Data processing method and device, equipment, storage medium and program product

By using the target key and target terminal identifier between the applet and the gateway server for data encryption and decryption, the problem of the applet interacting with the main application increases the data transmission link, and the data processing efficiency and security are improved.

CN119946029APending Publication Date: 2025-05-06TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311469770.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-02
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

During the data processing process, the mini program increases the data transmission link due to the interaction with the main application, resulting in a decrease in data processing efficiency and success rate.

Method used

By introducing the target key and target terminal identifier between the applet and the gateway server, data encryption and decryption are performed, the interaction between the applet and the main application is reduced, and data is processed directly between the applet and the gateway server.

Benefits of technology

It improves the data processing efficiency and success rate of the mini program, reduces the data transmission link, and enhances the security of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946029A_ABST
    Figure CN119946029A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and device, equipment, a storage medium and a program product. The method is applied to data processing scenes of various applets such as cloud technology, artificial intelligence, intelligent transportation, vehicle-mounted and resource interaction. The data processing method comprises the steps that a to-be-called applet obtains first to-be-processed data in response to a program calling request; encrypting the first to-be-processed data by using the target key to obtain a first to-be-processed data ciphertext; sending the first to-be-processed data ciphertext and a target terminal identifier to a gateway server; receiving a first target data ciphertext sent by the gateway server for the first to-be-processed data ciphertext and the target terminal identifier; the target key is adopted to decrypt the first target data ciphertext to obtain first target data; and executing applet calling processing based on the first target data. Through the application, the data processing efficiency of the applet can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to data processing technology in the field of computer applications, and in particular to a data processing method, device, equipment, storage medium and program product. Background Art

[0002] A web application, also known as an applet, is a program that can be downloaded over the Internet and run directly in a browser environment. Compared with the client, it saves the installation process and can flexibly expand and upgrade the client's functions.

[0003] Generally speaking, when a mini program is called, the mini program's business data is usually sent to the background server through the main application (also called the host application) that the mini program depends on; and the interaction between the mini program and the main application increases the transmission chain of the mini program's business data, which in turn affects the data transmission efficiency, and also affects the mini program's data processing efficiency. Summary of the invention

[0004] The embodiments of the present application provide a data processing method, apparatus, device, computer-readable storage medium, and computer program product, which can improve the data processing efficiency of mini-programs.

[0005] The technical solution of the embodiment of the present application is implemented as follows:

[0006] The present application provides a data processing method, the method comprising:

[0007] In response to a program call request, obtaining first data to be processed;

[0008] Encrypting the first data to be processed by using the target key to obtain a ciphertext of the first data to be processed;

[0009] Sending the first ciphertext of the data to be processed and the target terminal identifier to the gateway server, where the target terminal identifier is used to identify the terminal where the mini-program to be called runs;

[0010] Receiving a first target data ciphertext sent by the gateway service end in response to the first to-be-processed data ciphertext and the target terminal identifier;

[0011] Decrypting the first target data ciphertext using the target key to obtain first target data;

[0012] The applet calling process is performed based on the first target data.

[0013] The present application also provides a data processing method, the method comprising:

[0014] Receive a first ciphertext of data to be processed and a target terminal identifier sent by the mini-program to be called;

[0015] Determine a target key corresponding to the target terminal identifier based on a correspondence between the terminal identifier and the key;

[0016] Decrypting the first data to be processed ciphertext based on the target key to obtain the first data to be processed;

[0017] Obtaining first target data from a background server based on the first data to be processed;

[0018] Encrypting the first target data based on the target key to obtain a first target data ciphertext;

[0019] The first target data ciphertext is sent to the applet to be called, and the applet to be called is used to perform applet calling processing based on the first target data ciphertext.

[0020] The present application provides a first data processing device, the first data processing device comprising:

[0021] A request response module, used for obtaining first data to be processed in response to a program call request;

[0022] A first encryption module, used to encrypt the first data to be processed using a target key to obtain a ciphertext of the first data to be processed;

[0023] A first sending module, used for sending the first ciphertext of the data to be processed and a target terminal identifier to the gateway server, wherein the target terminal identifier is used for identifying the terminal on which the mini-program to be called is running;

[0024] A first decryption module is used to receive the first target data ciphertext sent by the gateway server for the first to-be-processed data ciphertext and the target terminal identifier, and decrypt the first target data ciphertext using the target key to obtain the first target data;

[0025] A calling processing module is used to execute mini-program calling processing based on the first target data.

[0026] In an embodiment of the present application, the first data processing device also includes a method determination module, which is used to obtain a key encryption public key in response to the first startup of the program to generate the target key; use the key encryption public key to encrypt the target key to obtain a target key ciphertext, and use the target key to encrypt the second data to be processed of the to-be-processed mini-program to obtain a second data ciphertext to be processed; send the target key ciphertext and the second data ciphertext to be processed to the gateway server; receive the second target data ciphertext and the target terminal identifier sent by the gateway server for the target key ciphertext and the second data to be processed; store the target terminal identifier, and execute the mini-program call processing based on the second target data corresponding to the second target data ciphertext.

[0027] In an embodiment of the present application, the method determination module is also used to send a public key acquisition request to the gateway client, and the gateway client is used to generate the key encryption public key in response to the public key acquisition request, and the main application that the mini program to be called depends on includes the gateway client; receive the key encryption public key sent by the gateway client in response to the public key acquisition request.

[0028] In an embodiment of the present application, the mode determination module is further used to send the target terminal identifier to the gateway client, and the gateway client is used to store the target terminal identifier.

[0029] In the embodiment of the present application, the first sending module is further used to obtain the target terminal identifier from the gateway client.

[0030] In an embodiment of the present application, the request response module is also used to obtain the original data to be processed in response to the program call request; determine the target metadata filter based on the data structure type of the original data to be processed; and serialize the original data to be processed based on the target metadata filter to obtain the first data to be processed.

[0031] In an embodiment of the present application, the request response module is also used to serialize the original data to be processed based on the target metadata filter to obtain the data to be obfuscated; and to obfuscate the data processing method name in the data to be obfuscated to obtain the first data to be processed.

[0032] In an embodiment of the present application, the request response module is further used to store the data to be obfuscated; and in response to a network retry request, obtain the first data to be processed based on the stored data to be obfuscated.

[0033] In an embodiment of the present application, the request response module is also used to obtain mini-program call information in response to the program call request when the mini-program to be called is awaiting authentication; when the calling permission of the mini-program to be called is determined based on the mini-program call information, the first data to be processed is obtained.

[0034] In an embodiment of the present application, the call processing module is also used to receive the call error information sent by the gateway server in response to the first ciphertext of the data to be processed and the target terminal identifier, the call error information including at least one of an error description and an error code, the error description being used to indicate the cause of the error; and output the call error information.

[0035] In an embodiment of the present application, the first data to be processed is obtained through the data layer of the mini-program to be called; the call processing module is also used to execute the mini-program interface update logic in the view model of the mini-program to be called based on the first target data to obtain the interface data to be updated; based on the interface data to be updated, the currently presented interface is updated in the view of the mini-program to be called.

[0036] This embodiment of the present application provides a second data processing device, the second data processing device comprising:

[0037] A key determination module, configured to receive a first ciphertext of data to be processed and a target terminal identifier sent by the mini-program to be called; and determine a target key corresponding to the target terminal identifier based on a correspondence between the terminal identifier and the key;

[0038] A second decryption module, used to decrypt the first ciphertext of the data to be processed based on the target key to obtain the first data to be processed;

[0039] A background interaction module, used for obtaining first target data from a background server based on the first data to be processed;

[0040] A second encryption module, used for encrypting the first target data based on the target key to obtain a ciphertext of the first target data;

[0041] The second sending module sends the first target data ciphertext to the mini-program to be called, and the mini-program to be called is used to execute mini-program calling processing based on the first target data ciphertext.

[0042] In an embodiment of the present application, the second data processing device also includes a relationship determination module, which is used to receive a target key ciphertext sent by the applet to be called when the program is first started; use the key encryption private key sent by the gateway client to decrypt the target key ciphertext to obtain the target key, the main application that the applet to be called depends on includes the gateway client, and the key encryption private key is generated by the gateway client in response to the public key acquisition request sent by the applet to be called, and the public key acquisition request is sent by the applet to be called to the gateway client when it is first started; determine the target terminal identifier of the target key; store the target key and the target terminal identifier accordingly to obtain the corresponding relationship between the terminal identifier and the key.

[0043] In an embodiment of the present application, the background interaction module is also used to detect the first data to be processed; determine at least one of an error code and an error description based on the detection result, and the error description is used to indicate the cause of the error; determine call error information based on at least one of the error code and the error description; send the call error information to the applet to be called, and the applet to be called is used to output the call error information.

[0044] An embodiment of the present application provides a terminal for data processing, wherein a small program to be called is run on the terminal, and the terminal includes:

[0045] A first memory, used to store computer executable instructions or computer programs;

[0046] The first processor is used to implement the data processing method applied to the terminal provided in the embodiment of the present application when executing the computer executable instructions or computer program stored in the first memory.

[0047] The embodiment of the present application provides a gateway server for data processing, the gateway server comprising:

[0048] A second memory, used to store computer executable instructions or computer programs;

[0049] The second processor is used to implement the data processing method applied to the gateway server provided in the embodiment of the present application when executing the computer executable instructions or computer program stored in the second memory.

