Data security protection method and device, computer equipment and readable storage medium

By setting the validity period of symmetric keys and regularly updating them, combining the grayscale release mechanism and platform gateway detection, the problems of large loss in data encryption performance, complex certificate management and difficult private key leakage detection in the existing technology are solved, and efficient and secure data processing and certificate management are achieved.

CN119939622APending Publication Date: 2025-05-06HANGZHOU PINGPONG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411938326.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, there are problems with large performance losses in the data encryption and signature process, especially in high concurrency scenarios, and the management of developer certificates and platform certificates expire is complex, and there are defects in private key leakage detection and processing.

Method used

By setting the validity period for the symmetric key and periodically updating the keys during the validity period, we avoid the need to generate a random key for each service processing request, reducing the performance loss of encryption and decryption. At the same time, the grayscale release mechanism is used to update the developer certificate, and the private key leakage is detected through the platform gateway, and the certificate and key are updated in a timely manner.

Benefits of technology

It effectively reduces performance losses in the data encryption and signature process, improves data security and processing efficiency, simplifies the management process of certificates and keys, and reduces the risks caused by private key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939622A_ABST
    Figure CN119939622A_ABST
Patent Text Reader

Abstract

The invention relates to a data security protection method and device, computer equipment and a readable storage medium. The method comprises the following steps: acquiring key information for encryption from a cache of a client according to a first preset detection period, wherein the key information comprises a first symmetric key and a first validity period of the first symmetric key; under the condition that the first validity period is not within the first preset time period, sending a key updating request to a platform gateway; receiving update key information sent by the platform gateway in response to the key update request, and determining a second symmetric key and a second validity period of the second symmetric key according to the update key information; updating the states of the first symmetric key and the second symmetric key, and determining the second symmetric key as the current key; and performing security protection processing on service data corresponding to the service processing request according to the current key under the condition that the service processing request is detected and within the second validity period. By adopting the method, the performance loss in the data encryption and signature process can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a data security protection method, device, computer equipment and readable storage medium. Background Art

[0002] In the digital age, the integrity and authenticity of data are of vital importance to any organization or individual. As an important means to ensure data security, data tamper prevention is increasingly gaining widespread attention and application. For example, in the application scenario of resource transfer, developers use the API (Application Programming Interface) provided by the platform to complete resource transfer. During the resource transfer process, the public network will be used, which poses security risks such as man-in-the-middle attacks. Therefore, data security protection is required.

[0003] In the related art, data security protection can be achieved through data encryption and data signing. However, the data encryption and signing in the related art have the problem of large performance loss. Summary of the invention

[0004] Based on this, it is necessary to provide a data security protection method, device, computer equipment, computer-readable storage medium and computer program product that can reduce performance loss in data encryption and signing processes in response to the above-mentioned technical problems.

[0005] In a first aspect, the present application provides a data security protection method, which is applied to a client and includes:

[0006] Acquire key information for encryption from the cache of the client according to a first preset detection period, the key information including a first symmetric key and a first validity period of the first symmetric key;

[0007] If the first validity period is not within a first preset time period, sending a key update request to the platform gateway;

[0008] Receiving the updated key information sent by the platform gateway in response to the key update request, and determining a second symmetric key and a second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period;

[0009] Updating the states of the first symmetric key and the second symmetric key, and determining the second symmetric key as the current key;

[0010] When a service processing request is detected and within the second validity period, security protection processing is performed on the service data corresponding to the service processing request according to the current key.

[0011] In one embodiment, the method further comprises:

[0012] In the case where the state of the first symmetric key and the state of the second symmetric key fail to be updated, if there is a business processing request, executing the step of sending a key update request to the platform gateway, and determining the second symmetric key as the current key;

[0013] Within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0014] In one embodiment, the receiving the updated key information sent by the platform gateway in response to the key update request, and determining the second symmetric key and the second validity period of the second symmetric key according to the updated key information, includes:

[0015] Receiving the updated key information sent by the platform gateway in response to the key update request, the updated key information including the key-encrypted data with signature and the second validity period of the key-encrypted data with signature; the encrypted data with signature is encrypted using the current developer certificate public key of the client and signed with the private key of the platform gateway;

[0016] Obtaining the public key of the platform gateway, using the public key to verify the signature of the key-encrypted data with the signature, and after the signature verification is passed, using the private key corresponding to the current developer certificate stored in the client to decrypt the key-encrypted data to obtain the second symmetric key;

[0017] The second symmetric key and the second validity period are stored in a cache of the client.

[0018] In one embodiment, the updated key information includes a key serial number of the second symmetric key, and the performing security protection processing on the business data corresponding to the business processing request according to the current key includes:

[0019] Create a corresponding entity object according to the interface, and assign values ​​to the entity object according to the business data;

[0020] Acquire a preset sensitive field from the cache according to the entity object type of the entity object, and encrypt the sensitive field data of the entity object using the second symmetric key to obtain encrypted sensitive data;

[0021] Sending the message carrying the encrypted sensitive data to the platform gateway.

[0022] In one embodiment, the method further comprises:

[0023] Obtaining the first developer certificate of the client and a third validity period of the first developer certificate from the cache according to a second preset detection period;

[0024] If the third validity period is not within the second preset time period, sending a certificate update request to the platform gateway;

[0025] receiving updated certificate information sent by the platform gateway in response to the certificate update request, and determining a second developer certificate and a fourth validity period of the second developer certificate according to the updated certificate information; the fourth validity period is later than the third validity period;

[0026] The second developer certificate is released in a grayscale manner. When the grayscale release is completed, the status of the first developer certificate and the second developer certificate is updated, and the second developer certificate is determined as the current developer certificate.

[0027] In one embodiment, the receiving the updated certificate information sent by the platform gateway in response to the certificate update request, and determining the second developer certificate and the fourth validity period of the second developer certificate according to the updated certificate information, includes:

[0028] Receiving the updated certificate information sent by the platform gateway in response to the key update request, the updated certificate information including the signed certificate encrypted data and the second validity period of the signed certificate encrypted data; the signed certificate encrypted data is encrypted using the first developer certificate public key and signed using the platform gateway private key;

[0029] Obtaining the public key of the platform gateway, using the public key to verify the encrypted data of the signed certificate, and after the verification is passed, decrypting the encrypted data using the private key corresponding to the first developer certificate to obtain the second developer certificate;

[0030] The second developer certificate and the fourth validity period are stored in a cache of the client.

[0031] In one embodiment, the grayscale release of the second developer certificate includes:

[0032] determining, from the platform gateway, all interfaces associated with the client service;

[0033] The interfaces are divided according to the business processing attributes of the interfaces to obtain multiple groups of interface sets for grayscale release; the grayscale release priorities of the interfaces combined are different;

[0034] According to the grayscale release priority, the grayscale release of the second developer certificate is performed in sequence for the corresponding interface sets according to a preset ratio until the grayscale release of the second developer certificate is completed for all interfaces.

[0035] In one embodiment, the method further comprises:

[0036] Receiving a key abnormality prompt sent by the platform gateway in response to the message;

[0037] According to the key abnormality prompt, the current developer certificate and the private key corresponding to the current developer certificate stored in the cache are deleted, and a key update request for the developer certificate and a developer certificate update request are sent to the platform gateway.

