A security protection method based on financial service data
By splitting financial service data into multiple segments and encrypting with different keys in distributed domain node clusters, the problems of encryption protocol limitations, weak identity authentication and insufficient adaptability in dynamic environments in financial data storage are solved, and the security of data is significantly improved.
Patent Information
- Application Number
- CN202510323080.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-03-19
AI Technical Summary
The prior art has problems such as limitations of encryption protocols, weak identity authentication and insufficient adaptability to dynamic environments in financial data storage. Especially when faced with complex scenarios such as quantum computing and mobile terminals, it is difficult to effectively ensure the security of financial data.
By dividing the financial service data into M-segment financial service sub-data, and encrypting each piece of data using the keys of different domain nodes in a distributed domain node cluster, and storing it on the corresponding domain nodes, thereby improving the security of the data.
This method can effectively improve the security of financial data storage. Even if an attacker steals the ciphertext data of a certain domain node, it cannot decrypt the data because the keys of other domain nodes are lacking, thereby enhancing the data protection capabilities.
Smart Images

Figure CN119830332B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular, to a security protection method based on financial service data. Background Art
[0002] With the rapid development of fintech, services such as electronic payment, cross-border transactions, and digital assets have shown exponential growth. As a core link, financial data transmission involves highly sensitive content such as user account information, transaction instructions, and risk assessment data. Existing technologies mainly ensure security through means such as SSL / TLS encrypted transmission, VPN channel isolation, and static key authentication. However, there are still significant defects in actual applications: limitations of encryption protocols: traditional SSL / TLS protocols have known vulnerabilities (such as POODLE and BEAST attacks), and the development of quantum computing poses a risk of RSA and other asymmetric encryption algorithms being cracked. Weakness of identity authentication: Authentication methods based on fixed keys or one-way biometrics are vulnerable to man-in-the-middle attacks (MITM) and replay attacks. Insufficient adaptability to dynamic environments: The popularity of mobile devices and Internet of Things devices has complicated data transmission scenarios.
[0003] Therefore, how to further improve the security of financial data storage is a current research issue. Summary of the Invention
[0004] An embodiment of this application provides a security protection method based on financial service data to improve the security of financial data storage.
[0005] To achieve the above objective, this application adopts the following technical solutions:
[0006] In a first aspect, an embodiment of this application provides a security protection method based on financial service data. The method is applied to a management device, and the management device is used to manage a distributed domain node cluster. The method includes: The management device obtains financial service data requested by a user for storage; the management device divides the financial service data into M segments of financial service sub-data, and determines M domain nodes in the domain node cluster that can store the financial service data, where M is an integer greater than 2; the management device encrypts the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data. When i traverses integers from 1 to M, a total of M ciphertext data are obtained, and thus the M ciphertext data are correspondingly stored in the i-th domain node among the M domain nodes. Among them, the key used when the i-th segment of financial service sub-data is encrypted is the key of other domain nodes, and the other domain nodes are the domain nodes other than the i-th domain node among the M domain nodes, and the keys of any two domain nodes among the M domain nodes are different.
[0007] Optionally, the management device obtains the financial service data requested to be stored by the user, including: the management device receives a data cloud storage request from the user, and the data cloud storage request includes the data encrypted by the user; the management device uses the user's key to decrypt the data encrypted by the user to obtain the financial service data. When the management device and the user are in the first trusted domain, the management device shares the user's key with the user.
[0008] Optionally, the management device divides the financial service data into M segments of financial service sub-data and determines M domain nodes in the domain node cluster that can store the financial service data, including: the management device divides the financial service data into M segments of financial service sub-data according to the data volume of the financial service data; in response to the financial service data being divided into M segments of financial service sub-data, the financial service data determines M domain nodes located within the second trusted domain from the domain node cluster according to the type of the financial service data indicated by the data cloud storage request, and the security level of the second trusted domain matches the type of the financial service data.
[0009] Optionally, the management device divides the financial service data into M segments of financial service sub-data according to the data volume of the financial service data, including: the management device determines that the number of segments corresponding to the data volume range is M according to the data volume range where the data volume of the financial service data is located, so as to determine that the financial service data needs to be divided into M segments; when the financial service data contains N characters, N is greater than or equal to 2*M, the management device determines the 1st character, the (M + 1)th character, the (2*M + 1)th character... extracted from the N characters in sequence as the 1st segment of financial service sub-data, and the management device determines the 2nd character, the (M + 2)th character, the (2*M + 2)th character... extracted from the N characters in sequence as the 2nd segment of financial service sub-data, and the management device determines the 3rd character, the (M + 3)th character, the (2*M + 3)th character... extracted from the N characters in sequence as the 3rd segment of financial service sub-data, and so on, until the Mth segment of financial service sub-data is obtained, and a total of M segments of financial service sub-data are obtained.