[0050] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions or a computer program, wherein the computer-executable instructions or the computer program are used to implement the data processing method applied to the terminal provided in the embodiment of the present application when executed by a first processor; or, the computer-executable instructions or the computer program are used to implement the data processing method applied to the gateway server provided in the embodiment of the present application when executed by a second processor.

[0051] An embodiment of the present application provides a computer program product, including computer executable instructions or a computer program. When the computer executable instructions or the computer program are executed by a first processor, the data processing method applied to a terminal provided by the embodiment of the present application is implemented; or, when the computer executable instructions or the computer program are executed by a second processor, the data processing method applied to a gateway server provided by the embodiment of the present application is implemented.

[0052] The embodiments of the present application have at least the following beneficial effects: when responding to a program call request of a mini-program to be called, the first data to be processed of the mini-program to be called is sent to the gateway server through the determined target key and target terminal identifier; in the gateway server, the first target data to be returned of the first data to be processed is determined through the target key and the target terminal identifier, and then the first target data ciphertext is sent to the called mini-program, so that the called mini-program can execute the mini-program call processing based on the target key and the first target data ciphertext; in this way, during the calling process of the mini-program to be called, data processing is performed between the mini-program to be called and the gateway server, which reduces the interaction between the mini-program to be called and the main application, thereby improving the data processing efficiency of the mini-program. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a schematic diagram of the architecture of the data processing system provided in the embodiment of the present application;

[0054] Figure 2 This is a method provided by the embodiment of the present application. Figure 1 A schematic diagram of the structure of the terminal in FIG.

[0055] Figure 3 This is a method provided by the embodiment of the present application. Figure 1 A schematic diagram of the structure of the server in FIG.

[0056] Figure 4 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 1 ;

[0057] Figure 5 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 2 ;

[0058] Figure 6 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 3 ;

[0059] Figure 7 is an exemplary data transmission schematic diagram provided in an embodiment of the present application;

[0060] Figure 8 is a schematic diagram of an exemplary refresh view provided in an embodiment of the present application;

[0061] Fig. 9 It is an exemplary data processing diagram provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.

[0063] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0064] In the following description, the terms "first\second" are used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0065] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meanings as those commonly understood by those skilled in the art. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0066] Before further describing the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations.

[0067] 1) Artificial Intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In the embodiment of the present application, AI can be used to perform data analysis on the mini program (for example, data analysis based on the frequency of mini program calls), and then information recommendation and other processing can be performed based on the data analysis results.

[0068] 2) Machine Learning (ML) is a multi-disciplinary cross-disciplinary subject involving probability theory, statistics, approximation theory, convex analysis and algorithm complexity theory. It is used to study computer simulation or realization of human learning behavior to acquire new knowledge or skills; reorganize the existing knowledge structure to continuously improve its performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent. Machine learning applications are spread across all fields of artificial intelligence. Machine learning generally includes technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning and inductive learning. Among them, artificial neural networks are mathematical models that imitate the structure and function of biological neural networks. The exemplary structures of artificial neural networks in the embodiments of the present application include graph convolutional networks (Graph Convolutional Network, GCN, a neural network for processing graph-structured data), deep neural networks (Deep Neural Networks, DNN), convolutional neural networks (Convolutional Neural Network, CNN) and recurrent neural networks (Recurrent Neural Network, RNN), neural state machines (Neural State Machine, NSM) and phase function neural networks (Phase-Functioned Neural Network, PFNN), etc. When the embodiment of the present application uses AI to perform data analysis on the mini program, it can be implemented using an artificial neural network in machine learning; that is, an artificial neural network model is used to perform data analysis on the mini program's call data to determine the information to be recommended, etc.

[0069] 3) Mobile gateway refers to a component that connects the client and server API interfaces, which can simplify the data protocol and communication protocol of the server API interface and improve network communication efficiency. In the embodiment of the present application, the mobile gateway is also called the mini program gateway or gateway client, which is used to connect the mini program and the backend server to transfer business data from the mini program to the backend server.

[0070] 4) Intercept filter, used to pre-process (or post-process) the application request (or response), such as authentication, authorization, logging, etc., and then pass the request (or response) to the corresponding processing program, that is, to be applied to the request (or response) before passing the request to the target application. In the embodiment of the present application, the intercept filter is also called the metadata filter (MDF) and is used to process the applet data and the call error information returned by the specification.

[0071] 5) Model-View-ViewModel (MVVM), which is mainly used to separate the data layer, view, and view model of the application. The embodiment of the present application uses MVVM to separate the applet from the host application in terms of data and view. Among them, the view is used to encapsulate the user interface (UI) and UI logic; the view model is used to encapsulate the logical representation and state; and the model is used to encapsulate the business logic and data.

[0072] 6) Mini programs are programs developed based on front-end languages ​​(such as JavaScript) and implement services in Hypertext Markup Language (HTML) pages. After being downloaded through the client, they can be interpreted and executed immediately, and there is no need to perform installation steps in the client. Among them, mini programs include public mini programs and private mini programs. There are functional limitations between public mini programs and host applications due to unclear application scenarios, while there are no scenario configuration files between private mini programs and host applications.

[0073] Generally speaking, when a mini program is called, the mini program's business data is usually sent to the background server through the main application (also called the host application) that the mini program depends on; and the interaction between the mini program and the main application increases the transmission chain of the mini program's business data, which in turn affects the data transmission efficiency, which also affects the data processing efficiency of the mini program. In other words, when the mini program transmits data to the background server, it usually does so through the mini program's main application, which increases the data transmission link and affects the data transmission efficiency and success rate. In addition, when the mini program transmits the mini program's business data to the background server, the main application transmits the mini program's business data. At this time, the first network security device corresponding to the host application obtains the business data from the host application by hijacking; based on the pre-stored communication address replication strategy, the source Media Access Control (Media Access Control, MAC) address and / or source Internet Protocol (Internet The method further comprises the steps of: rewriting specific fields of a virtualized MAC address and / or a virtualized IP address of a wireless router to generate a virtualized MAC address and / or a virtualized IP address including authentication information; sending a data packet carrying the virtualized MAC address and / or the virtualized IP address to a background server, so that the virtualized MAC address and / or the virtualized IP address can be parsed by a second network security device of the background server for authentication; receiving a data packet from the background server, parsing the virtualized MAC address and / or the virtualized IP address including authentication information in the received data packet based on the address replication strategy of the communicating parties, and authenticating the background server based on the parsing result; however, the above-mentioned data transmission is achieved by compiling the addresses by two network security devices, which increases the probability of network failure; in addition, the business data obtained through the hijacking technology may be data tampered with inside the terminal, such as other components or third-party libraries also using the hijacking technology, which affects the transmission of the mini-program business data and the security of the mini-program business data during network transmission.

[0074] Based on this, the embodiments of the present application provide a data processing method, apparatus, device, computer-readable storage medium and computer program product, which can improve the data processing efficiency, success rate and security of the mini program. The following describes the exemplary application of the device (including the terminal and the gateway server) provided in the embodiments of the present application. The terminal and the gateway server provided in the embodiments of the present application can be implemented as various types of electronic devices such as smart phones, smart watches, laptops, tablets, desktop computers, smart home appliances, set-top boxes, smart car devices, portable music players, personal digital assistants, dedicated messaging devices, intelligent voice interaction devices, portable gaming devices and smart speakers; they can also be implemented as servers. Below, the exemplary application of the gateway server when it is implemented as a server will be described.

[0075] See also Figure 1 , Figure 1 Schematic diagram of the data processing system provided in the embodiment of the present application; Figure 1 As shown, to support a data processing application, in the data processing system 100, the terminal 400 (exemplarily shown are the terminal 400-1 and the terminal 400-2) is connected to the server 200 via the network 300. The network 300 can be a wide area network or a local area network, or a combination of the two. In addition, the data processing system 100 also includes a database 500 for providing data support to the server 200; and Figure 1 What is shown in the figure is a situation where the database 500 is independent of the server 200. In addition, the database 500 can also be integrated in the server 200, which is not limited in the embodiment of the present application.

[0076] The mini-program to be called in the terminal 400 is used to obtain the first data to be processed in response to a program call request (the graphical interface 410-1 for generating the program call request is exemplarily shown); the first data to be processed is encrypted using the target key to obtain the first data ciphertext to be processed; the first data ciphertext to be processed and the target terminal identifier are sent to the server 200 via the network 300, and the target terminal identifier is used to identify the terminal on which the mini-program to be called is running; the first target data ciphertext sent by the server 200 in response to the first data ciphertext to be processed and the target terminal identifier is received via the network 300; the first target data ciphertext is decrypted using the target key to obtain the first target data; and the mini-program call processing is performed based on the first target data (the graphical interface 410-2 is exemplarily shown).

[0077] The server 200 is used to receive the first ciphertext of data to be processed and the target terminal identifier sent by the small program to be called in the terminal 400 through the network 300; determine the target key corresponding to the target terminal identifier based on the corresponding relationship between the terminal identifier and the key; decrypt the first ciphertext of data to be processed based on the target key to obtain the first data to be processed, and the target terminal identifier and the first ciphertext of data to be processed are sent by the small program to be called in response to the program call request; obtain the first target data from the background server based on the first data to be processed; encrypt the first target data based on the target key to obtain the first target data ciphertext; send the first target data ciphertext to the small program to be called in the terminal 400 through the network 300.

