodiment, the method of obtaining retrieved data according to the decryption result, performing row-level verification on the retrieved data, and reporting data errors or displaying data according to the verification content includes:
[0102] Obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value;
[0103] Compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result;
[0104] Determine whether the current hash value is the same as the target hash value based on the comparison result. If so, confirm that the stored encrypted data is consistent with the retrieved data, and display the table-level data and field-level data;
[0105] If not, confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a data tampering reminder.
[0106] In this embodiment, the user's personal data includes: the user's photo or ID number information and bank card number information, etc. If the hacker cracks the key and obtains the data, he can use the ID number information to make illegal operations such as loans, or change the original reserved bank card number to his own bank card number. When the user makes a refund operation later, the refund amount will be transferred to the hacker's account, causing property losses. By comparing the hash value, it can be determined whether the data accessed in real time is the same as the originally encrypted data, and then the confidence can be determined. The user's property safety and the privacy and security of identity information are guaranteed.
[0107] The beneficial effects of the above technical solution are: obtaining table-level data and field-level data according to the decryption results, and performing SM3 encryption, obtaining the current hash value, and comparing it with the target hash value of the stored encrypted data in the secret database, and determining whether the stored encrypted data is consistent with the retrieved data according to the comparison result. The retrieved data can be effectively obtained and decrypted, and the data can be verified at the first level, thereby ensuring the quality and security of the data. Once the data is tampered with, it cannot be decrypted, thereby ensuring the security and availability of the data from the source.
[0108] In one embodiment, this embodiment also discloses a personal data decryption and desensitization system for the omni-channel self-pickup business in the clothing industry, such as Figure 3 As shown, the system includes:
[0109] Confirmation module 301, used to obtain the user's access requirements, determine the user's expected retrieved data according to the access requirements, and confirm whether the expected retrieved data exists. If so, generate a verification request;
[0110] The verification module 302 is used to perform device-level verification and user-level verification on the user according to the verification request and obtain the verification result;
[0111] The decryption module 303 is used to retrieve multiple data tables from the user's database based on the verification result, perform table-level decryption and field-level decryption on the data tables, and obtain decryption results;
[0112] The data error reporting and display module 304 is used to obtain the retrieved data according to the decryption result, perform row-level verification on the retrieved data, and report data errors or display data according to the verification content.
[0113] The working principle of the above technical solution is: first, the user's access requirements are obtained through the confirmation module, and the user's expected retrieved data is determined according to the access requirements, and it is confirmed whether the expected retrieved data exists. If so, a verification request is generated; secondly, the verification module is used to perform device-level verification and user-level verification on the user according to the verification request to obtain the verification result; then, based on the decryption module, multiple data tables are retrieved from the user's database based on the verification result, and the data tables are decrypted at the table level and the field level to obtain the decryption result; finally, the data error reporting and display module is used to obtain the retrieved data according to the decryption result, and the retrieved data is verified at the row level, and data error reporting or data display is performed according to the verification content.
[0114] The beneficial effects of the above technical solution are: by performing device-level and user-level verification on users accessing data, the user's identity security and device security can be maximized, and malicious access to data can be avoided. Furthermore, by performing table-level encryption and field-level double encryption on the data table, the privacy and security of the data can be guaranteed even when the key is cracked, with a higher level of security.
[0115] In one embodiment, Figure 4 As shown, the confirmation module 301 includes:
[0116] The first determination submodule 3011 is used to obtain the user's online data access requirements through the blockchain network, and parse the online data access requirements to determine the type of data and data subject to be accessed by the user;
[0117] The first acquisition submodule 3012 is used to determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data;
[0118] The search submodule 3013 is used to generate search condition parameters according to the data description factors, search in the secret database according to the search condition parameters, and determine whether there is matching data according to the search results;
[0119] The first confirmation submodule 3014 is used to, if yes, confirm that the expected retrieved data exists and generate a device and identity authentication request for the user; if no, confirm that the expected retrieved data does not exist.
[0120] The beneficial effects of the above technical solution are: determining the type of data and data subject to be accessed by the user according to the user's access needs, obtaining the data description factor of the desired data, generating retrieval condition parameters, searching in the confidential database, and determining whether there is matching data based on the retrieval results. This can provide more precise and fine-grained data retrieval, making the retrieval results more accurate and efficient, avoiding fuzzy matching and unnecessary time and space consumption, and ensuring data retrieval efficiency.
[0121] In one embodiment, the verification module includes:
[0122] The second acquisition submodule is used to obtain the device identification and independent key of the user login device according to the verification request;
[0123] The second confirmation submodule is used to confirm whether the user login device is a trusted device according to the device identifier, and if so, confirm that the device verification is successful; if not, confirm that the device verification fails;
[0124] The second determination submodule is used to use an independent key to log in to the confidential database, determine the user level of the user according to the login result, and determine the user's operation authority and operation interface on the login device based on the user level.
[0125] The beneficial effects of the above technical solution are: determining whether the user's login device is a trusted device based on the device identification can ensure the security of data and avoid the hidden dangers caused by unauthorized access operations. At the same time, the database is logged in according to an independent key, and the user level of the user is determined according to the login result, thereby determining the user's operating permissions and operating interface on the device. Different operating permissions are allocated according to the user's role and responsibilities, which can also avoid unnecessary losses caused by abuse of permissions.
