A method, system and storage medium for online query of social security data

By establishing a government data query platform, unified online query of social security, provident fund and real estate data is achieved, and the problem of inefficient query in the existing technology is solved, ensuring the improvement of data security and query efficiency.

CN119539930BActive Publication Date: 2025-05-13BEIJING BIDI INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411564594.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-05-13
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

It is difficult for the existing technology to realize online inquiry of customer government data by commercial bank systems, especially unified inquiry of social security, provident fund and real estate data, resulting in inefficient inquiry.

Method used

By establishing a government data query platform, the data query party is configured to obtain the required interface parameters, perform identity verification and assign user ID, user key and access rights, and use the public key to encrypt and decrypt the request body and query results to achieve multi-level verification and data security.

Benefits of technology

It improves the efficiency of data query, ensures that only data queryers with valid identity, authorized by customers and have access rights can access government data, and protects personal privacy and sensitive information from unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119539930B_ABST
    Figure CN119539930B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, system and storage medium for online query of social security data, which belongs to data query processing technology, including: establishing a query platform for government data, configuring government data interface parameters, authenticating the data query party, and allocating user ID, user key and access rights and search tokens of the government data interface; the data query party obtains the identity token, builds a request body and an authorization code; the data query party encrypts the request body based on a public key, and sends the encrypted data and the identity token to the query platform; the query platform verifies the identity of the data query party based on the identity token, performs authorization verification on the data query party based on the authorization code, performs permission verification based on the search token, decrypts the request body based on the public key after verification, obtains original query information, obtains query results based on the original query information, and returns the results to the data query party. Through the present invention, the efficiency of government data query is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data query processing, and in particular relates to a method, system and storage medium for online query of social security data. Background Art

[0002] Currently, in ordinary commercial banking systems, personal social security, provident fund, and real estate related data are not connected to the People's Bank of China's credit reporting system. When inquiring about relevant information, one needs to go to different government departments to inquire, which is very inconvenient.

[0003] To solve the above problems, the following methods are proposed in the prior art, such as the Chinese patent application with publication number CN111539800A, which proposes a management system for outsourced project employees' wages, social security and provident fund, including an employee client APP, in which an employee login module, an attendance punching module, a wage query module, a social security query module and a provident fund query module are arranged; a background management system connected to the employee client APP by wireless data, the background management system includes a basic data module for managing social security, provident fund schemes and payroll templates in various places, and also includes a project management module, an employee management module, a wage management module, an attendance management module, a financial management module, a permission management module, an external interface module and a social security and provident fund management module. The present invention also provides a management method using the above management system. Through the present invention, a good payroll management list can be established, and at the same time, the payment of social security and provident fund of outsourced project employees can be guaranteed, and the interests of outsourced project employees can be effectively protected.

[0004] However, the above-mentioned existing technologies can only enable employees to view their own social security, provident fund and other government data, and do not provide solutions for some commercial bank systems that want to query customers' government data. Therefore, a method for online query of social security data is needed that can connect to the social security, provident fund and real estate data interfaces of different government departments to improve data query efficiency. Summary of the invention

[0005] To solve the above problems, the present invention provides a method, system and storage medium for online query of social security data to solve the problems in the prior art.

[0006] In order to achieve the above-mentioned purpose of the invention, the present invention proposes a method for online query of social security data, comprising:

[0007] S1: Establish a query platform for government data, and configure the query platform with interface parameters required by the data query party to obtain the government data;

[0008] S2: The query platform authenticates the data query party and allocates a user ID, a user key, access rights to the government data interface, and a search token to the data query party after the authentication is passed;

[0009] S3: The data querying party obtains an identity token based on the user ID and the user key, constructs a request body including the interface parameters and an authorization code, and submits authorization information in the query platform based on the authorization code;

[0010] S4: The data query party and the query platform generate a local private key and a platform private key respectively, and generate a public key based on the local private key and the platform private key. The data query party encrypts the request body based on the public key to obtain first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request;

[0011] S5: The query platform verifies whether the identity of the data query party is valid based on the identity token. If the identity is valid, the query platform performs authorization verification on the data query party based on the authorization information. After the authorization verification is passed, the query platform performs permission verification on the data query party based on the search token. After the permission verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information.

[0012] S6: The query platform obtains a query result based on the original query information, encrypts the query result based on the public key, obtains second encrypted data and returns it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain a final query result.

