Platform-based Parameter Transmission Method, System, Medium and Device

By generating key matrix encrypted data in the system platform and processing it in a secure storage area, the problems of low parameter transfer efficiency and insufficient security in terminal application systems are solved, and efficient, secure processing and cross-level sharing of data are achieved.

CN119577818BActive Publication Date: 2025-06-10深圳市亿晟科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510145337.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-06-10
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

In terminal application systems, due to the hierarchical structure, parameter transmission efficiency is low and security vulnerabilities exist, resulting in low security of system platform data.

Method used

By obtaining the eigenvectors and eigenvalues ​​of the system platform running data, the data is encrypted, and stored and processed in a secure storage area to ensure the security and availability of the data.

Benefits of technology

It improves the security and processing efficiency of the system platform data, ensures the timeliness and integrity of the data, and improves the overall performance and response speed of the system through cross-level data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119577818B_ABST
    Figure CN119577818B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data processing, and provides a platform-based parameter transmission method, system, computer-readable medium and electronic device. The platform-based parameter transmission method includes: obtaining operation data generated during the operation of the system platform, generating a key matrix according to the eigenvectors and eigenvalues corresponding to the operation data, and encrypting and storing the operation data of the system platform by dynamically generating the key matrix, ensuring the security of the data. At the framework layer or the program layer, the encrypted data is securely obtained and preprocessed through a data access interface, improving the availability and flexibility of the data. The operation layer can access the stored data based on a security mechanism and update the newly generated data in real time, ensuring the timeliness and integrity of the data. The bootloader then transmits the updated data through environment variables, realizing efficient cross-layer data sharing and enhancing the overall performance and response speed of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing. Specifically, it relates to a platform-based parameter transmission method, system, computer-readable medium, and electronic device. Background Art

[0002] In the application system of a terminal, due to the existence of the relationship of each hierarchical structure, it is particularly important to communicate between the upper and lower levels. And because there is an association between each level and they do not exist completely independently, usually, parameters need to be transmitted from bottom to top or from top to bottom. This way causes a problem that in the process of transmitting parameters, more transmission media need to be passed through, resulting in a low transmission efficiency.

[0003] At the same time, when multiple transmission media participate in data storage and invocation, different transmission media may use different protocols and technologies, and these protocols and technologies may have known security vulnerabilities. Attackers can use these vulnerabilities to steal or tamper with the data in transmission, which will also cause a problem of low security of the system platform data. Summary of the Invention

[0004] This application provides a platform-based parameter transmission method, system, computer-readable medium, and electronic device, which can at least to a certain extent solve the problem of low security of the system platform data.

[0005] Other features and advantages of this application will become obvious through the following detailed description, or be learned in part through the practice of this application.

[0006] According to one aspect of this application, a platform-based parameter transmission method is provided, including: obtaining the operation data generated during the operation of the system platform, generating a key matrix according to the eigenvector and eigenvalue corresponding to the operation data to encrypt the operation data to generate the first data, and storing the first data in the secure storage area of the system platform; in the framework layer or program layer of the system platform, obtaining the first data from the secure storage area by calling a data access interface, preprocessing the first data to generate the second data, and writing the second data into the secure storage area; in the operation layer of the system platform, obtaining the data in the secure storage area based on a secure access mechanism or the configuration information of the bootloader, and writing the newly generated third data during the operation of the system platform into the secure storage area; in the bootloader of the system platform, obtaining the updated data in the secure storage area based on a secure access mechanism, and transmitting the updated data to the operation layer in the form of environment variables, so that the data in the operation layer can be directly called in the framework layer or program layer.

[0007] In this application, based on the foregoing solution, for the operation data generated during the operation of the acquisition system platform, a key matrix is generated according to the eigenvector and eigenvalue corresponding to the operation data to encrypt the operation data to generate first data, including: acquiring the operation data generated during the operation of the acquisition system platform, and acquiring the attribute information corresponding to the operation data and the current status information of the system platform; extracting data features from the attribute information and the status information, generating an eigenvector and an eigenvalue according to the data matrix corresponding to the data features, and generating a key matrix according to the eigenvector and the eigenvalue; encrypting the operation data based on the key matrix to generate the first data.

[0008] In this application, based on the foregoing solution, the extracting data features from the attribute information and the status information, and generating an eigenvector and an eigenvalue according to the data matrix corresponding to the data features includes: based on the attribute information and the status information, extracting the data features therein, and constructing a data matrix according to the data features; calculating matrix parameters based on the data matrix and the mean vector of the data features as:

[0009]

[0010] wherein, n is the number of data features, X is the data matrix, μ is the mean vector of each data feature, σ is the standard deviation vector of each data feature, represents the transpose operation of the matrix; generating a solution formula for the eigenvalue and the eigenvector based on the matrix parameters: ; wherein, v is the eigenvector, λ is the corresponding eigenvalue; determining the eigenvector corresponding to the attribute information and the status information according to the solution formula.