[0010] Optionally, the management device encrypts the i-th segment of financial service sub-data in the M segments of financial service sub-data to obtain the i-th ciphertext data. When i traverses integers from 1 to M, a total of M ciphertext data are obtained. Then, the M ciphertext data are correspondingly stored in the i-th domain node among the M domain nodes, including: when i + 2 is less than or equal to M, the management device uses the key of the (i + 1)-th domain node among the M domain nodes to encrypt the i-th segment of financial service sub-data in the M segments of financial service sub-data and the key of the (i + 2)-th domain node among the M domain nodes to obtain the i-th ciphertext data among the M ciphertext data; or, when i + 1 is equal to M, the management device uses the key of the M-th domain node among the M domain nodes to encrypt the i-th segment of financial service sub-data in the M segments of financial service sub-data and the key of the management device to obtain the i-th ciphertext data among the M ciphertext data; or, when i is equal to M, the management device uses the key of the management device to encrypt the i-th segment of financial service sub-data in the M segments of financial service sub-data to obtain the i-th ciphertext data among the M ciphertext data; where the management device manages the respective keys of the M domain nodes; the management device sends the i-th ciphertext data and the information indicating the data size of the i-th ciphertext data to the i-th domain node among the M domain nodes for the i-th domain node to store the i-th ciphertext data and the information indicating the i-th ciphertext data;
[0011] Optionally, among the M domain nodes, the shortest data routing path during data reading is from the 1st domain node to the 2nd domain node, from the 2nd domain node to the 3rd domain node, and so on, until from the (M - 1)-th domain node to the M-th domain node. The management device determines the respective sequence numbers of the M domain nodes according to the shortest data routing path traversed during data reading.
[0012] Optionally, the method further includes: the management device receives a data reading request from the user, where the data reading request is used to request reading of financial service data; the management device sends a data routing request to the first domain node among the M domain nodes according to the data reading request, where the data routing request includes the respective routing information of the M domain nodes and information indicating the M ciphertext data; through the data routing sequentially executed by the M domain nodes, the management device receives the M financial ciphertext data sent by the Mth domain node among the M domain nodes; the management device decrypts the first financial ciphertext data among the M financial ciphertext data using the key of the management device to obtain the first segment of financial service sub-data among the M segments of financial service sub-data, and the management device decrypts the second financial ciphertext data among the M financial ciphertext data using the key of the management device to obtain the second segment of financial service sub-data among the M segments of financial service sub-data, and so on, the management device decrypts the Mth financial ciphertext data among the M financial ciphertext data using the key of the management device to obtain the Mth segment of financial service sub-data among the M segments of financial service sub-data, and thus, a total of M segments of financial service sub-data are obtained; the management device splices the M segments of financial service sub-data into financial service data, and encrypts the financial service data using the user's key and then sends it to the user.
[0013] Optionally, the method is further applied to M domain nodes, and the method further includes: when i + 1 is less than or equal to M: if i equals 1, the i-th domain node receives a data routing request from the management device, and routes the i-th ciphertext data to the (i + 1)-th domain node according to the data routing request; if i equals 2, the i-th domain node receives a data routing request from the (i - 1)-th domain node among the M domain nodes and the (i - 1)-th ciphertext data among the M ciphertext data; on this basis, in response to the data routing request, the i-th domain node decrypts the (i - 1)-th ciphertext data using the key of the i-th domain node, obtains the (i - 1)-th segment of financial service sub-data among the M segments of financial service sub-data and the key of the (i + 1)-th domain node, the i-th domain node encrypts the (i - 1)-th segment of financial service sub-data using the key of the (i + 1)-th domain node, obtains the (i - 1)-th financial ciphertext data, and routes the i-th ciphertext data and the (i - 1)-th financial ciphertext data to the (i + 1)-th domain node; if i is greater than 2, the i-th domain node receives a data routing request from the (i - 1)-th domain node among the M domain nodes, the (i - 1)-th ciphertext data among the M ciphertext data, and the previous (i - 2) financial ciphertext data, on this basis, in response to the data routing request, the i-th domain node decrypts the (i - 1)-th ciphertext data using the key of the i-th domain node, obtains the (i - 1)-th segment of financial service sub-data and the key of the (i + 1)-th domain node, and decrypts the previous (i - 2) financial ciphertext data using the key of the i-th domain node to obtain the previous (i - 2) segments of financial service sub-data among the M segments of financial service sub-data; the i-th domain node encrypts and routes the previous (i - 1) segments of financial service sub-data among the M segments of financial service sub-data to the (i + 1)-th domain node using the key of the (i + 1)-th domain node, and the i-th domain node routes the i-th ciphertext data to the (i + 1)-th domain node; when i equals M: the i-th domain node receives a data routing request from the (i - 1)-th domain node among the M domain nodes, the (i - 1)-th ciphertext data among the M ciphertext data, and the previous (i - 2) financial ciphertext data, on this basis, in response to the data routing request, the i-th domain node decrypts the (i - 1)-th ciphertext data using the key of the i-th domain node, obtains the (i - 1)-th segment of financial service sub-data and the key of the management device, and decrypts the previous (i - 2) financial ciphertext data using the key of the i-th domain node to obtain the previous (i - 2) segments of financial service sub-data among the M segments of financial service sub-data; the i-th domain node encrypts and routes the previous (i - 1) segments of financial service sub-data among the M segments of financial service sub-data to the management device using the key of the management device, and the i-th domain node routes the i-th ciphertext data to the management device, at this time, the management device receives M financial ciphertext data, and the i-th ciphertext data in the case of i = M is the i-th financial ciphertext data among the M financial ciphertext data.
[0014] Optionally, any two domain nodes among the M domain nodes are physically resource-isolated domain nodes.
[0015] Second aspect, an embodiment of the present application provides a security protection system based on financial service data. The system includes a management device, which is used to manage a distributed domain node cluster. The management device is configured to: obtain financial service data requested by a user for storage; determine M domain nodes capable of storing the financial service data from the domain node cluster, and divide the financial service data into M segments of financial service sub-data, where M is an integer greater than 2; encrypt the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data. When i traverses integers from 1 to M, a total of M ciphertext data are obtained, and thus the M ciphertext data are correspondingly stored in the i-th domain node among the M domain nodes. Among them, the key used for encrypting the i-th segment of financial service sub-data is the key of other domain nodes, and other domain nodes are the domain nodes other than the i-th domain node among the M domain nodes, and the keys of any two domain nodes among the M domain nodes are different.