[0126] In one embodiment, the decryption module includes:
[0127] The first encryption submodule is used to determine the data volume of each data table, determine the security level of each data table according to the data volume, and perform encryption protection in different ways on all data tables based on the security level;
[0128] The third determination submodule is used to determine the relevant business type and data table structure according to the data content of each data table, and determine the verification condition according to the relevant business type and data table structure;
[0129] The first decryption submodule is used to obtain the verification script of each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations;
[0130] The second decryption submodule is used to determine the field format of each data table and the verification rules, write a verification function according to the verification rules, and submit the verification function to the secret database for field-level decryption operations.
[0131] The beneficial effects of the above technical solution are: determining the verification conditions according to the relevant business type and data table structure of each data table, thereby obtaining the verification script of each data table, submitting the verification script to the confidential database to perform table-level decryption operations, making the decryption process more efficient and reusable, determining the verification rules of the data table, writing the verification function, performing field-level decryption, and submitting the verification function to the confidential database for field-level decryption operations, which can ensure the security and reliability of the code and avoid errors and vulnerabilities. At the same time, separating the decryption logic from the data also helps reduce potential attack risks.
[0132] In one embodiment, the data error reporting and display module includes:
[0133] The second encryption submodule is used to obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value;
[0134] A comparison submodule, used to compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result;
[0135] The data display submodule is used to determine whether the current hash value is the same as the target hash value based on the comparison result. If so, it confirms that the stored encrypted data is consistent with the retrieved data, and displays the table-level data and field-level data;
[0136] The data error reporting submodule is used to confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a reminder that the data has been tampered with.
[0137] The beneficial effects of the above technical solution are: obtaining table-level data and field-level data according to the decryption results, and performing SM3 encryption, obtaining the current hash value, and comparing it with the target hash value of the stored encrypted data in the secret database, and determining whether the stored encrypted data is consistent with the retrieved data according to the comparison result. The retrieved data can be effectively obtained and decrypted, and the data can be verified at the first level, thereby ensuring the quality and security of the data. Once the data is tampered with, it cannot be decrypted, thereby ensuring the security and availability of the data from the source.
[0138] Those skilled in the art should understand that the first and second in the present invention merely refer to different application stages.
[0139] Other embodiments of the present disclosure will be readily apparent to those skilled in the art after considering the specification and practicing the disclosure disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0140] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A personal data decryption and desensitization method for omni-channel self-pickup business in the clothing industry, characterized in that: The following steps are involved: Obtain the user's access requirements, determine the user's expected retrieved data based on the access requirements, confirm whether the expected retrieved data exists, and if so, generate a verification request; Perform device-level verification and user-level verification on the user according to the verification request, and obtain the verification result; Based on the verification results, multiple data tables are retrieved from the user's database, and table-level and field-level decryption is performed on the data tables to obtain the decryption results; Obtain retrieved data based on the decryption result, perform row-level verification on the retrieved data, and report data errors or display data based on the verification content; The method of retrieving multiple data tables from the user's database based on the verification results, performing table-level decryption and field-level decryption on the data tables, and obtaining decryption results includes: Determine the amount of data in each data table, determine the security level of each data table based on the amount of data, and perform different encryption protections on all data tables based on the security level; Determine the relevant business type and data table structure based on the data content of each data table, and determine the verification conditions based on the relevant business type and data table structure; Obtain the verification script for each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations; Determine the field format of each data table and the validation rules, write the validation function according to the validation rules, and submit the validation function to the secret database for field-level decryption operations; Get the validation script for each data table based on the validation conditions, including: Obtain the formal description factor for verifying each data table according to the verification conditions, and call the underlying verification function based on the formal description factor; Solve the underlying verification function, write the script code for verifying each data table according to the solution parameters, and generate the verification script; Determine the function attribute identifier of the verification script, and call the adapted test component from the component library according to the function attribute identifier; Get the verification logic of the underlying verification function and build a test framework based on the verification logic; Get the same format data of each data table and use it as a test case. Based on the test case, use the test framework and test components to test the verification script. Determine the qualification of the verification script for each data sheet based on the test results and correct and adjust the unqualified verification scripts.
2. According to claim 1, the personal data decryption and desensitization method for the omni-channel self-pickup business in the clothing industry is characterized in that: The obtaining of the user's access requirements, determining the user's expected retrieved data according to the access requirements, confirming whether the expected retrieved data exists, and if so, generating a verification request, includes: Obtain the user's online data access needs through the blockchain network, analyze the online data access needs to determine the type of data and data subject to be accessed by the user; Determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data; Generate retrieval condition parameters according to the data description factors, perform retrieval in the secret database according to the retrieval condition parameters, and determine whether there is matching data according to the retrieval results; If so, confirm that the expected data exists and generate a device and authentication request for the user; if not, confirm that the expected data does not exist.
