Data storage method, data acquisition method and device
By splitting and sharding data and encrypting storage according to the sensitivity level, the problem of low reliability of data storage methods in the prior art is solved, and high-reliability data storage is achieved.
Patent Information
- Application Number
- CN202411807511.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-12-10
AI Technical Summary
The reliability of data storage methods in the prior art leads to increased risk of data breaches and security.
By obtaining the operation request of the target account, splitting and sharding the data to be stored, and encrypting and storing the data shards according to the sensitivity level, ensuring that data of different sensitivity levels is stored in different databases.
Accurate storage of data corresponding to different operations is achieved, and the reliability of data storage is improved through encryption, reducing the risk of data leakage.
Smart Images

Figure CN119293857B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a data storage method, a data acquisition method and a device. Background Art
[0002] With the continuous development of the Internet and the increasing use of computers and networks, the value of research data has become an indispensable part of scientific research. While people are enjoying the great convenience brought by the Internet, they are also worried about the security of their private data, especially the transaction data of users involved in trading platforms.
[0003] In recent years, research on information security has become a research hotspot. In order to ensure information security, existing technologies usually adopt distributed storage based on the sensitivity of information. However, since distributed storage may distribute data on different nodes, it will increase the risk of data leakage and data security, thereby reducing the reliability of data storage.
[0004] With regard to the problem of low reliability of data storage methods in the prior art, no effective technical solution has been proposed yet. Summary of the invention
[0005] The embodiments of the present application provide a data storage method, a data acquisition method and a device to at least solve the problem of low reliability of data storage methods in the prior art.
[0006] According to one aspect of an embodiment of the present application, a data storage method is provided, including: obtaining a target operation request of a target account on a trading platform, and obtaining a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by the target user to log in to the trading platform; performing a split operation on the data to be stored to obtain multiple first data, and obtaining a type sensitivity level corresponding to the request type and a data sensitivity level corresponding to each of the multiple first data; performing a data sharding operation on the multiple first data according to the type sensitivity level and the multiple data sensitivity levels to obtain a data shard set corresponding to each first data; respectively storing multiple data shards in each data shard set in multiple databases corresponding to the multiple data shards, wherein the multiple data shards in the same data shard set correspond to different databases; determining a library sensitivity level corresponding to each database according to the data shards stored in the multiple databases, and performing encryption operations on the multiple databases according to the multiple library sensitivity levels.
[0007] According to another aspect of an embodiment of the present application, a data acquisition method is also provided, including: obtaining a data sensitivity level corresponding to the data to be acquired according to a data acquisition request, and a type sensitivity level corresponding to the data sensitivity level; determining a target data sharding method according to the data sensitivity level and the type sensitivity level, and determining multiple databases corresponding to the target data sharding method according to the target data sharding method; obtaining a target key and multiple reference keys corresponding to the multiple databases, and a data circulation channel corresponding to the data sensitivity level; after decrypting the multiple databases using the target key and the multiple reference keys, obtaining a data shard set corresponding to the data to be acquired from the multiple databases; after reorganizing the multiple data shards in the data shard set to obtain the data to be acquired, sending the data to be acquired to the client corresponding to the data acquisition request through the data circulation channel.
[0008] According to another aspect of the embodiment of the present application, a data storage device is also provided, including: an acquisition unit, used to acquire a target operation request of a target account on a trading platform, and acquire a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by the target user to log in to the trading platform; a splitting unit, used to split the data to be stored to obtain multiple first data, and acquire the type sensitivity level corresponding to the request type and the data sensitivity level corresponding to each of the multiple first data; a sharding unit, used to perform a data sharding operation on the multiple first data according to the type sensitivity level and the multiple data sensitivity levels, to obtain a data shard set corresponding to each first data; a storage unit, used to store the multiple data shards in each data shard set in the multiple databases corresponding to the multiple data shards, respectively, wherein the multiple data shards in the same data shard set correspond to different databases; an encryption unit, used to determine the library sensitivity level corresponding to each database according to the data shards stored in the multiple databases, and perform encryption operations on the multiple databases according to the multiple library sensitivity levels.
[0009] Optionally, the above-mentioned sharding unit includes an acquisition subunit, which is used to acquire a set of sharding methods corresponding to the type sensitivity level and multiple data sensitivity levels, wherein the sharding method set includes multiple data sharding methods, and each sharding method corresponds to a data sensitivity level; a first determination subunit, which is used to determine any first data among multiple first data as data to be sharded, and determine a reference sensitivity level corresponding to the data to be sharded from multiple data sensitivity levels; a second determination subunit, which is used to determine a reference sharding method corresponding to the reference sensitivity level from multiple data sharding methods, and use the reference sharding method to perform data sharding operations on the data to be sharded, so as to obtain a data sharding set corresponding to the data to be sharded; a third determination subunit, which is used to determine any first data among multiple first data except the data to be sharded as data to be sharded.
[0010] Optionally, the above-mentioned splitting unit includes a splitting sub-unit, which is used to use a data splitting model to perform a splitting operation on the data to be stored to obtain multiple first data, wherein the data splitting model integrates multiple data processing modules and multiple data splitting modules, and each data splitting module corresponds to a data splitting method.
[0011] Optionally, the above-mentioned splitting sub-unit includes a first acquisition module, which is used to acquire the data structure of the data to be stored, and select a target processing module corresponding to the data structure from multiple data processing modules according to the data structure; a target processing module, which is used to use the target processing module to perform target processing on the data to be stored, and obtain reference data corresponding to the data to be stored, wherein the target processing is used to process the data to be stored into data that meets a preset display format; a second acquisition module, which is used to acquire the data format of the reference data, and use the target splitting module corresponding to the data format among multiple data splitting modules to perform a splitting operation on the reference data to obtain multiple first data.