[0038] In a second aspect, the present application provides a data security protection method, which is applied to a platform gateway, including:

[0039] Receiving a key update request sent by a client; the key update request is initiated when the client obtains key information for encryption from a cache of the client according to a preset detection period and detects that a first validity period of a first symmetric key in the key information is not within a first preset period of time;

[0040] generating updated key information in response to the key update request;

[0041] The updated key information is sent to the client, so that the client determines the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the status of the first symmetric key and the second symmetric key is updated, and the second symmetric key is determined as the current key; when a business processing request is detected and within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0042] In one embodiment, the method further comprises:

[0043] In response to the service processing request sent by the client, obtaining a message with a signature carried in the service processing request;

[0044] Detecting the private key corresponding to the current developer certificate of the client according to the signed message, and generating a key abnormality prompt when an abnormality of the private key is detected;

[0045] The key abnormality prompt is sent to the client, so that the client deletes the current symmetric key and the current developer certificate stored in the cache, and sends a key update request and a certificate update request to the platform gateway.

[0046] In one embodiment, the detecting the private key corresponding to the current developer certificate of the client according to the signed message includes:

[0047] Obtain the current developer certificate public key of the client to verify the signature of the message. If the signature verification passes, if the IP address carried in the message is not the preset IP address, it is determined that the private key of the platform gateway is abnormal; or

[0048] In the case where the signature verification is passed, if the call information of the call interface associated with the message does not meet the preset call conditions, then the private key of the platform gateway is abnormal; or

[0049] In the case where the signature verification passes, if the verification of the business data carried by the message fails, it is determined that the private key of the platform gateway is abnormal; or

[0050] When the signature verification passes, if the client corresponding to the message is not a preset client, it is determined that the current developer certificate private key is abnormal.

[0051] In a third aspect, the present application further provides a data security protection device, the device comprising:

[0052] A detection module, configured to obtain key information for encryption from a cache of the client according to a first preset detection period, wherein the key information includes a first symmetric key and a first validity period of the first symmetric key;

[0053] A sending module, configured to send a key update request to a platform gateway when the first validity period is not within a first preset time period;

[0054] A data processing module, configured to receive the updated key information sent by the platform gateway in response to the key update request, and determine the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period;

[0055] An updating module, used for updating the states of the first symmetric key and the second symmetric key, and determining the second symmetric key as the current key;

[0056] The data security protection processing module is used to perform security protection processing on the business data corresponding to the business processing request according to the current key when a business processing request is detected and within the second validity period.

[0057] In a fourth aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps recorded in any of the above embodiments when executing the computer program.

[0058] In a fifth aspect, the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps recorded in any of the above embodiments are implemented.

[0059] In a sixth aspect, the present application also provides a computer program product, including a computer program, which implements the steps recorded in any of the above embodiments when executed by a processor.

[0060] The above-mentioned data security protection method, device, computer equipment, computer-readable storage medium and computer program product, by setting a validity period for the symmetric key, do not need to generate a random key for each business processing request separately during the validity period, thereby avoiding the performance loss caused by encryption and decryption every time. That is to say, compared with each call by the developer application to generate a new random key, the performance is greatly improved through public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly checked for expiration and the symmetric key in the client is updated in time to improve security. Furthermore, compared with the symmetric key being generated locally at the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of interception, reduces the risk of exposure on the terminal side, and improves security. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0062] Figure 1 An application environment diagram of a data security protection method in an embodiment;

[0063] Figure 2 A schematic diagram of a data security protection method in one embodiment;

[0064] Figure 3 A schematic diagram of a process of updating a symmetric key in one embodiment;

[0065] Figure 4 This is an example diagram of a platform gateway cache key in an embodiment;

[0066] Figure 5 An example diagram of a key replacement process in an embodiment;

[0067] Figure 6A schematic diagram of a safety protection processing method in one embodiment;

[0068] Figure 7 A schematic diagram of a process for encrypting sensitive fields in one embodiment;

[0069] Figure 8 A schematic diagram of a flow chart of a method for lossless replacement of a developer certificate in one embodiment;

[0070] Fig. 9 A flowchart of lossless replacement of a developer certificate in an embodiment;

[0071] Fig.10 A schematic diagram of a flow chart of a method for replacing a platform gateway private key leak in an embodiment;

[0072] Fig.11 A flowchart of replacing a developer's private key leak in one embodiment;

[0073] Fig.12 A schematic diagram of a developer side caching a developer certificate and a platform certificate in one embodiment;

[0074] Fig.13 A flowchart of replacing a platform private key leak in an embodiment;

[0075] Fig.14 A schematic diagram of a platform caching developer certificates and platform certificates in one embodiment;

[0076] Fig.15 A schematic diagram of a flow chart of a data security protection method in another embodiment;

[0077] Fig.16 This is an overall architecture diagram of a data security protection method in an embodiment;

[0078] Fig.17 A schematic diagram of the structure of a data security protection device in one embodiment;

[0079] Fig.18 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0080] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0081] API: Application Programming Interface, a set of features and rules in a software application that allows other software to interact with it.

[0082] Symmetric encryption: An encryption method that uses the same key for encryption and decryption.

[0083] Asymmetric encryption: The encryption key and decryption key are completely different, one is the public key and the other is the private key, and it is impossible to derive either one from the other.

[0084] RSA: Rivest-Shamir-Adleman (RSA), named after its developer, is an asymmetric encryption technique that uses two different but related encryption keys (a private key and a public key). RSA encryption uses opposing keys to encrypt and decrypt data.

[0085] Signature: A string of numbers that can only be generated by the sender of the information and cannot be forged by others, usually implemented using an RSA private key.

[0086] Signature verification: The recipient of the information determines whether the information has been tampered with by verifying the signature, which is generally achieved using the RSA public key.

[0087] Message digest: Extract fingerprint information from all data to implement functions such as data signature and data integrity verification.

[0088] It should be noted that the public key and private key in the developer certificate or platform certificate correspond one to one.

[0089] In the application scenario of resource transfer, developers use the API (Application Programming Interface) provided by the platform to complete resource transfer. During the resource transfer process, it will pass through the public network, which may cause security risks such as man-in-the-middle attacks. For example, when developers use the API provided by the platform to obtain the capabilities provided by the platform, it will pass through the public network, which may cause security risks such as man-in-the-middle attacks. Therefore, data encryption and signature are more important. However, there are currently the following problems with data encryption and signature:

[0090] First, each call is made by the developer application to generate a new random key, which is encrypted by the platform certificate public key and decrypted by the server with a private key. Asymmetric encryption has a large performance loss, which is particularly obvious under high concurrency. Second, the entire HTTP request body that needs to be processed by the business needs to be encrypted, which consumes a lot of resources and is slow. Third, when the developer certificate and platform certificate expire, developers are currently notified through email, in-site messages, etc., but developers may forget, and the operation is also relatively complicated, affecting the normal development of the business. Fourth, there is currently no effective means to detect whether the private key has been leaked. Basically, when there are serious problems with the business, both parties will find that it was called by the attacker after investigation. However, when the private key is leaked, it needs to be handled urgently and the other party needs to be informed. Communication, discarding the private key, applying for a new certificate, and application deployment take a long time.

[0091] In response to the technical problem of large performance loss in the above-mentioned issues, a data security protection method is proposed. This method sets a validity period for the symmetric key and regularly updates the symmetric key according to a first preset detection period. During the validity period of the symmetric key, security protection processing of business data can be achieved based on the symmetric key.

