Network submission method and system based on UKEY, and storage medium
By adopting UKEY physical media authentication and fingerprint biometric verification in network reporting, and combining the hybrid encryption transmission mechanism of SM2 asymmetric encryption and symmetric encryption, the problem of data being easily intercepted and tampered during network transmission is solved, and a higher level of identity authentication and data transmission security is achieved.
Patent Information
- Application Number
- CN202411980605.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-31
AI Technical Summary
The prior art data is easily intercepted and tampered during network transmission, and its security is insufficient.
The UKEY-based network reporting method is adopted, and the UKEY physical medium authentication combined with fingerprint biometric verification is used to achieve dual security guarantees for identity authentication and data transmission through a hybrid encryption transmission mechanism of SM2 asymmetric encryption and symmetric encryption.
It effectively solves the risks of intercepting and tampering of data during network transmission, improves the reliability of identity authentication and confidentiality of data transmission, and improves the security performance of the entire network reporting process.
Smart Images

Figure CN119945745A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a network reporting method, system and storage medium based on UKEY. Background Art
[0002] With the rapid development of financial technology and the continuous improvement of regulatory requirements, banking financial institutions need to regularly submit a large amount of business data and regulatory information to regulatory agencies. These data not only involve the operating conditions of financial institutions, but also include sensitive information such as customer information and transaction records.
[0003] In related technologies, financial institutions generally use dedicated network transmission and digital certificate authentication to submit data, that is, they connect to the regulatory agency's data receiving system through a dedicated network, use digital certificates for identity authentication, and then package the submitted data and upload it to the regulatory agency's server via FTP or SFTP. After the data is received, the regulatory agency's system parses and stores the data.
[0004] However, data in the process of network transmission using related technologies still faces the risk of being intercepted and tampered with, and is not sufficiently secure. Summary of the invention
[0005] The present application provides a UKEY-based network reporting method, system and storage medium for improving the security of network reporting.
[0006] In the first aspect, the present application provides a network reporting method based on UKEY, which is applied to a network reporting system, and the method includes: receiving a login authentication request containing an organization number and fingerprint data sent by the receiving organization based on UKEY; after verifying that the match degree between the fingerprint data and the pre-stored fingerprint is higher than a preset matching threshold, generating authentication information containing the organization number and the current timestamp; generating a session identifier based on the authentication information and a preset private field, and integrating the session identifier, the organization number and the current timestamp to generate key negotiation reference data; encrypting the key negotiation reference data using the SM2 algorithm to obtain first encrypted data; receiving the second encrypted data returned by the receiving organization in response to the first encrypted data, and generating a symmetric encryption key based on the first encrypted data and the second encrypted data; receiving an encrypted data packet encrypted by the receiving organization using the symmetric encryption key, and decrypting the encrypted data packet using the symmetric encryption key to obtain reporting data; after confirming the validity of the reporting data based on the session identifier, storing the reporting data in a preset database, and returning storage confirmation information to the organization.
[0007] In the above embodiment, the network reporting system realizes the full-process security protection of identity authentication, data encryption transmission and storage in the network reporting process through multiple security mechanisms such as UKEY, fingerprint verification, SM2 encryption and symmetric encryption. First, UKEY and fingerprint are verified to ensure user identity, and then the SM2 algorithm and symmetric encryption are used to ensure data transmission security. Finally, session identification verification is used to ensure data integrity. Multi-layer protection improves the security of network reporting.
[0008] In combination with some embodiments of the first aspect, in some embodiments, before the step of receiving a login authentication request containing an organization number and fingerprint data sent by the institution based on UKEY, the method also includes: receiving registration requests from multiple registration servers and performing identity authentication to determine multiple supervision-end servers; assigning a unique identification code to each supervision-end server, and establishing a general communication link between the master control server and multiple supervision-end servers; receiving heartbeat packet information containing load data sent by multiple supervision-end servers, and calculating the comprehensive load score of the supervision-end server based on the load data; after verifying that the match degree between the fingerprint data and the pre-stored fingerprint is higher than the preset matching threshold, generating the authentication information containing the organization number and the current timestamp, specifically including: after verifying that the match degree between the fingerprint data and the pre-stored fingerprint is higher than the preset matching threshold, screening out the target server with the lowest comprehensive load score, and assigning the target server to the institution; generating a matching relationship table containing the correspondence between the target server and the institution end; generating authentication information containing the device identification, organization number and current timestamp of the target server.
[0009] In the above embodiment, the network reporting system uses distributed technology for complex balancing. By real-time monitoring of the load of the supervisory server, it dynamically allocates reporting requests to the server with the lowest load, and establishes a matching relationship table to achieve precise correspondence, effectively realizing balanced scheduling and optimal utilization of system resources, and improving the overall performance and stability of the system.
[0010] In combination with some embodiments of the first aspect, in some embodiments, after the step of generating a matching relationship table containing the correspondence between the target server and the target institution end, the method also includes: sending a service allocation instruction containing access information of the target institution end to the target server; after receiving the service ready confirmation information returned by the target server, establishing a direct communication link between the target server and the target institution end; determining the reporting period of the target institution end, and counting down the binding connection of the direct communication link based on the reporting period.
[0011] In the above embodiment, the network reporting system establishes a direct communication link between the target server and the institution end, and sets a connection countdown based on the reporting period, thereby realizing the timed management and resource release of the network connection, avoiding invalid connections occupying system resources, and improving the system operation efficiency.
[0012] In combination with some embodiments of the first aspect, in some embodiments, after the step of generating a matching relationship table containing the correspondence between the target server and the target institution, the method also includes: receiving a file-sensitive operation request uploaded by an instruction server, and determining the corresponding file to be operated and the operation type; the instruction server is one of multiple regulatory end servers; after verifying the file-sensitive operation request based on the user operation, sending the file operation instruction to the instruction server through the communication link; receiving the operation execution result returned by the instruction server, and storing the file operation record of the instruction server.
[0013] In the above embodiment, the network reporting system ensures the controllability and traceability of file operations through a unified management and verification mechanism for sensitive file operations, verifies permissions for file operations and records operation logs, effectively preventing unauthorized file access and improving data security.
[0014] In combination with some embodiments of the first aspect, in some embodiments, after confirming the validity of the reported data based on the session identifier, the reported data is stored in a preset database, and the storage confirmation information is returned to the institution end, specifically including: verifying the timeliness and authorization scope of the session identifier to obtain the session verification result; when the session verification result is a preset result, parsing the data structure of the reported data to determine the storage location of the reported data; storing the reported data to the storage location, generating a warehousing record including the storage location and storage time, and returning the storage confirmation information to the institution end.
[0015] In the above embodiment, the network reporting system realizes the validity verification and accurate storage of the reported data through session identification verification and data structure analysis, and ensures the accuracy and traceability of data storage by verifying the session timeliness and authorization scope and determining the storage location according to the data structure.