[0013] Furthermore, the query platform authenticates the identity of the data querying party by the following steps:

[0014] The query platform sets multiple authentication items and generates a first random number for each of the authentication items. The data query party selects the required authentication item from all the authentication items and defines it as the first item. The data query party sends the authentication information of the first item to the query platform. The query platform authenticates the first item based on the authentication information. If the authentication is successful, based on the selection order of the first items, the data query party inputs the first random number corresponding to each of the first items in the query platform in turn. The input first random number sequence is defined as a first numerical sequence. The first numerical sequence is converted into a first hash value based on a hash function, and the first hash value is encrypted. The encrypted first hash value is defined as the first random authentication information. It is determined whether the first random authentication information is the same as the second random authentication information pre-stored in the database, wherein the second random authentication information refers to the hash value generated by encrypting the same first numerical sequence based on the hash function. If the two are the same, the identity authentication of the data query party is successful, otherwise the identity authentication fails.

[0015] Furthermore, allocating access rights and search tokens of the government data interface to the data query party includes the following steps:

[0016] The query platform configures an interface identifier for each of the government data interfaces, obtains hidden data in each of the government data interfaces based on the interface identifier, generates a first key pair and a second key, the first key pair is a query function encryption key and a query function decryption key, allocates query rights to the government data based on the first key pair, and encrypts the hidden data based on the query function encryption key and stores it in an encrypted database;

[0017] The second key is a query scope key. The query platform allocates query scope permissions to the data query party based on the query scope key, and generates a search token for the data query party. The search token embeds the query function decryption key and the query scope key.

[0018] Further, submitting authorization information in the query platform based on the authorization code includes the following steps:

[0019] The query platform establishes a list of objects to be authorized, and the data query party obtains the authorization letter corresponding to the object to be authorized from the list of objects to be authorized, converts the authorization letter into a data code, defines it as an authorization certificate, and stores the authorization code and the authorization certificate as the authorization information in a database.

[0020] Further, generating a public key based on the local private key and the platform private key comprises the following steps:

[0021] The data query party and the query platform randomly generate multiple second random numbers and third random numbers respectively, the data query party generates first shared data based on the local private key and the second random number, the query platform generates second shared data based on the platform private key and the third random number, the data query party and the query platform send the first shared data and the second shared data to each other, the data query party generates a first shared key based on the local private key, the second shared data and the second random number, the query platform generates a second shared key based on the platform private key, the first shared data and the third random number, the first shared key and the second shared key are converted into a second hash value and a third hash value based on a hash function, and it is determined whether the second hash value is the same as the third hash value. If so, the first shared key and the second shared key are the same and are defined as a public key.

[0022] Furthermore, performing authorization verification on the data querying party based on the authorization information includes the following steps:

[0023] The query platform verifies whether the authorization code in the authorization information is valid. If so, it checks whether the data access rights in the authorization letter corresponding to the authorization certificate in the authorization information match the data type and range requested by the data query party. If so, it indicates that the authorization verification of the data query party is passed.

[0024] Furthermore, the authorization verification of the data querying party includes the following steps:

[0025] The query platform extracts the query function decryption key and the query range key from the search token, and determines whether the query function decryption key matches the query function encryption key used for the hidden data stored in the encrypted database. If so, the query function authority verification of the data query party is passed. It also determines whether the query range key is consistent with the key stored in the database. If so, the query range authority verification of the data query party is passed. If the query range authority and the query function authority verification are passed, it means that the authority verification is passed.

[0026] Furthermore, the query platform obtains the query result based on the original query information, including the following steps:

[0027] The query platform performs data verification on the original query information, assembles the verified original query information into a government affairs interface JSON message, and initiates a government affairs data request to the government affairs end. The government affairs data includes personal social security, provident fund and real estate. The query platform sets a routing mapping table, and the routing mapping table includes a mapping relationship between each government affairs data request and the URL path of the government affairs service interface. Based on the routing mapping table, the query platform distributes the government affairs interface JSON message to different servers of the government affairs end through the government affairs data interface. The government affairs end parses the government affairs interface JSON message, unifies the format, and performs data desensitization operations to obtain the query results, and returns the query results to the query platform.

[0028] The present invention also provides a system for online query of social security data, which is used to implement the above method, and the system mainly includes:

[0029] A platform establishment module is used to establish a query platform for government data and configure interface parameters required by a data query party to obtain the government data on the query platform;

[0030] An identity authentication module, used for the query platform to authenticate the data query party, and after the authentication is passed, the data query party is assigned a user ID, a user key, and access rights and a search token for the government data interface;

[0031] A request body generation module, used for the data query party to obtain an identity token based on the user ID and the user key, construct a request body containing the interface parameters and an authorization code, and submit authorization information in the query platform based on the authorization code;

[0032] A request body encryption module, used for the data query party and the query platform to generate a local private key and a platform private key respectively, generate a public key based on the local private key and the platform private key, the data query party encrypts the request body based on the public key to obtain first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request;

[0033] A request body decryption module is used for the query platform to verify whether the identity of the data query party is valid based on the identity token. If it is, the data query party is authorized based on the authorization information. After the authorization verification is passed, the data query party is authorized based on the search token. After the authorization verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information;

[0034] A query result acquisition module is used for the query platform to obtain query results based on the original query information, encrypt the query results based on the public key, obtain second encrypted data and return it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain the final query result.