[0011] In this application, based on the foregoing solution, the generating a key matrix according to the eigenvector and the eigenvalue includes: preprocessing the eigenvalue to generate a standard eigenvalue, and generating a diagonal matrix based on the standard eigenvalue; encoding the eigenvector to generate an encoded vector, and generating an encoded matrix based on the encoded vector; generating the key matrix according to the diagonal matrix and the encoded matrix.

[0012] In this application, based on the foregoing solution, it further includes: in the framework layer or the program layer of the system platform, acquiring the latest generated fourth data during the operation; encrypting the fourth data to generate encrypted data, and storing the encrypted data in the secure storage area for other levels of the system platform to call.

[0013] In this application, based on the foregoing solution, the preprocessing of the first data to generate the second data includes: obtaining configuration information corresponding to the current display scenario; decrypting the first data to generate decrypted data; matching the configuration information with the decrypted data, determining unmatched data from the decrypted data, and deleting the unmatched data.

[0014] In this application, based on the foregoing solution, it further includes: detecting user operation information at the operation layer of the system platform; generating operation data according to the operation information, and encrypting and storing the operation data.

[0015] According to one aspect of this application, a platform-based parameter transmission system is provided, including:

[0016] An encryption unit, configured to obtain operation data generated during the operation of the system platform, generate a key matrix according to the eigenvector and eigenvalue corresponding to the operation data, encrypt the operation data to generate first data, and store the first data in the secure storage area of the system platform;

[0017] A program unit, configured to obtain the first data from the secure storage area by calling a data access interface at the framework layer or program layer of the system platform, preprocess the first data to generate second data, and write the second data into the secure storage area;

[0018] An operation unit, configured to obtain data in the secure storage area based on the secure access mechanism or the configuration information of the bootloader at the operation layer of the system platform, and write the newly generated third data during the operation of the system platform into the secure storage area;

[0019] An update unit, configured to obtain update data in the secure storage area based on the secure access mechanism in the bootloader of the system platform, and transmit the update data to the operation layer in the form of an environment variable, so that the data in the operation layer can be directly called at the framework layer or program layer.

[0020] According to one aspect of this application, a computer-readable medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, it implements the platform-based parameter transmission method as described in the above embodiments.

[0021] According to one aspect of this application, an electronic device is provided, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the platform-based parameter transmission method as described in the above embodiments.

[0022] According to one aspect of the present application, there is provided a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the platform-based parameter transmission method provided in the above various optional implementation manners.

[0023] In the technical solution of the present application, operation data generated during the operation of the system platform is obtained, a key matrix is generated according to the eigenvectors and eigenvalues corresponding to the operation data to encrypt the operation data to generate first data, and the first data is stored in the secure storage area of the system platform; in the framework layer or program layer of the system platform, the first data is obtained from the secure storage area by calling a data access interface, preprocessed to generate second data, and the second data is written into the secure storage area; in the operation layer of the system platform, the data in the secure storage area is obtained based on a secure access mechanism or the configuration information of the bootloader, and the third data newly generated during the operation of the system platform is written into the secure storage area; in the bootloader of the system platform, the updated data in the secure storage area is obtained based on a secure access mechanism, and the updated data is transmitted to the operation layer in the form of an environment variable, so that the data in the operation layer can be directly called in the framework layer or program layer. The above process encrypts and stores the operation data of the system platform by dynamically generating a key matrix, ensuring the security of the data. In the framework layer or program layer, the encrypted data is securely obtained and preprocessed through a data access interface, improving the availability and flexibility of the data. The operation layer can access the stored data based on a security mechanism and update the newly generated data in real time, ensuring the timeliness and integrity of the data. The bootloader transmits the updated data through an environment variable, realizing efficient cross-layer data sharing and enhancing the overall performance and response speed of the system. These series of technical operations together improve the data processing efficiency and security of the system platform.

[0024] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. Brief Description of the Drawings

[0025] The drawings here are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0026] Figure 1 Schematically shows a flowchart of a platform-based parameter transmission method in an embodiment of the present application.

[0027] Figure 2 Schematically shows a flowchart of data encryption in an embodiment of the present application.

[0028] Figure 3 Schematically shows a schematic diagram of a platform-based parameter transmission system in an embodiment of the present application.