[0078] In some embodiments, the server 200 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. The terminal and the server may be directly or indirectly connected via wired or wireless communication, which is not limited in the embodiments of the present application.

[0079] See also Figure 2 , Figure 2 This is a method provided by the embodiment of the present application. Figure 1 The schematic diagram of the terminal structure in FIG. Figure 2 As shown, the terminal 400 includes: at least one first processor 410, a first memory 450, at least one first network interface 420 and a user interface 430. The various components in the terminal 400 are coupled together through a first bus system 440. It can be understood that the first bus system 440 is used to realize the connection and communication between these components. In addition to the data bus, the first bus system 440 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 2 In the figure, various buses are labeled as a first bus system 440 .

[0080] The first processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0081] The user interface 430 includes one or more output devices 431 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0082] The first memory 450 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, etc. The first memory 450 may optionally include one or more storage devices physically located away from the first processor 410.

[0083] The first memory 450 includes a volatile memory or a non-volatile memory, and may also include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The first memory 450 described in the embodiment of the present application is intended to include any suitable type of memory.

[0084] In some embodiments, the first memory 450 can store data to support various operations, examples of which include programs, modules, and data structures, or a subset or superset thereof, as exemplarily described below.

[0085] The first operating system 451 includes system programs for processing various basic system services and performing hardware-related tasks, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks;

[0086] A first network communication module 452, used to reach other electronic devices via one or more (wired or wireless) first network interfaces 420, exemplary first network interfaces 420 include: Bluetooth, Wireless Fidelity (Wi-Fi), and Universal Serial Bus (USB), etc.;

[0087] a presentation module 453 for enabling presentation of information (e.g., a user interface for operating peripheral devices and displaying content and information) via one or more first output devices 431 (e.g., a display screen, a speaker, etc.) associated with the user interface 430;

[0088] The input processing module 454 is used to detect one or more user inputs or interactions from one of the one or more input devices 432 and translate the detected inputs or interactions.

[0089] In some embodiments, the first data processing device provided in the embodiments of the present application may be implemented in software. Figure 2 The first data processing device 455 stored in the first memory 450 is shown, which can be software in the form of a program and a plug-in, etc., and includes the following software modules: a request response module 4551, a first encryption module 4552, a first sending module 4553, a first decryption module 4554, a call processing module 4555 and a mode determination module 4556. These modules are logical, so they can be arbitrarily combined or further split according to the functions implemented. The functions of each module will be described below.

[0090] See also Figure 3 , Figure 3This is a method provided by the embodiment of the present application. Figure 1 The structural diagram of the server in Figure 3 As shown, the server 200 includes: at least one second processor 210, a second memory 250 and at least one second network interface 220. The various components in the server 200 are coupled together via a second bus system 240. It is understood that the second bus system 240 is used to achieve connection and communication between these components. In addition to the data bus, the second bus system 240 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 3 In the figure, various buses are labeled as a second bus system 240.

[0091] The second processor 210 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0092] The second memory 250 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, etc. The second memory 250 may optionally include one or more storage devices physically located away from the second processor 210.

[0093] The second memory 250 includes a volatile memory or a non-volatile memory, and may also include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory, and the volatile memory may be a random access memory. The second memory 250 described in the embodiment of the present application is intended to include any suitable type of memory.

[0094] In some embodiments, the second memory 250 can store data to support various operations, examples of which include programs, modules, and data structures, or a subset or superset thereof, as exemplarily described below.

[0095] The second operating system 251 includes system programs for processing various basic system services and performing hardware-related tasks, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks;

[0096] A second network communication module 252, used to reach other electronic devices via one or more (wired or wireless) second network interfaces 220, exemplary second network interfaces 220 include: Bluetooth, wireless compatibility certification, and universal serial bus, etc.;

[0097] In some embodiments, the second data processing device provided in the embodiments of the present application can be implemented in software. Figure 3 The second data processing device 255 stored in the second memory 250 is shown, which can be software in the form of a program and a plug-in, etc., including the following software modules: a key determination module 2551, a second decryption module 2552, a background interaction module 2553, a second encryption module 2554, a second sending module 2555 and a relationship determination module 2556. These modules are logical, so they can be arbitrarily combined or further split according to the functions implemented. The functions of each module will be explained below.

[0098] In some embodiments, the first data processing device and the second data processing device provided in the embodiments of the present application can be implemented in hardware. As an example, the first data processing device and the second data processing device provided in the embodiments of the present application can be processors in the form of hardware decoding processors, which are programmed to execute the data processing method provided in the embodiments of the present application. For example, the processor in the form of a hardware decoding processor can adopt one or more application specific integrated circuits (Application Specific Integrated Circuit, ASIC), DSP, programmable logic device (Programmable Logic Device, PLD), complex programmable logic device (Complex Programmable Logic Device, CPLD), field programmable gate array (Field-Programmable Gate Array, FPGA) or other electronic components.

[0099] Below, the data processing method provided by the embodiment of the present application will be described in combination with the exemplary application and implementation of the terminal and server provided in the embodiment of the present application. In addition, the data processing method provided by the embodiment of the present application is applied to data processing scenarios of various small programs such as cloud technology, artificial intelligence, smart transportation, vehicle-mounted and resource interaction.

[0100] See also Figure 4 , Figure 4 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 1 ; The following will be combined Figure 4 The steps shown are explained.

[0101] In an embodiment of the present application, the mini program to be called responds to the program call request, obtains the first data to be processed, and performs the following processing based on the obtained first data to be processed (see step 101, step 102, step 108 and step 109).

[0102] It should be noted that the applet to be called is the applet to be called, such as the asset processing applet, the game applet, etc.; the program call request is a request to call the applet to be called, that is, a request to start the applet to be called to perform the corresponding processing. Among them, the gateway server is used to process the business data to be processed of the applet to be called to obtain a business data return package corresponding to the business data to be processed. Here, the applet to be called responds to the program call request, obtains the business data requested to be processed by the program call request, and obtains the first data to be processed, such as the relevant data of the assets selected in the asset processing applet, the conversion processing data of the recommended information in the game applet, etc.; in addition, the first data to be processed is the business data to be sent by the applet to be called to the gateway server.

[0103] Step 101: The mini-program to be called encrypts the first data to be processed using the target key to obtain the ciphertext of the first data to be processed.

[0104] In an embodiment of the present application, a program call request occurs after the mini-program to be called and the gateway server have determined the target key, and the target key is a symmetric key for encrypting and decrypting business data when the mini-program to be called and the gateway server communicate with each other; thus, after the mini-program to be called obtains the first data to be processed, the target key is used to encrypt the first data to be processed, and the encrypted first data to be processed obtained is the ciphertext of the first data to be processed.

[0105] It should be noted that the target key is the key used in the symmetric encryption algorithm (for example, the elliptic curve public key cryptography algorithm SM2, etc.); that is, both the mini program to be called and the gateway server use the target key to decrypt the business data sent by the other party, and both use the target key to encrypt the business data to be sent to the other party.

[0106] Step 102: the mini-program to be called sends the first ciphertext of data to be processed and the target terminal identifier to the gateway server.

[0107] In an embodiment of the present application, the mini program to be called sends the first data to be processed ciphertext to the gateway server to send the first data to be processed to the gateway server; in addition, the mini program to be called sends the target terminal identifier to the gateway server while sending the first data to be processed ciphertext to the gateway server.

[0108] It should be noted that the target terminal identifier is used to identify the terminal on which the mini-program to be called is running, wherein the same mini-program corresponds to at least one terminal identifier, and the at least one terminal identifier is at least one terminal on which the mini-program is running; in addition, the target terminal identifier is the terminal identifier determined by the gateway server for the terminal on which the mini-program to be called is running, so that the mini-program to be called sends the first ciphertext of data to be processed and the target terminal identifier to the gateway server at the same time, so that the gateway server can decrypt the first ciphertext of data to be processed based on the target terminal identifier.

[0109] Step 103: The gateway server determines a target key corresponding to the target terminal identifier based on the correspondence between the terminal identifier and the key.

[0110] In an embodiment of the present application, when the calling applet sends the first data ciphertext to be processed and the target terminal identifier to the gateway server in response to the program call request, the gateway server receives the first data ciphertext to be processed and the target terminal identifier sent by the applet to be called; thus, after executing step 102, that is, when the applet to be called sends the first data ciphertext to be processed and the target terminal identifier to the gateway server, the gateway server also receives the first data ciphertext to be processed and the target terminal identifier. Here, the gateway server can access the correspondence between the terminal identifier and the key, so that after obtaining the target terminal identifier, the gateway server matches the target terminal identifier among the various terminal identifiers included in the correspondence between the terminal identifier and the key, and determines the key corresponding to the terminal identifier that matches the target terminal identifier as the target key.

[0111] It should be noted that, since the gateway server determines a terminal identifier for each terminal on which the mini program runs, the terminal identifier is associated and stored with the key sent by the mini program, so that the gateway server can obtain the keys corresponding to each terminal identifier; wherein the correspondence between the terminal identifier and the key is used to characterize the keys corresponding to each terminal identifier. Here, each key in the correspondence between the terminal identifier and the key is used to decrypt the business data corresponding to the corresponding terminal identifier.

[0112] Step 104: The gateway server decrypts the first data to be processed ciphertext based on the target key to obtain the first data to be processed.