[0035] The present invention also provides a computer storage medium, which stores program instructions, wherein when the program instructions are executed, the device where the computer storage medium is located is controlled to execute the above method.

[0036] Compared with the prior art, the beneficial effects of the present invention are at least as follows:

[0037] The present invention solves the problem of different service standards of government interface data related to social security, provident fund and real estate by establishing a query platform for personal social security, provident fund and real estate, and uniformly configuring interface parameters required by data query parties to obtain government data. The query platform sets identity authentication rules to authenticate data query parties, ensuring that only data query parties with successful identity authentication can access government data, and uniformly allocates user IDs, user keys, access rights and search tokens of government data interfaces to data query parties. The data query party obtains an identity token, constructs a request body including interface parameters and an authorization code, and submits authorization information in the query platform based on the authorization code.

[0038] The present invention obtains a public key based on a random number and a private key generated by the data query party and the query platform, and uses the public key to encrypt and decrypt data. Compared with traditional encryption and decryption methods, the complexity of the key is improved, and a higher level of security is provided. The present invention sets up a multi-level verification mechanism, including identity authentication, authorization information verification, and authority verification, which greatly guarantees the security of the data, ensuring that only data query parties with valid identities, customer authorization, and access rights can access government data, protecting personal privacy and sensitive information from unauthorized access and abuse. Finally, the present invention uses Java code to obtain the required query information, and assembles it into a query interface request JSON message, which is then verified and distributed to different government service ends, and then the returned message is parsed and encrypted in a unified format before being forwarded to the data query party, ensuring the security of the data during transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 A flowchart of the steps of a method for online query of social security data of the present invention;

[0040] Figure 2 It is a user information configuration diagram of the present invention;

[0041] Figure 3 It is the request message ciphertext diagram of the present invention;

[0042] Figure 4 It is the original query information result diagram of the present invention;

[0043] Figure 5 It is the social security decryption message diagram of the present invention;

[0044] Figure 6 A routing mapping table of the present invention;

[0045] Figure 7 This is a data desensitization operation diagram of the present invention;

[0046] Figure 8 The present invention is a system structure diagram for online query of social security data. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0048] It is understood that the terms "first", "second", etc. used in this application may be used herein to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, without departing from the scope of this application, a first xx script may be referred to as a second xx script, and similarly, a second xx script may be referred to as a first xx script.

[0049] like Figure 1 As shown, a method for online query of social security data includes:

[0050] S1: Establish a query platform for government data and configure the interface parameters required by the query platform for data query parties to obtain government data.

[0051] Specifically, before establishing a query platform for government data, it is necessary to build platform tools, including but not limited to server clusters, database systems, network equipment, etc., to ensure that the networks and ports between each link are connected, laying the foundation for subsequent interface docking and data transmission. The present invention builds a database management system based on MySQL8, which is responsible for the persistent storage of data, uses Nginx1.24 as a Web server to process HTTP requests and provide load balancing, and Redis 7.0.11Redis is used as a cache message queue system to improve data processing speed and efficiency. By reasonably configuring and optimizing these tools, a powerful and stable query platform is constructed.

[0052] The government affairs data in the present invention includes social security, provident fund and real estate.

[0053] To query the social security API interface, you need to visit the official website of the relevant social security bureau, find the API interface documentation they provide, understand the API access address, request method, request parameters, return data format and other information, and register on the official website of the Social Security Bureau and complete the relevant authentication process to obtain the credentials required for the API call. The query platform can use the python programming language to write code and call the API interface to query social security information.

[0054] For the docking of personal provident fund query interface, first use the support library released by the relevant department and set the configuration file, including address, organization, user name, password, etc. If the relevant department already has a personal interface user, directly submit an application for the activation of provident fund query user rights. If there is no personal interface user, it is necessary to submit an application form and CRS certificate to obtain permissions and realize interface docking.

[0055] The main parameters for real estate data interface configuration include input fields, such as name, district and county code, unified credit code, company name, ID number, etc.

[0056] S2: The query platform authenticates the data query party and assigns the data query party a user ID, user key, access rights to the government data interface, and a search token after the authentication is passed.

[0057] Specifically, the query platform authenticates the data query party to ensure that only legitimate users can access the system. The specific verification method will be described later. After the verification is passed, the data query party is assigned a user ID and user key, such as Figure 2 As shown, this is a user information configuration diagram. Taking the data query party Bank A as an example, the present invention configures the user ID (APPID) and user key for Bank A. The data query party also defines the access rights and search tokens of the government data interface. The search token is used to verify the use rights of the data query party, such as restricting certain data query parties to only access specific types of data or only view data without the right to modify data.