[0029] Figure 4 Shows a schematic diagram of the structure of a computer system of an electronic device suitable for implementing the embodiments of the present application. Detailed implementation manners

[0030] Now, example embodiments will be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.

[0031] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, systems, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0032] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0033] The flowcharts shown in the drawings are only exemplary illustrations and do not necessarily include all the content and operations / steps, nor do they necessarily need to be executed in the described order. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.

[0034] The implementation details of the technical solutions of the present application are elaborated in detail as follows:

[0035] Figure 1The flowchart of a platform-based parameter transmission method according to an embodiment of the present application is shown. Refer to Figure 1 As shown, the platform-based parameter transmission method at least includes steps S110 to S140, which are introduced in detail as follows:

[0036] In step S110, obtain the operation data generated during the operation of the system platform, generate a key matrix according to the eigenvector and eigenvalue corresponding to the operation data, encrypt the operation data to generate the first data, and store the first data in the secure storage area of the system platform.

[0037] In this embodiment, the system platform includes a framework layer, a program layer, and an operation layer. Among them, the framework layer is the core part of the system platform, which provides a stable foundation for developers to build and run application programs on this basis. The program layer is a collection of various application programs running on the system platform. These application programs can be system-built or downloaded by users from third-party channels. The operation layer is the layer in the system platform responsible for executing and managing the operation of application programs. It provides the necessary runtime environment and support libraries to ensure the smooth operation of application programs.

[0038] In this embodiment, during the operation of the system platform, operation data is collected and obtained, and according to the specific eigenvectors and corresponding eigenvalues of these operation data, a key matrix is constructed for encryption, effectively ensuring the confidentiality of the data. This dynamically generated key matrix increases the difficulty of data cracking and improves the security of the system.

[0039] As Figure 2 shown, in an embodiment of the present application, obtaining the operation data generated during the operation of the system platform, generating a key matrix according to the eigenvector and eigenvalue corresponding to the operation data, and encrypting the operation data to generate the first data includes:

[0040] S210, obtain the operation data generated during the operation of the system platform, and obtain the attribute information corresponding to the operation data and the current status information of the system platform;

[0041] S220, extract data features from the attribute information and the status information, generate an eigenvector and an eigenvalue according to the data matrix corresponding to the data features, and generate a key matrix according to the eigenvector and the eigenvalue;

[0042] S230, encrypt the operation data based on the key matrix to generate the first data.

[0043] In an embodiment of the present application, the operation data is information that is generated in real time or collected regularly during the operation of the system platform, including user behavior data, system performance metrics, or transaction records, etc. The attribute information describes the characteristics or metadata of the operation data, such as the type, format, source, and timestamp of the data, etc. The status information reflects the current working state of the system platform, which may include memory usage, processor load, and network connection status, etc.

[0044] In an embodiment of the present application, in step S220, extracting data features from the attribute information and the status information, and generating eigenvectors and eigenvalues according to the data matrix corresponding to the data features includes:

[0045] Based on the attribute information and the status information, extract the data features therein, and construct a data matrix according to the data features; specifically, based on the attribute information and the status information, extract the key data features from these two types of information, and these data features can reflect the essential attributes and current status of the data. Subsequently, using the extracted data features, construct a data matrix according to a preset logical structure. The rows of this data matrix represent different samples or observation points, while the columns correspond to various features extracted from the attribute information and the status information. In this way, the data matrix is not only convenient for data analysis and processing, but also can effectively capture and utilize the key elements in the original information.

[0046] Based on the data matrix corresponding to the data features X , calculate the matrix parameters as:

[0047]

[0048] wherein, n is the number of data features, X is the data matrix, μ is the mean vector corresponding to each data feature, σ is the standard deviation vector corresponding to each data feature, represents the transpose operation of the matrix;

[0049] Generate the solution formulas for eigenvalues and eigenvectors based on the matrix parameters: ;

[0050] wherein, v is the eigenvector, λ is the corresponding eigenvalue.

[0051] Based on the solution formulas for eigenvalues and eigenvectors generated from the matrix parameters, determine the eigenvectors corresponding to the attribute information and the status information. For example, a numerical linear algebra library can be used to solve for eigenvalues and eigenvectors.

[0052] Extract data features from the attribute information and status information of the running data, and construct a data matrix based on the data features to generate eigenvectors and eigenvalues, providing a solid foundation for the generation of the key matrix. This method ensures the diversity and complexity of the keys and enhances the encryption effect.

