Data security-based secret evaluation SDK (Software Development Kit) implementation system and method

By designing a secret review SDK implementation system based on data security, the problem of insufficient security of sensitive information in the mobile Internet environment is solved, and the confidentiality and integrity of data in transmission, processing and storage processes are achieved, reducing the cost of developers' integration and optimizing the user experience.

CN119939621APending Publication Date: 2025-05-06BEIJING AEROSPACE CLOUD ROAD CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411901388.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the mobile Internet environment, users' sensitive information is susceptible to potential risks during transmission, processing and storage, and the prior art lacks attention to data security.

Method used

A secret evaluation SDK implementation system based on data security is designed, including application management module, data source management module and security secret evaluation SDK module. Data is automatically protected through encryption and decryption methods to ensure its confidentiality and integrity.

Benefits of technology

Effectively protect the confidentiality and integrity of sensitive information in transmission, processing and storage, reduce developers' integration costs and time investment, enhance data security and optimize user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939621A_ABST
    Figure CN119939621A_ABST
Patent Text Reader

Abstract

The invention discloses a secret evaluation SDK implementation system and method based on data security. The system comprises an application management module, a data source management module and a security secret evaluation SDK module. The security encryption evaluation SDK module is used for automatically encrypting and decrypting data according to a strategy configured in data source management; the method comprises the steps of creating an application, authorizing encryption, adding dependency, modifying an SDK configuration file and modifying a driver. The system is strictly designed and developed according to national standards such as GB / T 39786-2021 Basic Requirements for Information Safety Technology Information System Password Application and the like, the core is to ensure the confidentiality and integrity of sensitive information in transmission, processing and storage processes, meanwhile, an SDK toolkit easy to use is provided, the integration cost and time investment of developers are reduced, and the development efficiency is improved. Therefore, developers can quickly introduce new security measures on the basis of not influencing original functions, the data security is enhanced, and the user experience is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data security-based secret review SDK implementation system and method. Background Art

[0002] With the development of information technology and the popularization of Internet applications, data leakage and personal privacy protection have become issues of widespread concern in society. Traditional security solutions focus on security protection at the network layer or application layer, but pay insufficient attention to the security of the underlying data layer. Especially in the mobile Internet environment, users frequently use terminal devices to conduct online transactions, social interactions and other activities, and a large amount of personal sensitive information such as identity information and payment information is exposed to potential risks. Therefore, how to effectively protect these sensitive data has become a key issue that needs to be solved urgently. Summary of the invention

[0003] In response to the above technical problems in the related technology, the present invention proposes a data security-based secret review SDK implementation system and method, which ensures the confidentiality and integrity of sensitive information during transmission, processing and storage, and can overcome the above shortcomings of the prior art.

[0004] To achieve the above technical objectives, the technical solution of the present invention is implemented as follows: A data security-based secret review SDK implementation system, including an application management module, a data source management module and a security secret review SDK module; The application management module is used for application creation, application editing, application review, application authorization and key management; specifically, the application management module is used to create applications, review applications, issue keys, obtain authentication identifiers appid and authentication keys secretKey, and issue them to corresponding developers; The data source management module is used to manage the target data source, specifically, to add a data source and configure an encryption policy for the data source. The encryption policy supports encryption of the table or field of the table of the selected data source, and supports selection of an encryption algorithm. The encryption / decryption key selects the key of the authorized application; The security review SDK module is used to automatically encrypt data using an encryption method according to the policy configured in the data source management before the data is written into the database, and to decrypt data using a corresponding decryption method when reading data from the database.

[0005] Furthermore, the encryption method is an encrypt(data, key) method, and the decryption method is a decrypt(data, key) method.

[0006] A method for implementing a secret review SDK based on data security, using the secret review SDK to implement a system, includes the following steps: S1 Create application: The application management module creates the application, reviews the application, issues keys, and takes the authentication identifier appid and authentication key secretKey and issues them to the corresponding developer; S2 Authorization Encryption: The data source management module configures the data source of the application. By default, all table fields of the data source are encrypted. If fine-grained encryption field-related authorization is required, it can be freely configured in the encryption policy configuration; S3 Add dependencies: When using Maven or Gradle to build, install cipher-sdk.jar to the local Maven repository and add dependency libraries by configuring pom.xml. If the project is not built using a dependency management tool, copy cipher-sdk.jar to the project's lib directory and add it to the classpath. S4 Modify the SDK configuration file: store sdk.properties in the resource directory; S5 Modify the driver: Change the data connection driver to the SDK driver class com.sec.sdk.jdbc.CipherDriver.

