Data transmission methods, apparatus, equipment, media and program products

By employing layered encryption and inducing the generation and storage of data, the security risks of sensitive data being decoded during data transmission are resolved, thereby enhancing the security of data transmission and storage.

CN119520149BActive Publication Date: 2025-12-02INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411769070.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2025-12-02
Estimated Expiration
2044-12-04

AI Technical Summary

Technical Problem

When data is transmitted between different terminals, even though encryption algorithms are used, sensitive data can still be obtained through decoding, posing a data security risk.

Method used

The data to be transmitted is encrypted in layers according to its sensitivity level. The encrypted sensitive data is stored in the first cloud and inducement data is generated and uploaded to the second cloud. Different encryption algorithms and processing methods are used to generate inducement data to improve the security of data transmission and storage.

Benefits of technology

It achieves layered encryption protection for data information, reduces the possibility of sensitive data being leaked during information exchange, and improves the security of data transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520149B_ABST
    Figure CN119520149B_ABST
Patent Text Reader

Abstract

This disclosure provides a data transmission method, apparatus, device, medium, and program product, which can be applied to the fields of information security technology or fintech. The data transmission method includes: acquiring data to be transmitted; determining an encryption permission level for the data to be transmitted by identifying its sensitivity level; encrypting the data to be transmitted by calling a first encryption algorithm corresponding to the encryption permission level, and then transmitting the encrypted data to be transmitted and its identifier to a first cloud; encrypting predetermined data by calling a second encryption algorithm corresponding to the encryption permission level to generate first inducement data; and transmitting the first inducement data and the identifier of the data to be transmitted to a second cloud.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of information security technology or financial technology, and more specifically to a data transmission method, apparatus, device, medium, and program product. Background Technology

[0002] Data transmission refers to the process of transferring data from a data source to a data terminal through one or more data links according to certain procedures, realizing the transmission and exchange of information between points. The real-time performance and reliability of data transmission are important indicators for evaluating data transmission methods. Data encryption refers to transforming plaintext into ciphertext using encryption algorithms and encryption keys, while data decryption is the process of restoring plaintext from ciphertext using decryption algorithms and decryption keys. Data encryption remains one of the most reliable methods for protecting information in computer systems. It uses cryptographic techniques to encrypt information, achieving information concealment and thus protecting information security.

[0003] In the process of realizing the inventive concept of this disclosure, the inventors discovered that when transmitting data between different terminals, although an encryption algorithm is used, it is still possible to obtain sensitive data by decoding the encrypted data, which poses a data security risk. Summary of the Invention

[0004] In view of the above problems, this disclosure provides data transmission methods, apparatus, devices, media and program products.

[0005] According to a first aspect of this disclosure, a data transmission method is provided, comprising: acquiring data to be transmitted; determining an encryption permission level for the data to be transmitted by identifying a sensitivity level of the data to be transmitted; encrypting the data to be transmitted by calling a first encryption algorithm corresponding to the encryption permission level, and then transmitting the encrypted data to be transmitted and an identifier of the data to be transmitted to a first cloud; encrypting predetermined data by calling a second encryption algorithm corresponding to the encryption permission level, and generating first inducement data; and transmitting the first inducement data and the identifier of the data to be transmitted to a second cloud.

[0006] According to embodiments of this disclosure, generating first inducement data by encrypting predetermined data using a second encryption algorithm corresponding to the encryption permission level includes: determining the inducement data type according to the encryption permission level; processing the predetermined data according to the inducement data type to generate data to be encrypted; and encrypting the data to be encrypted by calling the second encryption algorithm to generate the first inducement data.

[0007] According to embodiments of this disclosure, processing predetermined data according to the induced data type to generate data to be encrypted includes: in response to the induced data type being an error type, randomly changing at least two data in the predetermined data to generate data to be encrypted; in response to the induced data type being a missing type, randomly deleting at least two data in the predetermined data to generate data to be encrypted; and in response to the induced data type being a random type, modifying any number of random data at at least two random positions in the predetermined data to generate data to be encrypted.

[0008] According to embodiments of this disclosure, the method further includes: in response to receiving information indicating successful data transmission from the first cloud, deleting the operation record for data transmission to the first cloud.