[0016] In combination with some embodiments of the first aspect, in some embodiments, after confirming the validity of the reported data according to the session identifier, storing the reported data in a preset database, and returning the storage confirmation information to the institution end, the method also includes: receiving multiple reported data packets to be imported, and establishing an initial task queue containing multiple import tasks; according to the timeliness and data volume of the reported data packets, correcting the priority of the import tasks corresponding to the reported data packets in the initial task queue to obtain an optimized task queue; executing data import based on the optimized task queue, and generating an import progress report; the import progress report includes the number of completed tasks, the number of remaining tasks and the estimated completion time.
[0017] In the above embodiment, the network reporting system realizes intelligent scheduling and progress monitoring of the reporting data import, dynamically adjusts the task priority according to the timeliness and data volume of the data, and generates progress reports in real time, thereby improving the efficiency and controllability of large-scale data import.
[0018] In combination with some embodiments of the first aspect, in some embodiments, after the steps of executing data import based on the optimized task queue and generating an import progress report, the method also includes: receiving an add request containing a newly added temporary task sent by the management terminal, determining the task type and urgency of the newly added temporary task; calculating the task priority of the newly added temporary task based on the urgency, and determining the insertion position of the newly added temporary task in the optimized task queue; inserting the newly added temporary task into the insertion position, and updating the optimized task queue; and pushing a notification of the newly added temporary task to the institution end corresponding to the optimized task queue.
[0019] In the above embodiment, the network reporting system realizes the flexible insertion and priority management of temporary tasks, dynamically adjusts the task queue according to the urgency of the task, and promptly notifies the relevant agencies, ensuring the timely processing of urgent tasks and improving the system's responsiveness.
[0020] In a second aspect, an embodiment of the present application provides a network reporting system, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the network reporting system to execute the method described in the first aspect and any possible implementation method of the first aspect.
[0021] In a third aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when the computer program product is run on a network reporting system, enables the network reporting system to execute the method described in the first aspect and any possible implementation method of the first aspect.
[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, comprising instructions. When the instructions are executed on a network reporting system, the network reporting system executes the method described in the first aspect and any possible implementation method of the first aspect.
[0023] It is understandable that the network reporting system provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the method provided in the embodiment of the present application. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be repeated here.
[0024] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. Due to the adoption of a dual identity authentication mechanism combining UKEY physical media authentication with fingerprint biometric verification, as well as a hybrid encryption transmission mechanism based on SM2 asymmetric encryption and symmetric encryption, dual security guarantees for identity authentication and data transmission are achieved during data reporting, effectively solving the potential security risks of existing technologies that rely solely on digital certificates that are easily copied and network transmission data that are easily intercepted and tampered with, thereby achieving a higher level of identity authentication reliability and data transmission confidentiality. At the same time, the integrity and validity of the data are ensured through the session identification verification mechanism, thereby improving the security performance of the entire network reporting process.
[0025] 2. Due to the adoption of a unified management mechanism and multi-level verification process for sensitive file operations, and the distribution of instructions and result feedback through the general communication link, the file operation is fully controllable and traceable, effectively solving the problem of chaotic file operation authority management in the existing technology, and then realizing standardized management and full-process monitoring of file operations, ensuring the security and compliance of sensitive file operations.
[0026] 3. Due to the adoption of a dynamic adjustment mechanism for task priorities based on timeliness and data volume, as well as a task queue optimization and progress monitoring mechanism, intelligent scheduling and precise management of large-scale data import processes are achieved, effectively solving the problems of low data import efficiency or difficult progress control in existing technologies, and thus achieving efficient coordination and precise control of the data import process, which not only ensures timely processing of emergency data, but also achieves optimal utilization of system resources, thereby improving the system's operating efficiency and manageability. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 This is a flowchart of a network reporting method based on UKEY in an embodiment of the present application; Figure 2 This is another flowchart of the network reporting method based on UKEY in an embodiment of the present application; Figure 3 It is a schematic diagram of the structure of a physical device of the network reporting system in the embodiment of the present application. DETAILED DESCRIPTION
[0028] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to be used as limitations to the present application. As used in the specification of the present application, the singular expressions "one", "a kind of", "above", "the" and "this" are intended to also include plural expressions, unless there is a clear indication to the contrary in the context. It should also be understood that the term "and / or" used in the present application refers to any or all possible combinations comprising one or more of the listed items.
[0029] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, unless otherwise specified, "plurality" means two or more.
[0030] For ease of understanding, the application scenarios of the embodiments of the present application are introduced below.
[0031] A provincial regulatory agency needs to manage data reporting for more than 2,000 financial institutions within its jurisdiction. Each institution needs to submit multiple reporting tasks such as EAST and JRJC every month, and the reporting time, data volume and business type of different institutions are different. Due to the sensitivity of the data, institutional operators need to log in to the system through a USB key for authentication, but there may be security risks such as USB keys being copied and passwords being stolen. For example, a few years ago, a rural commercial bank had a data leak. The investigation found that it was because the operator's login password was stolen, resulting in unauthorized personnel gaining access to the reporting system. Traditional password authentication methods cannot ensure the uniqueness of the operator's identity, nor can they guarantee the security of data during transmission, which brings significant risks to financial data reporting.
[0032] In the related art, a two-factor authentication method based on a USB key and a password is usually used for identity authentication, and a fixed key is used for data encryption transmission. The following describes an application scenario using a traditional USB key authentication method in the related art.
[0033] A city commercial bank uses a traditional USB key authentication system for data reporting. The system requires the operator to insert a USB key and enter a password for identity authentication. For example, when performing monthly regulatory reporting, the operator inserts the USB key and enters a 6-digit password to log into the system. The system only verifies identity through a simple password match and uses a fixed encryption key for data transmission.
[0034] However, this method has multiple security loopholes: USB keys may be copied and passwords may be easily cracked or leaked; a single password authentication cannot ensure that the actual operator is the authorized person; fixed encryption keys may be easily cracked, resulting in the interception and tampering of transmitted data.
[0035] The UKEY-based network reporting method in the embodiment of the present application realizes the uniqueness of identity authentication and the security of data transmission through fingerprint biometric recognition, dynamic session management and multiple encryption mechanisms. The following describes the scenario in which the UKEY-based network reporting method in the present application is used.
[0036] A regional bank uses the UKEY-based network reporting system of this application to handle data reporting tasks. When the institutional operator needs to report data, he first inserts the UKEY into the terminal and performs fingerprint verification. After the system receives a login request containing the institution number "JG20240101" and the operator's fingerprint data, the verification fingerprint match reaches 98%, exceeding the preset 95% threshold. The system then generates authentication information containing the institution number and timestamp "202401271030", and combines the private field "SECRETKEY2024" to generate the session identifier "SESSION_JG20240101_1030". The system integrates this information into the key negotiation benchmark data, encrypts it using the SM2 algorithm, and generates the first encrypted data. After receiving the data, the institutional end returns the corresponding second encrypted data, and the system generates an AES-256-bit symmetric encryption key based on it. When the institutional end uses the key to encrypt the reporting data packet and sends it, the system decrypts it with the same key to obtain the original reporting data. After the system verifies that the session identifier is valid, it stores the data in the Oracle database and returns a confirmation message of "data storage successful" to the institution.