3. According to claim 1, the personal data decryption and desensitization method for the omni-channel self-pickup business in the clothing industry is characterized in that: The performing device-level verification and user-level verification on the user according to the verification request and obtaining the verification result includes: Obtaining the device identification and independent key of the user's login device according to the verification request; Confirm whether the user's login device is a trusted device based on the device identification. If so, confirm that the device verification is successful; if not, confirm that the device verification fails; Use an independent key to log in to the confidential database, determine the user's user level based on the login result, and determine the user's operation permissions and operation interface on the login device based on the user level.
4. According to claim 1, the personal data decryption and desensitization method for the omni-channel self-pickup business in the clothing industry is characterized in that: The method of obtaining retrieved data according to the decryption result, performing row-level verification on the retrieved data, and reporting data errors or displaying data according to the verification content includes: Obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value; Compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result; Determine whether the current hash value is the same as the target hash value based on the comparison result. If so, confirm that the stored encrypted data is consistent with the retrieved data, and display the table-level data and field-level data; If not, confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a data tampering reminder.
5. A personal data decryption and desensitization system for omni-channel self-pickup business in the clothing industry, characterized by: The system includes: The confirmation module is used to obtain the user's access requirements, determine the user's expected retrieved data based on the access requirements, and confirm whether the expected retrieved data exists. If so, generate a verification request; The verification module is used to perform device-level verification and user-level verification on the user according to the verification request and obtain the verification result; The decryption module is used to retrieve multiple data tables from the user's database based on the verification results, perform table-level and field-level decryption on the data tables, and obtain the decryption results; The data error reporting and display module is used to obtain the retrieved data according to the decryption result, perform row-level verification on the retrieved data, and report data errors or display data according to the verification content; The decryption module comprises: The first encryption submodule is used to determine the data volume of each data table, determine the security level of each data table according to the data volume, and perform encryption protection in different ways on all data tables based on the security level; The third determination submodule is used to determine the relevant business type and data table structure according to the data content of each data table, and determine the verification condition according to the relevant business type and data table structure; The first decryption submodule is used to obtain the verification script of each data table based on the verification conditions, and submit the verification script to the secret database to perform table-level decryption operations; The second decryption submodule is used to determine the field format of each data table and the verification rules, write the verification function according to the verification rules, and submit the verification function to the secret database for field-level decryption operation; Get the validation script for each data table based on the validation conditions, including: Obtain the formal description factor for verifying each data table according to the verification conditions, and call the underlying verification function based on the formal description factor; Solve the underlying verification function, write the script code for verifying each data table according to the solution parameters, and generate the verification script; Determine the function attribute identifier of the verification script, and call the adapted test component from the component library according to the function attribute identifier; Get the verification logic of the underlying verification function and build a test framework based on the verification logic; Get the same format data of each data table and use it as a test case. Based on the test case, use the test framework and test components to test the verification script. Determine the qualification of the verification script for each data sheet based on the test results and correct and adjust the unqualified verification scripts.
6. According to claim 5, the personal data decryption and desensitization system for the omni-channel self-pickup business in the clothing industry is characterized in that: The confirmation module comprises: The first determination submodule is used to obtain the user's online data access requirements through the blockchain network, and parse the online data access requirements to determine the type of data and data subject to be accessed by the user; The first acquisition submodule is used to determine the user's expected scheduling data according to the data type and the data subject, and obtain the data description factor of the expected retrieved data; A search submodule is used to generate search condition parameters according to the data description factors, search in the secret database according to the search condition parameters, and determine whether there is matching data according to the search results; The first confirmation submodule is used to confirm that the expected retrieved data exists and generate a device and identity authentication request for the user if yes, and if not, confirm that the expected retrieved data does not exist.
7. According to claim 5, the personal data decryption and desensitization system for the omni-channel self-pickup business in the clothing industry is characterized in that: The verification module comprises: The second acquisition submodule is used to obtain the device identification and independent key of the user login device according to the verification request; The second confirmation submodule is used to confirm whether the user login device is a trusted device according to the device identifier, and if so, confirm that the device verification is successful; if not, confirm that the device verification fails; The second determination submodule is used to use an independent key to log in to the confidential database, determine the user level of the user according to the login result, and determine the user's operation authority and operation interface on the login device based on the user level.
8. According to claim 5, the personal data decryption and desensitization system for the omni-channel self-pickup business in the clothing industry is characterized in that: The data error reporting and display module includes: The second encryption submodule is used to obtain table-level data and field-level data according to the decryption result, perform SM3 encryption on the table-level data and field-level data respectively, and obtain the current hash value; A comparison submodule, used to compare the current hash value with the target hash value of the encrypted data stored in the secret database to obtain a comparison result; The data display submodule is used to determine whether the current hash value is the same as the target hash value based on the comparison result. If so, it confirms that the stored encrypted data is consistent with the retrieved data, and displays the table-level data and field-level data; The data error reporting submodule is used to confirm that the stored encrypted data is inconsistent with the retrieved data, report a data error and issue a reminder that the data has been tampered with.
Citation Information
Patent Citations
Method for preventing data leakage, server and storage medium
CN110889121A
Database-based data processing method and device, equipment, and storage medium
CN113886357A
Network information security verification method and system based on block chain technology
CN117353893A