Data access method and apparatus, electronic device, and program product

By verifying user identity and generating anonymous target files in mobile edge computing, the problem of unauthorized users accessing electronic health record data is solved, improving the security and privacy protection of data access.

CN119323049BActive Publication Date: 2025-11-18CHINA MOBILE (XIONGAN) ICT CO LTD +3
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411258448.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2025-11-18
Estimated Expiration
2044-09-09

AI Technical Summary

Technical Problem

In mobile edge computing, unauthorized users remotely accessing electronic health record data can lead to lower data security.

Method used

By receiving access requests from users to be verified, verifying their identities, and determining the first data pointer of the target encrypted data after successful authentication, generating an anonymous target file, and finally sending the anonymous target file to the user, the original data is avoided being sent directly.

Benefits of technology

It improves the security of data access, prevents unauthorized users from accessing and leaking data, and protects the security of users' privacy data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119323049B_ABST
    Figure CN119323049B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a data access method and device, electronic equipment and program product, the data access method comprises the following steps: receiving an access request of a to-be-verified user, the access request is used for requesting access to target encrypted data; in response to the access request, the identity of the to-be-verified user is verified; in the case where the verification is passed, the first data pointer of the target encrypted data is determined; the anonymous target file corresponding to the target encrypted data is determined according to the first data pointer; the anonymous target file is sent to the to-be-verified user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a data access method, apparatus, electronic device, storage medium, and program product. Background Technology

[0002] With the rapid advancement of information technology and the wave of digital transformation, using lightweight encrypted security systems to manage and protect massive amounts of electronic health record data has become a key path to improve the quality and efficiency of medical services.

[0003] In some scenarios, Mobile Edge Computing (MEC) can be used to manage and protect massive amounts of electronic health record data. MEC is a distributed network architecture that migrates cloud computing, storage, networking, and other services from traditional cloud data centers to the network edge, providing mobile and cloud computing capabilities, such as storage, computing, and services at the network edge. The emerging development of MEC can be used in secure healthcare applications, such as remote patient monitoring, diagnosis, and treatment. However, if unauthorized users remotely access users' electronic health record data, data breaches can occur, resulting in lower data security. Summary of the Invention

[0004] The purpose of this application is to provide a data access method, apparatus, electronic device, and storage medium that solves the problem of low data security.

[0005] To solve the above-mentioned technical problems, the embodiments of this application are implemented as follows:

[0006] In a first aspect, embodiments of this application provide a data access method, which includes: receiving an access request from a user to be verified, the access request being used to request access to target encrypted data; in response to the access request, verifying the identity of the user to be verified; if the verification is successful, determining a first data pointer to the target encrypted data; determining an anonymous target file corresponding to the target encrypted data based on the first data pointer; and sending the anonymous target file to the user to be verified.

[0007] Secondly, embodiments of this application provide a data access device, comprising: a receiving module for receiving an access request from a user to be verified, the access request being for requesting access to target encrypted data; a verification module for verifying the identity of the user to be verified in response to the access request; a determining module for determining a first data pointer to the target encrypted data if the verification is successful; the determining module is further configured to determine an anonymous target file corresponding to the target encrypted data based on the first data pointer; and a sending module for sending the anonymous target file to the user to be verified.

[0008] Thirdly, embodiments of this application provide an electronic device, including a processor, a communication interface, a memory, and a communication bus; wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; the memory is used to store computer programs; and the processor is used to execute the programs stored in the memory to implement the data access method steps mentioned in the first aspect.

[0009] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the data access method steps mentioned in the first aspect.

[0010] Fifthly, embodiments of this application provide a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions that, when executed by a computer, cause the computer to perform the data access method steps mentioned in the first aspect.