[0058] S3: The data query party obtains an identity token based on the user ID and user key, constructs a request body containing interface parameters and an authorization code, and submits authorization information in the query platform based on the authorization code.

[0059] Specifically, the data query party first uses the user ID and user key to send an identity authentication service request to the query platform. The query platform will verify the validity of the user ID and user key. Once the verification is passed, the service will generate an identity token and return it to the data query party. After obtaining the identity token, the data query party needs to construct a request body containing interface parameters. The interface parameters may include requesting the government data interface endpoint (such as social security query, provident fund query, etc.), specific queried data (such as the customer's social security number, ID number, etc.) and other necessary parameters (request timestamp, request data type, etc.).

[0060] In response to data-related compliance requirements and relevant policy constraints of the Personal Data Protection Act, the corresponding personal data can only be queried with the customer's authorization. Therefore, the data query party also needs to obtain an authorization code. The authorization code is usually generated during the user authorization process to prove that the data query party has been authorized by the customer and has the right to access the requested data. It can be a short-term token to ensure the security of the data query party. The authorization information is submitted in the query platform according to the authorization code so that the subsequent query platform can verify the specific authorization authority of the data query party based on the authorization information.

[0061] S4: The data query party and the query platform generate a local private key and a platform private key respectively, and generate a public key based on the local private key and the platform private key. The data query party encrypts the request body based on the public key to obtain the first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request.

[0062] Specifically, the data query party and the query platform each generate a local private key and a platform private key. Based on their respective private keys, the data query party and the query platform generate a public key. The method of generating the public key will be described later. The public key combines the random number and the private key generated by the data query party and the query platform. Compared with the traditional encryption and decryption method, the complexity of the key is increased and a higher level of security is provided. Figure 3 The figure shows the ciphertext of the request message.

[0063] S5: The query platform verifies whether the identity of the data query party is valid based on the identity token. If it is, the data query party is authorized based on the authorization information. After the authorization verification is passed, the data query party is authorized based on the search token. After the authorization verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information.

[0064] Specifically, the query platform first verifies whether the identity of the data query party is valid based on the identity token, including the signature, validity period and issuer of the verification token. Then, the query platform verifies whether the data query party is authorized by the customer based on the authorization information. If authorized by the customer, the query function authority and query scope authority of the data query party are verified based on the search token. Through the multi-level verification mechanism, the security of the data is guaranteed to a great extent, ensuring that only data query parties with valid identities, customer authorization and access rights can access government data, protecting personal privacy and sensitive information from unauthorized access and abuse. After the authority verification is passed, the query platform uses the public key to decrypt the request body to obtain the original query information, such as Figure 4 The figure shows the original query information result.

[0065] S6: The query platform obtains the query result based on the original query information, encrypts the query result based on the public key, obtains the second encrypted data and returns it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain the final query result.

[0066] Specifically, the query platform initiates a government data request to the government end based on the original query information. The government end obtains the query results from the corresponding server and returns them to the query platform. The specific implementation process will be described later. The query platform then uses the public key to encrypt the query results. This step ensures the security of the data during transmission to the data query party. Only the data query party holding the corresponding public key can decrypt and access the data. Figure 5 The figure shows the social security decryption message diagram.

[0067] As a preferred technical solution of the present invention, the query platform authenticates the data query party by the following steps:

[0068] The query platform sets multiple authentication items and generates a first random number for each authentication item. The data query party selects the required authentication item from all authentication items and defines it as the first item. The data query party sends the authentication information of the first item to the query platform. The query platform authenticates the first item based on the authentication information. If the authentication is successful, based on the selection order of the first items, the data query party enters the first random number corresponding to each first item in the query platform in turn. The input first random number sequence is defined as the first numerical sequence. The first numerical sequence is converted into a first hash value based on a hash function, and the first hash value is encrypted. The encrypted first hash value is defined as the first random authentication information. It is determined whether the first random authentication information is the same as the second random authentication information pre-stored in the database of the query platform. The second random authentication information is a hash value obtained by processing and encrypting the same first numerical sequence based on a hash function. If the two are the same, the identity authentication of the data query party is successful, otherwise the identity authentication fails.