[0092] The data security protection method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage device can store the data that the terminal 102 or the server 104 needs to process. The data storage device can be integrated on the terminal 102 or the server 104, or it can be placed on a cloud server or other network server. Among them, the terminal 102 can be a client, and the terminal 102 can be but not limited to various personal computers, laptops, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The server 104 can be a platform gateway, and the server 104 can also be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0093] Correspondingly, based on the above application environment, the client obtains key information used for encryption from the client's cache according to a first preset detection cycle, and the key information includes a first symmetric key and a first validity period of the first symmetric key; when the first validity period is not within the first preset time period, a key update request is sent to the platform gateway; the updated key information sent by the platform gateway in response to the key update request is received, and the second symmetric key and the second validity period of the second symmetric key are determined according to the updated key information; the second validity period is later than the first validity period; the status of the first symmetric key and the second symmetric key is updated, and the second symmetric key is determined as the current key; when a business processing request is detected and is within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0094] In an exemplary embodiment, Figure 2 As shown, a data security protection method is provided, which is applied to Figure 1 The terminal in the example is used for explanation, and the terminal is a client, and the following steps 202 to 210 are included. Among them:

[0095] Step 202: Acquire key information for encryption from a cache of the client according to a first preset detection period, where the key information includes a first symmetric key and a first validity period of the first symmetric key.

[0096] There is at least one developer on the client, and each developer corresponds to a symmetric key. In addition to the first symmetric key and the first validity period of the first symmetric key, the key information may also include the key state of the first symmetric key and the key serial number. The first symmetric key obtained at this time can be regarded as the current symmetric key, and the corresponding key state can be the current key.

[0097] Exemplarily, each developer on the client obtains key information used for encryption from a cache of the client according to a first preset detection period.

[0098] Step 204: When the first validity period is not within the first preset time period, a key update request is sent to the platform gateway.

[0099] The method for determining that the first validity period is not within the first preset period can be to determine the remaining effective time of the first symmetric key based on the current time. If the remaining effective time is less than the preset time, it is determined that the first validity period is not within the first preset period. For example, the developer SDK periodically obtains key information from the cache, subtracts the validity period from the current time, and obtains the remaining days of the key. If the remaining days of the key are less than the preset time of 3 days, it is determined that the first validity period is not within the first preset period, and the current symmetric key needs to be updated.

[0100] Step 206: Receive the updated key information sent by the platform gateway in response to the key update request, and determine the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period.

[0101] The updated key information includes key-encrypted data with signature.

[0102] For example, when the developer needs to update the first symmetric key, he sends a key update request to the platform gateway and calls the platform gateway interface to obtain a new symmetric key, namely the second symmetric key. Further, the platform gateway responds to the key update request, randomly generates a new symmetric key, obtains the developer's current developer certificate public key to encrypt the new symmetric key, obtains key-encrypted data, and then uses the platform gateway's private key to sign the key-encrypted data, returns the key-encrypted data with the signature, and then determines the updated key information.

[0103] The developer receives the updated key information sent by the platform gateway in response to the key update request, obtains the public key of the platform gateway, and uses the public key to verify the signature of the key-encrypted data with the signature. After the signature verification is passed, the private key corresponding to the current developer certificate stored on the client is used to decrypt the key-encrypted data to obtain the second symmetric key; the second symmetric key and the second validity period are stored in the client's database and cache. The cache can be, but is not limited to, JVM memory.

[0104] Step 208: Update the status of the first symmetric key and the second symmetric key, and determine the second symmetric key as the current key.

[0105] Exemplarily, the developer interacts with the platform gateway based on the test interface of the platform gateway, and when the second symmetric key is available, secure, and can replace the first symmetric key in an actual environment, the state of the second symmetric key is updated to the current key, and the state of the first symmetric key is updated from the current key to the non-current key. Further, after the preset extension period, the first symmetric key is deleted.

[0106] In an exemplary embodiment, Figure 3 As shown, a symmetric key update flow chart is provided, and the developer SDK periodically obtains key information from the cache, subtracts the validity period of the first symmetric key in the key information from the current time, and obtains the remaining days of the key. If the remaining days of the key are not less than 3 days, there is no need to update, otherwise, the developer calls the platform gateway interface to obtain a new symmetric key, the platform gateway generates a new key, encrypts it with the developer's public key, and then signs it with the platform's private key and returns it to the developer, that is, the updated key information sent by the platform gateway in response to the key update request. The developer uses the platform gateway public key to verify the signature. Once it passes, it uses the private key corresponding to the current developer certificate to decrypt it to obtain the new key, that is, the second symmetric key. The new key is stored in the database and cached in the memory, such as Figure 4 As shown, it is an example diagram of developers caching keys on the platform gateway side (i.e., the platform side), including developer dev001, developer dev002, and developer dev003. The plaintext keys corresponding to the developers are key001, key002, and key003, and the corresponding serial numbers are ser001, ser002, and ser003. The validity period of different keys of the same developer may be different, and the validity period of keys of different developers may be the same.

[0107] Developers use the test interface to interact with the platform. After passing the test, the new key is set as the current key and the old key is set as the non-current key. When business processing is required, the new key is used to encrypt sensitive data; the old key can be deleted after a preset period of time. Figure 5 As shown, it is an example diagram of the key replacement process in an exemplary embodiment, the current key is key 1, including the key plaintext key001 of key 1, the key serial number ser001, the key status (current key) and the validity period 1, a new key 2 is added, including the key plaintext key002 of key 2, the key serial number ser001, the key status (non-current key) and the validity period 2, the status of key 1 and key 2 are updated, the status of key 1 is set to non-current key, the status of key 2 is set to current key, key 1 expires and is deleted, leaving only key 2.

[0108] Step 210: When a service processing request is detected and is within the second validity period, security protection processing is performed on the service data corresponding to the service processing request according to the current key.

[0109] Among them, the security protection processing can be to encrypt sensitive data in the business data, and to sign other business data except sensitive data in the business data.

[0110] Exemplarily, when a business processing request is detected and within the second validity period, before sending the business processing request to the platform gateway, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0111] In the above data security protection method, by setting a validity period for the symmetric key, it is not necessary to generate a random key for each business processing request separately for each business processing request within the validity period, thereby avoiding the performance loss caused by encryption and decryption each time. That is to say, compared with each call by the developer application to generate a new random key, the performance is greatly improved through public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly checked for expiration and the symmetric key in the client is updated in advance to improve security. Furthermore, compared with the symmetric key being generated locally in the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of interception, reduces the risk of exposure on the terminal side, and improves security.

[0112] It is understandable that the data security protection in the related technologies is all oriented towards consumers (ie toB), and the embodiments of the present application are oriented towards enterprises (ie ToB). There are many objects in the data protection mode under the consumer-oriented mode, and the symmetric keys are all randomly generated. If the corresponding validity period is set, it will lead to poor consumer experience. Consumers will be notified of each update, which brings a lot of operational inconveniences. The compliance requirements in different regions are different, which increases the complexity of management, security costs and security risks.

[0113] Furthermore, the symmetric key update may fail in advance. When the interface is called, if it is found that the symmetric key has expired and has not been updated, a call will be made to update the symmetric key.

[0114] In an exemplary embodiment, when the state of the first symmetric key and the state of the second symmetric key fail to be updated, if there is a business processing request, the step of sending a key update request to the platform gateway is executed, and the second symmetric key is determined as the current key; when it is within the second validity period, the business data corresponding to the business processing request is processed for security protection according to the current key. This method ensures security by performing symmetric key update compensation when calling the interface in the case of early update failure.