[0012] Optionally, the encryption unit includes a first acquisition subunit, which is used to acquire reference encryption methods corresponding to multiple library sensitivity levels, and obtain multiple reference encryption methods, wherein each library sensitivity level corresponds to a reference encryption method; a first encryption subunit, which is used to perform reference encryption on multiple databases using multiple reference encryption methods, and obtain multiple reference keys, and use replacement methods corresponding to multiple library sensitivity levels to replace the multiple reference keys, and determine the replaced multiple reference keys as multiple reference keys; a second acquisition subunit, which is used to acquire target sensitivity levels corresponding to multiple databases, and determine the target encryption method from the multiple reference encryption methods according to the target sensitivity levels; a second encryption subunit, which is used to perform target encryption on multiple reference keys using the target encryption method, and obtain a target key, and use the replacement method corresponding to the target sensitivity level to replace the target key, and determine the obtained target key as the target key.
[0013] Optionally, the above-mentioned data storage device also includes a setting unit, which is used to set multiple data circulation channels for multiple data sensitivity levels, wherein each data sensitivity level corresponds to a data circulation channel.
[0014] According to another aspect of the embodiment of the present application, a data acquisition device is also provided, including: a first acquisition unit, used to acquire the data sensitivity level corresponding to the data to be acquired according to a data acquisition request, and the type sensitivity level corresponding to the data sensitivity level; a determination unit, used to determine the target data sharding method according to the data sensitivity level and the type sensitivity level, and determine multiple databases corresponding to the target data sharding method according to the target data sharding method; a second acquisition unit, used to acquire target keys and multiple reference keys corresponding to multiple databases, and data circulation channels corresponding to the data sensitivity levels; a decryption unit, used to decrypt multiple databases using the target key and multiple reference keys, and then acquire a data shard set corresponding to the data to be acquired from the multiple databases; a reorganization unit, used to reorganize multiple data shards in the data shard set to obtain the data to be acquired, and then send the data to be acquired to the client corresponding to the data acquisition request through the data circulation channel.
[0015] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the above data storage method or data acquisition method.
[0016] According to another aspect of the embodiments of the present application, an electronic device is also provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the above data storage method or data acquisition method.
[0017] Through the above data storage method, the data corresponding to different operations can be accurately stored, and the database is encrypted through a special encryption method after storage, thereby improving the reliability of the data storage method. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 is a schematic diagram of a hardware environment of an optional data storage method and a data acquisition method according to an embodiment of the present invention;
[0020] Figure 2 is a flow chart of an optional data storage method according to an embodiment of the present invention;
[0021] Figure 3 is a schematic diagram of an optional data storage method according to an embodiment of the present invention
[0022] Figure 4 is a flow chart of an optional data acquisition method according to an embodiment of the present invention;
[0023] Figure 5 is a schematic diagram of the structure of an optional data storage device according to an embodiment of the present invention
[0024] Figure 6 It is a schematic structural diagram of an optional data acquisition device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. It should be noted that, in the absence of conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0027] In order to solve the problem of low reliability of data storage methods in the prior art, the embodiment of the present application provides a data storage method and a data acquisition method corresponding to the data storage method. As an optional implementation, the above data storage method and data acquisition method can be applied to, but not limited to, Figure 1 The data storage and data acquisition system shown in FIG. 1 is composed of a terminal device 100, a terminal device 102 and a server 104. Figure 1As shown, the terminal device 100 and the terminal device 102 are connected to the server 104 via a network 110. The network 110 may include, but is not limited to, a wired network, a wireless network, and the terminal device 100 and the terminal device 102 are both provided with a display, a processor, and a memory (such as Figure 1 As shown, the terminal device 102 is provided with a display 106, a processor 108 and a memory 112, and the terminal device 100 is provided with a display 118, a processor 120 and a memory 122). The display 106 can be used to display the operation interface corresponding to the target operation and the operation information filled in by the target user when using the target account to perform the target operation, etc. The display 118 can be used to display the selection interface of multiple data to be obtained before the data acquisition request is sent, the processor 108 can be used to perform data processing on the target operation request corresponding to the target operation, the processor 120 can be used to perform data processing on the data acquisition request, and the memory 112 and the memory 122 can be used to store the relevant information involved in this application; the server 104 can be a single server, or a server cluster composed of multiple servers, or a cloud server. The above-mentioned server 104 includes a database 114 and a processing engine 116. Among them, the above-mentioned database 114 can be used to store target accounts, target operation requests, request types, type sensitivity levels, multiple data sensitivity levels, etc., and the above-mentioned processing engine 116 is used to perform data processing on target accounts, target operation requests, request types, type sensitivity levels, multiple data sensitivity levels, etc.
[0028] According to one aspect of the embodiment of the present invention, the data storage and data acquisition system may further perform the following steps: when executing the data storage method, first, the terminal device 102 executes S102 to send a target operation request to the server 104 through the network 110; then, the server 104 executes Figure 1 S104 to S112 shown in the figure, thereby completing the storage of the data corresponding to the target operation request; when executing the data acquisition method, first, the terminal device 100 executes S114, sends a data acquisition request to the server 104 through the network 110, and then the server 104 executes as shown in the figure. Figure 1 S116 to S124 shown in FIG. 116 , thereby completing the acquisition of the data to be acquired. Finally, the server executes the following Figure 1 In S126 shown, the obtained data to be acquired is sent to the terminal device 100 through the corresponding data circulation channel.
[0029] Through the above data storage method, the data corresponding to different operations can be accurately stored, and the database is encrypted through a special encryption method after storage, thereby improving the reliability of the data storage method.
[0030] The above is only an example and is not limited in this embodiment.