[0037] Throughout the entire process, the security of the submitted data is ensured through the UKEY hardware medium and multiple encryption mechanisms. For ease of understanding, the following describes the process of the method provided by this implementation in combination with the above scenario. Figure 1 , which is a flow chart of the network reporting method based on UKEY in an embodiment of the present application.
[0038] S101. The receiving institution sends a login authentication request based on UKEY, which includes the institution number and fingerprint data.
[0039] Among them, the institutional end is a private network server of a financial institution with client software installed; UKEY represents a USB security authentication medium used to store digital certificates and encryption keys, and supports fingerprint verification function; the institutional number refers to the unique identification code assigned to each financial institution; and the fingerprint data refers to the user's biometric data collected through UKEY.
[0040] This step is executed when the institution initiates a login request to the supervisory end after the institution user inserts UKEY and verifies the fingerprint. Specifically, the institution collects the user's fingerprint data through the SDK interface of UKEY, packages the fingerprint data and the institution number into a login authentication request, and sends it to the supervisory end server through the HTTP protocol. After receiving the request, the supervisory end (network reporting system) first verifies the legitimacy of the request format, and then parses out the institution number and fingerprint data for subsequent verification.
[0041] In some embodiments, the reception and processing of login authentication requests can be implemented in a variety of ways: optionally, the supervisory end starts an independent authentication service thread, receives requests through a Socket long connection, queues the requests, and sets a timeout retry mechanism; optionally, a RESTful API is used to receive requests, Spring Security is used to filter and verify requests, and Redis is used to cache authentication status. It is understandable that other network communication protocols and authentication mechanisms can also be used to implement the reception and processing of requests, which are not limited here.
[0042] S102: after verifying that the matching degree between the fingerprint data and the pre-stored fingerprint is higher than a preset matching threshold, generate authentication information including an institution number and a current timestamp.
[0043] Among them, the pre-stored fingerprint refers to the legal fingerprint data of institutional users stored in the regulatory database in advance; the matching degree indicates the similarity between the current fingerprint data and the pre-stored fingerprint; the preset matching threshold is used to determine whether the fingerprint verification is passed; the timestamp refers to the numerical representation of the current system time.
[0044] This step performs fingerprint verification after receiving the login authentication request. Specifically, the supervisory end (network reporting system) calls the fingerprint comparison algorithm to calculate the matching degree between the current fingerprint data and the pre-stored fingerprint. When the matching degree exceeds the preset threshold (usually 0.8), the verification is considered to be successful. After the verification is successful, the current system timestamp is obtained and the authentication information containing these two fields is generated together with the institution number.
[0045] S103: Generate a session identifier based on the authentication information and the preset private field, and integrate the session identifier, the organization number and the current timestamp to generate key negotiation benchmark data.
[0046] Among them, the preset private field represents the key information pre-defined by the system for generating a session identifier; the session identifier refers to a unique identifier used to identify the current session; and the key negotiation reference data is a basic data packet used for subsequent generation of encryption keys.
[0047] This step performs session identifier generation and key negotiation preparation after generating authentication information. Specifically, the network reporting system mixes the authentication information with the preset private field to calculate the session identifier, ensuring the uniqueness and randomness of the session identifier. Then the session identifier, organization number and timestamp are spliced and integrated in a specific format to construct the key negotiation benchmark data in preparation for subsequent encrypted communication.
[0048] In some embodiments, session identification generation and data integration can be achieved in a variety of ways: optionally, using SHA-256 to calculate the hash value of the authentication information and private fields as the session identification, and using JSON format to organize the negotiation benchmark data; optionally, using UUID combined with timestamp to generate a session identification, and using a custom binary format to encapsulate the data. It is understandable that other encryption algorithms and data formats can also be used to implement session management, which is not limited here.
[0049] S104. Use the SM2 algorithm to encrypt the key negotiation reference data to obtain first encrypted data.
[0050] The SM2 algorithm refers to the public key cryptographic algorithm issued by the State Cryptography Administration; the first encrypted data represents the ciphertext data encrypted by the SM2 algorithm.
[0051] This step performs encryption after generating the key negotiation reference data. Specifically, the network reporting system calls the encryption interface of the SM2 algorithm, uses the SM2 public key corresponding to the institution end to encrypt the key negotiation reference data, and obtains the encrypted first encrypted data to ensure the security of the data transmission process.
[0052] S105. The receiving institution returns the second encrypted data in response to the first encrypted data, and generates a symmetric encryption key based on the first encrypted data and the second encrypted data.
[0053] The second encrypted data represents the encrypted response data returned by the institution; the symmetric encryption key refers to the session key used for subsequent data transmission.
[0054] This step waits for and processes the response from the institution after sending the first encrypted data. Specifically, the network reporting system receives the second encrypted data returned by the institution, combines it with the first encrypted data generated previously, and generates a symmetric encryption key through a specific key negotiation algorithm. This key will be used for subsequent data encryption transmission to provide more efficient encryption performance.
[0055] In some embodiments, symmetric key generation can be achieved in a variety of ways: optionally, using the Diffie-Hellman key exchange algorithm in combination with the SM3 hash algorithm to generate a symmetric key; optionally, using a key negotiation scheme based on SM2 to generate a shared key. It is understandable that other key negotiation mechanisms can also be used to achieve secure key exchange, which is not limited here.
[0056] S106. The receiving organization encrypts the encrypted data packet using the symmetric encryption key, and decrypts the encrypted data packet using the symmetric encryption key to obtain the reported data.
[0057] Among them, the encrypted data packet refers to the reporting data packet encrypted by the institution using a symmetric encryption key; the reporting data refers to the original business data after decryption.
[0058] This step performs data transmission and decryption after the symmetric encryption key is successfully generated. Specifically, the network reporting system receives the encrypted data packet sent by the institution, decrypts the data packet using the previously generated symmetric encryption key, and restores the original reporting data to ensure the confidentiality and integrity of data transmission.
[0059] In some embodiments, data decryption processing can be implemented in a variety of ways: optionally, using the SM4 algorithm for symmetric decryption and data integrity verification; optionally, using block decryption and parallel processing to improve the efficiency of decryption of large amounts of data. It is understandable that other efficient decryption processing mechanisms can also be used, which are not limited here.
[0060] S107. After confirming the validity of the submitted data according to the session identifier, the submitted data is stored in a preset database, and storage confirmation information is returned to the institution end.