[0016] Third aspect, an embodiment of the present application provides a computer-readable storage medium, on which program code is stored. When the program code is run by a computer, it executes the method described in the first aspect.
[0017] In summary, the above method and system have the following technical effects:
[0018] When a user requests to store financial service data in the cloud, the management device in the cloud can divide it into M segments of financial service sub-data and perform security protection separately to obtain M ciphertext data, and thus store the M ciphertext data correspondingly in M domain nodes. At this time, for any segment of financial service sub-data, such as the i-th segment of financial service sub-data, since the key used for its security protection is the key of other domain nodes, that is, the domain nodes other than the i-th domain node among the M domain nodes, even if an attacker steals the i-th ciphertext data from the i-th domain node, it will not be able to decrypt the i-th ciphertext data because it cannot obtain the keys of other domain nodes, thereby improving the security of financial data storage. Description of the Drawings
[0019] Figure 1 It is a schematic diagram of the architecture of a financial service system provided by an embodiment of the present application;
[0020] Figure 2 It is a flowchart of a security protection method based on financial service data provided by an embodiment of the present application;
[0021] Figure 3 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed Embodiments
[0022] In the embodiments of the present invention, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain piece of information is called the information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to achieve the indication of specific information by means of the arrangement order of each piece of information pre-agreed (such as stipulated in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by separately indicating the same information.
[0023] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above-mentioned indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present invention do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present invention should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0024] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending opportunities of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present invention. Among them, the sending periods and / or sending opportunities of these sub-information can be predefined, such as predefined according to the protocol, or can be configured by the sending device by sending configuration information to the receiving device.
[0025] "Predefined" or "pre-configured" can be achieved by pre-saving corresponding codes, tables or other ways that can be used to indicate relevant information in the device. The embodiments of the present invention do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately arranged, or can be integrated in an encoder or decoder, a processor, or an electronic device. The one or more memories can also be partially separately arranged and partially integrated in a decoder, a processor, or an electronic device. The type of memory can be any form of storage medium, which is not limited in the embodiments of the present invention.
[0026] The "protocol" involved in the embodiments of the present invention may refer to a protocol family in the communication field, a standard protocol with a frame structure similar to that of a protocol family, or a related protocol in a reliable access method system for future Internet of Things devices. The embodiments of the present invention do not make specific limitations in this regard.
[0027] In the embodiments of the present invention, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the device making corresponding processing under a certain objective situation, not limited to time, and do not require the device to have a judgment action when implemented, nor does it mean there are other limitations.
[0028] In the description of the embodiments of the present invention, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B; "and / or" in the embodiments of the present invention is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B may be singular or plural. Also, in the description of the embodiments of the present invention, unless otherwise specified, "a plurality of" means two or more than two. "At least one (piece) of the following" or its similar expressions refer to any combination of these items, including any combination of single item (piece) or plural items (pieces). For example, at least one (piece) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of the present invention, in the embodiments of the present invention, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first" and "second" do not necessarily mean different. At the same time, in the embodiments of the present invention, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present invention should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.
[0029] The network architecture and service scenarios described in the embodiments of the present invention are for more clearly explaining the technical solutions of the embodiments of the present invention, and do not constitute a limitation to the technical solutions provided by the embodiments of the present invention. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present invention are equally applicable to similar technical problems.
[0030] The technical solutions in the present application will be described below in conjunction with the accompanying drawings.
[0031] Please refer to Figure 2 , an embodiment of the present application provides a financial service system, and the financial service system may include: a management device and a domain node.
[0032] The form of the domain node may be a terminal, also referred to as a terminal device, and the terminal device may also be referred to as a user equipment (UE), access terminal, user unit, user station, mobile station, mobile terminal, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment. The terminal device in the embodiment of the present application may be a mobile phone, a tablet computer (Pad), a computer with a wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home.
[0033] The management device may be a service device, such as a server, a server cluster, a virtual server, a virtual service cluster, etc., such as network functions virtualization (NFV). NFV includes: network functions virtualization infrastructure (NFVI), virtual network function (VNF), element management system (EMS), management, automation, and network orchestration (MANO), etc.
[0034] The management device can be accessed by a user, where the user can refer to the device used by the user, such as a terminal. The management device and the user can be located in the same trusted domain, that is, they have the same security level, which is denoted as the first trusted domain. For example, the first trusted domain can be the operator network accessed by the user device, such as a mobile public land mobile network (PLMN). The management device can be a third-party management device docked with the PLMN or a third-party management device licensed by the PLMN, and can also be considered to be located in the first trusted domain. When the management device and the user are in the first trusted domain, the management device and the user share the user's key, that is, when the user registers with the management device, both the management device and the user can derive the same key, that is, the user's key. The keys of different users are different.
[0035] There can be multiple domain nodes, and the multiple domain nodes can be deployed in a distributed manner, that is, a distributed domain node cluster. The management device is used to manage the domain node cluster. Any two domain nodes in the domain node cluster are physically resource-isolated. For example, any two domain nodes are distributed on different physical hardware devices or in different computer rooms to ensure security. The domain nodes in the domain node cluster can be distributed in different trusted domains. For example, different domain nodes can be respectively distributed in different distributed subnets or private networks. Since the security capabilities of these distributed subnets or private networks are different, they can also be considered different trusted domains.