[0053] In an embodiment of the present application, generating the key matrix according to the eigenvectors and eigenvalues in step S220 includes:

[0054] Preprocess the eigenvalues to generate standard eigenvalues, and generate a diagonal matrix based on the standard eigenvalues;

[0055] Encode the eigenvectors to generate encoded vectors, and generate an encoding matrix based on the encoded vectors;

[0056] Generate the key matrix according to the diagonal matrix and the encoding matrix.

[0057] Specifically, preprocess the eigenvalues to generate corresponding standard eigenvalues as:

[0058]

[0059] where is the i th eigenvalue, m is the total number of eigenvalues, k represents the order of the eigenvalues, β is a weighting parameter for controlling the degree of non-linearity.

[0060] After that, arrange all the standard eigenvalues diagonally in sequence to generate the diagonal matrix W .

[0061] Encode the eigenvectors to generate encoded vectors as:

[0062]

[0063] where is a preset encoding factor, is the i th component of the j th eigenvector, N is the number of quantization levels of the encoding.

[0064] After that, arrange the encoded vectors in sequence to generate the encoding matrix V .

[0065] After that, generate the key matrix according to the diagonal matrix and the encoding matrix as:

[0066]

[0067] After generating the key matrix, the key matrix is used to encrypt the running data. Specifically, the running data is generated into a data matrix compatible with the key matrix according to a preset format. Then, the elements in the key matrix are combined with the elements in the data matrix through matrix multiplication to generate the encrypted first data. In addition to the above encryption method, other more complex encryption methods can also be used to further improve the complexity and security of encryption.

[0068] In this process, the eigenvalues and eigenvectors are preprocessed and encoded, further enhancing the security and reliability of the key matrix. The complexity and non-linear characteristics of the key matrix make the encrypted data difficult to be parsed or tampered with by unauthorized personnel, thereby improving the security of the running data.

[0069] The above process obtains the running data of the system platform and generates a key matrix based on the eigenvectors and eigenvalues of the data to encrypt the running data. This method ensures the confidentiality of the data because even if the data is intercepted, it cannot be decrypted without the key matrix. The encrypted data is stored in a secure storage area, which may adopt physical or logical isolation measures to prevent unauthorized access.

[0070] In step S120, in the framework layer or program layer of the system platform, the first data is obtained from the secure storage area by calling the data access interface, the first data is preprocessed to generate the second data, and the second data is written into the secure storage area.

[0071] In this embodiment, in the framework layer or program layer of the system platform, by calling a dedicated data access interface, the previously encrypted and stored first data can be securely obtained from the secure storage area. Subsequently, these data are subjected to necessary preprocessing (such as decryption and data cleaning) to generate the second data, and finally the processed second data is securely written back to the secure storage area of the system platform.

[0072] In an embodiment of the present application, preprocessing the first data to generate the second data includes:

[0073] Obtain the configuration information corresponding to the current display scenario;

[0074] Decrypt the first data to generate decrypted data;

[0075] Match the configuration information with the decrypted data, determine the unmatched data from the decrypted data, and delete the unmatched data.

[0076] In one embodiment of the present application, the current display scenario is identified by analyzing information such as user behavior, system status, and timestamp. According to the identified scenario, the corresponding configuration information is retrieved from the configuration database or configuration file. The configuration information includes parameters, settings, rules, etc. required for the scenario to ensure the correct presentation of the display scenario.

[0077] According to the algorithm and mode used during encryption, the corresponding decryption algorithm is selected. Ensure that the decryption algorithm is compatible with the encryption algorithm and can correctly restore the encrypted data. Decrypt the first data to generate decrypted data.

[0078] Perform a matching operation between the decrypted data and the configuration information to check whether the decrypted data meets the requirements of the configuration information, and identify the data that does not match the configuration information. These unmatched data include incorrect, outdated, irrelevant information, etc. Process the identified unmatched data, such as deleting the unmatched data, recording logs, triggering warnings, etc.

[0079] The above process is carried out at the framework layer or program layer. Encrypted data is obtained from the secure storage area by calling the data access interface and preprocessed (such as decryption, screening, etc.) to generate the second data. This multi-level data processing mechanism improves the availability and accuracy of the data.

[0080] In one embodiment of the present application, it further includes:

[0081] At the framework layer or program layer of the system platform, obtain the latest generated fourth data during operation;

[0082] Encrypt the fourth data to generate encrypted data, and store the encrypted data in the secure storage area for other levels of the system platform to call.

[0083] In one embodiment of the present application, at the framework layer or program layer of the system platform, a real-time monitoring mechanism is deployed to capture the latest generated fourth data during operation. This usually involves means such as log analysis, event listening, interface calls, etc.