[0061] Among them, data validity refers to the legality and timeliness of the submitted data; the preset database refers to the target database used to store the submitted data; and the storage confirmation information is used to feedback the data storage status to the institution.
[0062] This step performs data storage and confirmation after successfully decrypting the submitted data. Specifically, the network submission system first verifies the validity of the data through the session identifier, including checking the legitimacy of the data source and the validity of the timestamp. After verification, the submitted data is stored in the preset database system, and a confirmation message containing the storage status is generated and returned to the institution.
[0063] In some embodiments, the processing of data storage failure needs to be performed on the basis of ensuring data consistency and reliability. Specifically, the network reporting system will first capture the storage anomaly and record a detailed error log, including the cause of the failure, data characteristics and other information. Then, a hierarchical retry mechanism is initiated according to the type of anomaly. For temporary failures (such as network jitter), an exponential backoff algorithm is used for retry; for fatal errors (such as disk damage), a prompt message is immediately sent to notify the operation and maintenance personnel and switch to the backup storage system. At the same time, detailed error information is returned to the institution to guide subsequent reporting operations.
[0064] Failure handling can be implemented in a variety of ways, such as writing failed data to a local temporary file system and starting an independent retry thread to periodically attempt to re-store the data; migrating the data to a backup storage system after the maximum number of retries is reached, notifying relevant personnel in real time through a message push mechanism, and generating a detailed failure report for subsequent analysis.
[0065] The following is a more detailed description of the process of the method provided by this implementation. Figure 2 , which is another flow chart of the network reporting method based on UKEY in an embodiment of the present application.
[0066] S201. Receive registration requests from multiple registration servers and perform identity authentication to determine multiple supervisory end servers.
[0067] Among them, the registration server refers to the regulatory server node that can independently handle data reporting services; the registration request refers to the registration information package containing identity information and service capabilities sent by the server to the main control center; identity authentication is used to confirm the legitimacy and reliability of the server; the regulatory server refers to the server node that can be put into use after verification.
[0068] This step is performed when the system is started or a new server node is added. Specifically, after the network reporting system receives the registration request from the server, it first verifies the digital certificate and encrypted signature in the request, and then checks the server's hardware configuration, network connection status and other information. After verification, the server information is recorded in the server management list and an initial connection with the server is established.
[0069] In some embodiments, the authentication and management of the registration server can be achieved in a variety of ways: the system adopts an identity authentication mechanism based on a zero-trust architecture, first verifies the hardware fingerprint of the server, and then confirms the authenticity of the server identity through dynamic tokens and behavioral analysis. Multi-factor authentication technology is used in the authentication process, combined with certificate chain verification and two-way TLS authentication to ensure communication security. After the server identity is confirmed, the system will establish an encrypted communication channel and allocate resource quotas. Optionally, the system can also adopt a distributed identity authentication system based on blockchain, manage the life cycle of the server through smart contracts, and use a consensus mechanism to ensure the credibility of the authentication process. It is understandable that other identity authentication and server management mechanisms can also be used, which are not limited here.
[0070] S202: Allocate a unique identification code to each supervisory end server, and establish a general communication link between the master control server and multiple supervisory end servers.
[0071] Among them, the unique identification code represents the unique identity code of each server, which is composed of a hardware identifier and a random sequence; the total communication link refers to the encrypted communication channel established between the master control server and each supervision end server. The link status of the total communication link includes health and availability.
[0072] This step is performed after the server completes identity authentication. Specifically, the network reporting system generates a 128-bit unique identification code based on the server's MAC address, CPU serial number and other hardware information, combined with a timestamp and a random number. Then, an independent communication port and encryption key are assigned to each identification code to establish a secure communication link based on the TLS 1.3 protocol. The system monitors the link status in real time through a heartbeat detection mechanism to ensure the stability of communication.
[0073] In some embodiments, the establishment and maintenance of communication links can be achieved in a variety of ways: the system adopts a layered encryption communication architecture, uses a national secret algorithm for encryption at the transport layer, and implements a custom handshake protocol and session management at the application layer. Communication security is ensured through dynamic key updates and session renegotiation mechanisms. Bidirectional authentication and integrity verification are used during link establishment to prevent man-in-the-middle attacks. Optionally, the system can also use a P2P-based network topology to achieve direct communication between server nodes, improve network transmission efficiency and enhance the system's fault tolerance. It is understandable that other communication link management mechanisms can also be used, which are not limited here.
[0074] S203: Receive heartbeat packet information containing load data sent by multiple supervisory end servers, and calculate the comprehensive load score of the supervisory end servers according to the load data.
[0075] Among them, the heartbeat packet information represents the status report data sent regularly by the server; the load data includes real-time performance indicators such as CPU usage, memory occupancy, disk I / O, and network bandwidth; the comprehensive load score refers to the overall server load level assessment value obtained through weighted calculation.
[0076] This step is performed continuously during the normal operation of the server. Specifically, the network reporting system sets weight coefficients {w1, w2, ..., wn} based on the importance of performance indicators, normalizes each load indicator {x1, x2, ..., xn}, and calculates the comprehensive load score S = Σ (wi*xi) through a weighted average algorithm. At the same time, the system will consider historical load trends and use time series analysis methods such as exponential smoothing to predict future load changes of the server.
[0077] In some embodiments, load assessment can be achieved in a variety of ways: the system uses a machine learning method to build a neural network model including a multi-layer perceptron and a convolutional layer, namely a load prediction model, which takes real-time load data, historical load trends and service quality indicators as input features. The load prediction model can output a more accurate load prediction score.
[0078] Specifically, the load prediction model constructs a multi-layer neural network architecture to predict the load status of the server. The input layer receives multi-dimensional performance indicators of the server, including real-time data such as CPU usage, memory occupancy, disk I / O rate, and network bandwidth utilization. The hidden layer of the network contains a multi-layer perceptron structure, which performs nonlinear transformation through the ReLU activation function to extract high-order features; the convolution layer is used to capture the temporal correlation between performance indicators, and the kernel size is set to 5 minutes. The model training of the load prediction model uses a stochastic gradient descent optimizer, with mean square error as the loss function. The learning rate is initially set to 0.001 and uses Adam for adaptive adjustment. During the training process, the system collects performance data every 10 minutes, accumulates 24 hours to form a training batch, and continuously optimizes the model parameters through an online learning mechanism. In the use stage, by inputting the performance indicator sequence of the last hour, the load prediction model can output the load prediction score (standardized value between 0-100) for the next 15 minutes.
[0079] For example, when it is detected that the CPU usage of a server has been on an upward trend in the past 30 minutes and the memory usage exceeds 75%, the model may output a higher load prediction score (such as 85 points), prompting the system to reduce the task allocation weight of the server.
[0080] S204. The receiving institution sends a login authentication request based on UKEY, which includes the institution number and fingerprint data.
[0081] Referring to step S101, the network reporting system receives a login authentication request.