[0069] Specifically, the present invention establishes an identity authentication interface on the query platform, and sets multiple authentication items on the interface, such as authentication items for access data types, including access to provident funds, access to social security, and access to real estate, and authentication items for role types, including ordinary users, banking institutions, etc., and authentication items for compliance types and security. Now, it is assumed that there are seven authentication items in the identity authentication interface, namely, access to provident funds, access to social security, access to real estate, ordinary users, banking institutions, compliance, and security. A first random number is generated for each authentication item, which are 12, 56, 57, 34, 78, 45, and 76, respectively. If the data query party A bank wants to query the customer's social security data, the first item selected by the data query party is access to social security, banking institutions, compliance, and security. The data query party submits corresponding authentication information. For example, the authentication information required to be submitted for access to social security includes the specific information of the customer to be accessed, the authentication information of the banking institution includes the institution name, address, contact information, and identity certificate, the compliance authentication information includes the business license and business license of the data query party, and the security authentication information includes the security assessment report of the data query party.

[0070] The query platform background verifies the validity of the authentication information. If the authentication is successful, based on the selection order of the first item, that is, based on the order of accessing social security, banking institutions, compliance and security, the corresponding first random numbers are entered, which are 56, 78, 45 and 76 respectively. This first random number sequence is defined as a first numerical sequence, and the first numerical sequence is converted into a first hash value based on a hash function. The first hash value is then encrypted and the encrypted first hash value is defined as the first random authentication information. The query platform will pre-store the second random authentication information in the database. The second random authentication information includes the hash value obtained by processing and encrypting the first random number sequence of the same combination type based on the hash function. If the two authentication relationship items are the same, it means that Bank A's identity authentication is successful.

[0071] By using random number sequences and hash functions, the randomness and complexity of identity authentication are increased, requiring detailed authentication information to be submitted in sequence, which helps to confirm the true identity of the inquiring party in a short period of time, reduces the risk of identity theft, and makes it more difficult for attackers to predict and forge authentication information.

[0072] Allocating access rights and search tokens to the government data interface to data query parties includes the following steps:

[0073] The query platform configures an interface identifier for each government data interface, obtains hidden data in each government data interface based on the interface identifier, generates a first key pair and a second key, the first key pair is a query function encryption key and a query function decryption key, the query platform assigns query rights to the government data based on the first key pair, encrypts the hidden data based on the query function encryption key and stores it in an encrypted database;

[0074] The second key is the query scope key. The query platform assigns query scope permissions to the data query party based on the query scope key, and generates a search token for the data query party. The search token has embedded query function decryption key and query scope key.

[0075] Specifically, the corresponding tenantId (interface identifier) ​​is configured according to different government data interfaces. This identifier is used to identify and access the data hidden in a specific government data interface. The query platform can generate a first key pair based on the national secret algorithm, including a query function encryption key and a query function decryption key. Based on the first key pair, the query platform assigns query permissions to the data query party, which means that only the data query party holding the correct key can access specific data. The query platform generates a second key, namely the query scope key, which is used to control the query scope permission of the data query party. The query platform generates a search token for the data query party, with embedded query function decryption key and query scope key. In this way, the data query party can query data within the authorized scope. Through the allocation of query permissions and query scope permissions, fine-grained access control to the data is achieved, and different users can access the corresponding data according to their roles and needs.

[0076] Submitting authorization information in the query platform based on the authorization code includes the following steps:

[0077] The query platform establishes a list of objects to be authorized. The data query party obtains the authorization letter corresponding to the object to be authorized from the list of objects to be authorized, converts the authorization letter into a data code, defines it as an authorization credential, and stores the authorization code and authorization credential as authorization information in the database.

[0078] Specifically, only data query parties authorized by customers can query the corresponding personal data. Therefore, data query parties need to provide authorization information of relevant users, and the authorization information includes authorization letters and authorization codes. The query platform is designed with an interface for querying objects to be authorized. Personal social security, provident fund, and real estate related data query parties can obtain authorization letters based on the list of objects to be authorized, convert the authorization letters into data codes, and use the authorization codes and data codes as authorization information, and submit them through the authorization information submission interface.

[0079] Generating a public key based on the local private key and the platform private key includes the following steps:

[0080] The data query party and the query platform randomly generate multiple second random numbers and third random numbers respectively, the data query party generates first shared data based on the local private key and the second random number, the query platform generates second shared data based on the platform private key and the third random number, the data query party and the query platform send the first shared data and the second shared data to each other, the data query party generates a first shared key based on the local private key, the second shared data and the second random number, the query platform generates a second shared key based on the platform private key, the first shared data and the third random number, the first shared key and the second shared key are converted into a second hash value and a third hash value based on a hash function, and it is determined whether the first hash value and the second hash value are the same. If so, the first shared key and the second shared key are the same and are defined as a public key.