[0007] Furthermore, the installation command for adding dependencies in step S3 is: mvn install:install-file -DgroupId=com.sec -DartifactId=cipher-sdk -Dversion=small -Dfile=cipher-sdk.jar-Dpackaging=jar.

[0008] Furthermore, the specific content of step S4 is as follows: sdk.server.host=[Secret review server IP] sdk.server.port=8216 sdk.socket.timeout=60 sdk.appId=[AppId comes from the application management service] sdk.secretKey = [SecretKey comes from the application management service].

[0009] Beneficial effects of the invention: The present invention is designed and developed in strict accordance with national standards such as GB / T 39786-2021 "Basic Requirements for Cryptographic Application of Information Systems in Information Security Technology". The core of the present invention is to ensure the confidentiality and integrity of sensitive information during transmission, processing and storage. At the same time, it provides a set of easy-to-use SDK toolkits to reduce developers' integration costs and time investment, so that developers can quickly introduce new security measures without affecting the original functions, thereby enhancing data security, optimizing user experience, and promoting industrial development. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0011] Figure 1 It is a structural block diagram of a system for implementing a secret review SDK based on data security according to an embodiment of the present invention. DETAILED DESCRIPTION

[0012] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field belong to the scope of protection of the present invention.

[0013] like Figure 1 As shown, a data security-based secret review SDK implementation system according to an embodiment of the present invention includes an application management module, a data source management module and a security secret review SDK module; The application management module is used for application creation, application editing, application review, application authorization and key management; specifically, the application management module is used to create applications, review applications, issue keys, obtain authentication identifiers appid and authentication keys secretKey, and issue them to corresponding developers; The data source management module is used to manage the target data source, specifically, to add a data source and configure an encryption policy for the data source. The encryption policy supports encryption of the table or field of the table of the selected data source, and supports selection of an encryption algorithm. The encryption / decryption key selects the key of the authorized application; The security review SDK module is used to automatically encrypt data using an encryption method according to the policy configured in the data source management before the data is written into the database, and to decrypt data using a corresponding decryption method when reading data from the database.

[0014] The encryption method is the encrypt(data, key) method, and the decryption method is the decrypt(data, key) method.

[0015] A method for implementing a secret review SDK based on data security, using the secret review SDK to implement a system, includes the following steps: S1 Create application: The application management module creates the application, reviews the application, issues keys, and takes the authentication identifier appid and authentication key secretKey and issues them to the corresponding developer; S2 Authorization Encryption: The data source management module configures the data source of the application. By default, all table fields of the data source are encrypted. If fine-grained encryption field-related authorization is required, it can be freely configured in the encryption policy configuration; S3 Add dependencies: When using Maven or Gradle to build, install cipher-sdk.jar to the local Maven repository and add dependency libraries by configuring pom.xml. If the project is not built using a dependency management tool, copy cipher-sdk.jar to the project's lib directory and add it to the classpath. S4 Modify the SDK configuration file: store sdk.properties in the resource directory; S5 Modify the driver: Change the data connection driver to the SDK driver class com.sec.sdk.jdbc.CipherDriver.

[0016] The installation command to add dependencies in step S3 is: mvn install:install-file -DgroupId=com.sec -DartifactId=cipher-sdk -Dversion=small -Dfile=cipher-sdk.jar-Dpackaging=jar.

[0017] The specific content of step S4 is as follows: sdk.server.host=[Secret review server IP] sdk.server.port=8216 sdk.socket.timeout=60 sdk.appId=[AppId comes from the application management service] sdk.secretKey = [SecretKey comes from the application management service].

[0018] In order to facilitate understanding of the above technical solutions of the present invention, the above technical solutions of the present invention are described in detail below through specific usage methods.