[0031] As an optional implementation, please refer to Figure 2 The flowchart of the data storage method shown in FIG. 1 may include the following steps:
[0032] S202, obtaining a target operation request of a target account on a trading platform, and obtaining a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by a target user to log in to the trading platform;
[0033] S204, performing a splitting operation on the data to be stored to obtain a plurality of first data, and obtaining a type sensitivity level corresponding to the request type and a data sensitivity level corresponding to each of the plurality of first data;
[0034] S206, performing a data sharding operation on the plurality of first data according to the type sensitivity level and the plurality of data sensitivity levels, to obtain a data sharding set corresponding to each first data;
[0035] S208, storing the multiple data shards in each data shard set in multiple databases corresponding to the multiple data shards, respectively, wherein the multiple data shards in the same data shard set correspond to different databases;
[0036] S210, determining a database sensitivity level corresponding to each database according to the data fragments stored in the multiple databases, and performing encryption operations on the multiple databases according to the multiple database sensitivity levels.
[0037] The target account in the above S202 can be understood as, but not limited to, an account for the target user to log in to the transaction platform. The transaction platform is a platform where the target user can perform target operations. The target operations include: login operation, query operation, modification operation (such as modification of personal information, modification of payment information, etc.), transaction operation (such as payment operation), etc. Before the target user performs any target operation, the target user needs to initiate a corresponding target operation request. For example, the target operation request corresponding to the login operation is a login request, the target operation request corresponding to the query operation is a query request, the modification operation corresponds to a modification request, the transaction operation corresponds to a transaction request, etc. The above request type is the request type corresponding to the target operation request. For example, the request type corresponding to the login request is a login type, the request corresponding to the query request is a query type, the request corresponding to the modification request is a modification type, the request type corresponding to the transaction request is a transaction type, etc. It should be noted that the above target operations, target operation requests, and request types are all examples and do not constitute a limitation thereto. When the solution is specifically implemented, the specific operations will be divided more finely. For example, the modification operation is divided into a personal information modification operation corresponding to modifying personal information and a transaction information modification operation corresponding to modifying transaction information, etc.
[0038] The above-mentioned data to be stored include all data corresponding to the target operation request. For example, in the case where the request type is a query request for querying personal information, the data to be stored include the target account, the user name corresponding to the target account, the user information corresponding to the target account (such as name, gender, ID number, contact information, etc.), the current query record corresponding to the target operation request (such as query timestamp, query type (indicating whether the query is personal information or transaction information, etc.), the device fingerprint corresponding to the device that initiates the target operation request (the device is used to run the trading platform, and the device fingerprint uniquely corresponds to the device)), etc.
[0039] The splitting operation in the above S204 can be but is not limited to being understood as splitting all the data in the data to be stored, for example, the target account, the user name corresponding to the target account, the user information corresponding to the target account, the current query record corresponding to the target operation request, the device fingerprint corresponding to the device that initiates the target operation request, etc. included in the above data to be stored are separately split out to obtain 5 first data (that is, the above multiple first data). The above acquisition type sensitivity level can be but is not limited to being understood as acquiring the type sensitivity level corresponding to the request type from multiple preset type sensitivity levels, wherein different request types correspond to different sensitivity levels; acquiring the data sensitivity level corresponding to each of the multiple first data includes: determining a data sensitivity level set corresponding to the request type from multiple preset data sensitivity level sets, and determining the data sensitivity level corresponding to each first data from the multiple reference data sensitivity levels included in the data sensitivity level set, wherein each first data corresponds to a data sensitivity level, and the data sensitivity level corresponding to each data may be the same or different.
[0040] For example, the type sensitivity level and data sensitivity level mentioned above are as follows: when the request type is a query type, the type sensitivity level is 3, and when the request type is a transaction type, the type sensitivity level is 6 (higher than the type sensitivity level of the transaction request), and the first preset sensitivity level set corresponding to the query type is {1,2,3,4}, and the second preset sensitivity level set corresponding to the transaction type is {4,5,6,7,8,9}. If the target operation corresponding to the request type is an operation to query personal information, the corresponding first data to be stored includes the first account, the first user name corresponding to the first account, the first contact information, the first query timestamp of initiating the query request, the first query device, etc., and if the target operation corresponding to the transaction type is a payment operation, The second data to be stored includes the second account, the second user name corresponding to the second account, the second contact information, the first transaction timestamp for initiating the payment request, the first payment device, etc., so although the first data to be stored and the second data to be stored both include the contact information (i.e., the first contact information in the first data to be stored and the second contact information in the second data to be stored), the data sensitivity level corresponding to the first contact information finally determined can only be the data sensitivity level in the first preset sensitivity level set, and the data sensitivity level corresponding to the second contact information can only be the data sensitivity level in the second preset sensitivity level set. Because the sensitivity of the query operation and the transaction operation itself is different, the sensitivity of the same first data involved in different operations may be different. For example, for the query operation, the contact information in the data to be stored does not need to be too sensitive, and it is only necessary to query its corresponding information. However, for the payment operation, the contact information needs to be sensitive, so that it can not only detect whether there is fraudulent payment in multiple payment operations in the future, but also ensure the accuracy of the payment. However, for query operations such as querying personal information and querying payment records, the sensitivity of the target account may be the same.
[0041] The data sharding operation in the above S206 can be but is not limited to being understood as data sharding for each first data, for example, splitting a mobile phone number into 3 data shards, splitting an ID number into 4 data shards, and so on. The storage operation in the above S208 can be but is not limited to storing multiple data shards in each data shard set in different databases. The operation in the above S208 includes: determining any data shard set in the multiple data shard sets as the current data shard set, and determining the current database set determined by the current data shard set; storing multiple current data shards in the current data shard set in multiple current databases of the current database set, respectively, wherein each current data shard corresponds to a current database, and the multiple databases include multiple current databases; determining any data shard set in the multiple data shard sets except the current data shard set as the current data shard set.