[0113] It should be noted that the target key determined by the gateway server is the encryption key of the first data to be processed ciphertext obtained by the to-be-called applet through symmetric encryption, so the target key is the decryption key of the first data to be processed ciphertext; therefore, the gateway server uses the target key to decrypt the first data to be processed ciphertext sent by the to-be-called applet, and the decryption result obtained is the first data to be processed. It is easy to know that the target terminal identifier and the first data to be processed ciphertext are sent by the to-be-called applet in response to the program call request.

[0114] Step 105: The gateway server obtains first target data from the background server based on the first data to be processed.

[0115] In an embodiment of the present application, after the gateway server decrypts the first data to be processed, the authentication of the business data of the mini program to be called is completed; thus, the gateway server then interacts with the background server based on the first data to be processed to obtain the business data to be returned to the mini program to be called; here, the business data to be returned to the mini program to be called obtained based on the first data to be processed is called the first target data. It is easy to know that the first target data is the business data return package of the first data to be processed.

[0116] It should be noted that the background server can be the server of the mini program to be called, or the server of the main application that the mini program to be called depends on, or a combination of the two, which is determined based on the actual implementation situation and is not limited in this embodiment of the present application. Among them, the main application is the host application of the mini program to be called, that is, the application embedded in the mini program to be called; for example, the instant messaging program embedded in the game mini program, and the asset management program embedded in the asset processing program.

[0117] Step 106: The gateway server encrypts the first target data based on the target key to obtain a ciphertext of the first target data.

[0118] In an embodiment of the present application, before sending the first target data to the mini-program to be called, the gateway server uses the target key to encrypt the first target data, and the encryption result obtained is the first target data ciphertext; it is easy to know that the first target data ciphertext is the encrypted first target data.

[0119] It should be noted that the encryption of the first target data by the gateway server based on the target key is a symmetric encryption. Here, the gateway server is used to obtain the first target data ciphertext based on the first data to be processed ciphertext and the target terminal identifier.

[0120] Step 107: The gateway server sends the first target data ciphertext to the mini program to be called.

[0121] In an embodiment of the present application, the gateway server sends a first target data ciphertext to the mini-program to be called so that the mini-program to be called obtains the first target data.

[0122] Step 108: The mini-program to be called uses the target key to decrypt the first target data ciphertext to obtain the first target data.

[0123] In an embodiment of the present application, when the gateway server sends the first target data ciphertext to the applet to be called for the first data ciphertext to be processed and the target terminal identifier, the applet to be called receives the first target data ciphertext sent by the gateway server for the first target data ciphertext and the target terminal identifier; thus, after executing step 107, that is, after the gateway server sends the first target data ciphertext to the applet to be called, the applet to be called also receives the first target data ciphertext sent by the gateway server. Since the first target data ciphertext is obtained by the gateway server using the target key to symmetrically encrypt the first target data, after obtaining the first target data ciphertext, the applet to be called uses the target key to decrypt the first target data ciphertext, and the decryption result obtained is the first target data. It is easy to know that the first target data ciphertext in the applet to be called is sent by the gateway server for the first target data ciphertext and the target terminal identifier.

[0124] Step 109: The mini-program to be called executes mini-program calling processing based on the first target data.

[0125] In the embodiment of the present application, after the mini-program to be called obtains the first target data, it can perform mini-program call processing adapted to the program call request based on the first target data to complete the response to the program call request. Thus, the mini-program to be called is used to perform mini-program call processing based on the first target data ciphertext.

[0126] It should be noted that the applet to be called is independent of the main application that the applet to be called depends on in terms of data and interface, and the applet to be called adopts MVVM, including a data layer, a view, and a view model; thus, the applet to be called obtains the corresponding business data through the data layer, and thus, the first data to be processed is obtained through the data layer of the applet to be called; and the applet to be called performs the applet call processing based on the first target data, including: the applet to be called executes the applet interface update logic in the view model of the applet to be called based on the first target data to obtain the interface data to be updated; and updates the currently presented interface in the view of the applet to be called based on the interface data to be updated. Among them, executing the applet call processing includes executing the applet interface update logic processing and updating the currently presented interface processing.

[0127] It can be understood that the mini program to be called adopts MVVM, so that it can be independent of the main application when processing business data with the background server, which simplifies the transmission path of business data.

[0128] It can also be understood that when responding to the program call request of the mini-program to be called, the first data to be processed of the mini-program to be called is sent to the gateway server through the determined target key and target terminal identifier; in the gateway server, the first target data to be returned of the first data to be processed is determined through the target key and the target terminal identifier, and then the first target data ciphertext is sent to the called mini-program, so that the called mini-program can execute the mini-program call processing based on the target key and the first target data ciphertext; in this way, during the calling process of the mini-program to be called, data processing is performed between the mini-program to be called and the gateway server, which reduces the interaction between the mini-program to be called and the main application, thereby improving the data processing efficiency of the mini-program.

[0129] See also Figure 5 , Figure 5 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 2 ;like Figure 5 As shown, in the embodiment of the present application, steps 110 to 116 are also included before step 101; that is, before the mini program to be called responds to the program call request, the data processing method also includes steps 110 to 116, and each step is described below.

[0130] In the embodiment of the present application, the mini program to be called executes the following processing (steps 110 to 116) in response to the first startup of the program.

[0131] It should be noted that the first startup of a program refers to the startup when it is first called on the terminal where the mini-program to be called is running; that is, the first startup of a program corresponds to the first call of the mini-program to be called.

[0132] Step 110, the mini-program to be called obtains a key encryption public key, generates a target key, encrypts the target key using the key encryption public key to obtain a target key ciphertext, and uses the target key to encrypt the second data to be processed of the mini-program to be called to obtain a second data ciphertext to be processed.

[0133] It should be noted that when the applet to be called is started for the first time, it interacts with the gateway client to obtain the key encryption public key, so as to send the target key to the gateway server through the key encryption public key. Among them, the target key is a symmetric key generated by the applet to be called, for example, it can be the target key generated by the applet to be called calling a random function. Here, the applet to be called uses the key encryption public key to encrypt the target key, and the encryption result of the target key obtained is the target key ciphertext; in addition, the encryption of the target key by the applet to be called using the key encryption public key is asymmetric encryption. In addition, the process of the applet to be called using the target key to encrypt the second data to be processed of the applet to be called is similar to the process of using the target key to encrypt the first data to be processed of the applet to be called, the difference is that the encryption objects are different, and the embodiments of the present application will not be repeated here. The target key ciphertext is the encrypted target key, and the second data to be processed ciphertext is the encrypted second data to be processed.

[0134] In an embodiment of the present application, the mini program to be called obtains a key encryption public key, including: the mini program to be called sends a public key acquisition request to the gateway client; and receives the key encryption public key sent by the gateway client in response to the public key acquisition request.

[0135] It should be noted that when the mini program to be called is started for the first time, it sends a public key acquisition request to the gateway client, and the gateway client is used to generate a key encryption public key in response to the public key acquisition request, and send the key encryption public key to the mini program to be called; thus, the key encryption public key is generated by the gateway client in response to the public key acquisition request sent by the mini program to be called, the public key acquisition request is sent by the mini program to be called to the gateway client when the program is started for the first time, and the target key ciphertext is sent by the mini program to be called when the program is started for the first time. Among them, the main application that the mini program to be called depends on includes the gateway client, that is, the gateway client is built into the main application; and the gateway client is the front end of the gateway server.

[0136] Step 111: The mini-program to be called sends the target key ciphertext and the second data ciphertext to be processed to the gateway server.

[0137] It should be noted that the mini program to be called sends the target key ciphertext and the second data to be processed ciphertext to the gateway server, so that the gateway server obtains the target key and the second data to be processed based on the target key ciphertext and the second data to be processed ciphertext.

[0138] Step 112: The gateway server uses the key encryption private key sent by the gateway client to decrypt the target key ciphertext to obtain the target key.

[0139] It should be noted that when the mini-program to be called sends the target key ciphertext and the second data ciphertext to be processed to the gateway server, the gateway server receives the target key ciphertext and the second data ciphertext to be processed sent by the mini-program to be called; thus, after executing step 111, that is, after the mini-program to be called sends the target key ciphertext and the second data ciphertext to be processed to the gateway server, the gateway server also receives the target key ciphertext and the second data ciphertext to be processed. Since the gateway client generates a key encryption public key in response to the public key acquisition request, it also generates a key encryption private key corresponding to the key encryption public key, and sends the key encryption private key to the gateway server; thus, after receiving the target key ciphertext, the gateway server can use the key encryption private key to decrypt the target key ciphertext, and the decryption result of the target key ciphertext obtained is the target key; in this way, the gateway server also obtains the target key, indicating that the mini-program to be called has determined a common target key with the gateway server.

[0140] Step 113: The gateway server determines the target terminal identifier of the target key, stores the target key and the target terminal identifier accordingly, and obtains the corresponding relationship between the terminal identifier and the key.

[0141] It should be noted that the gateway server assigns a unique identifier to the decrypted target key, and the unique identifier is the determined target terminal identifier; then, the gateway server stores the target key and the target terminal identifier in correspondence, and the correspondence between the terminal identifier and the corresponding key stored at this time is called the correspondence between the terminal identifier and the key.

[0142] Step 114: The gateway server uses the target key to decrypt the second data to be processed ciphertext to obtain the second data to be processed; obtains the second target data from the background server based on the second data to be processed; and encrypts the second target data based on the target key to obtain the second target data ciphertext.