[0009] According to embodiments of this disclosure, the method further includes: responding to a received data interaction request from a target terminal, obtaining the identifier of the target terminal and the identifier of the data to be interacted with; if it is determined that the identifier of the target terminal is abnormal and the data to be interacted with is sensitive data, obtaining second inducement data corresponding to the identifier of the data to be interacted with from a second cloud; wherein the second inducement data is generated by encrypting predetermined data using an encryption data algorithm corresponding to the sensitivity level of the data to be interacted with; and sending the second inducement data to the target terminal.

[0010] According to embodiments of this disclosure, the method further includes: determining the sensitivity level of the data to be interacted with based on the identifier of the data to be interacted with; and sending a warning message to the target object in response to the sensitivity level being greater than a predetermined threshold; wherein the target object has operation permissions for the sensitive data.

[0011] According to embodiments of this disclosure, the method further includes: in response to receiving a data protection instruction from the target object for the data to be interacted with, cutting off data communication with the target terminal.

[0012] According to embodiments of this disclosure, the method further includes: in response to receiving a data protection instruction from a target object for the data to be interacted with, deleting sensitive data corresponding to the identifier of the data to be interacted with.

[0013] A second aspect of this disclosure provides a data transmission apparatus, comprising: an acquisition module for acquiring data to be transmitted; an identification module for determining an encryption permission level for the data to be transmitted by identifying the sensitivity level of the data to be transmitted; a first transmission module for encrypting the data to be transmitted by calling a first encryption algorithm corresponding to the encryption permission level, and then transmitting the encrypted data to be transmitted and an identifier of the data to be transmitted to a first cloud; a generation module for generating first inducement data by encrypting predetermined data by calling a second encryption algorithm corresponding to the encryption permission level; and a second transmission module for transmitting the first inducement data and the identifier of the data to be transmitted to a second cloud.

[0014] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0015] A fourth aspect of this disclosure also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0016] The fifth aspect of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method.

[0017] According to embodiments of this disclosure, encryption is performed at corresponding levels based on the sensitivity level of the data to be transmitted. The encrypted data is then transmitted to a first cloud platform, achieving layered encryption protection of data information, ensuring the security of data transmission, and enabling the owner to promptly recover sensitive data information after uploading to the first cloud platform. Simultaneously, for the data to be transmitted, inducement data is generated by encrypting predetermined data and transmitted to different second clouds. By specifically generating inducement data and uploading both to different clouds for storage, the security of data transmission and storage is improved, reducing the possibility of sensitive data leakage during information exchange. Attached Figure Description

[0018] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0019] Figure 1 This diagram schematically illustrates an application scenario of the data transmission method according to an embodiment of the present disclosure.

[0020] Figure 2 A flowchart illustrating a data transmission method according to an embodiment of the present disclosure is shown schematically.

[0021] Figure 3A An example flowchart illustrating predetermined data processing for error-type induced data according to an embodiment of the present disclosure is shown.

[0022] Figure 3B An example flowchart illustrating predetermined data processing for missing type induced data according to an embodiment of the present disclosure is shown.

[0023] Figure 3C An example flowchart illustrating the processing of predetermined data for randomly induced data according to embodiments of the present disclosure is shown.

[0024] Figure 4 A schematic block diagram of a data transmission apparatus according to an embodiment of the present disclosure is shown.

[0025] Figure 5 A block diagram of an electronic device according to an embodiment of the data transmission method of the present disclosure is shown schematically. Detailed Implementation

[0026] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0029] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0030] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0031] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this disclosure all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0032] Data transmission refers to the process of transferring data from a data source to a data terminal through one or more data links according to certain procedures, realizing the transmission and exchange of information between points. The real-time performance and reliability of data transmission are important indicators for evaluating data transmission methods. Data encryption refers to transforming plaintext into ciphertext using encryption algorithms and encryption keys, while data decryption is the process of restoring plaintext from ciphertext using decryption algorithms and decryption keys. Data encryption remains one of the most reliable methods for protecting information in computer systems. By encrypting information using cryptographic techniques, information is made hidden, thereby protecting information security.

[0033] In the process of realizing the inventive concept of this disclosure, the inventors discovered that when transmitting data between different terminals, although an encryption algorithm is used, it is still possible to obtain sensitive data by decoding the encrypted data, which poses a data security risk.