[0036] Next, the interaction between the domain nodes and the management device in the above system will be described in detail in combination with the method.
[0037] Please refer to Figure 2 , an embodiment of the present application provides a security protection method based on financial service data. This method can be applied to the communication between a user device and a data management center. The process of this method includes:
[0038] S201, the management device obtains the financial service data requested by the user to be stored.
[0039] The management device can receive a data cloud storage request from a user (a user registered with the management device). The data cloud storage request includes the data encrypted by the user, as well as the user's identifier and information indicating the financial service data, such as a data identifier. When the management device and the user are in the first trusted domain, the management device and the user share the user's key. In this way, the management device can obtain the user's key according to the user's identifier. The management device uses the user's key to decrypt the data encrypted by the user to obtain the financial service data.
[0040] S202, the management device divides the financial service data into M segments of financial service sub-data and determines M domain nodes in the domain node cluster that can store the financial service data, where M is an integer greater than 2.
[0041] The management device can divide the financial service data into M segments of financial service sub - data according to the data volume of the financial service data. For example, the management device determines that the number of segments corresponding to the data volume interval where the data volume of the financial service data is located is M, so as to determine that the financial service data needs to be divided into M segments. Among them, the larger the data volume, the larger M is.
[0042] When the financial service data contains N characters, where N is greater than or equal to 2*M, the management device determines the first character, the (M + 1)-th character, the (2*M + 1)-th character,... extracted from the N characters in sequence as the first segment of financial service sub - data, and the management device determines the second character, the (M + 2)-th character, the (2*M + 2)-th character,... extracted from the N characters in sequence as the second segment of financial service sub - data, and the management device determines the third character, the (M + 3)-th character, the (2*M + 3)-th character,... extracted from the N characters in sequence as the third segment of financial service sub - data, and so on, until the M - th segment of financial service sub - data is obtained, a total of M segments of financial service sub - data are obtained. That is to say, the segmentation is not a direct split, but characters are extracted from different positions to form the financial service sub - data to improve data security. Even if a certain financial service sub - data is stolen, since its data are all discrete characters, the attacker cannot obtain effective information. For example, if the financial service data is A1A2A3A4B2B2B3B4C1C2C3C4D1D2D3D4 and M = 4, the first segment of financial service sub - data is A1B1C1D1, the second segment of financial service sub - data is A2B2C2D2, the third segment of financial service sub - data is A3B3C3D3, and the fourth segment of financial service sub - data is A4B4C4D4.
[0043] In response to the financial service data being divided into M segments of financial service sub - data, the financial service data determines M domain nodes located in the second trusted domain from the domain node cluster according to the type of the financial service data indicated by the data cloud storage request. The security level of the second trusted domain matches the type of the financial service data. For example, the type can indicate whether the financial service data contains user privacy data. The security level of the data containing user privacy data is higher than that of the data not containing user privacy data. If it contains user privacy data, domain nodes need to be selected from a trusted domain with a higher security level. A trusted domain with a higher security level means that the security capabilities of the domain nodes in it are stronger, such as more complex encryption algorithms can be used to further improve security. The M domain nodes can be selected according to the storage situation of the domain nodes, such as selecting the M domain nodes with the least amount of stored data in the first M. Any two of the M domain nodes are domain nodes with physically isolated resources.
[0044] S203, the management device encrypts the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data. When i traverses integers from 1 to M, a total of M ciphertext data are obtained, and thus the M ciphertext data are correspondingly stored in the i-th domain node among the M domain nodes.
[0045] Among them, the key used for encrypting the i-th segment of financial service sub-data is the key of other domain nodes. Other domain nodes are the domain nodes among the M domain nodes except the i-th domain node, and the keys of any two domain nodes among the M domain nodes are different.
[0046] For example, when i + 2 is less than or equal to M, the management device uses the key of the (i + 1)-th domain node among the M domain nodes to encrypt the i-th segment of financial service sub-data among the M segments of financial service sub-data and the key of the (i + 2)-th domain node among the M domain nodes to obtain the i-th ciphertext data among the M ciphertext data; or, when i + 1 is equal to M, the management device uses the key of the M-th domain node among the M domain nodes to encrypt the i-th segment of financial service sub-data among the M segments of financial service sub-data and the key of the management device to obtain the i-th ciphertext data among the M ciphertext data; or, when i is equal to M, the management device uses the key of the management device to encrypt the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data among the M ciphertext data; among them, the management device manages the keys of each of the M domain nodes. On this basis, the management device sends the i-th ciphertext data and the information indicating the data size of the i-th ciphertext data to the i-th domain node among the M domain nodes for the i-th domain node to store the i-th ciphertext data and the information indicating the i-th ciphertext data (such as the identifier of the i-th ciphertext data).
[0047] That is to say, the i-th ciphertext data stored in the i-th domain node is not encrypted using the key of the i-th domain node. Even if an attack is launched on the i-th domain node and the key of the i-th domain node and the i-th ciphertext data are stolen from the i-th domain node, the plaintext data cannot be decrypted, thus further improving data security.