[0143] In an embodiment of the present application, the gateway server is also used to use the decrypted target key to decrypt the received second data to be processed ciphertext, and the decryption result of the second data to be processed ciphertext obtained is the second data to be processed; then, it can interact with the background server to obtain the business data return package of the second data to be processed, which is the second target data; here, the gateway server device is also used to use the target key to encrypt the second target data to send the encrypted second target data to the mini program to be called; wherein, the decryption result of the second target data is the second target data ciphertext.

[0144] Step 115: The gateway server sends the target terminal identifier and the second target data ciphertext to the mini-program to be called.

[0145] It should be noted that the gateway server sends the target terminal identifier to the mini program to be called and also sends the second target data ciphertext to the mini program to be called. It can be seen that the gateway server is also used to obtain the second target data ciphertext and the target terminal identifier based on the target key ciphertext and the second data ciphertext to be processed.

[0146] Step 116: The mini-program to be called stores the target terminal identifier, and executes mini-program calling processing based on the second target data corresponding to the second target data ciphertext.

[0147] It should be noted that the gateway service sends the target terminal identifier and the second target data ciphertext to the applet to be called, and the applet to be called receives the second target data ciphertext and the target terminal identifier sent by the gateway service for the target key ciphertext and the second data to be processed; thus, after executing step 115, that is, after the gateway service sends the target terminal identifier and the second target data ciphertext to the applet to be called, the applet to be called also receives the target terminal identifier and the second target data ciphertext. The applet to be called stores the target terminal identifier so as to carry the target terminal identifier when sending business data to the gateway service later to achieve authentication; and the applet to be called completes the first startup of the program based on the second target data ciphertext. The applet includes: the applet to be called uses the target key to decrypt the second target data ciphertext to obtain the second target data, and then executes the applet call processing based on the second target data. It is easy to know that the second target data ciphertext and the target terminal identifier are sent by the gateway service for the target key ciphertext and the second data to be processed.

[0148] In step 116 of the embodiment of the present application, the to-be-called applet stores the target terminal identifier, including: the to-be-called applet sends the target terminal identifier to the gateway client, so that the gateway client stores the target terminal identifier.

[0149] It should be noted that the gateway client is used to store the target terminal identifier. For example, the gateway client stores the target terminal identifier in the memory of the terminal where the mini-program to be called runs.

[0150] Accordingly, in the embodiment of the present application, before the mini-program to be called sends the first ciphertext of data to be processed and the target terminal identifier to the gateway server, the data processing method further includes: the mini-program to be called obtains the target terminal identifier from the gateway client.

[0151] It should be noted that, since the target terminal identifier assigned by the gateway server is stored by the gateway client after being received by the mini program to be called, the mini program to be called interacts with the gateway client to obtain the target terminal identifier from the gateway client.

[0152] It can be understood that when the mini program to be called is started for the first time, it jointly determines the target key and the target terminal identifier corresponding to the target key with the gateway server, so that in the subsequent call processing process, the call processing of the mini program to be called can be realized through the target terminal identifier and the business data to be processed.

[0153] In an embodiment of the present application, the data processing method also includes a process of obtaining first data to be processed, and the process of obtaining the first data to be processed includes: the mini program to be called obtains the original data to be processed corresponding to the program call request, and performs the following processing based on the original data to be processed: first, based on the data structure type of the original data to be processed, determine the target metadata filter; then, based on the target metadata filter, serialize the original data to be processed to obtain the first data to be processed.

[0154] It should be noted that the original data to be processed is the original business data requested to be processed by the program call request; here, the small program to be called serializes the original data to be processed through the target metadata filter, which improves the standardization and uniformity of the first data to be processed. In addition, the metadata filter is used to serialize the original business data, and different metadata filters are used to process the original business data of different data structures; the target metadata filter is a metadata filter adapted to the data structure of the original data to be processed.

[0155] In an embodiment of the present application, the mini program to be called can directly use the serialization result of the original business data as the first data to be processed, or it can perform obfuscation processing on the serialization result of the original business data and use the obfuscated result as the first data to be processed. The embodiment of the present application is not limited to this.

[0156] In an embodiment of the present application, the mini-program to be called serializes the original data to be processed based on the target metadata filter to obtain the first data to be processed, including: the mini-program to be called first serializes the original data to be processed based on the target metadata filter to obtain the data to be obfuscated; and obfuscates the name of the data processing method in the data to be obfuscated to obtain the first data to be processed.

[0157] It should be noted that the name of the data processing method in the data to be obfuscated refers to the name of a method used to perform at least one of the following processes: data preprocessing, static dictionary processing, compression, etc.

[0158] It can be understood that by obfuscating the name of the data processing method in the obfuscated data to obtain the first processed data to be transmitted, the complexity of deciphering the first processed data after being intercepted is improved, thereby improving the data processing security of the mini program.

[0159] In an embodiment of the present application, the mini-program to be called serializes the original data to be processed based on the target metadata filter to obtain the data to be obfuscated. The data processing method also includes: the mini-program to be called stores the data to be obfuscated, and performs the following processing based on the stored data to be obfuscated: in response to a network retry request, obtaining the first data to be processed based on the stored data to be obfuscated.

[0160] It should be noted that the network retry request is a retry request initiated when the mini program to be called fails to interact with the gateway server based on the first data to be processed.

[0161] It is understandable that after obtaining the data to be obfuscated, the mini program to be called backs up the data to be obfuscated, so that when the first data to be processed fails in the processing process, the first data to be processed can be obtained by reusing the data to be obfuscated, thereby improving data processing efficiency.

[0162] In an embodiment of the present application, the data processing method further includes: when the mini program to be called is waiting for authentication, the mini program to be called responds to the program call request and obtains the first data to be processed, including: in response to the program call request, obtaining mini program call information, and when it is determined based on the mini program call information that the call permission of the mini program to be called is included, obtaining the first data to be processed. When it is determined based on the mini program call information that the call permission of the mini program to be called is not included, generating call failure information of the mini program to be called, and outputting the call failure information.

[0163] It should be noted that when there is access authentication for the mini-program to be called, it is determined that the mini-program to be called is waiting for authentication; whether the mini-program to be called has access authentication can be determined based on the business function of the mini-program to be called, for example, the mini-program to be called with data security has access authentication. Mini-program call information refers to information used to call the mini-program to be called, including at least one of the following: caller name, call content, requested operation, request duration, current number of requests, etc. Here, the mini-program to be called determines whether the caller has the calling permission for the mini-program to be called based on the mini-program call information. When it is determined that it exists, it is determined that the calling permission for the mini-program to be called is included, and when it is determined that it does not exist, it is determined that the calling permission for the mini-program to be called is not included. Among them, the call failure information indicates that there is no authority to call the mini-program to be called.

[0164] See also Figure 6 , Figure 6 This is a flow chart of the data processing method provided in the embodiment of the present application. Figure 3 ;like Figure 6As shown, after step 104 in the embodiment of the present application, steps 117 to 119 are also included; that is, the gateway server decrypts the first ciphertext of the data to be processed sent by the calling applet based on the target key, and after obtaining the first data to be processed, the data processing method also includes steps 117 to 119, and each step is explained below.

[0165] Step 117: The gateway server detects the first data to be processed, determines at least one of an error code and an error description based on the detection result, and determines call error information based on at least one of the error code and the error description.

[0166] It should be noted that the error description is used to indicate the cause of the error, and the error code refers to the error code.

[0167] It can be understood that the gateway server implements the standardization of error information when the mini program is called by determining at least one of the error code and the error description as the call error information.

[0168] Step 118: The gateway server sends a call error message to the mini program to be called.

[0169] It should be noted that the applet to be called is used to output the calling error information; the gateway server sends the calling error information to the applet to be called so that the applet to be called outputs the calling error information.

[0170] Step 119: The mini-program to be called outputs a calling error message.

[0171] It should be noted that the gateway server sends the call error information to the applet to be called, and the applet to be called receives the call error information sent by the gateway server for the first ciphertext of data to be processed and the target terminal identifier; thus, after executing step 118, that is, after the gateway server sends the call error information to the applet to be called, the applet to be called also receives the call error information. It is easy to know that the call error information refers to the information sent by the gateway server for the first ciphertext of data to be processed and the target terminal identifier.

[0172] In an embodiment of the present application, the terminal on which the mini-program to be called runs can also be used to perform data analysis on the calling information of the mini-program to be called, so as to recommend and display the related information of the mini-program to be called based on the data analysis results.

[0173] Next, an exemplary application of the embodiment of the present application in an actual application scenario will be described. The exemplary application describes the process of calling a mini-program in a resource interaction scenario.

[0174] See also Figure 7 , Figure 7 is an exemplary data transmission schematic diagram provided in an embodiment of the present application; Figure 7 As shown, the exemplary data transmission interaction process includes steps 701 to 711, and each step is described below.

[0175] Step 701, applet 7-1 (referred to as the applet to be called) randomly generates a symmetric key (RandomKey, referred to as the target key).

[0176] It should be noted that when the mini program 7-1 is started on the terminal for the first time, the mini program 7-1 calls a random function (Random function) to generate a symmetric key.

[0177] Step 702, applet 7-1 uses the public key to asymmetrically encrypt the symmetric key to obtain the symmetric key ciphertext (Secret, called the target key ciphertext), and uses the symmetric key to symmetrically encrypt the business data (called the second data to be processed) to obtain the business data ciphertext (called the second data to be processed ciphertext).