[0042] The following Figure 3 Take S206 to S208 above as an example to illustrate:
[0043] Assume that Figure 3 The first data 302 and the second data 304 shown are any two first data among the above-mentioned multiple first data, such as Figure 3 As shown, a data sharding operation is performed on the first data 302 to obtain a first data shard set (i.e., the above-mentioned data shard set) corresponding to the first data 302, the first data shard set includes a first data shard, a second data shard, and a third data shard (i.e., multiple data shards included in the data shard set), and a data sharding operation is performed on the first data 304 to obtain a second data shard set (i.e., the above-mentioned data shard set) corresponding to the first data 304, the second data shard set includes a fourth data shard, a fifth data shard, a sixth data shard, a seventh data shard, and an eighth data shard (i.e., multiple data shards included in the data shard set). When the first data shard set is stored in the above-mentioned S208, it is first determined that the database set corresponding to the first data shard set includes database 1, database 4, and database 5 (i.e., the above-mentioned multiple databases), and then the first data shard, the second data shard, and the third data shard are stored in the database corresponding to each data shard, as shown in FIG. Figure 3 As shown, the first data shard is stored in database 1, the second data shard is stored in database 4, and the third data shard is stored in database 6. When the second data shard set is stored in S208, it is first determined that the database set corresponding to the second data shard set includes database 2, database 3, database 4, and database 5 (i.e., the above-mentioned multiple databases), and then the fourth data shard, the fifth data shard, the sixth data shard, the seventh data shard, and the eighth data shard are respectively stored in the database corresponding to each data shard, as shown in FIG. Figure 3 As shown, the first data shard is stored in database 3, the fifth data shard is stored in database 4, the sixth data shard is stored in database 2, and the seventh data shard and the eighth data shard are stored in database 5. At this point, multiple data shards in the first data shard set corresponding to the first data 302 and multiple data shards in the second data shard set corresponding to the second data 304 are stored.
[0044] It should be noted that when the data shards are stored in the database, the request type and target account corresponding to the data shards will also be stored accordingly. Before executing the operation in S204 above, the request type and the target account carried in the target operation request can be used to search in the database to see whether the request type and the target account are stored. If so, there is no need to perform S204 to S210. If not, the data storage operations in S204 to S210 can continue to be performed.
[0045] The operation in the above S210 can be understood, but is not limited to, as determining the library sensitivity level of each database based on the data shards stored in the database, and then each database can be encrypted using an encryption method corresponding to the library sensitivity level to further improve the reliability of data storage.
[0046] It should also be noted that after S206 and before S208, the encryption of data fragments is also included, specifically including: obtaining the type weight corresponding to the type sensitivity level and the data weight corresponding to each of the multiple first data; determining the comprehensive weight corresponding to each first data according to the type weight and the multiple data weights; selecting multiple reference encryption methods from the following multiple reference encryption methods according to the comprehensive weight to perform fragment encryption on the multiple data fragments corresponding to each of the first data, wherein each data fragment corresponds to a reference encryption method, and the reference encryption methods corresponding to each data fragment can be the same or different. Then execute S208, and the storage operation in S208 can be understood, but not limited to, as storing the fragments obtained after the fragment encryption.
[0047] The operations in S202 to S210 above can store the data corresponding to different request types in layers according to type sensitivity and data sensitivity. High-sensitivity data (such as payment information, personal identity information) and low-sensitivity data (such as general query records) are stored in different physical or logical databases (that is, the database type of the above multiple databases can be a physical database or a logical database), and independent encryption is used. This storage method can effectively prevent the problem of global data leakage caused by the breach of a certain database.
[0048] It should be noted that each of the above-mentioned multiple databases is encrypted with an independent key, and these keys are transmitted and managed in different channels. For example, identity information encryption uses AES-256 (i.e., one of the multiple reference encryption methods described below), while payment information encryption uses a double encryption strategy (AES-256+RSA-2048) (i.e., one of the multiple reference encryption methods described below). In addition, all keys are encrypted by one, and the keys are rotated periodically. In order to ensure that data flows of different types and sensitivities do not cross during data transmission, the data storage method in this application will also set different data circulation channels for data of different types and sensitivities, so that even if a security incident occurs in a certain channel, the data in other channels will still be safe.
[0049] The data storage method in the present application stores and sets different circulation channels separately according to the type sensitivity level of the request type (the request type also corresponds to the response operation type, that is, the operation type of the target operation that the target user wants to perform on the trading platform) and the data sensitivity level corresponding to the data (that is, the circulation channels corresponding to data of different data sensitivity levels in the same target operation are different). These data are encrypted and transmitted through independent communication channels (that is, data circulation channels), which effectively reduces the security risks that may be caused by single point failures.
[0050] Through the above data storage method, the data corresponding to the target operation can be split and fragmented for storage, which improves the reliability of data storage. At the same time, the database storing the corresponding data is encrypted, further improving the reliability of the data storage method.
[0051] As an optional implementation manner, a data sharding operation is performed on multiple first data according to the type sensitivity level and multiple data sensitivity levels to obtain a data sharding set corresponding to each first data, including:
[0052] S1, obtaining a set of sharding methods corresponding to a type sensitivity level and multiple data sensitivity levels, wherein the set of sharding methods includes multiple data sharding methods, and each sharding method corresponds to a data sensitivity level;
[0053] S2, determining any first data among the plurality of first data as data to be fragmented, and determining a reference sensitivity level corresponding to the data to be fragmented from a plurality of data sensitivity levels;
[0054] S3, determining a reference sharding method corresponding to a reference sensitivity level from a plurality of data sharding methods, and performing a data sharding operation on the data to be sharded using the reference sharding method to obtain a data sharding set corresponding to the data to be sharded;
[0055] S4, determining any first data among the plurality of first data except the data to be fragmented as the data to be fragmented.
[0056] The above S1 can be understood, but is not limited to, as different data sensitivity levels correspond to different data sharding methods, and the data sensitivity level indicates the sensitivity of the first data. For example, a high sensitivity level indicates high-sensitivity data (such as ID number and payment account number in payment operations, etc.), and a low sensitivity level indicates low-sensitivity data (target account number in query operations, user name corresponding to the target account number, etc.).