[0011] The technical solution disclosed in this application involves receiving an access request from a user to be verified, and then verifying the user's identity in response to the request. If the verification is successful, a first data pointer to the target encrypted data is determined, and then an anonymous target file corresponding to the target encrypted data is determined based on the first data pointer. Finally, the anonymous target file is sent to the user to be verified. Thus, by verifying the user's identity, access to data is only allowed after successful verification, preventing data leakage caused by unauthorized access. Furthermore, the target encrypted data is accessed by determining the corresponding anonymous target file through the first data pointer and sending the anonymous target file to the user, avoiding directly sending the original data to the user, further improving the security of user data access. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 A flowchart illustrating the data access method provided in an embodiment of this application;

[0014] Figure 2 A schematic diagram of the module composition of a model training device provided in an embodiment of this application;

[0015] Figure 3This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0016] The purpose of this application is to provide a data access method, apparatus, electronic device, and storage medium that solves the problem of low data security.

[0017] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0018] For example, such as Figure 1 As shown in the figure, this application provides a data access method, which can be executed by a server. The data access method may specifically include the following steps:

[0019] In step S101, an access request from the user to be verified is received.

[0020] The access request is used to request access to the target encrypted data.

[0021] Specifically, a user to be verified refers to a user accessing data stored on a cloud server. When such a user accesses the data, their identity needs to be verified. The type of user to be verified can be medical personnel, patients, or other individuals. Target encrypted data refers to encrypted data stored on the cloud server, such as patients' medical and health data and their personal privacy data.

[0022] In step S103, in response to the access request, the identity of the user to be verified is verified.

[0023] Specifically, anonymous verification can be used when verifying the identity of users to protect their personal privacy data from being leaked. For systems storing patient data, user registration can be implemented, allowing authorized users to access encrypted data stored on cloud servers.

[0024] In one possible implementation, before receiving the access request from the user to be verified, the method further includes: obtaining the identity identifier and pseudo-identity information of the user to be registered, wherein the pseudo-identity information is determined by the password and random number of the user to be registered; determining the public key of the user to be registered based on the pseudo-identity information and password; determining a first identity parameter based on the identity identifier and password, and determining a second identity parameter based on the first identity parameter and pseudo-identity information; and sending a smart card to the user to be registered to complete the registration, wherein the smart card includes the public key, random number, password, first identity parameter and second identity parameter.

[0025] Specifically, users who are about to register first enter the password PW DC and one's own identity identifier DID i The identity identifier DID i This can be used as the ID of the user to be registered, and then the password PW can be used. DC And a random number R1 to determine the pseudo-identity information of the user to be registered. Then, the user's terminal sends message M1 to the edge server, where M1 = {DID} i ||J D ||T}, where T is the time interval. The edge server calculates the following identity parameters based on the identity identifier, pseudo-identity information, and password, AP i =h(DID) i ||X), where X is equivalent to the password PW DC BP i =h(AP i ), Then select the master key M k =J D And calculate the public key PK. D =h(M k ||X). Among the parameters mentioned above, BP i Equivalent to the first identity parameter, VP i This is equivalent to a second identity parameter.

[0026] At this point, the edge server can provide a smart card to the user to be registered, which includes the following parameters (DID). i BP1, VP1, PK D It is worth noting that the user to be registered in this embodiment can be a medical staff member or the patient himself / herself.

[0027] Furthermore, users can also register in the following way: the user sends their identity to the edge server, the edge server randomly selects a value from the set of integers, and uses the value and identity to generate a public key, wherein the identity carries a hash key, which can be randomly generated.

[0028] Among them, users to be registered can use a hashed password h(PW) pi ) identity (PID) i The integer set is then sent to the edge service. The edge server then processes the integer set. Select a value Y and generate a public key PK. P =h(PID) i ||Y), then send message M2={PID} to the user to be registered. i ||PK P Registration is now complete.