[0178] It should be noted that when mini program 7-1 is started for the first time on the terminal, a pair of asymmetric keys is generated for mini program 7-1 by the gateway (also called gateway client) built into the host application of mini program 7-1. The pair of asymmetric keys includes a public key (called key encryption public key) and a private key (called key encryption private key); wherein the gateway sends the public key to mini program 7-1 and the private key to gateway server 7-2, so that mini program 7-1 can use the public key to encrypt the symmetric key. Here, business data refers to the data to be processed that is sent to the background server by calling mini program 7-1. The background server is at least one of the mini program server and the host application server. In the actual implementation process, the background server is determined based on the application scenario of the mini program.

[0179] Step 703, the mini program 7-1 sends the symmetric key ciphertext and the business data ciphertext to the gateway server 7-2.

[0180] It should be noted that the mini program 7-1 sends the symmetric key ciphertext to the gateway server 7-2 to send the symmetric key to the gateway server 7-2.

[0181] Step 704, the gateway server 7-2 uses the private key to decrypt the symmetric key ciphertext to obtain the symmetric key, and determines the terminal identifier (SessionID, called the target terminal identifier) ​​for the symmetric key, and stores the symmetric key and the terminal identifier accordingly.

[0182] It should be noted that, since the gateway has sent the private key to the gateway server 7-2, the gateway server 7-2 can use the private key to decrypt the symmetric key ciphertext. In this way, the gateway server 7-2 also obtains the symmetric key, and the key determination of the applet and the gateway server is completed. In addition, since the same applet can be run in multiple terminals, the terminal identifier can be used to distinguish different terminals running the same applet.

[0183] Step 705, the gateway server 7-2 uses a symmetric key to decrypt the business data ciphertext to obtain the business data; based on the business data, obtain the business data to be returned (called the second target data) from the background server, and use the symmetric key to symmetrically encrypt the business data to be returned to obtain the ciphertext of the business data to be returned (called the second target data ciphertext).

[0184] It should be noted that the gateway server 7 - 2 interacts with the background server based on the decrypted business data to obtain the business data to be returned.

[0185] Step 706: The gateway server 7-2 sends the terminal identification and the encrypted business data to be returned to the mini program 7-1.

[0186] It should be noted that when the gateway server 7-2 sends the ciphertext of the business data to be returned to the mini program 7-1, it also sends the terminal identification to the mini program 7-1 so as to process the business data based on the terminal identification during the subsequent business data transmission process.

[0187] Step 707, applet 7-1 uses the symmetric key to decrypt the ciphertext of the business data to be returned, obtains the business data to be returned, completes the corresponding business processing based on the business data to be returned, and stores the terminal identifier.

[0188] It should be noted that the mini program 7-1 can store the terminal identification through the gateway, and here, the gateway can store the terminal identification in the terminal memory. In addition, each time the mini program 7-1 sends service data to the gateway server 7-2, it carries the terminal identification.

[0189] Step 708, the mini program 7-1 uses a symmetric key to symmetrically encrypt the new business data (called the first data to be processed), obtains the new business data ciphertext (called the first data to be processed ciphertext), and sends the terminal identifier and the new business data ciphertext to the gateway server 7-2.

[0190] It should be noted that when mini program 7-1 is called again, mini program 7-1 also obtains new business data. Here, new business data refers to the new data to be processed that is to be sent to the background server by calling mini program 7-1; when mini program 7-1 sends the ciphertext of new business data to the gateway server 7-2, it also sends the terminal identification to the gateway server 7-2, so that the gateway server 7-2 obtains the corresponding symmetric key based on the terminal identification.

[0191] Step 709, the gateway server 7-2 determines the corresponding symmetric key from the corresponding relationship between the symmetric key and the terminal identifier based on the terminal identifier, and uses the symmetric key to decrypt the new business data ciphertext to obtain the new business data; then obtains the response business data from the background server based on the new business data, uses the symmetric key to symmetrically encrypt the response business data to obtain the response business data ciphertext.

[0192] It should be noted that the gateway server 7 - 2 interacts with the background server based on the decrypted business data to obtain the business data to be returned.

[0193] Step 710: The gateway server 7-2 sends a ciphertext of the response business data to the mini program 7-1.

[0194] Step 711, applet 7-1 uses a symmetric key to decrypt the ciphertext of the response business data, obtains the response business data, and completes the corresponding business processing based on the response business data.

[0195] It should be noted that the applet is separated from the host application in terms of data and UI through MVVM, and the data layer, view (View) and view model (ViewModel) of the applet are separated. Here, the applet stores the data structure used in the host application (i.e., the data structure of the applet) through the model file (e.g., Model.js), handles network requests and data processing. In addition, in the model file of the applet, methods for interacting with the backend server are encapsulated, such as methods for obtaining data, methods for updating data, methods for deleting data, etc. Here, the communication channel between the applet and the backend server is determined through steps 701 to 707, that is, the transmission of business data is performed using a determined terminal identifier and key; and a hardware security module (HSM) and a cryptographic machine (SSL VPN device) are used at the receiving end of the business data of the applet (i.e., the gateway server) to perform key management, and the business data is encrypted and transmitted to the applet or the backend server, and the backend server is used to analyze the request for business data and return the business data requested by the applet. Thus, the mini program 7-1 executes the corresponding UI update logic in the view model based on the business data, such as data formatting, button status, page refresh, etc. Among them, the function used to execute the UI update logic is bound by the view model to perform the corresponding calculation or logical operation in the view model, and return the execution result in the view, thereby achieving the function of refreshing the view. For example, the function of obtaining native capabilities such as Bluetooth, photography, positioning, and maps from the application is implemented in the ViewModel, and then returned to the view layer of the mini program for display.

[0196] For example, see Figure 8 , Figure 8 is a schematic diagram of an exemplary refresh view provided in an embodiment of the present application; Figure 8 As shown, based on the business data 8-2 transmitted by the filter channel 8-1, the corresponding calculation or logical operation is performed in the view model 8-3, and the execution result 8-4 is returned to the view Figure 8-5 , in order to achieve the effect of refreshing the interface.

[0197] It should be noted that the filter channel is used to assemble applet data of different applet data structures to obtain business data. Among them, the filter channel includes metadata filters (MDF) corresponding to different applet data structures. The applet data structure assembled by MDF includes business identification (ID), class name, script file (for example, js file) path, audio and video, and binary variables, etc. Here, the assembly process is the process of serializing (also known as encoding) the applet data, so that the assembled data is a fixed file format; in addition, each applet data structure corresponds to an MDF, and the MDFs of different applet data structures form a filter chain, that is, a filter channel.

[0198] Here, the applet or gateway server uses MDFs of different applet data structures to serialize the applet data to obtain different serialization results, and then verifies the serialization results in the process of assembling the obtained different serialization results into the target object (Target object) to determine whether the serialization result matches the preset information; for example, the serialization result is the serialization result of the input account name, and the applet verifies the serialization result based on the preset account name format rule to verify the illegal call of the filter channel by other modules, components or applet, or to verify the invalid data generated by the internal logic error of the applet. In addition, after the target object is assembled, the target object is stored in the stack area of ​​the gateway for reuse when the network request is retried; and the name of the data processing method (such as preprocessing method, static dictionary method, compression method, etc.) called by the target object is obfuscated to prevent the external access and modification of the data in the target object through hooks or reflection.

[0199] For example, see Fig. 9 , Fig. 9 is an exemplary data processing schematic diagram provided in the embodiment of the present application; Fig. 9As shown, after the applet data of different applet data structures (exemplarily showing applet data 9-11 and applet data 9-12) are injected into the filter chain 9-3, they are serialized based on the corresponding metadata filters (exemplarily showing metadata filter 9-31 corresponding to applet data 9-11, and metadata filter 9-32 corresponding to applet data 9-12) to obtain serialization results (exemplarily showing serialization result 9-41 corresponding to applet data 9-11, and serialization result 9-42 corresponding to applet data 9-12); in the process of assembling the serialization results, each serialization result is verified, and the serialization results are assembled into a target object 9-5 when the verification passes; then, the method parameters in the target object 9-5 are verified to determine whether the verification is successful, if not, an exception is determined; if so, the target object 9-5 is copied to be stored in the stack area 9-6 of the gateway, and the method name in the target object 9-5 is obfuscated to obtain business data 9-7, and the business data 9-7 is passed to the gateway server 9-8.

[0200] In an embodiment of the present application, mini-programs with different business functions in the host application correspond to different priorities. For example, there are three priorities with decreasing priorities: high priority (PRIORITY_HIGH), default priority (PRIORITY_DEFAULT) and low priority (PRIORITY_LOW); among them, the mini-program with high priority can only be called when the authentication is successful, such as the asset trading mini-program; the mini-program with default priority can be authenticated or not when called, such as the ID card shooting mini-program; the mini-program with low priority can be called directly, such as the QR code scanning mini-program. Here, the mini-program implements authentication based on the configured call object name, mini-program interface, expiration time and number of calls. Through authentication, the mini-program call request can be filtered for the gateway server.

[0201] In the embodiment of the present application, the gateway server can also perform request analysis based on business data, such as Uniform Resource Locator (URL) legitimacy, Domain Name Server (DNS) resolution, network status monitoring, etc.; when an error is analyzed, the error information (also called error call information) is sent back to the mini program caller in the form of error code definition plus error code. The corresponding relationship between error code definition and error code is shown in Table 1.