[0084] Optionally, the captured fourth data can be preprocessed, including steps such as data cleaning, format conversion, and anomaly detection. Ensure that the data quality meets the requirements for subsequent encryption and storage.

[0085] According to the sensitivity and importance of the data, use the selected encryption algorithm and key to encrypt the preprocessed fourth data to generate encrypted data, and retain the necessary metadata (such as encryption algorithm identifier or key version, etc.) for subsequent decryption.

[0086] Configure a dedicated secure storage area in the system platform to store encrypted data. Ensure that the storage area has sufficient physical and logical security to prevent data leakage or tampering. Design a unified data access interface between different levels of the system platform to enable cross-level invocation of encrypted data. These interfaces should provide functions such as data retrieval, decryption, and verification.

[0087] When other levels need to access encrypted data, request the decryption service through the data access interface. The decryption process should use the same algorithm and key as when encrypting, and verify the integrity and authenticity of the data. The decrypted data can be used in other levels of the system platform to support functions such as business logic processing, decision support, and report generation. At the same time, the data in the storage area should be updated and cleared regularly to maintain the timeliness and accuracy of the data.

[0088] In step S130, at the operation layer of the system platform, obtain the data in the secure storage area based on the configuration information of the secure access mechanism or the bootloader, and write the third data newly generated during the operation of the system platform into the secure storage area.

[0089] In this embodiment, according to the preset secure access mechanism (such as permission verification, encryption and decryption policies, etc.) or the configuration information in the bootloader (such as storage path, access permission settings, etc.), obtain the data stored in the secure storage area. These data may be the first data or the second data encrypted and stored previously, or other important system configuration information or user data. At the same time, during the operation of the system platform, new data will be continuously generated, which is called the third data. These data may be system logs, temporary files, user operation records, etc. To ensure the security and integrity of these newly generated data, the system will process them according to the established security policies (such as encryption, compression, verification, etc.) and write them securely into the aforementioned secure storage area. In this way, whether the system restarts or data is migrated, these key data can be properly saved and managed to ensure the stable operation of the system platform and the security and reliability of the data.

[0090] In an embodiment of the present application, it further includes: detecting the operation information of the user at the operation layer of the system platform; generating operation data according to the operation information, and encrypting and storing the operation data.

[0091] In an embodiment of the present application, at the operation layer of the system platform, deploy a module dedicated to monitoring user operations. This module captures and records all operation behaviors of the user on the interface in real time, including but not limited to clicks, inputs, selections, etc. The operation information is recorded in detail, including the operation time, operation type, operation object, and relevant context information.

[0092] Based on the preprocessed operation information, combined with the business logic and rules of the system platform, corresponding running data is generated. The running data may include user behavior logs, system status change records, business processing results, etc. The preprocessed, generated, and possibly encrypted running data is written into the secure storage area of the system platform.

[0093] In the above process, the running layer can obtain data based on the security access mechanism or the configuration information of the bootloader, and write the newly generated third data into the secure storage area, realizing real-time update and persistent storage of the data.

[0094] In step S140, in the bootloader of the system platform, based on the security access mechanism, the updated data in the secure storage area is obtained, and the updated data is transmitted to the running layer in the form of environment variables, so that the data in the running layer can be directly called in the framework layer or the program layer.

[0095] In this embodiment, in the startup process of the system platform, the bootloader plays a crucial role. At this stage, based on a strict security access mechanism, the bootloader will first access the secure storage area, which is specifically used to store key system update data. This data may include system configuration updates, security patches, or other important update information.

[0096] After obtaining this updated data, the bootloader does not directly load it into the framework layer or the program layer, but passes this data to the running layer in the form of secure and efficient environment variables. Environment variables act as a bridge here, allowing the running layer to be aware of the existence of this updated data during initialization and make corresponding configurations and preparations accordingly.

[0097] Subsequently, when the framework layer or the program layer starts running, it can directly obtain and use this updated data by accessing these environment variables that have been prepared by the running layer. This method not only improves the data access efficiency, but more importantly, it ensures that the flow of data throughout the system platform is secure and controllable, thus effectively reducing the risk of data leakage or tampering.

[0098] The bootloader passes the updated data to the running layer through environment variables, enabling the framework layer or the program layer to directly call the data in the running layer. This mechanism simplifies the data access process, improves the system's response speed and efficiency. At the same time, it also supports cross-layer data sharing and interaction, enhancing the flexibility and scalability of the system.