[0019] In specific use, according to the data security-based secret review SDK implementation system and method described in the present invention, the present invention relates to the field of information security, and in particular provides a commercial security assessment (referred to as "secret review") software development kit (SDK) based on data security. The SDK is designed to help developers quickly integrate security features that meet national commercial encryption standards into their applications to ensure the confidentiality and integrity of sensitive information during transmission, processing and storage. In addition, it also meets the requirements of national standards such as GB / T 39786-2021 "Basic Requirements for Cryptographic Application of Information Security Technology Information Systems", and is suitable for various application scenarios that require data security.

[0020] This invention is designed and developed in strict accordance with national standards such as GB / T 39786-2021 "Basic Requirements for the Application of Information Security Technology Information System Cryptography". Its core is to ensure the confidentiality and integrity of sensitive information during transmission, processing and storage. At the same time, it provides a set of easy-to-use SDK toolkits to reduce the integration cost and time investment of developers, so that developers can quickly introduce new security measures without affecting the original functions.

[0021] The present invention provides a design and implementation of a secret review SDK based on data security, and its implementation scheme is as follows: 1. Application management module Manage developers' applications, including application creation, review, authorization, key management, etc.

[0022] 2. Data source management module Manage target data sources. Developers can add data sources and configure encryption policies for them. The policies support selecting which tables or fields of the data sources to encrypt, as well as which encryption algorithm to use for encryption. For encryption / decryption keys, select the keys of authorized applications.

[0023] 3. Security Assessment (Secret Assessment) SDK (1) Database driver Provides a custom database driver class that implements data encryption and decryption logic internally and supports multiple database drivers, such as JDBC, ODBC, etc.

[0024] (2) Encryption / decryption function Provides the encrypt(data, key) method to encrypt data, and the decrypt(data, key) method to decrypt data.

[0025] (3) Encryption / decryption algorithm It supports multiple encryption algorithms, especially domestic encryption algorithms (such as SM2, SM3, and SM4), and provides users with data encryption and decryption services.

[0026] (4) Encryption / decryption process Before writing data to the database, the SDK will automatically encrypt the data using an encryption method based on the policy configured in the data source management; similarly, when reading data from the database, it will be decrypted using the corresponding decryption method.

[0027] 4. Application Integration (Secret Review) SDK (1) Create an application In the application management service, create applications, review them, and issue keys. Obtain the authentication identifier appid and authentication key secretKey, and issue them to the corresponding developers.

[0028] (2) Authorization encryption In the data source management service, configure the data source of the application. By default, all table fields of the data source will be encrypted. If you need fine-grained encryption field-related authorization, you can freely configure it in the encryption policy configuration.

[0029] (3) Add dependencies If your project is built using Maven or Gradle, you can install cipher-sdk.jar into the local Maven repository and add the dependency library by configuring pom.xml. Installation command: Mvn install:install-file -DgroupId=com.sec -DartifactId=cipher-sdk -Dversion=small-Dfile=cipher-sdk.jar -Dpackaging=jar If your project is not built with a dependency management tool, you can copy cipher-sdk.jar to the project's lib directory and then add it to the classpath.

[0030] (4) Modify the SDK configuration file sdk.properties is the configuration file of sdk, which is placed in the resource directory. The content is as follows: sdk.server.host=[Secret review server IP] sdk.server.port=8216 sdk.socket.timeout=60 sdk.appId=[AppId comes from the application management service] sdk.secretKey=[SecretKey comes from the application management service] (5) Modify the driver The data connection driver uses the official MySQL driver, which is changed to the SDK driver class, namely: com.sec.sdk.jdbc.CipherDriver. At this point, the configuration required for the application system to integrate the SDK has been modified.

[0031] The present invention brings about many significant beneficial effects: 1. Enhanced Data Security Efficient encryption: Use national secret algorithms (such as SM2, SM3, and SM4) to encrypt and decrypt sensitive data to ensure the confidentiality and integrity of data during transmission and storage.

[0032] Powerful key management: A complete key management system has been built to cover the entire life cycle of keys, including generation, distribution, storage, update and destruction, effectively preventing key leakage.