[0048] It should be understood that for the respective serial numbers of the M domain nodes, that is, the serial numbers can indicate which domain node a certain domain node is among the M domain nodes. For example, the first domain node, the second domain node, etc. The respective serial numbers of the M domain nodes are determined by the management device according to the shortest data routing path during data reading. That is, among the M domain nodes, from the first domain node to the second domain node, from the second domain node to the third domain node, and so on, until from the M-1th domain node to the Mth domain node is the shortest data routing path during data reading. The management device determines the respective serial numbers of the M domain nodes by traversing the shortest data routing path during data reading. For example, when M = 4, the M domain nodes include domain node A, domain node B, domain node C, and domain node D. The management device determines that during data reading, the data is routed from domain node B through other domain nodes to domain node C, then from domain node C through other domain nodes to domain node A, and finally from domain node A through other domain nodes to domain node D, and is directly sent by domain node D to the management device. In this case, the number of other domain nodes participating in the above routing is the least, so the above routing path is the shortest data routing path. Domain node B is the first domain node, domain node C is the second domain node, domain node A is the third domain node, and domain node D is the fourth domain node. That is to say, which key the management device uses, or which domain node D / management device key, to encrypt each segment of financial service sub-data is determined according to the shortest data routing path and is strongly related (or bound) to the data routing.
[0049] Exemplarily, the management device uses the key of the second domain node to encrypt the first segment of financial service sub-data and the key of the third domain node to obtain the first ciphertext data, and then sends it to the first domain node for storage. The management device uses the key of the third domain node to encrypt the second segment of financial service sub-data and the key of the fourth domain node to obtain the second ciphertext data, and then sends it to the second domain node for storage. The management device uses the key of the fourth domain node to encrypt the third segment of financial service sub-data and the key of the management device to obtain the third ciphertext data, and then sends it to the third domain node for storage. The management device uses the key of the management device to encrypt the fourth segment of financial service sub-data to obtain the fourth ciphertext data, and then sends it to the fourth domain node for storage.
[0050] After S203, the method further includes:
[0051] Step 1: The management device receives a data reading request from the user.
[0052] The data reading request is used to request to read financial service data, such as including information indicating the financial service data, so that the management device can determine, according to the information indicating the financial service data and the records during previous data storage, that the financial service data was previously divided into M segments and encrypted for storage, thereby determining the M domain nodes.
[0053] Step 2: The management device sends a data routing request to the first domain node among the M domain nodes according to the data reading request.
[0054] The data routing request includes the routing information of each of the M domain nodes (such as the identifiers of each of the M domain nodes) and the information indicating the M ciphertext data (such as the identifiers of each of the M ciphertext data set in sequence according to the routing order and the identifier of the management device).
[0055] Step 3: Through the data routing sequentially executed by the M domain nodes, the management device receives the M financial ciphertext data sent by the Mth domain node among the M domain nodes.
[0056] For example, this method is also applied to the M domain nodes, and the method further includes:
[0057] When i + 1 is less than or equal to M:
[0058] If i equals 1, the ith domain node receives the data routing request from the management device, and routes the ith ciphertext data to the (i + 1)th domain node according to the data routing request;
[0059] If i equals 2, the ith domain node receives the data routing request from the (i - 1)th domain node among the M domain nodes and the (i - 1)th ciphertext data among the M ciphertext data; on this basis, in response to the data routing request, the ith domain node decrypts the (i - 1)th ciphertext data using the key of the ith domain node to obtain the (i - 1)th financial service sub - data segment among the M segments of financial service sub - data and the key of the (i + 1)th domain node. The ith domain node encrypts the (i - 1)th financial service sub - data segment using the key of the (i + 1)th domain node to obtain the (i - 1)th financial ciphertext data, and routes the ith ciphertext data and the (i - 1)th financial ciphertext data to the (i + 1)th domain node;
[0060] If i is greater than 2, the ith domain node receives the data routing request from the (i - 1)th domain node among the M domain nodes, the (i - 1)th ciphertext data among the M ciphertext data, and the first (i - 2) financial ciphertext data. On this basis, in response to the data routing request, the ith domain node decrypts the (i - 1)th ciphertext data using the key of the ith domain node to obtain the (i - 1)th financial service sub - data segment and the key of the (i + 1)th domain node, and decrypts the first (i - 2) financial ciphertext data using the key of the ith domain node to obtain the first (i - 2) financial service sub - data segments among the M segments of financial service sub - data; the ith domain node encrypts and routes the first (i - 1) financial service sub - data segments among the M segments of financial service sub - data to the (i + 1)th domain node using the key of the (i + 1)th domain node, and the ith domain node routes the ith ciphertext data to the (i + 1)th domain node;
[0061] When i is equal to M:
[0062] The i-th domain node receives a data routing request from the i-1-th domain node among the M domain nodes, the i-1-th ciphertext data among the M ciphertext data, and the first i-2 financial ciphertext data. On this basis, in response to the data routing request, the i-th domain node uses the key of the i-th domain node to decrypt the i-1-th ciphertext data to obtain the i-1-th segment of financial service sub-data and the key of the management device, and uses the key of the i-th domain node to decrypt the first i-2 financial ciphertext data to obtain the first i-2 segments of financial service sub-data among the M segments of financial service sub-data; the i-th domain node uses the key of the management device to encrypt the first i-1 segments of financial service sub-data among the M segments of financial service sub-data and routes them to the management device, and the i-th domain node routes the i-th ciphertext data to the management device. At this time, the management device receives M financial ciphertext data, and the i-th ciphertext data in the case of i=M is the i-th financial ciphertext data among the M financial ciphertext data.