[0082] S205. After verifying that the matching degree between the fingerprint data and the pre-stored fingerprint is higher than the preset matching threshold, the target server with the lowest comprehensive load score is screened out and the target server is allocated to the institution end.
[0083] Among them, the target server refers to the server node with low load and suitable for processing new requests; server allocation refers to assigning the reporting task of a specific agency to the selected server for processing.
[0084] This step is performed after the identity verification of the institution is passed. Specifically, the network reporting system first sorts the comprehensive load scores of all regulatory servers and selects the server with the lowest score as the target server. At the same time, the geographical location of the server, network latency and other factors are considered, and a multi-objective optimization algorithm is used to ensure the rationality of the allocation. The system also evaluates the historical service quality of the target server to avoid assigning tasks to nodes with unstable performance.
[0085] In some embodiments, the network reporting system stores all revoked certificate serial numbers and revocation reasons by maintaining a regularly updated certificate revocation database. When a certification request is received, the system first obtains the latest certificate revocation list from the CRL distribution point, and then uses a binary search algorithm to retrieve the serial number of the current certificate in the revocation list; the certificate revocation list (CRL) status refers to the check result of the UKEY digital certificate in the certificate revocation list. If a matching record is found, the revocation time and reason code are further checked to determine whether the certificate is within the validity period. For example, when an institution's UKEY is reported lost due to a security incident, its corresponding certificate serial number will be added to the CRL, and all subsequent certification requests for the UKEY will be rejected due to CRL status check failure.
[0086] S206: Generate a matching relationship table including the correspondence between the target server and the institution end.
[0087] Among them, the matching relationship table represents the corresponding binding relationship data between the target server and the institution end;.
[0088] This step is executed immediately after the server allocation is completed. Specifically, the network reporting system creates a relationship record based on the allocation result, which contains fields such as the institution number, server identification code, allocation timestamp, and session identification. The system also calculates the validity period of the relationship and dynamically adjusts it based on the reporting cycle (such as the EAST reporting cycle). The system ensures atomic updates of the relationship table through a transaction mechanism and establishes indexes to accelerate query efficiency.
[0089] In some embodiments, the management of matching relationships can be achieved in a variety of ways: the system uses a distributed database to store matching relationships and uses a two-phase commit protocol to ensure data consistency. Concurrent access is handled through a multi-version concurrency control (MVCC) mechanism, and query performance is improved in combination with a cache mechanism. The system also implements an automatic check and cleanup mechanism for relationship validity periods. Optionally, the system can also use a graph database to store matching relationships, analyze the connection characteristics of servers and organizations through graph algorithms, and optimize resource allocation strategies. It is understandable that other relationship management mechanisms can also be used, which are not limited here.
[0090] In some embodiments, the network reporting system sends a service allocation instruction containing access information of the target organization to the target server; after receiving the service readiness confirmation information returned by the target server, a direct communication link between the target server and the target organization is established; the reporting period of the target organization is determined, and a countdown for binding the connection of the direct communication link is performed based on the reporting period.
[0091] Among them, the service allocation instruction represents the control command used to establish a connection between the server and the institution; the service readiness confirmation information refers to the response data of the server completing resource preparation; the communication direct link is used to represent the dedicated data channel between the institution and the server; the connection countdown refers to the link validity period set based on the reporting period.
[0092] This paragraph is executed after the server allocation is completed. Specifically, the network reporting system packages the IP address, access rights and security policy of the institution into a service allocation instruction and sends it to the target server. After receiving the instruction, the server will reserve computing resources and storage space, configure firewall rules and access control policies, and return a ready confirmation after completion. The system then establishes an encrypted channel from the institution to the server, and sets the link validity timer according to the reporting business type (such as EAST monthly report, JRJC quarterly report, etc.).
[0093] In some embodiments, server connection management can be implemented in a variety of ways: the system adopts a connection lifecycle management mechanism based on a state machine, and establishes a secure channel through a multi-stage handshake protocol. The system first performs two-way identity authentication, then negotiates encryption parameters and session keys, and finally establishes a data transmission channel and starts heartbeat monitoring. The entire process is protected by asymmetric encryption, and a time window mechanism is used to prevent replay attacks. Optionally, the system can also implement a dynamic load balancing mechanism, which monitors server resource usage in real time and automatically switches to backup links when necessary to ensure service continuity. It is understandable that other connection management mechanisms can also be used, which are not limited here.
[0094] In some embodiments, the network reporting system receives file-sensitive operation requests uploaded by the instruction server, determines the corresponding files to be operated and the operation types; the instruction server is one of multiple regulatory servers; after verifying the file-sensitive operation request based on the user operation, the file operation instruction is sent to the instruction server through the communication link; receives the operation execution results returned by the instruction server, and stores the file operation records of the instruction server.
[0095] Among them, the file sensitive operation request refers to an operation application involving the modification or deletion of important data; the file to be operated refers to the target file that needs to perform sensitive operations; the operation type is used to indicate the specific file processing method, such as modification, deletion, etc.; the instruction server refers to the supervisory server that executes the file operation; the file operation record refers to the audit log that records the operation execution process and results.
[0096] This section is executed when a file operation request is received from the supervisory end. Specifically, the network reporting system parses the file identifier and operation parameters in the request to verify the permission level of the operating user. The system calls the security audit module to record the operation application information, including the operator, timestamp, IP address, etc. When the user passes the identity authentication and authorization verification, the system constructs an encrypted message containing detailed operation instructions and sends it to the instruction server through the communication link. The system tracks the execution status of the instruction in real time and saves the execution results and operation logs to the security audit database.
[0097] In some embodiments, sensitive operation management can be achieved in a variety of ways: the system uses a multi-level authorization mechanism to handle sensitive operations, requiring that high-risk operations must be approved by multiple people. The system first performs a risk assessment on the operation request and determines the approval process based on the importance of the file and the scope of the operation. Then the multi-level approval is coordinated through the workflow engine, and finally the operation is performed after sufficient authorization is obtained. The entire process uses digital signatures to ensure that the operation is undeniable. Optionally, the system can also implement abnormal operation detection based on machine learning, identify potential violations by analyzing historical operation patterns, and automatically trigger security warnings and operation interception. It is understandable that other sensitive operation management mechanisms can also be used, which are not limited here.
[0098] S207: Generate authentication information including the device identification, organization number and current timestamp of the target server.
[0099] Among them, the device identification represents the hardware characteristics and network identification information of the target server; the authentication information refers to the credential data used to verify the identities of the communicating parties.
[0100] This step is performed after the matching relationship is established. Specifically, the network reporting system combines the device identification, organization number and millisecond timestamp of the target server, and uses a hash algorithm to generate a summary of the authentication information. The system sets a sliding time window for the authentication information, and the authentication information that exceeds the window range automatically becomes invalid. At the same time, the use record of the authentication information is maintained to prevent replay attacks.