[0057] It should be noted that, in addition to the sharding method set, the data obtained in the above S1 also includes the data type of the first data corresponding to each data sensitivity level. The sharding method set is also a sharding method set corresponding to multiple data types. The various data sharding methods include regional sharding (including multiple regional sharding methods corresponding to data types, such as regional sharding methods corresponding to mobile phone numbers, regional sharding methods corresponding to ID card numbers, regional sharding methods corresponding to bank card numbers, etc.), length sharding (which can be understood but not limited to sharding according to a pre-set number of bytes), hash sharding (the above three types can be used to shard mobile phone numbers and ID card numbers, for example), birthday sharding, gender sharding, age sharding (these three types can be used to shard ID card numbers, etc.), group sharding, and no sharding, etc.
[0058] The operation in S3 above can be understood, but is not limited to, as determining the corresponding reference sharding method according to the reference sensitivity level and data type. For example, assuming that the first data is a mobile phone number, and its corresponding data type is a personal information type, and the data sharding methods that can be determined according to the data type include at least three types: regional sharding, length sharding, and hash sharding. Then, when the reference sensitivity level is high, it can be finally determined from the three data sharding methods that the reference sharding method is the hash sharding method; when the reference sensitivity level is medium, it can be determined from the three data sharding methods that the reference sharding method is regional sharding; when the reference sensitivity level is low, it can be determined from the three data sharding methods that the reference sharding method is length sharding; the above-mentioned use of the reference sharding method to perform data sharding operations on the sharded data includes: when the reference sharding method is that no sharding is required, determining the data to be sharded as the data sharding corresponding to the data to be sharded; when the reference sharding method is not that no sharding is required, using the reference sharding method to perform corresponding data sharding on the sharded data.
[0059] The operations in S1 to S4 above can be understood as, but not limited to, when storing data of different sensitivities, for example, when storing highly sensitive data (such as bank card numbers, ID card numbers), the data needs to be randomly fragmented, each data is split into several small segments, each segment is encrypted separately and stored in different databases. Even if a database is hacked, the original data cannot be completely pieced together.
[0060] The formula corresponding to the data sharding method can be understood as, but not limited to:
[0061]
[0062] in, Indicates the data to be sharded. Indicates Each shard uses a different encryption algorithm (such as AES-256, ChaCha20, etc.) and is stored in a different database.
[0063] Through the above-mentioned data sharding method of the present application, data can be sharded more accurately to improve the reliability of subsequent shard storage.
[0064] As an optional implementation, performing a splitting operation on the data to be stored to obtain multiple first data includes: using a data splitting model to perform a splitting operation on the data to be stored to obtain multiple first data, wherein the data splitting model integrates multiple data processing modules and multiple data splitting modules, and each data splitting module corresponds to a data splitting method.
[0065] The data splitting model is used to split the data to be stored to obtain a plurality of first data, including:
[0066] S1, obtaining a data structure of data to be stored, and selecting a target processing module corresponding to the data structure from a plurality of data processing modules according to the data structure;
[0067] S2, using a target processing module to perform target processing on the data to be stored to obtain reference data corresponding to the data to be stored, wherein the target processing is used to process the data to be stored into data that meets a preset display format;
[0068] S3, obtaining the data format of the reference data, and using a target splitting module corresponding to the data format among multiple data splitting modules to perform a splitting operation on the reference data to obtain multiple first data.
[0069] The data structure in S1 above can be understood, but not limited to, as the original display format of the data to be stored, for example, a piece of data to be stored is displayed as a whole line. The above data structure includes JSON display structure, XML display structure, CSV display structure, YAML display structure, Avro display structure, etc. Each data structure corresponds to a data processing module, and each data processing module performs target processing on the data of the corresponding data structure separately. The above target processing can be understood, but not limited to, as processing the data to be stored so that each first data is displayed as a line (i.e., the above preset display format). Then, the reference data finally obtained is data including multiple lines, and the multiple lines of data included in the reference data correspond to the multiple first data included in the data to be processed. After that, the target splitting module corresponding to the reference data can be used to split the reference data to obtain multiple first data. Then, the splitting logic of the target splitting module at this time only needs to split the reference data by line.
[0070] Through the above implementation of the present application, the data to be stored can be quickly and uniformly split, so as to quickly obtain a plurality of first data that accurately corresponds to the data to be stored.
[0071] As an optional implementation, encryption operations are performed on multiple databases according to multiple database sensitivity levels, including:
[0072] S1, obtaining reference encryption methods corresponding to multiple library sensitivity levels, and obtaining multiple reference encryption methods, wherein each library sensitivity level corresponds to a reference encryption method;
[0073] S2, using multiple reference encryption methods to perform reference encryption on multiple databases to obtain multiple reference keys, and using replacement methods corresponding to the sensitivity levels of the multiple databases to replace the multiple reference keys, and determining the multiple reference keys obtained by replacement as multiple reference keys;
[0074] S3, obtaining target sensitivity levels corresponding to the multiple databases, and determining a target encryption method from multiple reference encryption methods according to the target sensitivity levels;
[0075] S4, target encryption is performed on multiple reference keys using a target encryption method to obtain a target key, and a replacement operation is performed on the target key using a replacement method corresponding to the target sensitivity level, and the obtained target key is determined as the target key.
[0076] It should be noted that the operations in S1 to S2 above can be understood, but not limited to, as the reference encryption method corresponding to each database can be determined according to the library sensitivity level of each database, and then the reference encryption corresponding to each database can be used to perform corresponding reference encryption on multiple databases respectively. After encryption, the reference key corresponding to each database can be obtained. In order to ensure the reliability of encryption, the reference key needs to be replaced regularly, but the reference key of the database with a low library sensitivity level does not need to be replaced too frequently, while the reference key of the database with a high library sensitivity level needs to be replaced relatively frequently, and the multiple new reference keys obtained after the replacement are determined as the reference keys corresponding to each database. Therefore, in the above S2, it is necessary to determine the replacement method corresponding to each database from multiple preset replacement methods according to multiple library sensitivity levels, and use the corresponding replacement method to replace the reference key, and the replacement method is used to indicate the replacement frequency of the key. The preset replacement method is a pre-set replacement method.