[0115] In an exemplary embodiment, receiving the updated key information sent by the platform gateway in response to the key update request, and determining the second symmetric key and the second validity period of the second symmetric key according to the updated key information, includes:

[0116] Receive the updated key information sent by the platform gateway in response to the key update request, update the key encrypted data with signature and the second validity period of the key encrypted data with signature in the key information; the encrypted data with signature is encrypted using the public key of the current developer certificate of the client and signed by the private key of the platform gateway; obtain the public key of the platform gateway, use the public key to verify the signature of the key encrypted data, after the signature verification is passed, use the private key corresponding to the current developer certificate stored in the client to decrypt the key encrypted data to obtain the second symmetric key; store the second symmetric key and the second validity period in the client's cache. In this way, by updating the developer's symmetric key in the client in advance and storing the new symmetric key in the cache, security can be ensured and the risks and inconveniences caused by key updates can be reduced.

[0117] To solve the problem of encrypting the entire HTTP request body, which consumes a lot of resources and is slow, the following security protection method is provided: Figure 6 As shown, it includes steps 602 to 606, wherein:

[0118] Step 602: Create a corresponding entity object according to the interface, and assign values ​​to the entity object according to the business data.

[0119] Step 604: Obtain a preset sensitive field from the cache according to the entity object type of the entity object, and encrypt the sensitive field data of the entity object using the second symmetric key to obtain encrypted sensitive data.

[0120] If the preset sensitive field does not exist in the cache, the preset sensitive field can be obtained by obtaining the entity class marked with the sensitive field from the platform gateway through reflection.

[0121] Step 606: Send the message carrying the encrypted sensitive data to the platform gateway.

[0122] It is understandable that when a developer sends a business processing request to the platform gateway, the message including the business processing request will be sent to the platform gateway through the existing communication protocol. The platform gateway will first verify the signature of the message based on the developer's current developer certificate public key. After the signature verification is passed, the encrypted sensitive data will be decrypted using the symmetric key corresponding to the current developer certificate to obtain all the business plaintext data, and then the corresponding business processing will be performed on this basis.

[0123] The message includes a request header and a request body. The request header includes metadata, and the request body includes business data. The metadata may be a signature, timestamp, server address, etc. The request body may include business data, wherein sensitive fields in the business data are encrypted.

[0124] In an exemplary embodiment, Figure 7 As shown, a flowchart of sensitive field encryption is provided. Before calling the API, the developer obtains the list of sensitive fields of the corresponding entity class from the cache. If there is no preset sensitive field, the preset sensitive field is obtained from the entity class marked with sensitive fields in the platform gateway by reflection. If it exists, the entity object is assigned a value according to the business data, and the sensitive field of the business data is obtained. The sensitive field is encrypted using the second symmetric key to obtain encrypted sensitive data; the encrypted sensitive data is signed according to the private key corresponding to the current developer certificate of the client to obtain encrypted sensitive data with a signature; the message carrying the encrypted sensitive data is sent to the platform gateway. The platform gateway uses the symmetric key to decrypt the encrypted sensitive data according to the preset sensitive fields in the cache to obtain the business plaintext data, that is, the original message, and perform business processing.

[0125] In the above embodiment, by encrypting the designated sensitive fields, the technical effect of reducing resource loss and improving processing speed is achieved.

[0126] In order to ensure the security protection of data, in an exemplary embodiment, the first developer certificate of the client and the third validity period of the first developer certificate can also be obtained from the cache according to the second preset detection cycle; when the third validity period is not within the second preset time period, a certificate update request is sent to the platform gateway; the updated certificate information sent by the platform gateway in response to the certificate update request is received, and the second developer certificate and the fourth validity period of the second developer certificate are determined according to the updated certificate information; the fourth validity period is later than the third validity period; the second developer certificate is gray-released, and when the gray-release is completed, the status of the first developer certificate and the second developer certificate is updated, and the second developer certificate is determined as the current developer certificate.

[0127] Among them, the third validity period not being within the second preset period can be based on the current time to determine the effective remaining time of the third validity period, if the effective remaining time is less than the preset time, then it is determined that the third validity period is not within the second preset period. For example, the developer SDK periodically obtains the third validity period of the developer certificate from the cache, subtracts the third validity period from the current date, and if it is less than 30 days, it is determined that the third validity period is not within the second preset period. When the grayscale release is completed, the status of the first developer certificate and the second developer certificate is updated, the second developer certificate is determined as the current developer certificate, the first developer certificate is determined as the non-current certificate, and the first developer certificate is deleted after expiration.

[0128] Further, receiving the updated certificate information sent by the platform gateway in response to the certificate update request, and determining the second developer certificate and the fourth validity period of the second developer certificate according to the updated certificate information, includes:

[0129] Receive the updated certificate information sent by the platform gateway in response to the key update request, update the signed certificate encrypted data and the second validity period of the signed certificate encrypted data in the certificate information; the signed certificate encrypted data is encrypted using the first developer certificate public key and signed by the platform gateway private key; obtain the platform gateway public key, use the public key to verify the signed certificate encrypted data, after the verification is passed, use the private key corresponding to the first developer certificate to decrypt the encrypted data to obtain the second developer certificate; store the second developer certificate and the fourth validity period in the client's cache. Further, store the second developer certificate and the public and private keys corresponding to the second developer certificate in the database and cache.

[0130] Grayscale release of the second developer certificate provides a lossless replacement method for the developer certificate, such as Figure 8 As shown, it includes steps 802 to 806, wherein:

[0131] Step 802, determine all interfaces associated with the client service from the platform gateway.

[0132] Among them, all interfaces associated with client services can be understood as all interfaces associated with developer services on the client. All interfaces include test interfaces and business interfaces of different importance.

[0133] Step 804: Divide the interfaces according to their business processing attributes to obtain multiple groups of interface sets for grayscale release; the grayscale release priorities of the interfaces are different.

[0134] Exemplarily, interfaces are divided according to their business processing attributes to obtain multiple groups of interface sets for grayscale release, the interface sets including a test interface set, a first business interface set, and a second business interface set, wherein the priority of the test interface set is lower than that of the first business interface set, and the priority of the first business interface set is lower than that of the second business interface set.

[0135] Step 806 , according to the grayscale release priority, grayscale release of the second developer certificate is performed in sequence for the corresponding interface sets according to a preset ratio until the grayscale release of the second developer certificate is completed for all interfaces.

[0136] For example, for the test interface, the second developer certificate is used to perform an interactive test with the platform gateway. If the interaction is successful, the first business interface with a preset proportion (such as 10%, 1 of 10 interfaces) in the first business interface set is interactively tested with the platform gateway using the second developer certificate. If the interaction is successful, the percentage is increased until all first business interface sets are interactively tested with the platform gateway using the second developer certificate; otherwise, a failure alarm is issued and manual intervention is performed. When all first business interface sets complete the grayscale release of the second developer certificate, the second business interface with a preset proportion (such as 10%, 1 of 10 interfaces) in the second business interface set is interactively tested with the platform gateway using the second developer certificate. If the interaction is successful, the percentage is increased until all second business interface sets are interactively tested with the platform gateway using the second developer certificate; otherwise, a failure alarm is issued and manual intervention is performed. For example, including interface 1, interface 2, interface 3 and interface 4, the importance of interface 1 is less than interface 2, interface 3 and interface 4, interface 1 is tested first, and then interface 2, interface 3 and interface 4 are tested in sequence.