[0034] In view of this, embodiments of the present disclosure provide a data transmission method that performs corresponding levels of encryption based on the sensitivity level of the data to be transmitted, and transmits the encrypted data to a first cloud platform. This achieves layered encryption protection of data information, ensuring the security of data transmission, and allows the owner to promptly recover sensitive data information after uploading to the first cloud platform. Simultaneously, for the data to be transmitted, inducement data is generated by encrypting predetermined data and transmitted to different second clouds. By specifically generating inducement data and uploading both to different clouds for storage, the security of data transmission and storage is improved, reducing the possibility of sensitive data leakage during information exchange.

[0035] Figure 1 The diagram illustrates an application scenario of the data transmission method according to an embodiment of the present disclosure.

[0036] like Figure 1As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0037] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (these are just examples). Furthermore, users can transmit data with external storage via the first terminal device 101, the second terminal device 102, and the third terminal device 103.

[0038] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0039] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0040] It should be noted that the data transmission method provided in this embodiment can generally be executed by server 105. Correspondingly, the data transmission device provided in this embodiment can generally be located in server 105. The data transmission method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the data transmission device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0041] It should be understood that Figure 1The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0042] The following will be based on Figure 1 The scenario described herein provides a detailed description of the data transmission method of the disclosed embodiments.

[0043] Figure 2 A flowchart illustrating a data transmission method according to an embodiment of the present disclosure is shown schematically.

[0044] like Figure 2 As shown, the data transmission method of this embodiment includes operations S210 to S250.

[0045] In operation S210, the data to be transmitted is obtained.

[0046] In operation S220, the level of encryption permission for the data to be transmitted is determined by identifying the sensitivity level of the data to be transmitted.

[0047] In operation S230, after encrypting the data to be transmitted by calling the first encryption algorithm corresponding to the encryption permission level, the encrypted data to be transmitted and the identifier of the data to be transmitted are transmitted to the first cloud.

[0048] In operation S240, after encrypting the predetermined data by calling the second encryption algorithm corresponding to the encryption permission level, the first inducement data is generated.

[0049] During operation S250, the identifiers of the first induction data and the data to be transmitted are transmitted to the second cloud.

[0050] According to embodiments of this disclosure, the data to be transmitted includes sensitive data and non-sensitive data, where non-sensitive data is readable representation information. The sensitivity level of the data to be transmitted includes Level 1 sensitive data, Level 2 sensitive data, Level 3 sensitive data, Level 4 sensitive data, etc. The sensitivity level is used to characterize the importance of the data to be transmitted. For example, Level 1 sensitive data indicates that the data is very important, and its leakage will cause unpredictable risks; Level 4 sensitive data indicates that the data contains sensitive information, and its leakage will cause minor impact.

[0051] By identifying the sensitivity level of the data to be transmitted, the encryption permission level for the data to be transmitted is determined. This includes a one-to-one correspondence between the sensitivity level of the data to be transmitted and the encryption permission level. For example, Level 1 sensitive data has Level 1 encryption permission, and Level 2 sensitive data has Level 2 encryption permission.

[0052] Determining the encryption permission level for the data to be transmitted by identifying its sensitivity level also includes determining the encryption permission level based on the weighting coefficient of the sensitivity level of the data. For example, the weighting coefficient for Level 1 sensitive data is 0.8, for Level 2 sensitive data it is 0.6, for Level 3 sensitive data it is 0.4, and for Level 4 sensitive data it is 0.2. If the data to be transmitted contains both Level 2 and Level 4 sensitive data, then the encryption permission coefficient is 0.6 + 0.2 = 0.8, which falls within the range of 0.6 to 1.0 for Level 2 encryption permission coefficients.

[0053] According to embodiments of this disclosure, a first encryption algorithm is used for the encryption processing of sensitive data, including one or more encryption algorithms corresponding to the encryption permission level. For example, the first encryption algorithm includes one or more of the following methods: Transact-SQL functions, asymmetric keys, symmetric keys, certificates, and transparent data encryption. Users can update the first encryption algorithm in real time as needed.

[0054] The identifier of the data to be transmitted can serve as the data's ID identity information, enabling the transmitted data to be quickly identified and retrieved.

[0055] First Cloud is used to store sensitive data of different levels. Users can update sensitive data and upload it to First Cloud as needed to update the stored sensitive data.

[0056] According to embodiments of this disclosure, predetermined data is used to generate inducement data, including data generated by random permutation and combination from a database, data generated after random replacement or deletion of data in the database, and non-sensitive data.