[0202] Table 1

[0203]

[0204]

[0205] It is understandable that when the applet is first started, after the symmetric key and terminal identification are determined by the gateway and the gateway server, the communication with the gateway server can be realized based on the symmetric key and terminal identification in the subsequent business data transmission; that is, the business data can be transmitted through a layer of gateway service, which reduces the interaction between the applet and the host application, and shortens the business data transmission link, thereby improving the success rate and efficiency of business data transmission and improving the stability of business data transmission. In addition, MVVM is used to separate the applet and the host application from the data and user interface, so that the applet can directly obtain business data from the gateway server, and perform corresponding calculations or logical operations in the view model based on the business data to achieve normal rendering of the applet interface. In addition, by determining the business data to be transmitted to the gateway server through MDF, the security of data transmission can be improved; and by authenticating the call of the applet, the influence of the host application or other applet on the current call of the applet can be reduced, and the stability of the applet operation can be improved; and the format of business data and error information is also standardized, which improves the versatility of data processing of the applet.

[0206] The following is a description of an exemplary structure of the first data processing device 455 provided in the embodiment of the present application implemented as a software module. In some embodiments, for example Figure 2 As shown, the software modules stored in the first data processing device 455 of the first memory 450 may include:

[0207] The request response module 4551 is used to obtain first data to be processed in response to a program call request;

[0208] A first encryption module 4552 is used to encrypt the first data to be processed using a target key to obtain a ciphertext of the first data to be processed;

[0209] The first sending module 4553 is used to send the first ciphertext of the data to be processed and the target terminal identifier to the gateway server, where the target terminal identifier is used to identify the terminal where the mini-program to be called is running;

[0210] The first decryption module 4554 is used to receive the first target data ciphertext sent by the gateway server in response to the first data ciphertext to be processed and the target terminal identifier; decrypt the first target data ciphertext using the target key to obtain the first target data;

[0211] The call processing module 4555 is used to perform mini-program call processing based on the first target data.

[0212] In an embodiment of the present application, the first data processing device 455 also includes a method determination module 4556, which is used to obtain a key encryption public key in response to the first startup of the program to generate the target key; use the key encryption public key to encrypt the target key to obtain a target key ciphertext, and use the target key to encrypt the second data to be processed of the to-be-processed mini-program to obtain a second data ciphertext to be processed; send the target key ciphertext and the second data ciphertext to be processed to the gateway server; receive the second target data ciphertext and the target terminal identifier sent by the gateway server for the target key ciphertext and the second data to be processed; store the target terminal identifier, and execute the mini-program call processing based on the second target data corresponding to the second target data ciphertext.

[0213] In an embodiment of the present application, the method determination module 4556 is also used to send a public key acquisition request to the gateway client, and the gateway client is used to generate the key encryption public key in response to the public key acquisition request, and the main application that the mini program to be called depends on includes the gateway client; receive the key encryption public key sent by the gateway client in response to the public key acquisition request.

[0214] In the embodiment of the present application, the mode determination module 4556 is further used to send the target terminal identifier to the gateway client, and the gateway client is used to store the target terminal identifier.

[0215] In the embodiment of the present application, the first sending module 4553 is further used to obtain the target terminal identifier from the gateway client.

[0216] In an embodiment of the present application, the request response module 4551 is also used to obtain the original data to be processed in response to the program call request; determine the target metadata filter based on the data structure type of the original data to be processed; and serialize the original data to be processed based on the target metadata filter to obtain the first data to be processed.

[0217] In an embodiment of the present application, the request response module 4551 is also used to serialize the original data to be processed based on the target metadata filter to obtain the data to be obfuscated; and to obfuscate the data processing method name in the data to be obfuscated to obtain the first data to be processed.

[0218] In the embodiment of the present application, the request response module 4551 is further used to store the data to be obfuscated; and in response to a network retry request, obtain the first data to be processed based on the stored data to be obfuscated.

[0219] In an embodiment of the present application, the request response module 4551 is also used to obtain mini-program call information in response to the program call request when the mini-program to be called is waiting for authentication; when the calling permission of the mini-program to be called is determined based on the mini-program call information, the first data to be processed is obtained.

[0220] In an embodiment of the present application, the call processing module 4555 is also used to receive the call error information sent by the gateway server for the first data ciphertext to be processed and the target terminal identifier, the call error information including at least one of an error description and an error code, the error description being used to indicate the cause of the error; and output the call error information.

[0221] In an embodiment of the present application, the first data to be processed is obtained through the data layer of the mini-program to be called; the call processing module 4555 is also used to execute the mini-program interface update logic in the view model of the mini-program to be called based on the first target data to obtain the interface data to be updated; based on the interface data to be updated, the currently presented interface is updated in the view of the mini-program to be called.

[0222] The following further describes an exemplary structure of the second data processing device 255 provided in the embodiment of the present application implemented as a software module. In some embodiments, for example Figure 3 As shown, the software modules stored in the second data processing device 255 of the second memory 250 may include:

[0223] The key determination module 2551 is used to receive the first data ciphertext to be processed and the target terminal identifier sent by the mini-program to be called; based on the correspondence between the terminal identifier and the key, determine the target key corresponding to the target terminal identifier;

[0224] A second decryption module 2552 is used to decrypt the first data to be processed ciphertext based on the target key to obtain the first data to be processed;

[0225] A background interaction module 2553 is used to obtain first target data from a background server based on the first data to be processed;

[0226] A second encryption module 2554 is used to encrypt the first target data based on the target key to obtain a first target data ciphertext;

[0227] The second sending module 2555 sends the first target data ciphertext to the mini-program to be called, and the mini-program to be called is used to perform mini-program calling processing based on the first target data ciphertext.

[0228] In an embodiment of the present application, the second data processing device 255 also includes a relationship determination module 2556, which is used to receive the target key ciphertext sent by the applet to be called when the program is first started; use the key encryption private key sent by the gateway client to decrypt the target key ciphertext to obtain the target key, the main application that the applet to be called depends on includes the gateway client, and the key encryption private key is generated by the gateway client in response to the public key acquisition request sent by the applet to be called, and the public key acquisition request is sent by the applet to be called to the gateway client when it is first started; determine the target terminal identification of the target key; store the target key and the target terminal identification accordingly to obtain the corresponding relationship between the terminal identification and the key.

[0229] In an embodiment of the present application, the background interaction module 2553 is also used to detect the first data to be processed; determine at least one of an error code and an error description based on the detection result, and the error description is used to indicate the cause of the error; determine a call error message based on the error code and at least one of the error description; send the call error message to the applet to be called, and the applet to be called is used to output the call error message.

[0230] The embodiment of the present application provides a computer program product, which includes computer executable instructions or computer programs, and the computer executable instructions or computer programs are stored in a computer-readable storage medium. The first processor of the terminal reads the computer executable instructions or computer programs from the computer-readable storage medium, and the first processor executes the computer executable instructions or computer programs, so that the terminal executes the data processing method applied to the terminal described in the embodiment of the present application. The second processor of the gateway server reads the computer executable instructions or computer programs from the computer-readable storage medium, and the second processor executes the computer executable instructions or computer programs, so that the terminal executes the data processing method applied to the gateway server described in the embodiment of the present application.

[0231] The present application embodiment provides a computer-readable storage medium, in which computer-executable instructions or computer programs are stored. When the computer-executable instructions or computer programs are executed by a first processor, the first processor will be caused to execute the data processing method applied to the terminal provided by the embodiment of the present application; when the computer-executable instructions or computer programs are executed by a second processor, the second processor will be caused to execute the data processing method applied to the gateway server provided by the embodiment of the present application; for example, Figure 4 The data processing method is shown.

[0232] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or may be various devices including one or any combination of the above memories.

[0233] In some embodiments, computer executable instructions may be in the form of a program, software, software module, script or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine or other unit suitable for use in a computing environment.

[0234] As an example, computer-executable instructions may, but need not, correspond to a file in a file system, may be stored as part of a file that stores other programs or data, such as in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinated files (e.g., files storing one or more modules, subroutines, or code portions).

[0235] As an example, computer executable instructions may be deployed to be executed on multiple electronic devices located at one location (in this case, the multiple electronic devices located at one location are terminals and a gateway server), or, to be executed on multiple electronic devices distributed at multiple locations and interconnected by a communication network (in this case, the multiple electronic devices distributed at multiple locations and interconnected by a communication network are terminals and a gateway server).

[0236] It is understandable that in the embodiments of the present application, when the embodiments of the present application are applied to specific products or technologies, the user's permission or consent is required, and the collection, use and processing of relevant data need to comply with the relevant laws, regulations and standards of relevant countries and regions. In addition, the collection and processing of relevant data in this application should strictly follow the requirements of relevant national laws and regulations when applying in examples, obtain the informed consent or separate consent of the subject of personal information, and carry out subsequent data use and processing within the scope of authorization of laws and regulations and the subject of personal information. In addition, in this application, the face (or other biometric) recognition technology involved, when the above embodiments of this application are applied to specific products or technologies, the relevant data collection, use and processing process should comply with the requirements of national laws and regulations, and the information processing rules should be informed before collecting face information and the separate consent of the target object should be sought, and face information should be processed in strict accordance with the requirements of laws and regulations and personal information processing rules, and technical measures should be taken to ensure the security of relevant data. In addition, in this application, if the implementation of a data capture technical solution is involved, when the above embodiments of this application are applied to specific products or technologies, the relevant data collection, use and processing processes should comply with the requirements of national laws and regulations, and conform to the principles of legality, legitimacy and necessity. It does not involve the acquisition of data types prohibited or restricted by laws and regulations, and will not hinder the normal operation of the target website.