[0101] S208. Generate a session identifier based on the authentication information and the preset private field, and integrate the session identifier, the organization number and the current timestamp to generate key negotiation benchmark data.
[0102] Referring to step S103, the network reporting system generates key negotiation benchmark data.
[0103] S209. Use the SM2 algorithm to encrypt the key negotiation reference data to obtain first encrypted data.
[0104] Referring to step S104, the network reporting system generates first encrypted data.
[0105] S210. The receiving institution returns the second encrypted data in response to the first encrypted data, and generates a symmetric encryption key based on the first encrypted data and the second encrypted data.
[0106] Referring to step S105, the network reporting system will generate a symmetric encryption key.
[0107] S211. The receiving organization encrypts the encrypted data packet using the symmetric encryption key, and decrypts the encrypted data packet using the symmetric encryption key to obtain the reported data.
[0108] Referring to step S106, the network reporting system will decrypt and obtain the reporting data.
[0109] S212. After confirming the validity of the submitted data according to the session identifier, the submitted data is stored in a preset database, and storage confirmation information is returned to the institution end.
[0110] Referring to step S107, the network reporting system will store the reporting data.
[0111] In some embodiments, the network reporting system verifies the timeliness and authorization scope of the session identifier to obtain a session verification result; when the session verification result is a preset result, the data structure of the reported data is parsed to determine the storage location of the reported data; the reported data is stored in the storage location, and a storage record containing the storage location and storage time is generated, and storage confirmation information is returned to the institution.
[0112] Among them, the session ID represents the unique identifier of the user's current login session; timeliness refers to the validity period of the session; the authorization scope is used to represent the set of operations allowed to be performed by the session; the data structure represents the organizational form and format specifications of the reported data; the storage location refers to the storage path of the data in the file system; and the storage record is used to represent detailed information on data storage.
[0113] This section is executed when the reported data is received. Specifically, the network reporting system first checks the validity period and authorization level of the session identifier to verify whether the user has the data reporting authority. The system parses the file format and data organization of the reported data packet, and determines the storage strategy based on the data type and institutional information. The system writes the data to the specified storage location and generates a storage record containing information such as the file path, storage timestamp, and data checksum. Finally, a confirmation message with the storage status is returned to the institutional end.
[0114] In some embodiments, data storage management can be implemented in a variety of ways: the system uses a distributed storage architecture to process reported data and ensures data reliability through data sharding and replication mechanisms. The system first classifies and labels the data, and then selects appropriate storage nodes based on the storage strategy. The consistent hashing algorithm is then used to calculate the data sharding scheme to evenly distribute the data to the storage cluster. Finally, data copies are maintained through an asynchronous replication mechanism. Optionally, the system can also implement intelligent storage optimization by analyzing data access patterns, automatically adjusting the storage levels of hot and cold data, and optimizing storage resource utilization. It is understandable that other storage management mechanisms can also be used, which are not limited here.
[0115] S213, receiving a plurality of report data packets to be imported, and establishing an initial task queue including a plurality of import tasks.
[0116] The submitted data packet represents a collection of data files to be processed; the initial task queue refers to a list of tasks to be processed generated by the system based on the submitted data packet.
[0117] This step is executed after receiving the data submission request from the institution. Specifically, the system parses the metadata of the submitted data packet, including data type, file size, submission time, etc. Based on this information, a task object is created, and the initial priority and expected execution time of the task are set. The system uses a queue data structure to maintain the task list to ensure the orderliness of task processing.
[0118] In some embodiments, the construction and management of task queues can be implemented in a variety of ways: the network reporting system uses a priority queue to store tasks, and the task priority is determined by factors such as data timeliness, business importance, and resource consumption. The read-write lock mechanism is used to protect queue operations, and the dynamic insertion and adjustment functions of tasks are realized. The system supports breakpoint resumption and failed retry of tasks. Optionally, the system can also use a workflow engine to manage the task execution process, control the life cycle of tasks through a state machine, and provide flexible task scheduling capabilities. It is understandable that other task management mechanisms can also be used, which are not limited here.
[0119] S214. According to the timeliness and data volume of the reported data packets, the priority of the imported tasks corresponding to the reported data packets in the initial task queue is modified to obtain an optimized task queue.
[0120] Among them, timeliness refers to the urgency and processing period of the reported data; data volume refers to the storage capacity of the reported data packet; priority correction refers to the adjustment of the task execution order based on multi-dimensional indicators; and optimized task queue refers to the task execution sequence after priority rearrangement.
[0121] This step is performed after the initial task queue is established. Specifically, the network reporting system first calculates the basic priority score of each task, P=w1xT+w2xS, where T is the timeliness score, S is the data volume score, and w1 and w2 are weight coefficients. Then, the priority is corrected considering business rules (such as the reporting time requirements of EAST / JRJC), and the task queue is reorganized using the heap sort algorithm. The system dynamically monitors the queue status and adaptively adjusts the task scheduling strategy according to the system load.
[0122] Among them, for the heap sorting algorithm, the system uses the max-heap data structure to implement task priority sorting. First, a complete binary tree is constructed, and each node stores the task object and its priority score. The heap sorting process starts from the last non-leaf node, and recursively compares the priority scores of the parent node and the child node to ensure that the parent node priority is always greater than the child node. When the task order needs to be adjusted, the priority score of the target task is updated, and the floating or sinking operation starts from this node to maintain the heap property. The left child node index of node k is 2k+1, the right child node index is 2k+2, and the parent node index is (k-1) / 2. In this way, the system can complete the priority adjustment of a single task within the O (logn) time complexity, and ensure that the task with the highest priority is always at the top of the heap, so as to facilitate the rapid acquisition of the next task to be executed. For example, when an emergency report task arrives, the system sets its priority to the highest and inserts it into the heap. The task will quickly reach the top of the heap through the floating operation and be processed first.
[0123] In some embodiments, dynamic adjustment of task priorities can be achieved in a variety of ways: the system uses a multi-level feedback queue algorithm to dynamically adjust the priority based on the execution history and resource consumption of the task. The task execution time is predicted by a machine learning model to optimize the scheduling order of tasks. The system implements automatic analysis of task dependencies and a priority propagation mechanism. Optionally, the system can also use a heuristic algorithm to solve the constrained optimization problem of task scheduling to maximize the system throughput while meeting the deadline constraints. It is understandable that other task scheduling algorithms can also be used, which are not limited here.
[0124] S215. Execute data import based on the optimized task queue and generate an import progress report.
[0125] Among them, data import refers to the process of writing reported data into the system database; the import progress report refers to the statistical information reflecting the execution status of the current import task. The import progress report includes the number of completed tasks, the number of remaining tasks and the estimated completion time.