[0099] In the technical solution of this application, operation data generated during the operation of the system platform is obtained, and a key matrix is generated according to the eigenvectors and eigenvalues corresponding to the operation data to encrypt the operation data to generate first data, and the first data is stored in the secure storage area of the system platform; in the framework layer or program layer of the system platform, the first data is obtained from the secure storage area by calling a data access interface, preprocessed to generate second data, and the second data is written into the secure storage area; in the operation layer of the system platform, data in the secure storage area is obtained based on a secure access mechanism or configuration information of the bootloader, and third data newly generated during the operation of the system platform is written into the secure storage area; in the bootloader of the system platform, updated data in the secure storage area is obtained based on a secure access mechanism, and the updated data is transmitted to the operation layer in the form of environment variables, so that data in the operation layer can be directly called in the framework layer or program layer. The above process encrypts and stores the operation data of the system platform by dynamically generating a key matrix, ensuring the security of the data. In the framework layer or program layer, encrypted data is securely obtained and preprocessed through a data access interface, improving the availability and flexibility of the data. The operation layer can access stored data based on a security mechanism and update newly generated data in real time, ensuring the timeliness and integrity of the data. The bootloader transmits updated data through environment variables, realizing efficient cross-layer data sharing and enhancing the overall performance and response speed of the system. These series of technical operations together improve the data processing efficiency and security of the system platform.

[0100] The following introduces the device embodiments of this application, which can be used to execute the platform-based parameter transmission method in the above embodiments of this application. It can be understood that the device can be a computer program (including program code) running in a computer device, for example, the device is an application software; the device can be used to execute the corresponding steps in the method provided in the embodiments of this application. For details not disclosed in the device embodiments of this application, please refer to the embodiments of the platform-based parameter transmission method above in this application.

[0101] Figure 3 The block diagram of a platform-based parameter transmission system according to an embodiment of this application is shown.

[0102] Refer to Figure 3 As shown, a platform-based parameter transmission system according to an embodiment of this application includes:

[0103] An encryption unit 310, configured to obtain operation data generated during the operation of the system platform, generate a key matrix according to the eigenvector and eigenvalue corresponding to the operation data, encrypt the operation data to generate first data, and store the first data in a secure storage area of the system platform;

[0104] A program unit 320, configured to obtain the first data from the secure storage area by calling a data access interface in the framework layer or program layer of the system platform, preprocess the first data to generate second data, and write the second data into the secure storage area;

[0105] An operation unit 330, configured to obtain data in the secure storage area based on a secure access mechanism or configuration information of a bootloader in the operation layer of the system platform, and write third data newly generated during the operation of the system platform into the secure storage area;

[0106] An update unit 340, configured to obtain update data in the secure storage area based on a secure access mechanism in the bootloader of the system platform, transmit the update data to the operation layer in the form of an environment variable, so that data in the operation layer can be directly called in the framework layer or program layer.

[0107] In this application, based on the foregoing solution, the obtaining operation data generated during the operation of the system platform, generating a key matrix according to the eigenvector and eigenvalue corresponding to the operation data, and encrypting the operation data to generate first data includes: obtaining operation data generated during the operation of the system platform, and obtaining attribute information corresponding to the operation data and current status information of the system platform; extracting data features from the attribute information and the status information, generating an eigenvector and an eigenvalue according to a data matrix corresponding to the data features, and generating a key matrix according to the eigenvector and the eigenvalue; encrypting the operation data based on the key matrix to generate the first data.

[0108] In this application, based on the foregoing solution, the extracting data features from the attribute information and the status information, and generating an eigenvector and an eigenvalue according to a data matrix corresponding to the data features includes: based on the attribute information and the status information, extracting data features therein, and constructing a data matrix according to the data features; calculating matrix parameters as:

[0109]

[0110] wherein, n is the number of data features, X is the data matrix,μ is the mean vector of each data feature, σ is the standard deviation vector of each data feature, represents the transpose operation of a matrix; generating a solution formula for eigenvalues and eigenvectors based on the matrix parameters: ; where, v is the eigenvector, λ is the corresponding eigenvalue; determining the eigenvectors corresponding to the attribute information and the status information according to the solution formula.

[0111] In the present application, based on the foregoing solution, generating the key matrix according to the eigenvector and the eigenvalue includes: preprocessing the eigenvalue to generate a standard eigenvalue, and generating a diagonal matrix based on the standard eigenvalue; encoding the eigenvector to generate an encoded vector, and generating an encoded matrix based on the encoded vector; generating the key matrix according to the diagonal matrix and the encoded matrix.