[0063] Step 4: The management device uses the key of the management device to decrypt the first financial ciphertext data among the M financial ciphertext data, and obtains the first segment of financial service sub-data among the M segments of financial service sub-data, and the management device uses the key of the management device to decrypt the second financial ciphertext data among the M financial ciphertext data, and obtains the second segment of financial service sub-data among the M segments of financial service sub-data. Similarly, the management device uses the key of the management device to decrypt the Mth financial ciphertext data among the M financial ciphertext data, and obtains the Mth segment of financial service sub-data among the M segments of financial service sub-data. So far, a total of M segments of financial service sub-data are obtained.
[0064] Step 5: The management device assembles the M segments of financial service sub-data into financial service data, and encrypts the financial service data using the user's key and sends it to the user.
[0065] Continuing with the above example, the first domain node receives the data routing request, obtains the first ciphertext data saved this time according to the identifier of the first domain node and the identifier of the first ciphertext data, and then sends the first ciphertext data and the data routing request to the second domain node according to the identifier of the second domain node. The second domain node receives the data routing request, obtains the second ciphertext data saved this time according to the identifier of the second domain node and the identifier of the second ciphertext data.
[0066] The second domain node decrypts the first ciphertext data using the key of the second domain node to obtain the first segment of financial service sub-data and the key of the third domain node. The second domain node encrypts the first segment of financial service sub-data using the key of the third domain node to obtain the first financial ciphertext data. The second domain node sends the second ciphertext data, the first financial ciphertext data, and the data routing request to the second domain node according to the identifier of the third domain node.
[0067] The third domain node decrypts the second ciphertext data using the key of the third domain node to obtain the second segment of financial service sub-data and the key of the fourth domain node. The third domain node decrypts the first financial ciphertext data using the key of the third domain node to obtain the first segment of financial service sub-data. The third domain node encrypts the first segment of financial service sub-data and the second segment of financial service sub-data using the key of the fourth domain node to obtain the second financial ciphertext data. The third domain node sends the third ciphertext data, the second financial ciphertext data, and the data routing request to the fourth domain node according to the identifier of the fourth domain node.
[0068] The fourth domain node decrypts the third ciphertext data using the key of the fourth domain node to obtain the third segment of financial service sub-data and the key of the management device. The fourth domain node decrypts the second financial ciphertext data using the key of the fourth domain node to obtain the first segment of financial service sub-data and the second segment of financial service sub-data. The third domain node encrypts the first to third segments of financial service sub-data using the key of the management device to obtain the third financial ciphertext data. The fourth domain node sends the fourth ciphertext data, the third financial ciphertext data to the management node according to the identifier of the management node.
[0069] The management node decrypts the fourth ciphertext data and the third financial ciphertext data using the key of the management node to obtain the first to fourth segments of financial service sub-data. The management node performs the reverse process of the above division on the first to fourth segments of financial service sub-data to obtain the financial service data. The management node encrypts and sends the financial service data to the user using the key of the user.
[0070] In summary, in the case where a user requests to store financial service data in the cloud, the management device in the cloud can divide it into M segments of financial service sub-data and perform security protection on each segment separately to obtain M ciphertext data, and then store the M ciphertext data corresponding to M domain nodes. At this time, for any segment of financial service sub-data, such as the i-th segment of financial service sub-data, since the key used for its security protection is the key of other domain nodes, that is, the domain nodes other than the i-th domain node among the M domain nodes, even if an attacker steals the i-th ciphertext data from the i-th domain node, it will not be able to decrypt the i-th ciphertext data because it cannot obtain the keys of other domain nodes, thereby improving the security of financial data storage.
[0071] The above has been Figure 2 described in detail the method provided by the embodiments of the present application. The following introduces a security protection system based on financial service data for executing the method provided by the embodiments of the present application.
[0072] The system includes a management device, and the management device is used to manage a distributed domain node cluster. The management device is configured to: obtain the financial service data requested by the user for storage; determine M domain nodes in the domain node cluster that can store the financial service data, and divide the financial service data into M segments of financial service sub-data, where M is an integer greater than 2; encrypt the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data. When i traverses integers from 1 to M, a total of M ciphertext data are obtained, and then store the M ciphertext data corresponding to the i-th domain node among the M domain nodes, where the key used for encrypting the i-th segment of financial service sub-data is the key of other domain nodes, and other domain nodes are the domain nodes other than the i-th domain node among the M domain nodes, and the keys of any two domain nodes among the M domain nodes are different.
[0073] The specific implementation of this system can refer to the above method and will not be elaborated here.
[0074] Next, in combination with Figure 3 each component of the electronic device 500 will be specifically introduced:
[0075] Among them, the processor 501 is the control center of the electronic device 500, which can be a single processor or a collective term for multiple processing elements. For example, the processor 501 is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or an integrated circuit configured to implement the embodiments of the present application, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0076] Optionally, the processor 501 can execute various functions of the electronic device 500 by running or executing software programs stored in the memory 502 and calling data stored in the memory 502, such as the functions in the method as described above Figure 3 shown in the method.
[0077] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as Figure 3 the CPU0 and CPU1 shown in.
[0078] In a specific implementation, as an embodiment, the electronic device 500 may also include multiple processors. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0079] Among them, the memory 502 is used to store the software program for executing the solution of the present application and is controlled by the processor 501 for execution. The specific implementation manner can refer to the above method embodiments and will not be elaborated here.
[0080] Optionally, the memory 502 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), or
[0081] Other types of dynamic storage devices that can store information and instructions can also be electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or any other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 can be integrated with the processor 501 or exist independently, and the interface circuit of the electronic device 500 (not shown in ) is coupled to the processor 501. The embodiments of the present application do not make specific limitations on this.