[0029] It is worth noting that the user to be registered in this embodiment can be either the patient or a medical staff member. Furthermore, during registration, medical staff can use a smart card, while the patient can use a hash password h(PW). pi ) identity (PID) i Register using the following method:

[0030] Furthermore, when verifying the identity of the user to be verified, the following methods can be used: obtain the verification parameters carried in the access request; extract the identity identifier and password of the user to be verified from the verification parameters; calculate the first identity parameter of the user to be verified based on the identity identifier and password; if a first identity parameter matching the first identity parameter of the user to be verified exists in the registration database, confirm that the user to be verified has passed the verification.

[0031] Specifically, when a user seeking authentication wants to access encrypted data, they can enter a smart card along with a random value randomly selected from a set of integers. The access request carries verification parameters, including but not limited to the identity identifier and password of the user to be verified, as well as a random value. Then, the first identity parameter BP1 is extracted from the smart card entered by the user. This first identity parameter BP1 is generated during the registration of the user corresponding to the smart card. The user to be verified enters their identity DID. i And the password X, calculate AP i =h(DID) i ||X), BP i =h(AP1), BP i 'This is the first identity parameter of the user to be verified, used to determine BP' i 'Is it equal to BP1? If it matches, then it means that the user is legitimate.'

[0032] After the user to be verified passes the first verification, a token is generated for the user to access the target encrypted data. This token serves as a first data pointer, which points to the anonymous target file containing the target encrypted data. This first data pointer can be determined by the user selecting a random value from a set of integers. And calculate α1=ω.DID i α2=ω.PK D , α3=h(querystring,l)ω, α4=ω.PK P ,TokenTK=(l||α2||α4||T2), PK D PK is the public key of the user to be verified. P The public key of the user who wants to access the target encrypted data is used for verification. For example, if the user to be verified is a medical worker, the PK... D PK is a public key for healthcare workers. P The public key of the patient corresponding to the target encrypted data to be accessed is used, where l is the length of the query string, querystring is the data to be accessed (i.e., the query string), and T2 is the query time interval. Token TK can serve as the first data pointer, which corresponds to the target encrypted data. The user to be verified can be a user with certain permissions, such as medical personnel.

[0033] Furthermore, when verifying the identity of the user to be verified, the following methods can also be used: obtain the verification parameters carried in the access request; extract the identity of the user to be verified from the verification parameters; calculate the token of the user to be verified based on the identity; and verify the identity of the user to be verified based on the token.

[0034] Specifically, when a user seeking authentication wants to access encrypted data, the user can select a random value from the set of integers. And using random values ​​and the PID of the user to be verified i Calculate the public key (PK) of the user to be verified. P =h(PID) i ||δ), determine the public key PK of the registered user based on the first data pointer corresponding to the target encrypted data that the user wants to access. D And generate a token. The token can be determined as follows: Token TK=(l||β2||β4||T1), where β1=β.PID i β2=δ.PK D , β3=h(querystring,l)δ, β4=δ.PK P `querystring` represents the data to be accessed, i.e., the query string, and `l` represents the length of the query string. Extract β2 and β4 from the token and verify whether β2 and β4 match the registered PK. D And PK P If they match, then the verification passes.

[0035] Furthermore, after the user to be verified has passed the first verification, a token for the target encrypted data to be accessed is generated for the user. This token can serve as a data pointer for the user to be verified, and the user to be verified can be the patient himself / herself.

[0036] In step S105, if the verification is successful, the first data pointer of the target encrypted data is determined.

[0037] Specifically, through the above method implementation, after a user registers and passes the initial verification, a data pointer is assigned to each user and the data accessed by the user. This data pointer points to the corresponding target encrypted data in the target file. Therefore, after successful verification, the first data pointer for the target encrypted data is determined.

[0038] In one possible implementation, upon successful verification, determining the first data pointer of the target encrypted data includes: if the user to be verified is a user of type 1, determining the second data pointer of the target encrypted data, wherein the first data pointer corresponds to the user of type 1 and the second data pointer corresponds to the user of type 2; and determining the first data pointer corresponding to the second data pointer based on the mapping relationship between the first data pointer and the second data pointer.