[0137] In an exemplary embodiment, Fig. 9As shown, a flowchart for lossless replacement of developer certificates is provided. The developer SDK periodically obtains the validity period of the developer certificate from the cache and subtracts it from the current date. If it is less than 30 days, a new developer certificate is applied for; otherwise, exit. The developer calls the platform interface to obtain a new certificate. The platform generates a new certificate, encrypts it with the developer's old public key, and signs the data with the platform's private key. The developer uses the platform's public key to verify the signature and the developer's old private key to decrypt it to obtain new public and private keys. The new certificate and public and private keys are placed in the database and cache, and the status of the old developer certificate is set to a non-current certificate. Use the developer's new certificate to test the interface. If the interaction is successful, select some (for example, 10%, 1 out of 10 interfaces) of the interfaces with a certain importance (i.e., the first business interface set) to use the new certificate. If the interaction is successful, the percentage is increased until all interfaces with a certain importance use the new certificate; otherwise, a failure alarm is issued and manual intervention is required. Select some (e.g. 10%, 1 out of 10 interfaces) interfaces with high importance and use the new certificate. If the interaction is successful, increase the percentage until all interfaces with high importance (i.e., the second business interface set) use the new certificate. Otherwise, a failure alarm is issued and manual intervention is required. When the grayscale release is completed, use the new developer certificate, set the new certificate as the current certificate, set the old certificate as the non-current certificate, and delete it after it expires.

[0138] In the above embodiment, by regularly checking the validity period of the developer and platform certificates, new developer and platform certificates are downloaded in advance through the interface, and the smooth switching of the old and new certificates is implemented in grayscale according to the built-in test interface, interface importance, and percentage. After the new certificate is stable, the new certificate is fully switched and the old certificate is offline, avoiding the expiration of the developer certificate and platform certificate. At present, notifications through email, site messages, etc. will be forgotten, and the operation is also relatively complicated, affecting the normal development of the business.

[0139] Optionally, in an exemplary embodiment, if it is detected that the validity period of the platform certificate is not within a preset time period, the platform will generate a corresponding new platform certificate. The specific generation method can be implemented by existing methods and will not be described in detail here.

[0140] In view of the technical problems that there are effective means to detect whether the private key is leaked in related technologies, and when the private key is leaked, it is necessary to deal with it urgently and inform the other party, communicate, abandon the private key, apply for a new certificate, and deploy the application, which takes a long time, a platform gateway private key leakage replacement method is proposed, such as Fig.10 As shown, it includes steps 1002 to 1004, wherein:

[0141] Step 1002: Receive a key abnormality prompt sent by the platform gateway in response to the message.

[0142] Among them, the platform gateway will detect the leakage of the developer's private key. When the private key is detected, it will generate a corresponding key abnormality prompt and send the key abnormality prompt to the client, so that the client can delete the private key and certificate stored in the cache, call the platform developer certificate cancellation interface, and the platform will verify it. The certificate will be deleted from the platform side, and the platform interface will be called to apply for a new certificate, and the developer certificate key update request and developer certificate update request will be sent to the platform gateway.

[0143] The methods for determining whether the developer's private key is abnormal include any of the following:

[0144] Obtain the client's current developer certificate public key to verify the message. If the verification passes, but the IP address carried in the message is not the preset IP address, it is determined that the private key of the current developer certificate is abnormal. For example, the platform gateway platform receives the request sent by the client. If the verification passes, but the source IP corresponding to the message is not in the agreed IP list, confirm with the developer that it is not the developer's export IP, or search the platform to search for the private key.

[0145] When the signature verification passes, if the call information of the calling interface associated with the message does not meet the preset call conditions, the private key of the platform gateway is abnormal. For example, the signature verification passes, but the call information does not meet the preset call conditions, that is, the difference between the call frequency, time period and usual statistics is greater than the preset difference.

[0146] If the business data carried by the message fails to be verified when the signature verification is passed, it is determined that the private key of the platform gateway is abnormal. If the client corresponding to the message is not the preset client when the signature verification is passed, it is determined that the private key of the platform gateway is abnormal.

[0147] Step 1004: based on the key abnormality prompt, delete the current developer certificate and the private key corresponding to the current developer certificate stored in the cache, and send a key update request for the developer certificate and a developer certificate update request to the platform gateway.

[0148] For example, if the private key corresponding to the current developer certificate is leaked, the developer SDK deletes the private key and certificate from the cache and database. The developer calls the platform developer certificate cancellation interface. After the platform verifies the certificate, it deletes the certificate from the platform side. The developer calls the platform interface to apply for a new certificate. The platform generates a new developer certificate, encrypts it with a symmetric key, and signs the data with the platform private key. The developer uses the platform public key to verify the signature and the symmetric key to decrypt it to obtain a new certificate and public and private keys. The new developer certificate and public and private keys are stored in the database and cache, and the status is set to the current developer certificate. The private key is used for signing in the future.

[0149] Optionally, in an exemplary embodiment, as Fig.11 As shown, a flowchart for replacing the developer's private key leakage is provided. When the developer's private key is detected to be leaked, the developer SDK deletes the private key corresponding to the current developer certificate and the current developer certificate from the cache and database. The developer calls the platform developer certificate invalidation interface. After the platform verifies the certificate, it deletes the certificate from the platform side. The developer calls the platform interface to apply for a new developer certificate. The platform generates a new developer certificate, encrypts it with a symmetric key, and signs the data with the platform private key. The developer uses the platform public key to verify the signature and decrypts it with the symmetric key to obtain the new certificate and public and private keys. The new developer certificate and public and private keys are stored in the database and cache, and the status of the new developer certificate is set to the current certificate. In subsequent processing, the private key corresponding to the new developer certificate is used for signing. In this way, security and convenience are greatly improved through the platform's built-in key leakage detection, alarm, and rapid replacement mechanism. It is understandable that the developer-side cache has developer certificates and platform certificates, such as Fig.12 As shown, it is a schematic diagram of a developer-side cache developer certificate and platform certificate in an exemplary embodiment. The cached developer certificate includes a developer ID, a public key, a serial number, and a validity period. The cached developer certificate includes a public key, a private key, a serialization, a current certificate, and a validity period.

[0150] It is understandable that the key abnormality prompt can also be a prompt for the leakage of the platform private key. However, the platform gateway private key is only stored on the platform. The following is a flowchart of replacing the platform private key leakage in an exemplary embodiment, such as Fig.13 As shown, for the convenience of description, the platform gateway is referred to as the platform below. When the platform detects that the platform private key is leaked, the platform private key and certificate are deleted from the cache and database, the platform generates new public and private keys and platform certificates, stores the new public and private keys and platform certificates in the database and cache, and sets the status of the new platform certificate to the current certificate. When the developer obtains the key exception prompt sent by the platform, the platform interface is called and the PLAT_LEAK response code is returned. The developer deletes the old platform certificate and platform public key from the database and cache. The interface is called to obtain the latest platform certificate. The platform uses a symmetric key to encrypt the latest platform certificate, and then generates a message digest for the data. The developer verifies the message digest, decrypts with the symmetric key, and obtains the new platform certificate and platform public key. The developer verifies the message digest sent by the platform, decrypts with the symmetric key, and obtains the new platform certificate and platform public key. The developer stores the new platform certificate and platform public key in the database and cache, and uses the new platform certificate public key for signature verification in subsequent business processing.

[0151] Among them, the detection method of platform private key leakage can be to detect the configuration information of the private key in the source code (i.e., the public code repository). If the configuration information of the private key exists, it indicates that the platform private key has been leaked. Alternatively, if the confidentiality of the platform private key authority is changed to public, it indicates that the private key may have been leaked.