[0057] The second encryption algorithm is used for the encryption processing of predetermined data, including one or more encryption algorithms, corresponding to the encryption permission level. Users can update the second encryption algorithm in real time as needed, which is not limited here.

[0058] The first inducement data is generated when the data to be transmitted is transmitted. Based on the level of the data to be transmitted, corresponding to different encryption permissions, the first inducement data has different types.

[0059] The second cloud is used to store different levels of inducement data. Correspondingly, users can update the inducement data in a timely manner and upload it to the second cloud as needed to update the stored inducement data. The identifiers of the first inducement data and the data to be transmitted are transmitted to the second cloud, which can serve as inducement information to mislead abnormal data transmission behavior and prolong the data decryption time when abnormal devices transmit data.

[0060] According to embodiments of this disclosure, encryption is performed at corresponding levels based on the sensitivity level of the data to be transmitted. The encrypted data is then transmitted to a first cloud platform, achieving layered encryption protection of data information, ensuring the security of data transmission, and enabling the owner to promptly recover sensitive data information after uploading to the first cloud platform. Simultaneously, for the data to be transmitted, inducement data is generated by encrypting predetermined data and transmitted to different second clouds. By specifically generating inducement data and uploading both to different clouds for storage, the security of data transmission and storage is improved, reducing the possibility of sensitive data leakage during information exchange.

[0061] According to embodiments of this disclosure, generating first inducement data by encrypting predetermined data using a second encryption algorithm corresponding to the encryption permission level includes: determining the inducement data type according to the encryption permission level; processing the predetermined data according to the inducement data type to generate data to be encrypted; and encrypting the data to be encrypted by calling the second encryption algorithm to generate the first inducement data.

[0062] Different encryption permissions can generate different levels of inducement data. For example, inducement data includes level 1 inducement data, level 2 inducement data, level 3 inducement data, and level 4 inducement data. Based on the different levels of inducement data, the type of inducement data can be determined.

[0063] The types of inducement data include non-sensitive data, erroneous data, missing data, and randomly generated data. Different types of inducement data are processed in different ways to generate data to be encrypted.

[0064] Different levels of manipulative data contain different types of manipulative data. For example, Level 1 manipulative data can be formed by combining various types of manipulative data, including erroneous data, missing data, and randomly generated data, while Level 4 manipulative data can be formed by randomly generated manipulative data. Level 1 manipulative data includes data generated in multiple ways, while Level 4 manipulative data includes data generated in only one way. Therefore, the higher the level, the higher the security of the generated manipulative data and the less likely it is to be cracked.

[0065] According to embodiments of this disclosure, the type of inducement data is determined based on the encryption permission level, and the predetermined data is processed according to the type of inducement data to generate data to be encrypted. After encrypting the data to be encrypted using an encryption algorithm, inducement data is generated, which prolongs the time it takes for the inducement data to be deciphered and reduces the possibility of discovering encrypted sensitive data.

[0066] According to embodiments of this disclosure, processing predetermined data according to the induced data type to generate data to be encrypted includes: in response to the induced data type being an error type, randomly changing at least two data in the predetermined data to generate data to be encrypted; in response to the induced data type being a missing type, randomly deleting at least two data in the predetermined data to generate data to be encrypted; and in response to the induced data type being a random type, adding any number of random data at at least two random positions in the predetermined data to generate data to be encrypted.

[0067] Figure 3A An example flowchart illustrating predetermined data processing for error-type induced data according to an embodiment of this disclosure is shown.

[0068] According to embodiments of this disclosure, when the induced data is determined to be of an error type, at least two data points in the predetermined data are randomly changed. For example... Figure 3A As shown, 300A includes predetermined data "ab11200h" 311, random numbers "x and y" 312, and data to be encrypted "ax1120yh" 313. Based on the encryption permission level, the predetermined data "ab11200h" 311 is generated from the database. After determining the change location, data 311A ​​with a change location marker is obtained. According to the random numbers "x and y" 312 randomly generated from the database, the data is changed at the marked change location, and finally, the data to be encrypted "ax1120yh" 313 is generated.

[0069] Figure 3B An example flowchart illustrating predetermined data processing for missing type induced data is shown in accordance with an embodiment of the present disclosure.