[0039] Specifically, the first type of user can be the patient, and the second type of user can be medical staff. When the user to be verified is a medical staff member, the data pointer corresponding to the medical staff member is the first data pointer, which points to the anonymous file of the target encrypted data. When the user to be verified is a patient, the patient's data pointer is the second data pointer, which points to the target encrypted data. The first and second data pointers have a mapping relationship. When the patient accesses the target encrypted data, the first data pointer is determined according to the mapping relationship between the first and second data pointers. This allows the anonymous file of the target encrypted data corresponding to the first data pointer to be returned to the patient, thereby protecting the security of the patient's personal privacy data.

[0040] In step S107, the anonymous target file corresponding to the target encrypted data is determined according to the first data pointer.

[0041] Specifically, an anonymous target file refers to anonymizing the personal privacy data of the target encrypted data. For example, if the target encrypted data is a patient's health information and the patient's personal data (such as gender, name, and contact information), the anonymous target file includes anonymized information of the patient's health information and personal data. That is, the patient's health information is only displayed to the user to be verified, thereby protecting the security of the patient's personal privacy data.

[0042] In step S109, an anonymous target file is sent to the user to be verified.

[0043] Specifically, after obtaining the anonymous target file, the anonymous target file is returned to the user to be verified with an anonymous identity.

[0044] The technical solution disclosed in this application involves receiving an access request from a user to be verified, and then verifying the user's identity in response to the request. If the verification is successful, a first data pointer to the target encrypted data is determined, and then an anonymous target file corresponding to the target encrypted data is determined based on the first data pointer. Finally, the anonymous target file is sent to the user to be verified. Thus, by verifying the user's identity, access to data is only allowed after successful verification, preventing data leakage caused by unauthorized access. Furthermore, the target encrypted data is accessed by determining the corresponding anonymous target file through the first data pointer and sending the anonymous target file to the user, avoiding directly sending the original data to the user, further improving the security of user data access.

[0045] The encryption method for the target encrypted data can be as follows: obtain the user data to be encrypted and the publicly available deoxyribonucleic acid sequence; convert the user data into at least one data block, where each data block is a two-dimensional matrix; generate an initial key for each data block based on the publicly available deoxyribonucleic acid sequence; generate a key for each data block based on the initial key; and encrypt the user data using the key to obtain the encrypted data.

[0046] Specifically, user data can be patient health information. This user data is converted into at least one data block, which is a two-dimensional matrix. The size of the data block, BSize, can be calculated using the following formula:

[0047] BSize=(N×8)*(N×8)where N≥1

[0048] The number of data blocks, TotNoBlocks, can be calculated using the following formula:

[0049] TotNoBlocks=Size of PHI / Bsize

[0050] Where N is the number of rows, Size is the total amount of user data, PHI represents user data, and Bsize is the size of the data block.

[0051] The initial key can be selected from publicly available deoxyribonucleic acid (DNA) sequences. With approximately 163 million publicly available DNA sequences, the probability of an attacker cracking the key is extremely low. Encrypting user data based on this initial key further enhances data security. Specifically, the initial key extracted from each data block within the DNA sequence can be a DNA fragment selected from any sequence segment, or it can be an array of rows, columns, and mutations extracted from the DNA sequence according to the size of the data block or the index of the user-defined data.

[0052] The following methods can be used to extract row arrays, column arrays, and mutation arrays from DNA sequences as initial keys: determine the row arrays and column arrays of the data block based on the number of rows and columns of the two-dimensional matrix; map the deoxyribonucleic acid sequence to the row arrays and column arrays respectively based on the transformation rules; generate the mutation array based on the row arrays and column arrays; and use the row arrays, column arrays, and mutation arrays as the initial keys of the data block.