[0152] It is understandable that the platform caches the developer certificate and the platform certificate, such as Fig.14 As shown, it is a schematic diagram of a platform-side cached developer certificate and a platform certificate in an exemplary embodiment. The cached developer certificate includes a developer ID, a public key, a serial number, and a validity period. The cached platform certificate includes a public key, a private key, a serialization, a current certificate, and a validity period.

[0153] In the above-mentioned platform gateway private key leakage replacement method, by detecting the platform gateway private key, in the event of a private key leak, the platform promptly notifies the client so that the client can update the certificate and symmetric key in time, and through the platform's built-in key leakage detection, alarm and rapid replacement mechanism, the security and convenience are greatly improved. Based on the same inventive concept, the above-mentioned data security protection method can also be applied to the platform gateway. The implementation solution for solving the problem provided by the data security protection method applied to the platform gateway is similar to the implementation solution recorded in the above-mentioned method, so the specific limitations of one or more data security protection method embodiments applied to the platform gateway provided below can refer to the limitations of the data security protection method applied in the client above, and the specific implementation in the following embodiments will not be repeated here.

[0154] In an exemplary embodiment, Fig.15 As shown, a data security protection method is provided, which is applied to Figure 1 The server in the example is used for explanation, the server is a platform gateway, and the steps include the following steps 1502 to 1506. Among them:

[0155] Step 1502, receiving a key update request sent by the client; the key update request is initiated when the client obtains key information used for encryption from the client's cache according to a preset detection period and detects that the first validity period of the first symmetric key in the key information is not within a first preset period of time.

[0156] Step 1504: Generate updated key information in response to the key update request.

[0157] Step 1506, sends the updated key information to the client, so that the client determines the second symmetric key and the second validity period of the second symmetric key according to the updated key information; updates the status of the first symmetric key and the second symmetric key, and determines the second symmetric key as the current key; and when a business processing request is detected and is within the second validity period, performs security protection processing on the business data corresponding to the business processing request according to the current key.

[0158] In the above data security protection method, by setting a validity period for the symmetric key, it is not necessary to generate a random key for each business processing request separately for each business processing request within the validity period, thereby avoiding the performance loss caused by encryption and decryption each time. That is to say, compared with each call by the developer application to generate a new random key, the performance is greatly improved through public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly checked for expiration and the symmetric key in the client is updated in advance to improve security. Furthermore, compared with the symmetric key being generated locally in the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of interception, reduces the risk of exposure on the terminal side, and improves security.

[0159] In an exemplary embodiment, the platform responds to a business processing request sent by a client and obtains a signed message carried in the business processing request; detects the private key corresponding to the current developer certificate of the client based on the signed message, and generates a key abnormality prompt when an abnormality is detected in the private key; sends the key abnormality prompt to the client so that the client deletes the current symmetric key and the current developer certificate stored in the cache, and sends a key update request and a certificate update request to the platform gateway.

[0160] In an exemplary embodiment, a method for detecting a private key leakage is provided, comprising:

[0161] Obtain the client's current developer certificate public key to verify the message. If the verification passes, but the IP address carried in the message is not the preset IP address, the private key of the platform gateway is determined to be abnormal; or if the verification passes, but the call information of the calling interface associated with the message does not meet the preset call conditions, the private key of the platform gateway is abnormal; or, if the verification passes, but the business data carried by the message fails to be verified, the private key of the platform gateway is determined to be abnormal; or, if the verification passes, but the client corresponding to the message is not the preset client, the developer's private key is determined to be leaked.

[0162] In the above-mentioned developer's private key leakage detection method, the developer's private key is detected through the platform gateway. In the case of private key leakage, the platform promptly notifies the client so that the client can update the certificate and symmetric key in time. The platform's built-in key leakage detection, alarm and rapid replacement mechanism greatly improves security and convenience.

[0163] In an exemplary embodiment, Fig.16As shown, an overall architecture diagram of a data security protection method is provided, including developer applications, platform gateways, and business services, where the developer application SDK can support encryption requests, signature requests, certificate storage, and key storage, and the platform gateway implements certificate management, request signature verification, data decryption, and key management. Business services support business management and business storage. After the platform gateway verifies and decrypts the encrypted data with signatures sent by the client, it forwards the business data to be processed to the business service for business processing.

[0164] Specifically, the client obtains key information used for encryption from the client's cache according to a first preset detection cycle, where the key information includes a first symmetric key and a first validity period of the first symmetric key; when the first validity period is not within the first preset time period, a key update request is sent to the platform gateway; updated key information sent by the platform gateway in response to the key update request is received, and a second symmetric key and a second validity period of the second symmetric key are determined according to the updated key information; the second validity period is later than the first validity period; the status of the first symmetric key and the second symmetric key are updated, and the second symmetric key is determined as the current key; when a business processing request is detected and is within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0165] Obtain the first developer certificate of the client and the third validity period of the first developer certificate from the cache according to a second preset detection cycle; if the third validity period is not within the second preset time period, send a certificate update request to the platform gateway; receive the updated certificate information sent by the platform gateway in response to the certificate update request, and determine the second developer certificate and the fourth validity period of the second developer certificate according to the updated certificate information; the fourth validity period is later than the third validity period; perform grayscale release on the second developer certificate, and when the grayscale release is completed, update the status of the first developer certificate and the second developer certificate, and determine the second developer certificate as the current developer certificate.

[0166] When receiving the key exception prompt sent by the platform gateway in response to the message, delete the current symmetric key and the current developer certificate stored in the cache according to the key exception prompt, and send a key update request and a certificate update request to the platform gateway.

[0167] It can be understood that the specific implementation method in the above embodiment can be implemented in the above-mentioned limited manner, which will not be elaborated here.

[0168] In the above method, by setting the validity period for the symmetric key, it is not necessary to generate a random key for each business processing request during the validity period, thereby avoiding the performance loss caused by encryption and decryption each time. That is to say, compared with the developer application generating a new random key each time, the performance is greatly improved by public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly detected to see if it is invalid and the symmetric key in the client is updated in advance to improve security. Furthermore, compared with the symmetric key being generated locally at the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of being intercepted, reduces the risk of exposure on the terminal side, and improves security. And only sensitive fields are encrypted, which improves performance and reduces the size of transmitted data. The sensitive annotation method is adopted, which is simple to access and reduces intrusion. The SDK integrated certificate replacement realizes smooth switching, which will not affect the business, solves production failures caused by human forgetfulness and manual operation, and greatly improves security and convenience through the platform's built-in key leakage detection, alarm and rapid replacement mechanism.

[0169] The above method can be applied to merchants or institutions that use the open platform provided by a cross-border payment company to complete fund collection and payment needs. The public network will be used in the middle, and there are security risks such as man-in-the-middle attacks, data leakage, and even asset loss. Among them, the platform certificate can be applied for by the platform to the CA, and the developer certificate can use the CA built by the platform. Symmetric encryption uses AES256 bits to meet encryption strength and compliance requirements; asymmetric encryption uses RSA, private key signature, public key verification; public key encryption, private key decryption; platform gateway is implemented using SpringCloud Gateway, and authentication uses JWT Token (server-side storage to improve security); SDK is developed in Java and communicates through OkHttpClient; HTTPS channel encryption uses TLS1.2, which is highly secure.