[0077] The method for determining the target sensitivity level in the above S3 includes: determining the database weight corresponding to each database according to multiple database sensitivity levels to obtain multiple database weights, determining the target sensitivity level according to the multiple database weights and the multiple database sensitivity levels (that is, the sum of the products of the multiple database weights and the corresponding library sensitivity levels is the target sensitivity level), and then determining the target encryption method from multiple reference encryption methods according to the target sensitivity level and the preset sensitivity level interval set, and determining the replacement method corresponding to the target sensitivity level from multiple preset replacement methods. After using the target encryption method to perform target encryption on multiple reference keys to obtain the target key, the determined replacement method can be used to replace the target key, and the new key obtained by replacement can be determined as the target key.
[0078] It should be noted that after the above-mentioned shard encryption operation is performed on the data shards, the shard keys obtained by the shard encryption can also be periodically replaced by using a variety of preset replacement methods.
[0079] Through the above implementation of the present application, the reliability of data storage is further improved through multi-layer encryption and periodic replacement of keys.
[0080] As an optional implementation, the above data storage method further includes: setting multiple data circulation channels for multiple data sensitivity levels, wherein each data sensitivity level corresponds to a data circulation channel.
[0081] Through the above-mentioned implementation manner of the present application, different data fragments and first data can be obtained from different data circulation channels when acquiring data.
[0082] According to another aspect of the embodiment of the present invention, a data acquisition method for acquiring data stored by the above data storage method is also provided. Figure 4 The data acquisition method shown in the flowchart may include the following steps:
[0083] S402, obtaining a data sensitivity level corresponding to the data to be obtained according to the data acquisition request, and a type sensitivity level corresponding to the data sensitivity level;
[0084] S404, determining a target data sharding method according to the data sensitivity level and the type sensitivity level, and determining a plurality of databases corresponding to the target data sharding method according to the target data sharding method;
[0085] S406, obtaining target keys and reference keys corresponding to multiple databases, and data circulation channels corresponding to data sensitivity levels;
[0086] S408, after decrypting the multiple databases using the target key and the multiple reference keys, obtain a data shard set corresponding to the data to be obtained from the multiple databases;
[0087] S410, after reorganizing multiple data shards in the data shard set to obtain data, the data to be obtained is sent to a client corresponding to the data acquisition request through a data circulation channel.
[0088] For example, the operation in S402 above assumes that the data acquisition request is for requesting to obtain an ID card number, and the ID card number has a corresponding data sensitivity level, but multiple types of sensitivity levels can be determined based on the data sensitivity level, that is, the sensitivity level corresponding to the request type of the target operation request corresponding to the data to be acquired when the above data storage method is used to store the data, and because the request type of the corresponding target operation request may be different during storage, there may be one or more type sensitivity levels that can be determined based on the data sensitivity level corresponding to the ID card number; then the target data sharding method corresponding to the data sensitivity level and the type sensitivity level determined in S404 may also include one or more data sharding methods, and then any one of the one or more data sharding methods can be randomly determined as the above target data sharding method, and then multiple databases corresponding to the target data sharding method are determined, for example, the determined database is as follows Figure 3The databases 2 to 5 shown in the figure can obtain the target key and the reference keys corresponding to the databases 2 to 5, and then use the target key and the reference keys corresponding to the databases 2 to 5 to unlock the corresponding four databases, and then search the data shards separated by the target data sharding method from the four databases, and then obtain the sharding keys of the corresponding data shards to unlock the separated shards, that is, first unlock all the databases, and then perform the second-layer unlocking on multiple databases in a targeted manner, and unlock the data shards after finding the corresponding data shards. Then perform the reorganization in S410 to reorganize the unlocked multiple data shards to obtain the data to be obtained, and finally send the data to be obtained to the client that initiates the data acquisition request through the corresponding data circulation channel.
[0089] The reorganization operation in S410 (which may be understood as the need to restore the original data, but is not limited to) may be understood as recombining the fragments into complete data through a preset randomized reorganization algorithm, and returning the data to the requester after decryption. The formula corresponding to the data reorganization may be understood as, but is not limited to:
[0090]
[0091] in, For the final restored data, It is a shard reorganization function. During the reorganization process, this application will also perform shard verification on each data shard (to verify the integrity and correctness of the shard) to ensure that there is no tampering or loss.
[0092] It should be noted that before the above S402, the present application will also adopt an access control strategy, specifically including: obtaining the user permissions corresponding to the data acquisition request, determining whether the user permissions match the data to be acquired (which can be understood but not limited to as whether the user is allowed to acquire the data to be acquired); when the user permissions match the data to be acquired, executing the above S402 to S410; when the user permissions do not match the data to be acquired, sending a prompt message to the client that initiated the data acquisition request, wherein the prompt message is used to prompt the matching relationship between the user permissions and the data to be acquired.
[0093] Through the above-mentioned implementation modes of the present application, accurate acquisition of data stored by the above-mentioned data storage method and consistency of data storage and data acquisition can be achieved.
[0094] It should be noted that, for the above-mentioned method embodiments, for the sake of simplicity, they are all described as a series of action combinations, but those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0095] According to another aspect of the embodiment of the present invention, a data storage device for implementing the above data storage method is also provided. Figure 5 As shown, the device comprises:
[0096] The acquisition unit 502 is used to acquire a target operation request of a target account on the trading platform, and acquire a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by the target user to log in to the trading platform;
[0097] The splitting unit 504 is used to split the data to be stored to obtain a plurality of first data, and obtain a type sensitivity level corresponding to the request type and a data sensitivity level corresponding to each of the plurality of first data;
[0098] A sharding unit 506, configured to perform a data sharding operation on the plurality of first data according to the type sensitivity level and the plurality of data sensitivity levels, to obtain a data sharding set corresponding to each first data;
[0099] A storage unit 508, configured to store the multiple data shards in each data shard set in multiple databases corresponding to the multiple data shards, wherein the multiple data shards in the same data shard set correspond to different databases;
[0100] The encryption unit 510 is used to determine the database sensitivity level corresponding to each database according to the data fragments stored in the multiple databases, and perform encryption operations on the multiple databases according to the multiple database sensitivity levels.