[0237] To sum up, when the embodiment of the present application responds to the call request of the mini program to be called, the first to-be-processed data of the mini program to be called is sent to the gateway server through the determined target key and target terminal identifier; in the gateway server, the first target data to be returned of the first to-be-processed data is determined through the target key and the target terminal identifier, and then the first target data ciphertext is sent to the called mini program, so that the called mini program can execute the mini program call processing based on the target key and the first target data ciphertext; in this way, during the calling process of the mini program to be called, data processing is performed between the mini program to be called and the gateway server, which reduces the interaction between the mini program to be called and the main application, thereby improving the data processing efficiency and accuracy of the mini program.

[0238] The above is only an embodiment of the present application and is not intended to limit the protection scope of the present application. Any modifications, equivalent substitutions and improvements made within the spirit and scope of the present application are included in the protection scope of the present application.

Claims

1. A data processing method, characterized in that: The method is executed by the applet to be called, and the method includes: In response to a program call request, obtaining first data to be processed; Encrypting the first data to be processed by using the target key to obtain a ciphertext of the first data to be processed; Sending the first ciphertext of the data to be processed and the target terminal identifier to the gateway server, where the target terminal identifier is used to identify the terminal where the mini-program to be called runs; Receiving a first target data ciphertext sent by the gateway service end in response to the first to-be-processed data ciphertext and the target terminal identifier; Decrypting the first target data ciphertext using the target key to obtain first target data; The applet calling process is performed based on the first target data.

2. The method according to claim 1, characterized in that Before obtaining the first data to be processed in response to the program call request, the method further includes: In response to the program being started for the first time, obtaining a key encryption public key and generating the target key; The target key is encrypted using the key encryption public key to obtain a target key ciphertext, and the second to-be-processed data of the to-be-called applet is encrypted using the target key to obtain a second to-be-processed data ciphertext; Sending the target key ciphertext and the second data to be processed ciphertext to the gateway server; Receiving a second target data ciphertext and a target terminal identifier sent by the gateway server in response to the target key ciphertext and the second data to be processed; The target terminal identifier is stored, and a mini-program call process is executed based on the second target data corresponding to the second target data ciphertext.

3. The method according to claim 2, characterized in that The obtaining of the key encryption public key comprises: Sending a public key acquisition request to a gateway client, the gateway client being used to generate the key encryption public key in response to the public key acquisition request, wherein the main application program that the mini-program to be called depends on includes the gateway client; The key encryption public key is received, which is sent by the gateway client in response to the public key acquisition request.

4. The method according to claim 2, characterized in that: The storing of the target terminal identifier includes: Sending the target terminal identifier to a gateway client, wherein the gateway client is used to store the target terminal identifier; Before sending the first ciphertext of the data to be processed and the target terminal identifier to the gateway server, the method further includes: The target terminal identifier is obtained from the gateway client.

5. The method according to any one of claims 1 to 4, characterized in that: The step of obtaining first data to be processed in response to the program call request includes: In response to the program call request, obtaining original data to be processed; Determining a target metadata filter based on the data structure type of the original data to be processed; The original data to be processed is serialized based on the target metadata filter to obtain the first data to be processed.

6. The method according to claim 5, characterized in that The serializing the original data to be processed based on the target metadata filter to obtain the first data to be processed includes: Serializing the original data to be processed based on the target metadata filter to obtain data to be obfuscated; Obfuscating the data processing method name in the data to be obfuscated to obtain the first data to be processed.

7. The method according to claim 6, characterized in that After the original data to be processed is serialized based on the target metadata filter to obtain the data to be obfuscated, the method further includes: Storing the data to be obfuscated; In response to the network retry request, the first data to be processed is obtained based on the stored data to be obfuscated.

8. The method according to any one of claims 1 to 4, characterized in that: When the mini program to be called is waiting for authentication, the step of obtaining first data to be processed in response to the program calling request includes: In response to the program call request, obtaining mini-program call information; When the calling permission of the mini-program to be called is determined based on the mini-program calling information, the first data to be processed is obtained.

9. The method according to any one of claims 1 to 4, characterized in that: After sending the first ciphertext of the data to be processed and the target terminal identifier to the gateway server, the method further includes: Receiving call error information sent by the gateway server in response to the first ciphertext of the data to be processed and the target terminal identifier, the call error information including at least one of an error description and an error code, the error description being used to indicate a cause of the error; Output the call error information.

10. The method according to any one of claims 1 to 4, characterized in that: The first data to be processed is obtained through the data layer of the mini-program to be called; The performing of mini-program calling processing based on the first target data includes: Based on the first target data, the mini-program interface update logic is executed in the view model of the mini-program to be called to obtain the interface data to be updated; Based on the interface data to be updated, the currently presented interface is updated in the view of the mini-program to be called.

11. A data processing method, characterized in that: The method comprises: Receive a first ciphertext of data to be processed and a target terminal identifier sent by the mini-program to be called; Determine a target key corresponding to the target terminal identifier based on a correspondence between the terminal identifier and the key; Decrypting the first data to be processed ciphertext based on the target key to obtain the first data to be processed; Obtaining first target data from a background server based on the first data to be processed; Encrypting the first target data based on the target key to obtain a first target data ciphertext; The first target data ciphertext is sent to the applet to be called, and the applet to be called is used to perform applet calling processing based on the first target data ciphertext.

12. The method according to claim 11, characterized in that Before receiving the first ciphertext of data to be processed and the target terminal identifier sent by the mini-program to be called, the method further includes: Receiving the target key ciphertext sent by the mini program to be called when the program is first started; The target key is decrypted by using the key encryption private key sent by the gateway client to obtain the target key, wherein the main application that the to-be-called applet depends on includes the gateway client, and the key encryption private key is generated by the gateway client in response to a public key acquisition request sent by the to-be-called applet, and the public key acquisition request is sent by the to-be-called applet to the gateway client when it is first started; Determine a target terminal identifier of the target key; The target key and the target terminal identifier are stored correspondingly to obtain a corresponding relationship between the terminal identifier and the key.

13. The method according to claim 11 or 12, characterized in that: After decrypting the first data to be processed ciphertext based on the target key to obtain the first data to be processed, the method further includes: detecting the first data to be processed; Determine at least one of an error code and an error description based on the detection result, wherein the error description is used to indicate the cause of the error; Determine call error information based on at least one of the error code and the error description; The calling error information is sent to the applet to be called, and the applet to be called is used to output the calling error information.

14. A first data processing device, characterized in that: The first data processing device comprises: A request response module, used for obtaining first data to be processed in response to a program call request; A first encryption module, used to encrypt the first data to be processed using a target key to obtain a ciphertext of the first data to be processed; A first sending module, used for sending the first ciphertext of the data to be processed and a target terminal identifier to the gateway server, wherein the target terminal identifier is used for identifying the terminal on which the mini-program to be called is running; A first decryption module is used to receive the first target data ciphertext sent by the gateway server for the first to-be-processed data ciphertext and the target terminal identifier, and decrypt the first target data ciphertext using the target key to obtain the first target data; A calling processing module is used to execute mini-program calling processing based on the first target data.

15. A second data processing device, characterized in that: The second data processing device comprises: A key determination module, configured to receive a first ciphertext of data to be processed and a target terminal identifier sent by the mini-program to be called; and determine a target key corresponding to the target terminal identifier based on a correspondence between the terminal identifier and the key; A second decryption module, used to decrypt the first ciphertext of the data to be processed based on the target key to obtain the first data to be processed; A background interaction module, used for obtaining first target data from a background server based on the first data to be processed; A second encryption module, used for encrypting the first target data based on the target key to obtain a ciphertext of the first target data; The second sending module sends the first target data ciphertext to the mini-program to be called, and the mini-program to be called is used to execute mini-program calling processing based on the first target data ciphertext.

16. A terminal for data processing, characterized in that: The terminal runs a small program to be called, and the terminal includes: A first memory, used to store computer executable instructions or computer programs; The first processor is used to implement the data processing method according to any one of claims 1 to 10 when executing the computer executable instructions or computer programs stored in the first memory.

17. A gateway server for data processing, characterized in that: The gateway server includes: A second memory, used to store computer executable instructions or computer programs; The second processor is used to implement the data processing method described in any one of claims 11 to 13 when executing the computer executable instructions or computer programs stored in the second memory.

18. A computer-readable storage medium storing computer-executable instructions or a computer program, characterized in that: When the computer-executable instructions or computer program are executed by the first processor, the data processing method described in any one of claims 1 to 10 is implemented; or, when the computer-executable instructions or computer program are executed by the second processor, the data processing method described in any one of claims 11 to 13 is implemented.

19. A computer program product comprising computer executable instructions or a computer program, characterized in that: When the computer-executable instructions or computer program are executed by the first processor, the data processing method described in any one of claims 1 to 10 is implemented; or, when the computer-executable instructions or computer program are executed by the second processor, the data processing method described in any one of claims 11 to 13 is implemented.