[0070] When the induced data is determined to be missing, at least two data points from the predetermined data are deleted. For example... Figure 3B As shown, 300B includes predetermined data "ab11200h" 311 and data to be encrypted "a1120h" 314. Based on the encryption permission level, the predetermined data "ab11200h" 311 is generated from the database. After determining the deletion position, data 311B with a deletion position marker is obtained. The data is deleted at the marked deletion position, and finally, the data to be encrypted "a1120h" 314 is generated.

[0071] Figure 3C An example flowchart illustrating the processing of predetermined data for randomly induced data according to an embodiment of the present disclosure is shown.

[0072] When the induced data is determined to be of a random type, any number of data points are modified at at least two random locations within the predetermined data set, including randomly adding, deleting, or changing any number of data points. For example... Figure 3CAs shown, 300C includes predetermined data "ab11200h" 311, random numbers "m and n" 315, and data to be encrypted "man1120mhn" 316. Based on the encryption permission level, the predetermined data "ab11200h" 311 is generated from the database. After determining the modification location, data 311C with modification location markers is obtained. According to the random numbers "m and n" 315 randomly generated from the database, data is added and replaced at the marked modification locations, finally generating the data to be encrypted "man1120mhn" 316.

[0073] In some embodiments, comprehensive inducement data can be generated based on the encryption permission level, and the length of the generated inducement data can be the same as the length of the corresponding sensitive data to further increase the difficulty of cracking and improve the security of data transmission.

[0074] According to embodiments of this disclosure, based on the type of inducement data, including error type, missing type, and random type, predetermined data is processed according to the inducement data type to generate various types of data to be encrypted, thereby obtaining various inducement data. The above method provides multiple ways to generate inducement data, increasing the difficulty of deciphering the inducement data and reducing the possibility of sensitive data being discovered.

[0075] According to embodiments of this disclosure, the method further includes deleting the operation record for transmitting data to the first cloud in response to receiving a successful data transmission message from the first cloud.

[0076] The operation record for data transmission to the first cloud includes information such as the time of data transmission, the identifier of the transmitted data, and a summary of the content of the transmitted data.

[0077] Deleting operation records for data transmission to the first cloud includes automatically deleting data transmission operation records immediately after receiving a successful data transmission message from the first cloud, and also includes deleting data transmission operation records periodically.

[0078] According to embodiments of this disclosure, after the first cloud data transmission is successful, the cloud backup operation record is promptly cleared to reduce the possibility of sensitive data being discovered and effectively reduce the risk of data theft from the cloud.

[0079] According to embodiments of this disclosure, the method further includes responding to a received data interaction request from a target terminal, obtaining the identifier of the target terminal and the identifier of the data to be interacted with; if it is determined that the identifier of the target terminal is abnormal and the data to be interacted with is sensitive data, obtaining second inducement data corresponding to the identifier of the data to be interacted with from a second cloud, wherein the second inducement data is generated by encrypting predetermined data using an encryption data algorithm corresponding to the sensitivity level of the data to be interacted with; and sending the second inducement data to the target terminal.

[0080] According to embodiments of this disclosure, the target terminal includes an external storage device, such as a portable hard drive, USB, optical disc, etc. Each independent external storage device has a unique target terminal identifier, that is, the target terminal identifier can be used as identity information to characterize the external storage device.

[0081] According to embodiments of this disclosure, determining that a target terminal's identifier is abnormal can be done by checking whether the target terminal's identifier is in a list of abnormal target terminals. If the target terminal is in the list, it is an abnormal target terminal. Alternatively, determining that a target terminal's identifier is abnormal can be done by checking whether the target terminal's identifier is in a list of target terminals owned by the target object. If the target terminal is not in the list, it is an abnormal target terminal.

[0082] When the target terminal identifier is confirmed to be normal, the encrypted sensitive data corresponding to the data identifier to be interacted with is obtained. For example, the external storage device connected to the computer mobile terminal is identified and detected. When the owner connects the external storage device to the computer mobile data port for the first time, the security key and transmission channel are identified and established, and the encrypted sensitive data corresponding to the data identifier to be interacted with is obtained.

[0083] When the target terminal identifier is determined to be abnormal and the data to be interacted with is sensitive data, a second inducement data is sent to the target terminal. For example, when an abnormal external storage device not used by the user is accessed and sensitive data is transmitted, the ID is recorded and identified. After determining that the target terminal identifier is abnormal, the encrypted inducement data of the mobile data terminal is displayed, the data is transmitted, and the built-in security connection of the mobile terminal is activated to send warning information.