[0053] Specifically, the row array of the data block is determined according to the number of rows in the two-dimensional matrix; that is, the row array is an array with multiple rows and one column, and the column array is an array with multiple columns and one row. The conversion rules are shown in the table below:

[0054] R-1 R-2 R-3 R-4 R-5 R-6 R-7 R-8 A 00 00 01 01 10 10 11 11 C 01 10 11 00 11 00 10 01 G 10 01 00 11 00 11 01 10 T 11 11 10 10 01 01 00 00

[0055] In the table above, the only possible letters for a DNA sequence are A, C, G, and T, representing the four nucleotides that make up DNA: adenine, cytosine, guanine, and thymine, respectively. Each letter represents a base, and two bases form a base pair. The pairing rule for base pairs is fixed, i.e., AT, CG. Typically, they are arranged together without gaps, such as the sequence AAAGTCTGAC. Any string of nucleotides longer than 4 is called a sequence. In binary, 0 and 1 are complementary, therefore 00 and 11 are complementary, and 01 and 10 are also complementary. Therefore, the four bases A, C, G, and T are used to encode 00, 01, 10, and 11.

[0056] In this embodiment of the application, the row array can be represented by RowArray, the column array can be represented by ColumnArray, and the mutation array can be represented by MutationArray. The following algorithm can be used to extract the row array, column array, and mutation array from the DNA sequence:

[0057]

[0058]

[0059] Here, Data(SSize) represents the input user data, and DNA Sequence represents the DNA sequence. The MutationArray is obtained by performing a bitwise XOR operation on the data in the row array and the data in the column array.

[0060] After obtaining the initial key, the keys for each data block can be generated as follows: Perform logical XOR operations on the two-dimensional matrix and the row array, and on the two-dimensional matrix and the column array, respectively, to obtain the first target row array and the first target column array; perform XOR operations on the first target row array and the first target column array and then rotate them to the right to obtain the second target row array; perform XOR operations on the second target row array and the mutation array and then rotate them to the right to obtain the third target row array; perform XOR operations on the first target column array and the mutation array to obtain the second target column array; use the third target row array and the second target column array of each data block as the key for each data block.

[0061] Specifically, for each data block, an XOR operation is performed between it and the row array and the column array. A logical XOR operation is performed between the bits of the row array and the bits of the corresponding data block to obtain the first target row array. A logical XOR operation is performed between the bits of the column array and the bits of the corresponding data block to obtain the first target column array.

[0062] Furthermore, for each data block, a unique "RowArray" and "ColumnArray" are required. These new "RowArray" and "ColumnArray" arrays can be generated using "MutationArray". At this layer, an XOR operation is performed between each bit of the first target row array (RowArray) and the corresponding bit of the first target column array (ColumnArray). Then, a right rotation of any number of bits is performed, determined by the dimension x of the chaotic map, to generate the second target row array (RowArray). Subsequently, an XOR operation is performed between the second target row array (RowArray) and the mutation array (MutationArray), followed by a right rotation of any number of bits, to generate a unique "newRowArray" (the third target row array) for each data block. Similarly, the arbitrary number of bits for the right rotation is determined by the dimension y of the chaotic map. The second target column array ("newcolumnArray") is generated by performing an XOR operation on the mutation array (MutationArray) and the first target column array (ColumnArray), thus using the third target row array and the second target column array as the keys for each data block. In this way, by selecting an initial key from the DNA sequence and generating a key according to the initial key, the difficulty of cracking the key is increased, and the security of the data is further improved.

[0063] Furthermore, the performance of the encryption provided in the embodiments of this application can be analyzed:

[0064] First, terminal devices have limited memory; therefore, memory analysis is necessary. The total size of keys can be calculated using the following formula:

[0065]

[0066] In the above formula, Size of blocks represents the size of the data blocks, and Number of Keys represents the keys.

[0067] Secondly, encryption time is an important parameter for lightweight encryption algorithms. Encryption time is the total time required to encrypt data. Encryption and decryption times should be shorter to make the encryption system lightweight.