[0112] In the present application, based on the foregoing solution, it further includes: obtaining the latest generated fourth data during operation in the framework layer or the program layer of the system platform; encrypting the fourth data to generate encrypted data, and storing the encrypted data in the secure storage area for other levels of the system platform to call.

[0113] In the present application, based on the foregoing solution, preprocessing the first data to generate the second data includes: obtaining the configuration information corresponding to the current display scene; decrypting the first data to generate decrypted data; matching the configuration information with the decrypted data, determining the unmatched data from the decrypted data, and deleting the unmatched data.

[0114] In the present application, based on the foregoing solution, it further includes: detecting the operation information of the user in the operation layer of the system platform; generating operation data according to the operation information, and encrypting and storing the operation data.

[0115] In the technical solution of this application, operation data generated during the operation of the system platform is obtained, and a key matrix is generated according to the eigenvectors and eigenvalues corresponding to the operation data to encrypt the operation data to generate first data, and the first data is stored in the secure storage area of the system platform; in the framework layer or program layer of the system platform, the first data is obtained from the secure storage area by calling a data access interface, preprocessed to generate second data, and the second data is written into the secure storage area; in the operation layer of the system platform, data in the secure storage area is obtained based on a secure access mechanism or configuration information of the boot program, and third data newly generated during the operation of the system platform is written into the secure storage area; in the boot program of the system platform, updated data in the secure storage area is obtained based on a secure access mechanism, and the updated data is transmitted to the operation layer in the form of an environment variable, so that data in the operation layer can be directly called in the framework layer or program layer. The above process encrypts and stores the operation data of the system platform by dynamically generating a key matrix, ensuring the security of the data. In the framework layer or program layer, encrypted data is securely obtained and preprocessed through a data access interface, improving the availability and flexibility of the data. The operation layer can access stored data based on a security mechanism and update newly generated data in real time, ensuring the timeliness and integrity of the data. The boot program transmits updated data through environment variables, realizing efficient cross-layer data sharing and enhancing the overall performance and response speed of the system. These series of technical operations together improve the data processing efficiency and security of the system platform.

[0116] Figure 4 FIG. shows a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application.

[0117] It should be noted that the computer system of the electronic device in this embodiment is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.

[0118] The computer system in this embodiment includes a central processing unit 401, which can perform various appropriate actions and processes according to the program stored in the read-only memory 402 or the program loaded from the storage section 408 into the random access memory 403, such as executing the platform-based parameter transmission method described in the above embodiment. In the random access memory 403, various programs and data required for system operation are also stored. The central processing unit 401, the read-only memory 402, and the random access memory 403 are connected to each other through a bus 404. The input / output interface 405 is also connected to the bus 404.

[0119] The following components are connected to the input / output interface 405: an input section 406 including a keyboard, a mouse, etc.; an output section 407 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the input / output interface 405 as required. A removable medium 411, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 410 as required so that a computer program read from it can be installed into the storage section 408 as required.

[0120] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 409, and / or installed from the removable medium 411. When the computer program is executed by the central processing unit 401, various functions defined in the system of the present application are executed.

[0121] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0123] The units involved in the embodiments of the present application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.

[0124] According to one aspect of the present application, there is provided a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above various alternative implementation manners.

[0125] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the one or more programs are executed by an electronic device, the electronic device implements the parameter transmission method based on the platform described in the above embodiments.

[0126] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0127] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented in software or in the form of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of the present application.

[0128] After considering the specification and practicing the disclosed embodiments herein, those skilled in the art will readily conceive of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application.

[0129] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A platform-based parameter transmission method, characterized in that: include: Acquire operation data generated by the system platform during operation, generate a key matrix according to the eigenvectors and eigenvalues ​​corresponding to the operation data, encrypt the operation data to generate first data, and store the first data in a secure storage area of ​​the system platform; At the framework layer or program layer of the system platform, the first data is acquired from the secure storage area by calling a data access interface, the first data is preprocessed to generate second data, and the second data is written into the secure storage area; At the operation layer of the system platform, based on the security access mechanism or the configuration information of the boot program, the data in the secure storage area is obtained, and the third data newly generated when the system platform is running is written into the secure storage area; In the boot program of the system platform, the update data in the secure storage area is obtained based on the security access mechanism, and the update data is transmitted to the operation layer in the form of environment variables, so that the data in the operation layer can be directly called at the framework layer or the program layer; The method of obtaining operation data generated by the system platform during operation and generating a key matrix according to the characteristic vectors and characteristic values ​​corresponding to the operation data to encrypt the operation data and generate the first data includes: Acquire operation data generated by the system platform during operation, and acquire attribute information corresponding to the operation data and current status information of the system platform; Extracting data features from the attribute information and the state information, generating feature vectors and feature values ​​according to a data matrix corresponding to the data features, and generating a key matrix according to the feature vectors and feature values; Encrypting the operation data based on the key matrix to generate the first data; The step of extracting data features from the attribute information and the state information and generating feature vectors and feature values ​​according to a data matrix corresponding to the data features includes: Based on the attribute information and state information, the data features are extracted and a data matrix is ​​constructed according to the data features; Based on the data matrix and the mean vector of the data features, the matrix parameters are calculated for: in, n is the number of data features, X is the data matrix, μ is the mean vector of each data feature, σ is the standard deviation vector of each data feature, Represents the transpose operation of a matrix; The solution formula for generating eigenvalues ​​and eigenvectors based on the matrix parameters is: ; in, v is the eigenvector, λ is the corresponding eigenvalue; Determine the characteristic vectors corresponding to the attribute information and the state information according to the solution formula.