[0082] The interface circuit of ( Figure 3 not shown in ) is coupled to the processor 501. The embodiments of the present application do not make specific limitations on this.
[0083] The transceiver 503 is used for communication with other devices. For example, when the multi-beam based positioning device is a terminal, the transceiver 503 can be used for communication with a network device or with another terminal.
[0084] Optionally, the transceiver 503 can include a receiver and a transmitter ( Figure 3 not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.
[0085] Optionally, the transceiver 503 can be integrated with the processor 501 or exist independently, and is coupled to the processor 501 through the interface circuit of the electronic device 500 (not shown in ). The embodiments of the present application do not make specific limitations on this. Figure 3 not shown in ) is coupled to the processor 501. The embodiments of the present application do not make specific limitations on this.
[0086] It should be noted that Figure 3 the structure of the electronic device 500 shown in does not constitute a limitation on the device. The actual electronic device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component layout.
[0087] In addition, for the technical effects of the electronic device 500, reference can be made to the technical effects of the method in the above method embodiments, which will not be elaborated here.
[0088] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0089] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0090] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0091] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context before and after.
[0092] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0093] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0094] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0095] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0096] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some feature fields can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0097] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0098] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0099] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0100] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A security protection method based on financial service data, characterized in that: The method is applied to a management device, the management device is used to manage a distributed domain node cluster, and the method includes: The management device obtains the financial service data requested to be stored by the user; The management device receives a data cloud storage request from the user, wherein the data cloud storage request includes data encrypted by the user; The management device uses the user's key to decrypt the data encrypted by the user to obtain the financial service data. When the management device and the user are located in the first trusted domain, the management device and the user share the user's key. The management device divides the financial service data into M segments of financial service sub-data, and determines M domain nodes from the domain node cluster that can store the financial service data, where M is an integer greater than 2. The management device divides the financial service data into the M segments of financial service sub-data according to the data volume of the financial service data; In response to the financial service data being segmented into the M segments of financial service sub-data, the financial service data is determined from the domain node cluster to be located in the M domain nodes in a second trusted domain according to the type of the financial service data indicated by the data cloud storage request, and the security level of the second trusted domain matches the type of the financial service data; The management device encrypts the i-th segment of financial service sub-data among the M segments of financial service sub-data to obtain the i-th ciphertext data, and when i is an integer traversing from 1 to M, a total of M ciphertext data are obtained, so that the M ciphertext data are correspondingly stored in the i-th domain node among the M domain nodes, wherein the key used when the i-th segment of financial service sub-data is encrypted is the key of other domain nodes, and the other domain nodes are domain nodes among the M domain nodes except the i-th domain node, and the keys of any two domain nodes among the M domain nodes are different.
2. The method according to claim 1, characterized in that The management device divides the financial service data into the M segments of financial service sub-data according to the data volume of the financial service data, including: The management device determines, according to the data volume interval in which the data volume of the financial service data is located, that the number of segments corresponding to the data volume interval is M, thereby determining that the financial service data needs to be divided into M segments; In the case that the financial service data contains N characters, N is greater than or equal to 2*M, and the management device will extract the 1st character, the M+1th character, the 2*M+1th character... and so on from the N characters in sequence to determine them as the 1st segment of financial service sub-data, and the management device will extract the 2nd character, the M+2th character, the 2*M+2th character... and so on from the N characters in sequence to determine them as the 2nd segment of financial service sub-data, and the management device will extract the 3rd character, the M+3th character, the 2*M+3th character... and so on from the N characters in sequence to determine them as the 3rd segment of financial service sub-data, and so on, until the Mth segment of financial service sub-data is obtained, and a total of M segments of financial service sub-data are obtained.
3. The method according to any one of claims 1 to 2, characterized in that: The management device encrypts the i-th segment of financial service sub-data in the M segments of financial service sub-data to obtain the i-th ciphertext data, where i is an integer traversing from 1 to M, a total of M ciphertext data are obtained, and the M ciphertext data are stored in the i-th domain node in the M domain nodes, including: When i+2 is less than or equal to M, the management device uses the key of the i+1th domain node among the M domain nodes to encrypt the i-th segment of financial service sub-data in the M segments of financial service sub-data and the key of the i+2th domain node among the M domain nodes to obtain the i-th ciphertext data in the M ciphertext data; Alternatively, when i+1 is equal to M, the management device uses the key of the Mth domain node among the M domain nodes to encrypt the i-th segment of the financial service sub-data in the M segments of the financial service sub-data and the key of the management device to obtain the i-th ciphertext data in the M ciphertext data; Alternatively, when i is equal to M, the management device uses the key of the management device to convert the i-th segment of financial service sub-data in the M segments of financial service sub-data to obtain the i-th ciphertext data in the M ciphertext data; Wherein, the management device manages the keys of the M domain nodes respectively; The management device sends the i-th ciphertext data and information indicating the data size of the i-th ciphertext data to the i-th domain node among the M domain nodes, so that the i-th domain node stores the i-th ciphertext data and the information indicating the i-th ciphertext data.
4. The method according to claim 3, characterized in that Among the M domain nodes, the 1st domain node to the 2nd domain node, the 2nd domain node to the 3rd domain node, and so on, until the M-1th domain node to the Mth domain node is the shortest data routing path when reading data, and the management device determines the respective serial numbers of the M domain nodes by traversing the shortest data routing path when reading data.