[0068] Then, information entropy represents the degree of uncertainty of the data. The higher the information entropy value, the better, because it is difficult to predict the content of the data. The formula for calculating information entropy (IE) is as follows:

[0069]

[0070] Where L is the total number of distinct data values. It is the xth i The probability of each data point.

[0071] Finally, avalanche effect analysis is performed. The main purpose of this analysis is to examine the strength of brute-force attacks on key pairs. Small changes to the data or key should alter most of the encrypted data. A good encryption scheme should have an avalanche effect greater than 50%. The avalanche effect AE(%) is calculated as follows:

[0072]

[0073] Thus, through the analysis of the encryption scheme provided in this application embodiment using the above indicators, the key required by this application embodiment requires less memory, consumes less memory, and has a shorter encryption time, making the encryption more lightweight. The information entropy is high, making it difficult to predict the content of the encrypted user data, resulting in good data security. The avalanche effect is higher than 50%, indicating that the key has high resistance to brute-force attacks, further ensuring the security of user data.

[0074] Corresponding to the data access method provided in the above embodiments, based on the same technical concept, this application also provides a data access device. Figure 2 This application provides a schematic diagram of the module composition of a data access device, which is used to perform... Figure 1 The described data access methods, such as Figure 2As shown, the data access device 200 includes: a receiving module 201, used to receive an access request from a user to be verified, the access request being used to request access to target encrypted data; a verification module 202, used to verify the identity of the user to be verified in response to the access request; a determining module 203, used to determine a first data pointer of the target encrypted data if the verification is successful; the determining module 203 is also used to determine an anonymous target file corresponding to the target encrypted data based on the first data pointer; and a sending module, used to send the anonymous target file to the user to be verified.

[0075] As can be seen from the technical solutions provided in the embodiments of this application above, by receiving the access request from the user to be verified, and then responding to the access request, the identity of the user to be verified is verified. If the verification is successful, a first data pointer to the target encrypted data is determined, and then an anonymous target file corresponding to the target encrypted data is determined based on the first data pointer. Finally, the anonymous target file is sent to the user to be verified. In this way, by verifying the identity of the user to be verified, access to data is only allowed after successful verification, avoiding the problem of data leakage caused by unauthorized users accessing data; and the target encrypted data to be accessed is determined by the first data pointer to determine the anonymous target file corresponding to the target encrypted data, and the anonymous target file is sent to the user, avoiding the direct sending of the original data to the user, further improving the security of user access to data.

[0076] In one possible implementation, the determining module 203 is further configured to, when the user to be verified is a user of the first type, determine a second data pointer of the target encrypted data, wherein the first data pointer corresponds to the user of the first type and the second data pointer corresponds to the user of the second type; and determine a first data pointer corresponding to the second data pointer based on the mapping relationship between the first data pointer and the second data pointer.

[0077] In one possible implementation, the system further includes: an acquisition module for acquiring user data to be encrypted and a publicly available DNA sequence; a conversion module for converting the user data into at least one data block, wherein the data block is a two-dimensional matrix; a generation module for generating an initial key for each data block based on the publicly available DNA sequence; the generation module is also used to generate a key for each data block based on the initial key; and an encryption module for encrypting the user data using the key to obtain encrypted data.

[0078] In one possible implementation, the generation module is further configured to determine the row array and column array of the data block based on the number of rows and columns of the two-dimensional matrix; map the deoxyribonucleic acid sequence to the row array and column array respectively based on the transformation rules; generate a mutation array based on the row array and column array; and use the row array, column array and mutation array as the initial key of the data block.

[0079] In one possible implementation, the generation module is further configured to perform logical XOR operations on the two-dimensional matrix and the row array, and on the two-dimensional matrix and the column array, respectively, to obtain a first target row array and a first target column array; perform XOR operations on the first target row array and the first target column array and then perform a circular right rotation to obtain a second target row array; perform XOR operations on the second target row array and the mutation array and then perform a circular right rotation to obtain a third target row array; perform XOR operations on the first target column array and the mutation array to obtain a second target column array; and use the third target row array and the second target column array of each data block as the key of each data block.