[0081] Specifically, the data query party generates two second random numbers, assuming A1=23 and 18, and the query platform randomly generates two third random numbers, assuming A2=34 and 29. The data query party uses its own local private key 11 and one of the second random numbers, assuming 23, to generate the first shared data B1, assuming B1=11 23. The platform uses its own platform private key 14 and one of the third random numbers, assuming it is 34, to generate the second shared data B2. Assume B2=14 34. The data query party sends B1 to the query platform, and the query platform sends B2 to the data query party. After receiving B2, the data query party generates a first shared key C1=11 based on the local private key 11, the second shared data B2 and the second random number 23. 14 34 23, the platform generates a second shared key C2=14 based on the platform private key 11, the first shared data B1 and the third random number 34 11 twenty three 34. The second hash value and the third hash value obtained by processing C1 and C2 using the same hash function (such as SHA-256) are the same, so C1 and C2 are defined as public keys. The public key for each query is different, and the public key generated by each data querying party is also different.

[0082] Authorization verification of the data query party based on the authorization information includes the following steps:

[0083] The query platform verifies whether the authorization code in the authorization information is valid. If so, it checks whether the data access rights in the authorization letter corresponding to the authorization certificate in the authorization information match the data type and range requested by the data query party. If so, it means that the authorization verification of the data query party has passed.

[0084] Specifically, after receiving the authorization information submitted by the data query party, the query platform first checks whether the authorization code contained in the authorization information is valid. The authorization code is usually an identifier or key used to verify the authenticity of the authorization information. By confirming the authorization code, it is confirmed that the authorization information of the data query party is correctly issued by the authorized party. If the authorization code verification is successful, the query platform will next check the authorization certificate in the authorization information. The certificate is a credential associated with the authorization letter, which proves that the data query party has the right to access specific data. This step ensures that the data query party can only access the data for which it is authorized. For example, if the authorization letter clearly states that the query party can only access the social security information of a specific customer, then the query party's request to access the social security information of that customer will be allowed, while requests to access the information of other customers will not be allowed.

[0085] The authorization verification of the data query party includes the following steps:

[0086] The query platform extracts the query function decryption key and query range key from the search token, and determines whether the query function decryption key matches the query function encryption key used for the hidden data stored in the encrypted database. If so, the query function authority of the data query party is verified. It also determines whether the query range key is consistent with the key stored in the database. If so, the query range authority of the data query party is verified. If the query range authority and query function authority are verified, it means that the authority verification is passed.

[0087] Specifically, after the query platform completes the authorization verification, it also needs to verify the specific scope of authority. The query platform compares the extracted query function decryption key with the query function encryption key used for the hidden data stored in the encrypted database to determine whether they match. If they match, the data query party has the ability to correctly decrypt the data, that is, the authority of its query function is verified, and the extracted query range key is compared with the corresponding key stored in the database to determine whether they are consistent. This step verifies whether the data query party has the right to access the requested data range, that is, verifies the authority of its query range. For example, a bank can provide provident fund housing loan services to help eligible customers apply for loans, but if a customer uses provident funds for non-housing consumption, the bank usually cannot view the specific details of the related consumption.

[0088] The query platform obtains the query results based on the original query information, including the following steps:

[0089] The query platform performs data verification on the original query information, assembles the verified original query information into a government affairs interface JSON message, and initiates a government affairs data request to the government affairs end. The government affairs data includes personal social security, provident fund and real estate. The query platform sets a routing mapping table. The routing mapping table includes the mapping relationship between each government affairs service request and the URL path of the government affairs service interface. Based on the routing mapping table, the query platform distributes the government affairs interface JSON message to different servers of the government affairs end through the government affairs data interface. The government affairs end parses the government affairs interface JSON message, unifies the format, and desensitizes the data to obtain the query results, and returns the query results to the query platform.

[0090] Specifically, the query platform uses JSONObject.parseObject to assemble the original query information into a government interface JSON message, such as Figure 6 As shown in the figure, it is a routing mapping table. Based on the routing mapping table query platform, the apiAproxy forwarding service is used to distribute the request to different government service ends. The government end parses the government interface JSON message and unifies the format, such as Figure 7 As shown, the government end also uses a custom function to desensitize the message data and returns the encrypted data.

[0091] The present invention solves the problem of different service standards of government interface data related to social security, provident fund and real estate by establishing a query platform for personal social security, provident fund and real estate, and uniformly configuring interface parameters required by data query parties to obtain government data. The query platform sets identity authentication rules to authenticate data query parties, ensuring that only data query parties with successful identity authentication can access government data, and uniformly allocates user IDs, user keys, access rights and search tokens of government data interfaces to data query parties. The data query party obtains an identity token, constructs a request body including interface parameters and an authorization code, and submits authorization information in the query platform based on the authorization code.