[0084] According to embodiments of this disclosure, when a data interaction request is received from a target terminal, the system identifies whether the target terminal is abnormal based on its identifier and whether the data to be interacted is sensitive based on the identifier information of the data to be interacted. When the target terminal's identifier is abnormal and the data to be interacted is sensitive, the system sends second inducement data, obtained from a second cloud and corresponding to the identifier of the data to be interacted, to the target terminal. This induces the abnormal target terminal, preventing it from obtaining the real sensitive data for a short period, providing operation time for destroying the sensitive data, and reducing the probability that the abnormal target terminal reads the real data.

[0085] According to embodiments of this disclosure, the method further includes determining the sensitivity level of the data to be interacted with based on the identifier of the data to be interacted with; and sending a warning message to the target object in response to the sensitivity level being greater than a predetermined threshold; wherein the target object has operation permissions for the sensitive data.

[0086] According to embodiments of this disclosure, the predetermined threshold for the sensitivity level can be determined based on the actual application. It can be a level number, such as a predetermined threshold of level two, or a sensitivity level coefficient, such as a predetermined threshold of 0.5.

[0087] The warning information includes data from the abnormal target terminal, the operation steps of the target terminal, and the operation time of the target terminal. For example, the warning information might be: "Warning! An abnormal target terminal at address x is transmitting highly sensitive data A at time t!". The warning information can be sent to the remote client of the target object, indicating that the target object's mobile device data has been compromised.

[0088] The target object's access permissions for sensitive data include remote operation to forcibly destroy mobile terminal data, remote operation to cut off the mobile terminal data signal transmission module path, remote operation to cut off the mobile terminal main power supply module, remote operation to start the backup power supply, and remote operation to execute formatting commands, etc., to promptly handle abnormal transmission of sensitive data.

[0089] According to embodiments of this disclosure, the sensitivity level of the data to be interacted with is determined based on its identifier. When the sensitivity level exceeds a predetermined threshold, a warning message is sent to the target object, alerting the data owner that an abnormal interaction of sensitive data has occurred. Therefore, when highly sensitive data is requested for interaction, the target object can receive the warning signal in a timely manner, thereby promptly handling any risky data interaction processes and ensuring the security of sensitive data.

[0090] According to embodiments of this disclosure, the method further includes: in response to receiving a data protection instruction from the target object for the data to be interacted with, cutting off data communication with the target terminal.

[0091] When an abnormal target terminal interacts with highly sensitive data, cutting off data communication with the target terminal includes forcibly destroying mobile data, cutting off the mobile data signal transmission module's path, cutting off the mobile terminal's main power supply module, and activating the backup power supply, as well as energizing the electromagnets around the internal memory. The electromagnetic effect generated by energizing the electromagnets around the internal memory can forcibly destroy the data in the mobile terminal's internal memory, making it irrecoverable. Even if criminals steal the owner's mobile device, they will not be able to recover the sensitive data. Furthermore, the owner can recover the data from the cloud and delete the cloud-based data information, further reducing the risk of accidental data transmission.

[0092] According to embodiments of this disclosure, upon receiving a data protection instruction from the target object regarding the data to be interacted with, data communication with the target terminal can be cut off in various ways, preventing data transmission and effectively reducing the risk of data leakage.

[0093] According to embodiments of this disclosure, the method further includes: in response to receiving a data protection instruction from a target object for the data to be interacted with, deleting sensitive data corresponding to the identifier of the data to be interacted with.

[0094] According to embodiments of this disclosure, deleting sensitive data corresponding to the identifier of the data to be interacted with includes performing a self-formatting operation to delete the sensitive data.

[0095] According to embodiments of this disclosure, upon receiving a data protection instruction from the target object regarding the data to be interacted with, sensitive data that the abnormal target terminal wanted to read is deleted, effectively reducing the risk of data leakage.

[0096] Based on the above data transmission method, this disclosure also provides a data transmission apparatus. The following will be combined with... Figure 4 The device is described in detail.

[0097] Figure 4 A schematic block diagram of a data transmission apparatus according to an embodiment of the present disclosure is shown.

[0098] like Figure 4 As shown, the data transmission device 400 of this embodiment includes an acquisition module 410, an identification module 420, a first transmission module 430, a generation module 440, and a second transmission module 450.