[0080] In one possible implementation, the acquisition module is further configured to acquire the identity identifier and pseudo-identity information of the user to be registered, wherein the pseudo-identity information is determined by the password and random number of the user to be registered; the determination module 203 is further configured to determine the public key of the user to be registered based on the pseudo-identity information and password; determine a first identity parameter based on the identity identifier and password, and determine a second identity parameter based on the first identity parameter and pseudo-identity information; and send a smart card to the user to be registered to complete the registration, wherein the smart card includes the public key, random number, password, first identity parameter and second identity parameter.

[0081] In one possible implementation, the verification module 202 is further configured to obtain the verification parameters carried in the access request; extract the identity identifier and password of the user to be verified from the verification parameters; calculate the first identity parameter of the user to be verified based on the identity identifier and password; and confirm that the user to be verified has passed the verification if a first identity parameter matching the first identity parameter of the user to be verified exists in the registration database.

[0082] The data access device provided in this application embodiment can implement the various processes in the embodiments corresponding to the above data access method, and has the same or similar beneficial effects. To avoid repetition, it will not be described again here.

[0083] It should be noted that the data access device provided in this application embodiment and the data access method provided in this application embodiment are based on the same application concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned data access method and has the same or similar beneficial effects. Repeated parts will not be described again.

[0084] Corresponding to the data access method provided in the above embodiments, based on the same technical concept, this application also provides an electronic device for executing the above data access method. Figure 3 To illustrate the structure of an electronic device according to various embodiments of this application, as shown in the following diagrams... Figure 3As shown. Electronic devices can vary considerably due to differences in configuration or performance, and may include one or more processors 301 and memory 302. Memory 302 may store one or more application programs or data. Memory 302 may be temporary or persistent storage. The application programs stored in memory 302 may include one or more modules (not shown), and each module may include a series of computer-executable instructions for the electronic device.

[0085] Furthermore, the processor 301 may be configured to communicate with the memory 302 and execute a series of computer-executable instructions stored in the memory 302 on the electronic device. The electronic device may also include one or more power supplies 303, one or more wired or wireless network interfaces 304, one or more input / output interfaces 305, and one or more keyboards 306.

[0086] Specifically, in this embodiment, the electronic device includes a processor, a communication interface, a memory, and a communication bus; wherein, the processor, the communication interface, and the memory communicate with each other via the bus; the memory is used to store computer programs; and the processor is used to execute the programs stored in the memory to achieve the above. Figure 1 The steps in the method embodiments are the same as those in the above method embodiments, and have the same beneficial effects. To avoid repetition, the embodiments of this application will not be described again here.

[0087] This embodiment also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the above-mentioned functions. Figure 1 The steps in the method embodiments are the same as those in the above method embodiments, and have the same beneficial effects. To avoid repetition, the embodiments of this application will not be described again here.

[0088] This application provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, which, when executed by a computer, cause the computer to perform the above-described actions. Figure 1 The steps in the method embodiments are the same as those in the above method embodiments, and have the same beneficial effects. To avoid repetition, the embodiments of this application will not be described again here.

[0089] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0090] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0091] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0092] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0093] In a typical configuration, an electronic device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0094] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0095] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0096] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0097] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0098] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A data access method, characterized in that, The data access method includes: Receive an access request from a user to be verified, the access request being used to request access to target encrypted data; In response to the access request, the identity of the user to be verified is verified; If the verification passes, a first data pointer to the target encrypted data is determined; The anonymous target file corresponding to the target encrypted data is determined based on the first data pointer; Send the anonymous target file to the user to be verified; The step of determining the first data pointer of the target encrypted data upon successful verification includes: If the user to be verified is a user of the first type, a second data pointer of the target encrypted data is determined, wherein the first data pointer corresponds to the user of the first type and the second data pointer corresponds to the user of the second type; Based on the mapping relationship between the first data pointer and the second data pointer, determine the first data pointer corresponding to the second data pointer.