[0170] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0171] Based on the same inventive concept, the embodiment of the present application also provides a data security protection device for implementing the data security protection method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more data security protection device embodiments provided below can refer to the limitations on the data security protection method above, and will not be repeated here.

[0172] In an exemplary embodiment, Fig.17 As shown, a data security protection device is provided, which includes a detection module 1702, a sending module 1704, a data processing module 1706, an update module 1708 and a security protection module 1710, wherein:

[0173] The detection module 1702 is used to obtain key information used for encryption from the cache of the client according to a first preset detection period, where the key information includes a first symmetric key and a first validity period of the first symmetric key.

[0174] The sending module 1704 is configured to send a key update request to the platform gateway when the first validity period is not within a first preset period of time.

[0175] The data processing module 1706 is used to receive the updated key information sent by the platform gateway in response to the key update request, and determine the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period.

[0176] The updating module 1708 is used to update the status of the first symmetric key and the second symmetric key, and determine the second symmetric key as the current key.

[0177] The security protection module 1710 is used to perform security protection processing on the business data corresponding to the business processing request according to the current key when a business processing request is detected and within the second validity period.

[0178] The above-mentioned data security protection device sets a validity period for the symmetric key. During the validity period, there is no need to generate a random key for each business processing request separately for each business processing request, thereby avoiding the performance loss caused by encryption and decryption each time. That is to say, compared with each call by the developer application to generate a new random key, the performance is greatly improved through public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly checked for expiration and the symmetric key in the client is updated in time to improve security. Furthermore, compared with the symmetric key being generated locally at the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of interception, reduces the risk of exposure on the terminal side, and improves security.

[0179] In an exemplary embodiment, the sending module 1704 is further configured to, when the state of the first symmetric key and the state of the second symmetric key fail to be updated, send a key update request to the platform gateway if there is a business processing request, and determine the second symmetric key as the current key;

[0180] The security protection module 1710 is also used to perform security protection processing on the business data corresponding to the business processing request according to the current key within the second validity period.

[0181] In an exemplary embodiment, the data processing module 1706 is further used to receive the updated key information sent by the platform gateway in response to the key update request, and update the key encrypted data with signature and the second validity period of the key encrypted data with signature in the key information; the encrypted data with signature is encrypted using the current developer certificate public key of the client and signed by the private key of the platform gateway;

[0182] Obtain the public key of the platform gateway, and use the public key to verify the signature of the key-encrypted data. After the signature is verified, use the private key corresponding to the current developer certificate stored on the client to decrypt the key-encrypted data to obtain the second symmetric key;

[0183] In an exemplary embodiment, the apparatus further includes a storage module, configured to store the second symmetric key and the second validity period in a cache of the client.

[0184] The security protection module 1710 is used to create a corresponding entity object according to the interface and assign values ​​to the entity object according to the business data;

[0185] Obtaining a preset sensitive field from the cache according to the entity object type of the entity object, and encrypting the sensitive field data of the entity object using the second symmetric key to obtain encrypted sensitive data;

[0186] Send the message carrying encrypted sensitive data to the platform gateway.

[0187] The detection module 1702 is further configured to obtain the first developer certificate of the client and the third validity period of the first developer certificate from the cache according to a second preset detection period;

[0188] If the third validity period is not within the second preset period, sending a certificate update request to the platform gateway;

[0189] The data processing module 1706 is used to receive the updated certificate information sent by the platform gateway in response to the certificate update request, and determine the second developer certificate and the fourth validity period of the second developer certificate according to the updated certificate information; the fourth validity period is later than the third validity period;

[0190] In an exemplary embodiment, the apparatus further includes a grayscale release module for performing grayscale release on the second developer certificate. When the grayscale release is completed, the status of the first developer certificate and the second developer certificate are updated, and the second developer certificate is determined as the current developer certificate.

[0191] The data processing module 1706 is used to receive the updated certificate information sent by the platform gateway in response to the key update request, and update the certificate encrypted data with signature and the second validity period of the certificate encrypted data with signature in the certificate information; the certificate encrypted data with signature is encrypted by the first developer certificate public key and signed by the platform gateway private key;

[0192] Obtain the public key of the platform gateway, and use the public key to verify the encrypted data of the signed certificate. After the verification is passed, use the private key corresponding to the first developer certificate to decrypt the encrypted data to obtain the second developer certificate.

[0193] The storage module is used to store the second developer certificate and the fourth validity period in a cache of the client.

[0194] The grayscale release module is used to determine all interfaces associated with client services from the platform gateway;

[0195] Divide interfaces according to their business processing attributes to obtain multiple groups of interface sets for grayscale release; each interface has a different grayscale release priority.

[0196] According to the grayscale release priority, the grayscale release of the second developer certificate is carried out in sequence for the corresponding interface sets according to the preset ratio until the grayscale release of the second developer certificate is completed for all interfaces.

[0197] In an exemplary embodiment, the above-mentioned device further includes a key exception processing module, which is used to receive a key exception prompt sent by the platform gateway in response to the message;

[0198] According to the key abnormality prompt, the current developer certificate and the private key corresponding to the current developer certificate stored in the cache are deleted, and a key update request and a developer certificate update request for the developer certificate are sent to the platform gateway.

[0199] In an exemplary embodiment, a data security protection device is provided, the device comprising a request receiving module, a response module and a data sending module, wherein:

[0200] A request receiving module, used to receive a key update request sent by a client; the key update request is initiated when the client obtains key information for encryption from a cache of the client according to a preset detection period and detects that a first validity period of a first symmetric key in the key information is not within a first preset period;

[0201] A response module, used to generate updated key information in response to the key update request;

[0202] A data sending module is used to send updated key information to the client so that the client can determine the second symmetric key and the second validity period of the second symmetric key based on the updated key information; update the status of the first symmetric key and the second symmetric key, and determine the second symmetric key as the current key; when a business processing request is detected and it is within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

[0203] The above-mentioned data security protection device sets a validity period for the symmetric key. During the validity period, there is no need to generate a random key for each business processing request separately for each business processing request, thereby avoiding the performance loss caused by encryption and decryption each time. That is to say, compared with each call by the developer application to generate a new random key, the performance is greatly improved through public key encryption and private key decryption; and the first symmetric key in the cache is detected according to the first preset detection period, and the symmetric key in the cache is regularly checked for expiration and the symmetric key in the client is updated in time to improve security. Furthermore, compared with the symmetric key being generated locally at the sending terminal, it is generated through the platform gateway, and the key does not need to be transmitted in the network, which reduces the risk of interception, reduces the risk of exposure on the terminal side, and improves security.

[0204] In an exemplary embodiment, the response module is used to respond to the service processing request sent by the client and obtain a message with a signature carried in the service processing request.

[0205] In an exemplary embodiment, the above-mentioned device also includes a key anomaly detection module, which is used to detect the private key of the platform gateway according to the signed message, and generate a key anomaly prompt when a private key anomaly is detected.

[0206] In an exemplary embodiment, the data sending module is used to send a key abnormality prompt to the client, so that the client deletes the current symmetric key and the current developer certificate stored in the cache, and sends a key update request and a certificate update request to the platform gateway.

[0207] In an exemplary embodiment, the key anomaly detection module is used to obtain the current developer certificate public key of the client to verify the signature of the message. If the IP address carried in the message is not the preset IP address, it is determined that the private key of the platform gateway is abnormal; or

[0208] If the signature verification passes, but the call information of the call interface associated with the message does not meet the preset call conditions, the private key of the platform gateway is abnormal; or

[0209] If the signature verification passes, but the business data carried in the message fails to be verified, it is determined that the private key of the platform gateway is abnormal; or

[0210] When the signature verification passes, if the client corresponding to the message is not the preset client, it is determined that the private key corresponding to the current developer certificate is abnormal.