[0101] According to another aspect of the embodiment of the present invention, a data acquisition device for implementing the above data acquisition method is also provided. Figure 6 As shown, the device comprises:
[0102] A first acquisition unit 602 is used to acquire a data sensitivity level corresponding to the to-be-acquired data according to the data acquisition request, and a type sensitivity level corresponding to the data sensitivity level;
[0103] A determination unit 604 is used to determine a target data sharding method according to the data sensitivity level and the type sensitivity level, and determine a plurality of databases corresponding to the target data sharding method according to the target data sharding method;
[0104] A second acquisition unit 606 is used to acquire target keys and reference keys corresponding to multiple databases, and data circulation channels corresponding to data sensitivity levels;
[0105] A decryption unit 608, configured to obtain a data shard set corresponding to the to-be-acquired data from the multiple databases after decrypting the multiple databases using the target key and the multiple reference keys;
[0106] The reorganization unit 610 is used to reorganize multiple data fragments in the data fragment set to obtain the data to be obtained, and then send the data to be obtained to the client corresponding to the data acquisition request through the data circulation channel.
[0107] The specific manner in which each unit in the above device embodiment performs operations has been described in detail in the embodiment of the method, and will not be elaborated on again here.
[0108] According to another aspect of an embodiment of the present invention, an electronic device for implementing the above-mentioned data storage method or data acquisition method is also provided, and the electronic device may be a terminal device or a server. This embodiment is illustrated by taking the electronic device as a terminal device as an example. The electronic device includes: at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores a computer program executable by at least one processor, and the computer program is executed by at least one processor so that at least one processor performs the steps in any one of the above-mentioned method embodiments. The electronic device may be located in at least one network device among multiple network devices of a computer network. The processor may be configured to execute the above-mentioned data storage method or data acquisition method through a computer program.
[0109] Optionally, a person skilled in the art can understand that the structure of the electronic device described above is only for illustration, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, and other terminal devices. The above description does not limit the structure of the above electronic device. For example, the electronic device may also include more or fewer components (such as a network interface, etc.) than the above description, or have a configuration different from the above description.
[0110] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data storage method, data acquisition method and device in the embodiment of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned data storage method or data acquisition method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network and a combination thereof. Among them, the memory can be specifically used, but not limited to, for storing various data involved in the above-mentioned data storage method or data acquisition method. As an example, the electronic device is used to implement the data storage method or data acquisition method. When the electronic device is used to implement the data storage method, the memory may include, but is not limited to, the acquisition unit 502, split unit 504, fragmentation unit 506, storage unit 508, and encryption unit 510 in the data storage device; when the electronic device is used to implement the data acquisition method, the memory may include, but is not limited to, the first acquisition unit 602, determination unit 604, second acquisition unit 606, decryption unit 608, and reorganization unit 610 in the data acquisition device. In addition, other module units in the data storage device or data acquisition device may also be included but are not limited to, which will not be repeated in this example.
[0111] Optionally, the transmission device is used to receive or send data via a network. Specific examples of the above-mentioned network may include wired networks and wireless networks. In one example, the transmission device includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices and routers via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device is a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet wirelessly. In addition, the above-mentioned electronic device also includes: a display and a connection bus, which is used to connect the various module components in the above-mentioned electronic device.
[0112] According to one aspect of the present application, a computer-readable storage medium is provided, and a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned data storage method or data acquisition method.
[0113] Those skilled in the art will appreciate that the implementation of all or part of the processes in the above method embodiments can be accomplished by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include processes such as those in the above method embodiments.
[0114] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A data storage method, characterized in that: include: Obtaining a target operation request of a target account on a trading platform, and obtaining a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by a target user to log in to the trading platform; Performing a split operation on the data to be stored to obtain a plurality of first data, and obtaining a type sensitivity level corresponding to the request type and a data sensitivity level corresponding to each of the plurality of first data; Performing a data sharding operation on the plurality of first data according to the type sensitivity level and the plurality of data sensitivity levels to obtain a data sharding set corresponding to each first data; Respectively storing the multiple data shards in each of the data shard sets into multiple databases corresponding to the multiple data shards, wherein the multiple data shards in the same data shard set correspond to different databases; Determine the database sensitivity level corresponding to each database according to the data slices stored in the multiple databases, and perform encryption operations on the multiple databases according to the multiple database sensitivity levels; The encryption operation on the plurality of databases according to the sensitivity levels of the plurality of databases comprises: Obtaining reference encryption methods corresponding to a plurality of library sensitivity levels, respectively, to obtain a plurality of reference encryption methods, wherein each library sensitivity level corresponds to a reference encryption method; Using multiple reference encryption methods to perform reference encryption on multiple databases to obtain multiple reference keys, and using replacement methods corresponding to multiple database sensitivity levels to replace the multiple reference keys, and determining the multiple reference keys obtained by replacement as the multiple reference keys; Obtaining target sensitivity levels corresponding to the plurality of databases, and determining a target encryption method from a plurality of reference encryption methods according to the target sensitivity levels; The target encryption method is used to target encrypt the multiple reference keys to obtain a target key, and a replacement method corresponding to the target sensitivity level is used to replace the target key, and the obtained target key is determined as the target key.