2. The data access method according to claim 1, characterized in that, Before receiving the access request from the user to be verified, the method further includes: Obtain the user data to be encrypted and the publicly available DNA sequence; The user data is converted into at least one data block, wherein the data block is a two-dimensional matrix; An initial key for each of the data blocks is generated based on the disclosed deoxyribonucleic acid sequence; Generate the key for each of the data blocks based on the initial key for each of the data blocks; The user data is encrypted using the key to obtain encrypted data.

3. The data access method according to claim 2, characterized in that, The initial key for generating each data block based on the disclosed deoxyribonucleic acid sequence includes: The row array and column array of the data block are determined based on the number of rows and columns of the two-dimensional matrix; Based on the conversion rules, the deoxyribonucleic acid sequence is mapped to the row array and the column array, respectively; Generate a mutation array based on the row array and the column array; The row array, the column array, and the mutation array are used as the initial key for the data block.

4. The data access method according to claim 3, characterized in that, The step of generating the key for each data block based on the initial key of each data block includes: Perform logical XOR operations on the two-dimensional matrix and the row array, and on the two-dimensional matrix and the column array, respectively, to obtain the first target row array and the first target column array; After performing an XOR operation on the first target row array and the first target column array, a circular right rotation is performed to obtain the second target row array; After performing an XOR operation on the second target row array and the mutation array, a circular right rotation is performed to obtain the third target row array; Perform an XOR operation on the first target column array and the mutation array to obtain the second target column array; The third target row array and the second target column array of each data block are used as the key of each data block.

5. The data access method according to claim 1, characterized in that, Before receiving the access request from the user to be verified, the method further includes: Obtain the identity identifier and pseudo-identity information of the user to be registered, wherein the pseudo-identity information is determined by the password and random number of the user to be registered; The public key of the user to be registered is determined based on the pseudo-identity information and the password; A first identity parameter is determined based on the identity identifier and the password, and a second identity parameter is determined based on the first identity parameter and the pseudo identity information; The smart card is sent to the user to be registered to complete the registration. The smart card includes the public key, the random number, the password, the first identity parameter, and the second identity parameter.

6. The data access method according to claim 5, characterized in that, The verification of the identity of the user to be verified includes: Obtain the verification parameters carried in the access request; Extract the identity identifier and password of the user to be verified from the verification parameters; Calculate the first identity parameter of the user to be verified based on the identity identifier and password; If a first identity parameter matching the first identity parameter of the user to be verified exists in the registration database, the user to be verified is confirmed to have passed the verification.

7. A data access device, characterized in that, include: The receiving module is used to receive access requests from users to be verified, the access requests being used to request access to target encrypted data; The verification module is used to verify the identity of the user to be verified in response to the access request; The determination module is used to determine a first data pointer to the target encrypted data if the verification is successful. The determining module is further configured to determine the anonymous target file corresponding to the target encrypted data based on the first data pointer; The sending module is used to send the anonymous target file to the user to be verified; The determining module is further configured to, when the user to be verified is a user of the first type, determine a second data pointer of the target encrypted data, wherein the first data pointer corresponds to the user of the first type and the second data pointer corresponds to the user of the second type; Based on the mapping relationship between the first data pointer and the second data pointer, determine the first data pointer corresponding to the second data pointer.

8. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus; wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; the memory is used to store computer programs; the processor is used to execute the programs stored in the memory to implement the data access method steps as described in any one of claims 1-6.

9. A computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the data access method steps as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Multidimensional information pointer platform and data access method thereof

    CN104506527A

  • Method for storage management, electronic equipment and computer program product

    CN114063886A

  • Image encryption method and device, computer equipment, storage medium and computer program product

    CN118590592A