[0092] The present invention obtains a public key based on a random number and a private key generated by the data query party and the query platform, and uses the public key to encrypt and decrypt data. Compared with traditional encryption and decryption methods, the complexity of the key is improved, and a higher level of security is provided. The present invention sets up a multi-level verification mechanism, including identity authentication, authorization information verification, and authority verification, which greatly guarantees the security of the data, ensuring that only data query parties with valid identities, customer authorization, and access rights can access government data, protecting personal privacy and sensitive information from unauthorized access and abuse. Finally, the present invention uses Java code to obtain the required query information, and assembles it into a query interface request JSON message, which is then verified and distributed to different government service ends, and then the returned message is parsed and encrypted in a unified format before being forwarded to the data query party, ensuring the security of the data during transmission.

[0093] like Figure 8 As shown, the present invention also provides a system for online query of social security data, which is used to implement the above method, and the system mainly includes:

[0094] The platform establishment module is used to establish a query platform for government data and configure the interface parameters required by the query platform for data query parties to obtain government data.

[0095] The identity authentication module is used by the query platform to authenticate the data query party. After the verification is passed, the data query party is assigned a user ID, user key, access rights to the government data interface, and a search token.

[0096] The request body generation module is used by the data query party to obtain an identity token based on the user ID and user key, construct a request body containing interface parameters and an authorization code, and submit authorization information in the query platform based on the authorization code.

[0097] The request body encryption module is used for the data query party and the query platform to generate a local private key and a platform private key respectively, and generate a public key based on the local private key and the platform private key. The data query party encrypts the request body based on the public key to obtain the first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request.

[0098] The request body decryption module is used to query the platform to verify whether the identity of the data query party is valid based on the identity token. If it is, the data query party is authorized to verify based on the authorization information. After the authorization verification is passed, the data query party is authorized to verify based on the search token. After the authorization verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information.

[0099] The query result acquisition module is used for the query platform to obtain the query result based on the original query information, encrypt the query result based on the public key, obtain the second encrypted data and return it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain the final query result.

[0100] The present invention also provides a computer storage medium, which stores program instructions. When the program instructions are executed, the device where the computer storage medium is located is controlled to execute the above method.

[0101] It should be understood that, although each step in the flow chart of each embodiment of the present invention is shown in sequence according to the indication of the arrow, these steps are not necessarily performed in sequence according to the order indicated by the arrow. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.

[0102] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the above-mentioned program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0103] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0104] The above embodiments only express several implementation methods of the present invention, and the description is relatively specific and detailed, but it cannot be understood as limiting the scope of the present invention. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention.

[0105] The above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for online query of social security data, characterized in that: The method comprises the following steps: S1: Establish a query platform for government data, and configure the query platform with interface parameters required by a data query party to obtain the government data; S2: The query platform authenticates the data query party and allocates a user ID, a user key, access rights to the government data interface, and a search token to the data query party after the authentication is passed; S3: The data querying party obtains an identity token based on the user ID and the user key, constructs a request body including the interface parameters and an authorization code, and submits authorization information in the query platform based on the authorization code; S4: The data query party and the query platform generate a local private key and a platform private key respectively, and generate a public key based on the local private key and the platform private key. The data query party encrypts the request body based on the public key to obtain first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request; S5: The query platform verifies whether the identity of the data query party is valid based on the identity token. If the identity is valid, the query platform performs authorization verification on the data query party based on the authorization information. After the authorization verification is passed, the query platform performs permission verification on the data query party based on the search token. After the permission verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information. S6: The query platform obtains a query result based on the original query information, encrypts the query result based on the public key, obtains second encrypted data and returns it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain a final query result.

2. The method according to claim 1, characterized in that The query platform authenticates the data query party by performing the following steps: The query platform sets multiple authentication items and generates a first random number for each of the authentication items. The data query party selects the required authentication item from all the authentication items and defines it as the first item. The data query party sends the authentication information of the first item to the query platform. The query platform authenticates the first item based on the authentication information. If the authentication is successful, based on the selection order of the first items, the data query party inputs the first random number corresponding to each of the first items in the query platform in turn. The input first random number sequence is defined as a first numerical sequence. The first numerical sequence is converted into a first hash value based on a hash function, and the first hash value is encrypted. The encrypted first hash value is defined as the first random authentication information. It is determined whether the first random authentication information is the same as the second random authentication information pre-stored in the database, wherein the second random authentication information refers to the hash value generated by encrypting the same first numerical sequence based on the hash function. If the two are the same, the identity authentication of the data query party is successful, otherwise the identity authentication fails.

3. The method according to claim 2, characterized in that Allocating access rights and search tokens to the government data interface for the data query party includes the following steps: The query platform configures an interface identifier for each of the government data interfaces, obtains hidden data in each of the government data interfaces based on the interface identifier, generates a first key pair and a second key, the first key pair is a query function encryption key and a query function decryption key, allocates query rights to the government data based on the first key pair, and encrypts the hidden data based on the query function encryption key and stores it in an encrypted database; The second key is a query scope key. The query platform allocates query scope permissions to the data query party based on the query scope key, and generates a search token for the data query party. The search token embeds the query function decryption key and the query scope key.