2. The method according to claim 1, characterized in that Performing a data sharding operation on the plurality of first data according to the type sensitivity level and the plurality of data sensitivity levels to obtain a data sharding set corresponding to each of the first data includes: Obtaining a set of sharding methods corresponding to the type sensitivity level and the plurality of data sensitivity levels, wherein the set of sharding methods includes a plurality of data sharding methods, and each sharding method corresponds to a data sensitivity level; Determine any first data among the plurality of first data as data to be fragmented, and determine a reference sensitivity level corresponding to the data to be fragmented from the plurality of data sensitivity levels; Determining a reference sharding method corresponding to the reference sensitivity level from a plurality of data sharding methods, and performing a data sharding operation on the data to be sharded by using the reference sharding method to obtain a data sharding set corresponding to the data to be sharded; Any first data among the plurality of first data except the data to be fragmented is determined as the data to be fragmented.
3. The method according to claim 1, characterized in that: Performing a split operation on the data to be stored to obtain multiple first data, including: using a data splitting model to perform a split operation on the data to be stored to obtain multiple first data, wherein the data splitting model integrates multiple data processing modules and multiple data splitting modules, and each data splitting module corresponds to a data splitting method.
4. The method according to claim 3, characterized in that The data to be stored is split by using a data splitting model to obtain a plurality of the first data, including: Acquire the data structure of the data to be stored, and select a target processing module corresponding to the data structure from the plurality of data processing modules according to the data structure; The target processing module is used to perform target processing on the data to be stored to obtain reference data corresponding to the data to be stored, wherein the target processing is used to process the data to be stored into data that meets a preset display format; The data format of the reference data is acquired, and a target splitting module corresponding to the data format among a plurality of data splitting modules is used to perform the splitting operation on the reference data to obtain a plurality of the first data.
5. The method according to claim 1, characterized in that The method further includes: setting a plurality of data circulation channels for the plurality of data sensitivity levels, wherein each data sensitivity level corresponds to a data circulation channel.
6. A data acquisition method, characterized in that: Used to obtain data stored in the data storage method according to any one of claims 1 to 5, the method comprising: Acquire the data sensitivity level corresponding to the data to be acquired according to the data acquisition request, and the type sensitivity level corresponding to the data sensitivity level; Determine a target data sharding method according to the data sensitivity level and the type sensitivity level, and determine a plurality of databases corresponding to the target data sharding method according to the target data sharding method; Acquire a plurality of target keys and a plurality of reference keys corresponding to the databases, and a data circulation channel corresponding to the data sensitivity level; After decrypting the multiple databases using the target key and the multiple reference keys, a data shard set corresponding to the data to be obtained is obtained from the multiple databases; After the multiple data shards in the data shard set are reorganized to obtain the data to be acquired, the data to be acquired is sent to the client corresponding to the data acquisition request through the data circulation channel.
7. A data storage device, characterized in that: include: an acquisition unit, configured to acquire a target operation request of a target account on a trading platform, and acquire a request type corresponding to the target operation request and data to be stored corresponding to the request type according to the target operation request, wherein the target account is an account used by a target user to log in to the trading platform; a splitting unit, configured to split the data to be stored to obtain a plurality of first data, and obtain a type sensitivity level corresponding to the request type and a data sensitivity level corresponding to each of the plurality of first data; A sharding unit, configured to perform a data sharding operation on the plurality of first data according to the type sensitivity level and the plurality of data sensitivity levels, to obtain a data sharding set corresponding to each of the first data; A storage unit, used to store the multiple data shards in each of the data shard sets in multiple databases corresponding to the multiple data shards, wherein the multiple data shards in the same data shard set correspond to different databases; An encryption unit, used to determine the database sensitivity level corresponding to each of the databases according to the data fragments stored in the multiple databases, and perform encryption operations on the multiple databases according to the multiple database sensitivity levels; The encryption operation on the plurality of databases according to the sensitivity levels of the plurality of databases comprises: Obtaining reference encryption methods corresponding to a plurality of library sensitivity levels, respectively, to obtain a plurality of reference encryption methods, wherein each library sensitivity level corresponds to a reference encryption method; Using multiple reference encryption methods to perform reference encryption on multiple databases to obtain multiple reference keys, and using replacement methods corresponding to multiple database sensitivity levels to replace the multiple reference keys, and determining the multiple reference keys obtained by replacement as the multiple reference keys; Obtaining target sensitivity levels corresponding to the plurality of databases, and determining a target encryption method from a plurality of reference encryption methods according to the target sensitivity levels; The target encryption method is used to target encrypt the multiple reference keys to obtain a target key, and a replacement method corresponding to the target sensitivity level is used to replace the target key, and the obtained target key is determined as the target key.
8. A data acquisition device, characterized in that: Used to obtain data stored in the data storage device of claim 7, the data acquisition device comprising: A first acquisition unit, configured to acquire a data sensitivity level corresponding to the to-be-acquired data according to a data acquisition request, and a type sensitivity level corresponding to the data sensitivity level; a determination unit, configured to determine a target data sharding method according to the data sensitivity level and the type sensitivity level, and determine a plurality of databases corresponding to the target data sharding method according to the target data sharding method; A second acquisition unit, used to acquire a plurality of target keys and a plurality of reference keys corresponding to the databases, and a data circulation channel corresponding to the data sensitivity level; A decryption unit, configured to obtain a data shard set corresponding to the to-be-acquired data from the multiple databases after decrypting the multiple databases using the target key and the multiple reference keys; The reorganization unit is used to reorganize multiple data fragments in the data fragment set to obtain the data to be obtained, and then send the data to be obtained to the client corresponding to the data acquisition request through the data circulation channel.
9. An electronic device, comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to execute the data storage method according to any one of claims 1 to 5, or the data acquisition method according to claim 6, through the computer program.
Citation Information
Patent Citations
Computer storage system security access method and system
CN112182519A
User data storage method and device and user data reading method and device
CN115495520A
Streaming data processing method and system for multi-level security protection
WO2022161327A1