5. The method according to claim 4, characterized in that The method further comprises: The management device receives a data reading request from the user, where the data reading request is used to request to read the financial service data; The management device sends a data routing request to a first domain node among the M domain nodes according to the data reading request, wherein the data routing request includes routing information of each of the M domain nodes and information indicating the M ciphertext data; Through the data routing sequentially performed by the M domain nodes, the management device receives M financial ciphertext data sent by the Mth domain node among the M domain nodes; The management device uses the key of the management device to decrypt the first financial ciphertext data among the M financial ciphertext data to obtain the first segment of financial service sub-data among the M segments of financial service sub-data, and the management device uses the key of the management device to decrypt the second financial ciphertext data among the M financial ciphertext data to obtain the second segment of financial service sub-data among the M segments of financial service sub-data, and so on, the management device uses the key of the management device to decrypt the Mth financial ciphertext data among the M financial ciphertext data to obtain the Mth segment of financial service sub-data among the M segments of financial service sub-data, so far, a total of the M segments of financial service sub-data are obtained; The management device splices the M segments of financial service sub-data into the financial service data, and uses the user's key to encrypt the financial service data and then sends it to the user.
6. The method according to claim 5, characterized in that The method is also applied to the M domain nodes, and the method further comprises: When i+1 is less than or equal to M: If i is equal to 1, the i-th domain node receives the data routing request from the management device, and routes the i-th ciphertext data to the i+1-th domain node according to the data routing request; If i is equal to 2, the i-th domain node receives the data routing request from the i-1-th domain node among the M domain nodes and the i-1-th ciphertext data among the M ciphertext data; on this basis, in response to the data routing request, the i-th domain node decrypts the i-1-th ciphertext data using the key of the i-th domain node to obtain the i-1-th segment of financial service sub-data among the M segments of financial service sub-data and the key of the i+1-th domain node, the i-th domain node encrypts the i-1-th segment of financial service sub-data using the key of the i+1-th domain node to obtain the i-1-th financial ciphertext data, and routes the i-th ciphertext data and the i-1-th financial ciphertext data to the i+1-th domain node; If i is greater than 2, the i-th domain node receives the data routing request from the i-1-th domain node among the M domain nodes, the i-1-th ciphertext data among the M ciphertext data, and the first i-2 financial ciphertext data. On this basis, in response to the data routing request, the i-th domain node decrypts the i-1-th ciphertext data using the key of the i-th domain node to obtain the i-1-th segment of financial service sub-data and the key of the i+1-th domain node, and decrypts the first i-2 financial ciphertext data using the key of the i-th domain node to obtain the first i-2 segments of financial service sub-data among the M segments of financial service sub-data; the i-th domain node encrypts the first i-1 segments of financial service sub-data among the M segments of financial service sub-data using the key of the i+1-th domain node and routes them to the i+1-th domain node, and the i-th domain node routes the i-th ciphertext data to the i+1-th domain node; When i is equal to M: The i-th domain node receives the data routing request from the i-1-th domain node among the M domain nodes, the i-1-th ciphertext data among the M ciphertext data, and the first i-2 financial ciphertext data. On this basis, in response to the data routing request, the i-th domain node decrypts the i-1-th ciphertext data using the key of the i-th domain node to obtain the i-1-th segment of financial service sub-data and the key of the management device, and decrypts the first i-2 financial ciphertext data using the key of the i-th domain node to obtain the first i-2 segments of financial service sub-data among the M segments of financial service sub-data; the i-th domain node encrypts the first i-1 segments of financial service sub-data among the M segments of financial service sub-data using the key of the management device and routes them to the management device, and the i-th domain node routes the i-th ciphertext data to the management device. At this time, the management device receives the M financial ciphertext data, and the i-th ciphertext data in the case of i=M is the i-th financial ciphertext data among the M financial ciphertext data.
7. The method according to claim 6, characterized in that Any two domain nodes among the M domain nodes are domain nodes with isolated physical resources.
8. A security protection system based on financial service data, characterized in that: The system includes a management device, which is used to manage a distributed domain node cluster, and the management device is configured to: The management device obtains the financial service data requested to be stored by the user; The management device receives a data cloud storage request from the user, wherein the data cloud storage request includes data encrypted by the user; The management device uses the user's key to decrypt the data encrypted by the user to obtain the financial service data. When the management device and the user are located in the first trusted domain, the management device and the user share the user's key; The management device determines M domain nodes from the domain node cluster that can store the financial service data, and divides the financial service data into M segments of financial service sub-data, where M is an integer greater than 2; The management device divides the financial service data into the M segments of financial service sub-data according to the data volume of the financial service data; In response to the financial service data being divided into the M segments of financial service sub-data, the financial service data is determined from the domain node cluster to be located in the M domain nodes in the second trusted domain according to the type of the financial service data indicated by the data cloud storage request, and the security level of the second trusted domain matches the type of the financial service data; the management device encrypts the i-th segment of the financial service sub-data in the M segments of the financial service sub-data to obtain the i-th ciphertext data, and when i is an integer traversing from 1 to M, a total of M ciphertext data are obtained, so that the M ciphertext data are correspondingly stored in the i-th domain node in the M domain nodes, wherein the key used when the i-th segment of the financial service sub-data is encrypted is the key of other domain nodes, and the other domain nodes are domain nodes other than the i-th domain node in the M domain nodes, and the keys of any two domain nodes in the M domain nodes are different.
Citation Information
Patent Citations
Financial data encryption method, encryption device, equipment and medium
CN118200049A
KR20210059182A