[0126] This step is performed after the optimization task queue is generated. Specifically, the network reporting system processes the import tasks one by one in the queue order and starts an independent work thread for each task. The system counts the number of completed tasks and the processing speed in real time, and predicts the completion time of the remaining tasks through a linear regression model. At the same time, it monitors the database performance indicators and dynamically adjusts the number of concurrent import tasks to avoid system overload.
[0127] Among them, the expected completion time of the task is predicted based on the time prediction model. The time prediction model uses a linear regression algorithm and is constructed by analyzing the processing records of historical tasks. The system collects the data volume and corresponding processing time of historical tasks as training samples, and constructs a data matrix X containing n sample points and a processing time vector y. The least squares method is used to solve the normal equation (X'X) β=X'y, and the regression coefficient β=(X'X)^(-1)X'y is obtained, where β0 represents the basic processing time (intercept) and β1 represents the processing time increment (slope) per unit data volume. The time prediction model evaluates the fitting effect by calculating the determination coefficient R²=1-∑(yi-ŷi)² / ∑(yi-ȳ)², and triggers model retraining when R² is lower than the preset threshold (such as 0.8). In actual applications, by inputting the data volume x of the new task, the time prediction model can calculate the expected processing time based on the prediction equation y=β0+β1x, and make corrections based on the current system CPU utilization. For example, when the system load reaches 80%, the prediction time will increase by 25% accordingly.
[0128] In some embodiments, the network reporting system receives an addition request containing a newly added temporary task sent by the management terminal, determines the task type and urgency of the newly added temporary task; calculates the task priority of the newly added temporary task based on the urgency, and determines the insertion position of the newly added temporary task in the optimized task queue; inserts the newly added temporary task into the insertion position, and updates the optimized task queue; and pushes the newly added temporary task notification to the institution end corresponding to the optimized task queue.
[0129] Among them, temporary tasks refer to additional work items that need to be inserted into the existing task queue; adding requests refer to task creation applications initiated by the management terminal; the urgency level refers to the time requirement for task processing; and new temporary task notifications refer to task arrival reminders pushed to the institution end.
[0130] This section is executed when a temporary task addition request is received from the management terminal. Specifically, the network reporting system parses the task description information in the request and identifies the task type and time limit. The system calculates a comprehensive priority score based on the urgency value (such as urgent, expedited, ordinary, etc.) combined with the business weight. The system traverses the current task queue, locates the position with the closest priority score through a binary search algorithm, and inserts the new task into that position. The system updates the execution time estimate of the affected tasks in the queue and notifies the relevant agencies in real time through a message push mechanism.
[0131] Among them, when the network reporting system applies binary search in the optimization task queue, the task queue is first sorted according to the priority score to form an ordered array. Set the left pointer left to point to the starting position 0 of the array, and the right pointer right to point to the end of the array n-1. In each iteration, calculate the middle position mid = (left + right) / 2, and compare the priority score of the new task with the priority score of the task at the mid position. If the new task has a higher priority, narrow the search range to the left half and update right = mid - 1; if the new task has a lower priority, narrow the search range to the right half and update left = mid + 1. Repeat this process until left>right, at which time the left position is the insertion position of the new task. For example, a temporary task with a priority score of 75 needs to be inserted into the priority sequence [90, 80, 70, 60, 50]. After binary search, it is determined that it should be inserted at index 2, that is, before 70. The time complexity of the algorithm is O (logn), where n is the queue length.
[0132] In some embodiments, temporary task management can be implemented in a variety of ways: the network reporting system uses a dynamic task scheduling mechanism to handle temporary task insertion. The system first builds a task dependency graph and analyzes the relationship between new tasks and existing tasks. Then, a heuristic algorithm is used to calculate the optimal insertion position. The algorithm comprehensively considers factors such as task urgency, resource usage, and dependency restrictions, and minimizes the impact on existing tasks through iterative optimization. Finally, the system adjusts the execution plan of the affected tasks in real time, triggers the reordering of the task queue when necessary, and the entire process uses a transaction mechanism to ensure the consistency of the queue state.
[0133] When a new task is inserted, the execution order of the task conflicts with that of the existing tasks. For example, the newly inserted task A can only be executed after task B is completed, but task B depends on the output of task A, which forms a circular dependency; or a temporary task must be completed before the submission deadline, but other tasks it depends on may not be completed before the deadline.
[0134] The network reporting system handles dependency conflicts by constructing a task dependency graph and performing topological analysis. Specifically, the adjacency matrix is first used to represent the dependency relationship between tasks, and the matrix element aij indicates whether task i depends on task j. When a new task is inserted, the system calculates the dependency strength of the task with the existing tasks and updates the adjacency matrix. The system uses the Tarjan algorithm to detect whether there is a loop in the dependency graph. If there is, it indicates that a circular dependency has occurred. For the detected dependency conflicts, the system calculates the critical path length and time margin of each affected task, and rearranges the task execution order through a dynamic programming algorithm based on the task priority and deadline constraints. For example, when a temporary task that needs to be completed before the reporting deadline depends on other tasks that are being executed, the system calculates whether there is a feasible scheduling solution that meets all time constraints. If no feasible solution can be found, the system will trigger the task priority negotiation mechanism and notify the management terminal to adjust the task parameters or processing strategy. The time complexity of the entire conflict handling process is O(V+E), where V is the number of tasks and E is the number of dependencies.
[0135] In the embodiment of the present application, due to the adoption of a dynamic resource scheduling strategy, it is possible to achieve accurate positioning and dynamic optimization of temporary tasks. The system calculates the task priority score through a multi-dimensional priority evaluation model, combines the task dependency graph analysis to ensure the rationality of the execution order, and uses the prediction model trained with historical data to evaluate resource requirements. It effectively solves the problems of inflexible temporary task processing, frequent task conflicts, and unreasonable resource allocation in the traditional reporting system, thereby realizing the intelligent scheduling, optimal resource utilization, and stable and reliable operation of the reporting system, and improving the overall reporting efficiency and system availability.
[0136] The network reporting system in the embodiment of the present invention is described below from the perspective of hardware processing. Figure 3 , which is a schematic diagram of a physical device structure of a network reporting system in an embodiment of the present application.
[0137] It should be noted that Figure 3 The structure of the network reporting system shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.
[0138] like Figure 3 As shown, the network reporting system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage part 308 to the random access memory (RAM) 303, such as executing the method described in the above embodiment. In RAM 303, various programs and data required for system operation are also stored. CPU 301, ROM 302 and RAM 303 are connected to each other through bus 304. Input / output (I / O) interface 305 is also connected to bus 304.
[0139] The following components are connected to the I / O interface 305: an input section 306 including an audio input device, a button switch, etc.; an output section 307 including a liquid crystal display (LCD) and an audio output device, an indicator light, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed so that a computer program read therefrom is installed into the storage section 308 as needed.
[0140] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 309, and / or installed from a removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, various functions defined in the present invention are performed.
[0141] It should be noted that specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, apparatus, or device.