[0033] 2. Optimized user experience Transparent integration: Minimize the impact on existing business logic, allowing developers to quickly introduce new security measures without affecting original functions.

[0034] Dynamic adaptability: The database-driven design allows the SDK to flexibly respond to different business scenarios and technical architectures, maintain efficient performance, and support plug-in architecture to facilitate adding new features or adapting to different types of databases.

[0035] 3. Comply with national standards Follow the latest specifications: Designed and developed in strict accordance with national standards such as GB / T 39786-2021 "Basic Requirements for the Application of Cryptography in Information Systems of Information Security Technology", ensuring that the product not only has advanced technical levels, but also meets the requirements of national laws and regulations, providing compliance protection for users.

[0036] 4. Promote industrial development Promote the improvement of information security level: As more companies realize the importance of data security, it is expected that more and more applications will adopt similar secret review SDKs, which will jointly push the information security level of the entire society forward a big step forward and promote the development of the information security industry.

[0037] The secret review SDK described in the present invention, through its unique design and technical implementation, not only ensures data security, but also greatly improves the reliability of the system and user experience, and also promotes the healthy development of the information security industry.

[0038] To sum up, with the help of the above-mentioned technical scheme of the present invention, it is designed and developed in strict accordance with national standards such as GB / T 39786-2021 "Basic Requirements for Cryptographic Application of Information Systems in Information Security Technology", and its core is to ensure the confidentiality and integrity of sensitive information during transmission, processing and storage. At the same time, it provides a set of easy-to-use SDK toolkits to reduce the integration cost and time investment of developers, so that developers can quickly introduce new security measures without affecting the original functions, thereby enhancing data security, optimizing user experience, and promoting industrial development.

[0039] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A data security-based secret review SDK implementation system, characterized in that: Including application management module, data source management module and security review SDK module; The application management module is used for application creation, application editing, application review, application authorization and key management; specifically, the application management module is used to create applications, review applications, issue keys, obtain authentication identifiers appid and authentication keys secretKey, and issue them to corresponding developers; The data source management module is used to manage the target data source, specifically, to add a data source and configure an encryption policy for the data source. The encryption policy supports encryption of the table or field of the table of the selected data source, and supports selection of an encryption algorithm. The encryption / decryption key selects the key of the authorized application; The security review SDK module is used to automatically encrypt data using an encryption method according to the policy configured in the data source management before the data is written into the database, and to decrypt data using a corresponding decryption method when reading data from the database.

2. The data security-based review SDK implementation system according to claim 1, characterized in that: The encryption method is the encrypt(data, key) method, and the decryption method is the decrypt(data, key) method.

3. A method for implementing a secret review SDK based on data security, characterized in that: The system for implementing the secret review SDK described in any one of claims 1 to 2 comprises the following steps: S1 Create application: The application management module creates the application, reviews the application, issues keys, and takes the authentication identifier appid and authentication key secretKey and issues them to the corresponding developer; S2 Authorization Encryption: The data source management module configures the data source of the application. By default, all table fields of the data source are encrypted. If fine-grained encryption field-related authorization is required, it can be freely configured in the encryption policy configuration; S3 Add dependencies: When using Maven or Gradle to build, install cipher-sdk.jar to the local Maven repository and add dependency libraries by configuring pom.xml; If the project is not built using a dependency management tool, copy cipher-sdk.jar to the project's lib directory and add it to the classpath; S4 Modify the SDK configuration file: store sdk.properties in the resource directory; S5 Modify the driver: Change the data connection driver to the SDK driver class com.sec.sdk.jdbc.CipherDriver.

4. The method for implementing a secret review SDK based on data security according to claim 3, characterized in that: The installation command to add dependencies in step S3 is: mvn install:install-file -DgroupId=com.sec -DartifactId=cipher-sdk -Dversion=small -Dfile=cipher-sdk.jar -Dpackaging=jar.

5. The method for implementing a secret review SDK based on data security according to claim 3 is characterized in that: The specific content of step S4 is as follows: sdk.server.host=[Secret review server IP] sdk.server.port=8216 sdk.socket.timeout=60 sdk.appId=[AppId comes from the application management service] sdk.secretKey = [SecretKey comes from the application management service].