[0099] The acquisition module is used to acquire the data to be transmitted. In one embodiment, the acquisition module 410 can be used to perform the operation S210 described above, which will not be repeated here.

[0100] The identification module is used to determine the encryption permission level for the data to be transmitted by identifying the sensitivity level of the data. In one embodiment, the identification module 420 can be used to perform the operation S220 described above, which will not be repeated here.

[0101] The first transmission module is used to encrypt the data to be transmitted by calling a first encryption algorithm corresponding to the encryption permission level, and then transmit the encrypted data to be transmitted and its identifier to the first cloud. In one embodiment, the first transmission module 430 can be used to perform the operation S230 described above, which will not be repeated here.

[0102] The generation module is used to generate first inducement data by encrypting predetermined data using a second encryption algorithm corresponding to the encryption permission level. In one embodiment, the generation module 440 can be used to perform the operation S240 described above, which will not be repeated here.

[0103] The second transmission module is used to transmit the identifiers of the first induction data and the data to be transmitted to the second cloud. In one embodiment, the second transmission module 450 can be used to perform the operation S250 described above, which will not be repeated here.

[0104] According to embodiments of this disclosure, the generation module includes a first determining submodule, a predetermined data processing submodule, and a data encryption submodule. The first determining submodule is used to determine the inducement data type based on the encryption permission level. The predetermined data processing submodule is used to process predetermined data according to the inducement data type to generate data to be encrypted. The data encryption submodule is used to encrypt the data to be encrypted by calling a second encryption algorithm to generate first inducement data.

[0105] According to embodiments of this disclosure, the predetermined data processing submodule includes a modification subunit, a deletion subunit, and a modification subunit. The modification subunit is used to randomly modify at least two data points in the predetermined data in response to the induced data type being an error type, generating data to be encrypted. The deletion subunit is used to randomly delete at least two data points in the predetermined data in response to the induced data type being a missing type, generating data to be encrypted. The modification subunit is used to modify any number of random data points at at least two random positions in the predetermined data in response to the induced data type being a random type, generating data to be encrypted.

[0106] According to an embodiment of this disclosure, the above-described apparatus further includes: an operation record deletion module, configured to delete the operation record of transmitting data to the first cloud in response to receiving a data transmission success message from the first cloud.

[0107] According to embodiments of this disclosure, the apparatus further includes: an identifier acquisition module, a second inducement data acquisition module, and a second inducement data sending module. The identifier acquisition module is used to acquire the identifier of the target terminal and the identifier of the data to be interacted in response to receiving a data interaction request from a target terminal. The second inducement data acquisition module is used to acquire second inducement data corresponding to the identifier of the data to be interacted from a second cloud when it is determined that the identifier of the target terminal is abnormal and the data to be interacted is sensitive data; wherein the second inducement data is generated by encrypting predetermined data using an encryption data algorithm corresponding to the sensitivity level of the data to be interacted. The second inducement data sending module is used to send the second inducement data to the target terminal.

[0108] According to embodiments of this disclosure, the apparatus further includes a sensitivity level determination module and a warning information sending module. The sensitivity level determination module is used to determine the sensitivity level of the data to be interacted with based on the identifier of the data. The warning information sending module is used to send a warning message to a target object in response to a sensitivity level exceeding a predetermined threshold; wherein the target object has operational permissions for the sensitive data.

[0109] According to embodiments of this disclosure, the apparatus further includes a sensitive data deletion module, configured to delete sensitive data corresponding to the identifier of the data to be interacted in response to receiving a data protection instruction from a target object for the data to be interacted.

[0110] According to embodiments of this disclosure, any multiple modules among the acquisition module 410, identification module 420, first transmission module 430, generation module 440, and second transmission module 450 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 410, identification module 420, first transmission module 430, generation module 440, and second transmission module 450 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in a suitable combination of any of these. Alternatively, at least one of the acquisition module 410, identification module 420, first transmission module 430, generation module 440 and second transmission module 450 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0111] Figure 5 A block diagram of an electronic device according to an embodiment of the data transmission method of the present disclosure is shown schematically.