[0211] Each module in the above data security protection device can be implemented in whole or in part by software, hardware and their combination. Each module can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0212] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Fig.18As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input system. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input system are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (Near Field Communication, NFC) or other technologies. When the computer program is executed by the processor, a data security protection method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection system or a virtual reality imaging system. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input system of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse.

[0213] Those skilled in the art will understand that Fig.18 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0214] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.

[0215] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0216] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0217] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0218] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.

[0219] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0220] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A data security protection method, characterized in that: Applied to a client, the method comprises: Acquire key information for encryption from the cache of the client according to a first preset detection period, the key information including a first symmetric key and a first validity period of the first symmetric key; If the first validity period is not within a first preset time period, sending a key update request to the platform gateway; Receiving the updated key information sent by the platform gateway in response to the key update request, and determining a second symmetric key and a second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period; Updating the states of the first symmetric key and the second symmetric key, and determining the second symmetric key as the current key; When a service processing request is detected and within the second validity period, security protection processing is performed on the service data corresponding to the service processing request according to the current key.

2. The method according to claim 1, characterized in that The method further comprises: In the case where the state of the first symmetric key and the state of the second symmetric key fail to be updated, if there is a business processing request, executing the step of sending a key update request to the platform gateway, and determining the second symmetric key as the current key; Within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

3. The method according to claim 1, characterized in that The receiving the updated key information sent by the platform gateway in response to the key update request, and determining the second symmetric key and the second validity period of the second symmetric key according to the updated key information, comprises: Receiving the updated key information sent by the platform gateway in response to the key update request, the updated key information including the key-encrypted data with signature and the second validity period of the key-encrypted data with signature; the encrypted data with signature is encrypted using the current developer certificate public key of the client and signed with the private key of the platform gateway; Obtaining the public key of the platform gateway, using the public key to verify the signature of the key-encrypted data with the signature, and after the signature verification is passed, using the private key corresponding to the current developer certificate stored in the client to decrypt the key-encrypted data to obtain the second symmetric key; The second symmetric key and the second validity period are stored in a cache of the client.

4. The method according to claim 1, characterized in that: The updated key information includes a key serial number of the second symmetric key, and the performing security protection processing on the business data corresponding to the business processing request according to the current key includes: Create a corresponding entity object according to the interface, and assign values ​​to the entity object according to the business data; Acquire a preset sensitive field from the cache according to the entity object type of the entity object, and encrypt the sensitive field data of the entity object using the second symmetric key to obtain encrypted sensitive data; The message carrying the encrypted sensitive data is sent to the platform gateway.

5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: Obtaining the first developer certificate of the client and a third validity period of the first developer certificate from the cache according to a second preset detection period; If the third validity period is not within the second preset time period, sending a certificate update request to the platform gateway; receiving updated certificate information sent by the platform gateway in response to the certificate update request, and determining a second developer certificate and a fourth validity period of the second developer certificate according to the updated certificate information; the fourth validity period is later than the third validity period; The second developer certificate is released in a grayscale manner. When the grayscale release is completed, the status of the first developer certificate and the second developer certificate is updated, and the second developer certificate is determined as the current developer certificate.

6. The method according to claim 5, characterized in that The receiving the updated certificate information sent by the platform gateway in response to the certificate update request, and determining the second developer certificate and the fourth validity period of the second developer certificate according to the updated certificate information, includes: Receiving the updated certificate information sent by the platform gateway in response to the key update request, the updated certificate information including the signed certificate encrypted data and the second validity period of the signed certificate encrypted data; the signed certificate encrypted data is encrypted using the first developer certificate public key and signed using the platform gateway private key; Obtaining the public key of the platform gateway, using the public key to verify the encrypted data of the signed certificate, and after the verification is passed, decrypting the encrypted data using the private key corresponding to the first developer certificate to obtain the second developer certificate; The second developer certificate and the fourth validity period are stored in a cache of the client.

7. The method according to claim 5, characterized in that The grayscale release of the second developer certificate includes: determining, from the platform gateway, all interfaces associated with the client service; The interfaces are divided according to the business processing attributes of the interfaces to obtain multiple groups of interface sets for grayscale release; the grayscale release priorities of the interfaces combined are different; According to the grayscale release priority, the grayscale release of the second developer certificate is performed in sequence for the corresponding interface sets according to a preset ratio until the grayscale release of the second developer certificate is completed for all interfaces.

8. The method according to claim 4, characterized in that The method further comprises: Receiving a key abnormality prompt sent by the platform gateway in response to the message; According to the key abnormality prompt, the current developer certificate and the private key corresponding to the current developer certificate stored in the cache are deleted, and a key update request for the developer certificate and a developer certificate update request are sent to the platform gateway.

9. A data security protection method, characterized in that: Applied to a platform gateway, the method includes: Receiving a key update request sent by a client; the key update request is initiated when the client obtains key information for encryption from a cache of the client according to a preset detection period and detects that a first validity period of a first symmetric key in the key information is not within a first preset period of time; generating updated key information in response to the key update request; The updated key information is sent to the client, so that the client determines the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the status of the first symmetric key and the second symmetric key is updated, and the second symmetric key is determined as the current key; when a business processing request is detected and within the second validity period, security protection processing is performed on the business data corresponding to the business processing request according to the current key.

10. The method according to claim 9, characterized in that The method further comprises: In response to the service processing request sent by the client, obtaining a message with a signature carried in the service processing request; Detecting the private key corresponding to the current developer certificate of the client according to the signed message, and generating a key abnormality prompt when an abnormality of the private key is detected; The key abnormality prompt is sent to the client, so that the client deletes the current symmetric key and the current developer certificate stored in the cache, and sends a key update request and a certificate update request to the platform gateway.

11. The method according to claim 10, characterized in that The detecting, according to the signed message, a private key corresponding to the current developer certificate of the client includes: Obtain the current developer certificate public key of the client to verify the signature of the message. If the signature verification passes, if the IP address carried in the message is not the preset IP address, it is determined that the private key of the platform gateway is abnormal; or In the case where the signature verification is passed, if the call information of the call interface associated with the message does not meet the preset call conditions, then the private key of the platform gateway is abnormal; or In the case where the signature verification passes, if the verification of the business data carried by the message fails, it is determined that the private key of the platform gateway is abnormal; or When the signature verification passes, if the client corresponding to the message is not a preset client, it is determined that the private key corresponding to the current developer certificate is abnormal.

12. A data security protection device, characterized in that: The device comprises: A detection module, configured to obtain key information for encryption from a cache of a client according to a first preset detection period, wherein the key information includes a first symmetric key and a first validity period of the first symmetric key; A sending module, configured to send a key update request to a platform gateway when the first validity period is not within a first preset time period; A data processing module, configured to receive the updated key information sent by the platform gateway in response to the key update request, and determine the second symmetric key and the second validity period of the second symmetric key according to the updated key information; the second validity period is later than the first validity period; An updating module, used for updating the states of the first symmetric key and the second symmetric key, and determining the second symmetric key as the current key; The data security protection processing module is used to perform security protection processing on the business data corresponding to the business processing request according to the current key when a business processing request is detected and within the second validity period.

13. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.