[0142] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. Each box in the flowchart or block diagram may represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box may also occur in an order different from that marked in the accompanying drawings.
[0143] Specifically, the network reporting system of this embodiment includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, the UKEY-based network reporting method provided in the above embodiment is implemented.
[0144] As another aspect, the present invention further provides a computer-readable storage medium, which may be included in the network reporting system described in the above embodiment; or may exist independently without being assembled into the network reporting system. The above storage medium carries one or more computer programs, and when the above one or more computer programs are executed by a processor of the network reporting system, the network reporting system implements the UKEY-based network reporting method provided in the above embodiment.
[0145] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0146] As used in the above embodiments, the term "when..." may be interpreted to mean "if..." or "after..." or "in response to determining..." or "in response to detecting...", depending on the context. Similarly, the phrases "upon determining..." or "if (the stated condition or event) is detected" may be interpreted to mean "if determining..." or "in response to determining..." or "upon detecting (the stated condition or event)" or "in response to detecting (the stated condition or event)", depending on the context.
[0147] Those skilled in the art can understand that to implement all or part of the processes in the above-mentioned embodiments, the processes can be completed by computer programs to instruct related hardware, and the programs can be stored in computer-readable storage media. When the programs are executed, they can include the processes of the above-mentioned method embodiments. The aforementioned storage media include: ROM or random access memory RAM, magnetic disk or optical disk and other media that can store program codes.
Claims
1. A network reporting method based on UKEY, characterized in that: Applied to a network reporting system, the method comprises: The receiving institution sends a login authentication request based on UKEY, which contains the institution number and fingerprint data; After verifying that the fingerprint data matches the pre-stored fingerprint to a higher degree than a preset matching threshold, generating authentication information including the institution number and a current timestamp; Generate a session identifier based on the authentication information and a preset private field, and integrate the session identifier, the organization number and the current timestamp to generate key negotiation reference data; The key negotiation reference data is encrypted using the SM2 algorithm to obtain first encrypted data; The receiving institution returns the second encrypted data in response to the first encrypted data, and generates a symmetric encryption key according to the first encrypted data and the second encrypted data; Receiving an encrypted data packet encrypted by the institution end using the symmetric encryption key, and decrypting the encrypted data packet using the symmetric encryption key to obtain reporting data; After confirming the validity of the submitted data according to the session identifier, the submitted data is stored in a preset database, and storage confirmation information is returned to the institution end.
2. The method according to claim 1, characterized in that Before the step of receiving the login authentication request including the institution number and fingerprint data sent by the institution end based on UKEY, the method further includes: Receive registration requests from multiple registration servers and perform identity authentication to determine multiple supervisory end servers; Allocate a unique identification code to each of the supervisory end servers, and establish a general communication link between the master control server and the multiple supervisory end servers; Receiving heartbeat packet information containing load data sent by the multiple supervisory end servers, and calculating a comprehensive load score of the supervisory end servers according to the load data; The step of generating authentication information including the institution number and the current timestamp after verifying that the matching degree between the fingerprint data and the pre-stored fingerprint is higher than a preset matching threshold specifically includes: After verifying that the matching degree between the fingerprint data and the pre-stored fingerprint is higher than a preset matching threshold, screening out the target server with the lowest comprehensive load score, and allocating the target server to the institution end; Generate a matching relationship table including the corresponding relationship between the target server and the institution end; Generate authentication information including the device identification of the target server, the organization number and the current timestamp.
3. The method according to claim 2, characterized in that After the step of generating a matching relationship table including the corresponding relationship between the target server and the target institution end, the method further includes: Sending a service allocation instruction including access information of the target institution end to the target server; After receiving the service readiness confirmation information returned by the target server, establishing a direct communication link between the target server and the target institution end; Determine the reporting period of the target institution end, and count down the binding connection of the communication direct link based on the reporting period.
4. The method according to claim 2, characterized in that: After the step of generating a matching relationship table including the corresponding relationship between the target server and the target institution end, the method further includes: Receiving a file-sensitive operation request uploaded by an instruction server, and determining a corresponding file to be operated and an operation type; the instruction server is one of the multiple supervisory end servers; After verifying the file-sensitive operation request based on the user operation, sending the file operation instruction to the instruction server through the general communication link; Receive the operation execution result returned by the instruction server, and store the file operation record of the instruction server.
5. The method according to claim 1, characterized in that After confirming the validity of the submitted data according to the session identifier, the step of storing the submitted data in a preset database and returning storage confirmation information to the institution side specifically includes: Verify the timeliness and authorization scope of the session identifier to obtain a session verification result; When the session verification result is a preset result, parsing the data structure of the reported data to determine the storage location of the reported data; The reported data is stored in the storage location, a storage record including the storage location and storage time is generated, and storage confirmation information is returned to the institution end.
6. The method according to claim 1, characterized in that After confirming the validity of the submitted data according to the session identifier, storing the submitted data in a preset database, and returning storage confirmation information to the institution end, the method further includes: Receive multiple report data packets to be imported, and establish an initial task queue including multiple import tasks; According to the timeliness and data volume of the reported data packet, priority correction is performed on the import task corresponding to the reported data packet in the initial task queue to obtain an optimized task queue; Data import is performed based on the optimized task queue, and an import progress report is generated; the import progress report includes the number of completed tasks, the number of remaining tasks and the estimated completion time.
7. The method according to claim 6, characterized in that After the step of executing data import based on the optimization task queue and generating an import progress report, the method further includes: Receive an adding request including a newly added temporary task from a management terminal, and determine a task type and an urgency level of the newly added temporary task; Calculate the task priority of the newly added temporary task based on the urgency, and determine the insertion position of the newly added temporary task in the optimized task queue; Inserting the newly added temporary task into the insertion position, and updating the optimized task queue; Push a new temporary task notification to the institution end corresponding to the optimization task queue.
8. A network reporting system, characterized in that: The network reporting system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the network reporting system to execute the method as described in any one of claims 1-7.
9. A computer-readable storage medium comprising instructions, characterized in that: When the instruction is executed on the network reporting system, the network reporting system executes the method as described in any one of claims 1-7.
10. A computer program product, characterized in that When the computer program product runs on a network reporting system, the network reporting system executes the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Fingerprint authentication method and system
CN105207776A
An identity authentication method and system based on a USBKey
CN109728909A
Instant message processing method and system based on multi-factor authentication
CN118713892A
Security object providing encryption scheme and key
US20040123112A1
Cited By
Video safety playing method and device based on multi-dimensional protection and medium
CN120676205A
Secure FTP (File Transfer Protocol) method, system and device based on elliptic curve and Hash fusion
CN120856333A
A secure FTP method, system, and apparatus based on elliptic curve and hash fusion
CN120856333B
Authorization use method and system of self-service equipment module
CN121333725A
Defense system for information security of trusted data space
CN121808768A