[0112] like Figure 5 As shown, an electronic device 500 according to an embodiment of the present disclosure includes a processor 501, which can perform various appropriate actions and processes according to a program stored in ROM 502 or a program loaded from storage portion 508 into RAM 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0113] RAM 503 stores various programs and data required for the operation of electronic device 500. Processor 501, ROM 502, and RAM 503 are interconnected via bus 504. Processor 501 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 502 and / or RAM 503. It should be noted that the programs may also be stored in one or more memories other than ROM 502 and RAM 503. Processor 501 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0114] According to embodiments of this disclosure, the electronic device 500 may further include an I / O interface 505, which is also connected to a bus 504. The electronic device 500 may also include one or more of the following components connected to the I / O interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 510 as needed so that computer programs read from it can be installed into the storage section 508 as needed.

[0115] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0116] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 502 and / or RAM 503 and / or one or more memories other than ROM 502 and RAM 503 described above.

[0117] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the data transmission method provided in the embodiments of this disclosure.

[0118] When the computer program is executed by the processor 501, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0119] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 509, and / or installed from a removable medium 511. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0120] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by processor 501, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0121] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0123] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0124] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A data transmission method, characterized in that, The method includes: Get the data to be transmitted; By identifying the sensitivity level of the data to be transmitted, the encryption permission level for the data to be transmitted is determined. After encrypting the data to be transmitted by calling the first encryption algorithm corresponding to the encryption permission level, the encrypted data to be transmitted and the identifier of the data to be transmitted are transmitted to the first cloud. After encrypting the predetermined data by calling the second encryption algorithm corresponding to the encryption permission level, first inducement data is generated; and The identifiers of the first induction data and the data to be transmitted are transmitted to the second cloud.

2. The method according to claim 1, characterized in that, The step of encrypting the predetermined data by calling the second encryption algorithm corresponding to the encryption permission level and generating the first inducement data includes: Based on the encryption permission level, determine the type of inducement data; According to the induced data type, the predetermined data is processed to generate data to be encrypted; The first inducement data is generated by encrypting the data to be encrypted by calling the second encryption algorithm.

3. The method according to claim 2, characterized in that, The step of processing the predetermined data according to the induced data type to generate data to be encrypted includes: In response to the fact that the induced data type is an error type, at least two data points in the predetermined data are randomly changed to generate the data to be encrypted; In response to the induced data type being a missing type, at least two data points are randomly deleted from the predetermined data to generate the data to be encrypted; and In response to the fact that the induced data type is random, an arbitrary number of random data are modified at at least two random positions in the predetermined data to generate the data to be encrypted.

4. The method according to claim 1, characterized in that, The method further includes: In response to receiving a successful data transmission message from the first cloud, the operation record for transmitting data to the first cloud is deleted.

5. The method according to claim 1, characterized in that, The method further includes: In response to a received data interaction request from a target terminal, the identifier of the target terminal and the identifier of the data to be interacted with are obtained; If it is determined that the target terminal's identifier is abnormal and the data to be interacted with is sensitive data, second inducement data corresponding to the identifier of the data to be interacted with is obtained from the second cloud; wherein, the second inducement data is generated by encrypting predetermined data using an encryption data algorithm corresponding to the sensitivity level of the data to be interacted with; and The second inducement data is sent to the target terminal.

6. The method according to claim 5, characterized in that, The method further includes: The sensitivity level of the data to be interacted with is determined based on the identifier of the data to be interacted with; In response to the sensitivity level exceeding a predetermined threshold, a warning message is sent to the target object; wherein the target object has the permission to operate on the sensitive data.

7. The method according to claim 6, characterized in that, The method further includes: In response to receiving a data protection instruction from the target object regarding the data to be interacted with, data communication with the target terminal is cut off.

8. The method according to claim 6, characterized in that, The method further includes: in response to receiving a data protection instruction from a target object for the data to be interacted with, deleting sensitive data corresponding to the identifier of the data to be interacted with.

9. A data transmission device, characterized in that, The device includes: The acquisition module acquires the data to be transmitted. The identification module is used to determine the encryption permission level for the data to be transmitted by identifying the sensitivity level of the data to be transmitted; The first transmission module is used to encrypt the data to be transmitted by calling the first encryption algorithm corresponding to the encryption permission level, and then transmit the encrypted data to be transmitted and the identifier of the data to be transmitted to the first cloud. The generation module is used to generate first inducement data by encrypting predetermined data through a second encryption algorithm corresponding to the encryption permission level; and The second transmission module is used to transmit the first induction data and the identifier of the data to be transmitted to the second cloud.

10. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Big data processing method for authenticity verification and credible traceability and cloud server

    CN112749181A

  • Data processing method and processor

    CN116707958A