4. The method according to claim 1, characterized in that: Submitting authorization information in the query platform based on the authorization code includes the following steps: The query platform establishes a list of objects to be authorized, and the data query party obtains the authorization letter corresponding to the object to be authorized from the list of objects to be authorized, converts the authorization letter into a data code, defines it as an authorization certificate, and stores the authorization code and the authorization certificate as the authorization information in a database.

5. The method according to claim 1, characterized in that Generating a public key based on the local private key and the platform private key comprises the following steps: The data query party and the query platform randomly generate multiple second random numbers and third random numbers respectively, the data query party generates first shared data based on the local private key and the second random number, the query platform generates second shared data based on the platform private key and the third random number, the data query party and the query platform send the first shared data and the second shared data to each other, the data query party generates a first shared key based on the local private key, the second shared data and the second random number, the query platform generates a second shared key based on the platform private key, the first shared data and the third random number, the first shared key and the second shared key are converted into a second hash value and a third hash value based on a hash function, and it is determined whether the second hash value is the same as the third hash value. If so, the first shared key and the second shared key are the same and are defined as a public key.

6. The method according to claim 4, characterized in that Performing authorization verification on the data querying party based on the authorization information includes the following steps: The query platform verifies whether the authorization code in the authorization information is valid. If so, it checks whether the data access rights in the authorization letter corresponding to the authorization certificate in the authorization information match the data type and range requested by the data query party. If so, it indicates that the authorization verification of the data query party is passed.

7. The method according to claim 3, characterized in that The authorization verification of the data querying party includes the following steps: The query platform extracts the query function decryption key and the query range key from the search token, and determines whether the query function decryption key matches the query function encryption key used for the hidden data stored in the encrypted database. If so, the query function authority verification of the data query party is passed. It also determines whether the query range key is consistent with the key stored in the database. If so, the query range authority verification of the data query party is passed. If the query range authority and the query function authority verification are passed, it means that the authority verification is passed.

8. The method according to claim 1, characterized in that: The query platform obtains the query result based on the original query information, including the following steps: The query platform performs data verification on the original query information, assembles the verified original query information into a government affairs interface JSON message, and initiates a government affairs data request to the government affairs end. The government affairs data includes personal social security, provident fund and real estate. The query platform sets a routing mapping table, and the routing mapping table includes a mapping relationship between each government affairs data request and the URL path of the government affairs service interface. Based on the routing mapping table, the query platform distributes the government affairs interface JSON message to different servers of the government affairs end through the government affairs data interface. The government affairs end parses the government affairs interface JSON message, unifies the format, and performs data desensitization operations to obtain the query results, and returns the query results to the query platform.

9. A system for online query of social security data, used to implement the method according to any one of claims 1 to 8, characterized in that: The system includes the following modules: A platform establishment module is used to establish a query platform for government data and configure interface parameters required by a data query party to obtain the government data on the query platform; An identity authentication module, used for the query platform to authenticate the data query party, and after the authentication is passed, the data query party is assigned a user ID, a user key, and access rights and a search token for the government data interface; A request body generation module, used for the data query party to obtain an identity token based on the user ID and the user key, construct a request body containing the interface parameters and an authorization code, and submit authorization information in the query platform based on the authorization code; A request body encryption module, used for the data query party and the query platform to generate a local private key and a platform private key respectively, generate a public key based on the local private key and the platform private key, the data query party encrypts the request body based on the public key to obtain first encrypted data, and sends the first encrypted data and the identity token to the query platform, and initiates a query request; A request body decryption module is used for the query platform to verify whether the identity of the data query party is valid based on the identity token. If it is, the data query party is authorized based on the authorization information. After the authorization verification is passed, the data query party is authorized based on the search token. After the authorization verification is passed, the query platform decrypts the request body based on the public key to obtain the original query information; A query result acquisition module is used for the query platform to obtain query results based on the original query information, encrypt the query results based on the public key, obtain second encrypted data and return it to the data query party, and the data query party decrypts the encrypted second encrypted data based on the public key to obtain the final query result.

10. A computer storage medium, characterized in that: The computer storage medium stores program instructions, wherein when the program instructions are executed, the device where the computer storage medium is located is controlled to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Outsourcing project employee salary, social security and accumulation fund management system, and management method thereof

    CN111539800A

  • Key information query processing method and device and key information management system

    CN105553654A

  • Data sharing method, client, server, computing device and storage medium

    CN107979590A