2. The platform-based parameter transmission method according to claim 1, characterized in that: Generating a key matrix according to the eigenvector and the eigenvalue includes: Preprocessing the eigenvalues ​​to generate standard eigenvalues, and generating a diagonal matrix based on the standard eigenvalues; Encoding the feature vector to generate a coding vector, and generating a coding matrix based on the coding vector; The key matrix is ​​generated according to the diagonal matrix and the encoding matrix.

3. The platform-based parameter transmission method according to claim 1, characterized in that: Also includes: At the framework layer or program layer of the system platform, acquiring the fourth data most recently generated during the operation; The fourth data is encrypted to generate encrypted data, and the encrypted data is stored in the secure storage area for use in other layers of the system platform.

4. The platform-based parameter transmission method according to claim 1, characterized in that: Preprocessing the first data to generate second data includes: Get the configuration information corresponding to the current display scene; decrypting the first data to generate decrypted data; The configuration information is matched with the decrypted data, unmatched data is determined from the decrypted data, and the unmatched data is deleted.

5. The platform-based parameter transmission method according to claim 1, characterized in that: Also includes: At the operation layer of the system platform, detecting the user's operation information; According to the operation information, operation data is generated, and the operation data is encrypted and stored.

6. A platform-based parameter transmission system, characterized in that: include: an encryption unit, used for acquiring operation data generated by the system platform during operation, generating a key matrix according to the eigenvectors and eigenvalues ​​corresponding to the operation data, encrypting the operation data to generate first data, and storing the first data in a secure storage area of ​​the system platform; A program unit, configured to obtain the first data from the secure storage area by calling a data access interface at a framework layer or a program layer of the system platform, preprocess the first data to generate second data, and write the second data into the secure storage area; An operation unit, configured to obtain data in the secure storage area based on a security access mechanism or configuration information of a boot program at an operation layer of the system platform, and write third data newly generated when the system platform is running into the secure storage area; An updating unit, configured to obtain update data in the secure storage area based on a secure access mechanism in a boot program of the system platform, and transmit the update data to the running layer in the form of environment variables, so that the framework layer or the program layer can directly call the data in the running layer; The method of obtaining operation data generated by the system platform during operation and generating a key matrix according to the characteristic vectors and characteristic values ​​corresponding to the operation data to encrypt the operation data and generate the first data includes: Acquire operation data generated by the system platform during operation, and acquire attribute information corresponding to the operation data and current status information of the system platform; Extracting data features from the attribute information and the state information, generating feature vectors and feature values ​​according to a data matrix corresponding to the data features, and generating a key matrix according to the feature vectors and feature values; Encrypting the operation data based on the key matrix to generate the first data; The step of extracting data features from the attribute information and the state information and generating feature vectors and feature values ​​according to a data matrix corresponding to the data features includes: Based on the attribute information and state information, the data features are extracted and a data matrix is ​​constructed according to the data features; Based on the data matrix and the mean vector of the data features, the matrix parameters are calculated for: in, n is the number of data features, X is the data matrix, μ is the mean vector of each data feature, σ is the standard deviation vector of each data feature, Represents the transpose operation of a matrix; The solution formula for generating eigenvalues ​​and eigenvectors based on the matrix parameters is: ; in, v is the eigenvector, λ is the corresponding eigenvalue; Determine the characteristic vectors corresponding to the attribute information and the state information according to the solution formula.

7. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the platform-based parameter transmission method according to any one of claims 1 to 5 is implemented.

8. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the platform-based parameter transmission method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Block chain-based pension guarantee data transmission method and device, equipment and medium

    CN115758423A

  • Database platform for maintaining secure data

    US20190207769A1