Data encryption method, data processing method and related equipment

By partially extending the first key, the second key is obtained, and sensitive data is encrypted, the problem of computing resource consumption caused by the generation of a new key for each encryption in the prior art is solved, and the effect of saving computing resources while ensuring security is achieved.

CN119995984APending Publication Date: 2025-05-13TIANJIU SHARING NETWORK TECH GRP CO LTD

Patent Information

Application Number
CN202510141798.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In data encryption technology, a new key needs to be generated every time sensitive data is encrypted to avoid the key being brute-forced, resulting in increased computing resource consumption.

Method used

By obtaining the data to be encrypted and the first key that has not reached the usage limit, the metadata is obtained according to the security level of the data, and partially expanding the first key to obtain a second key, and the data is encrypted using the second key.

Benefits of technology

Without reducing security, the consumption of computing resources is reduced and the difficulty of cracking keys is increased.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995984A_ABST
    Figure CN119995984A_ABST
Patent Text Reader

Abstract

The invention provides a data encryption method, a data processing method and related equipment, and relates to the technical field of data processing. The method comprises the following steps: acquiring to-be-encrypted data and a first key, wherein the first key is a key which does not reach a use limit; determining the security level of the to-be-encrypted data according to the to-be-encrypted data; under the condition that the security level is the first security level, obtaining metadata; partially expanding the first key according to the metadata to obtain a second key; and encrypting the to-be-encrypted data by using the second key to obtain encrypted transmission data. Under the condition that the security level is the first security level, the first secret key is partially expanded through the metadata to obtain the second secret key, and the to-be-encrypted data is encrypted through the second secret key, so that computing resources are saved under the condition that the security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the field of data processing technology, with the continuous development of the information society, data security has become an important issue that all walks of life need to pay attention to, especially in areas involving personal privacy, financial transactions, and medical health. In order to prevent the leakage of sensitive data and ensure the privacy and integrity of information, data encryption technology has been widely used. Encryption technology converts raw data into ciphertext, and only authorized users with keys can decrypt the data, thereby effectively preventing unauthorized access and data tampering. With the surge in data transmission volume, especially in the era of cloud computing and big data, how to ensure the security of large amounts of data has become a key problem in technological development.

[0003] In the related art, each time sensitive data is encrypted, a new set of keys needs to be generated to prevent data leakage after the keys are cracked by brute force. Although this approach can increase security, it increases the consumption of computing resources.

[0004] How to save computing resources without reducing security is an urgent problem to be solved. Summary of the invention

[0005] The present disclosure provides a data encryption method, a processing method and related devices, which save computing resources without reducing security.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, there is provided a data encryption method, including obtaining data to be encrypted and a first key, wherein the first key is a key that has not reached a usage limit; determining a security level of the data to be encrypted based on the data to be encrypted; obtaining metadata when the security level is a first security level; partially expanding the first key based on the metadata to obtain a second key; and encrypting the data to be encrypted using the second key to obtain encrypted transmission data; wherein the metadata includes at least a creation time and / or a data channel mark.

[0008] According to another aspect of the present disclosure, a multi-channel data processing method is provided, the method comprising: obtaining data to be processed through multiple data collection channels, the data to be processed comprising data to be encrypted and non-encrypted data; extracting the data to be encrypted; encrypting the data to be encrypted according to a first key or a second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached a usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; storing the encrypted transmission data in a database of a first application; and in response to log changes in a storage clue table of the database, adopting a real-time stream processing mode, transmitting the change data of the database to a message middleware, so that a downstream receiving device receives it according to resource usage.

[0009] According to another aspect of the present disclosure, there is provided a data encryption device, the device comprising: a first acquisition module, used to acquire data to be encrypted and a first key, the first key being a key that has not reached a usage limit; a level determination module, used to determine the security level of the data to be encrypted based on the data to be encrypted; a first encryption module, used to acquire metadata when the security level is the first security level; partially expand the first key based on the metadata to obtain a second key; encrypt the data to be encrypted using the second key to obtain encrypted transmission data; wherein the metadata at least includes a creation time and / or a data channel mark.

[0010] According to another aspect of the present disclosure, a multi-channel data processing device is provided, the device comprising: a second acquisition module, used to acquire data to be processed through multiple data collection channels, the data to be processed comprising data to be encrypted and non-encrypted data; an extraction module, used to extract the data to be encrypted; a second encryption module, used to encrypt the data to be encrypted according to a first key or a second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached a usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; a storage module, used to store the encrypted transmission data in a database of a first application; a transmission module, used to respond to log changes in a storage clue table of the database, and adopt a real-time stream processing mode to transmit the change data of the database to the message middleware, so that the downstream receiving device receives it according to resource usage.

[0011] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned data encryption methods or multi-channel data processing methods by executing the executable instructions.

[0012] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, any of the above-mentioned data encryption methods or multi-channel data processing methods is implemented.

[0013] According to another aspect of the present disclosure, a computer program product is provided, which includes a computer program or computer instructions, and the computer program or the computer instructions are loaded and executed by a processor to enable a computer to implement any of the above-mentioned data encryption methods or multi-channel data processing methods.

[0014] In the embodiment of the present disclosure, by obtaining the data to be encrypted and the first key, the first key is a key that has not reached the usage limit; according to the data to be encrypted, the security level of the data to be encrypted is determined; when the security level is the first security level, metadata is obtained; the first key is partially expanded according to the metadata to obtain the second key; the data to be encrypted is encrypted using the second key to obtain encrypted transmission data. In the present disclosure, when the security level is the first security level, the first key is partially expanded through metadata (not regenerating a new key) to obtain the second key, and the data to be encrypted (sensitive data) is encrypted by the second key. The present disclosure can increase the difficulty of cracking the second key by partially expanding the key, thereby saving computing resources while ensuring security.

[0015] In addition, the present disclosure solves the problem of lack of personal information positioning due to limited data acquisition channels through a processing method for collecting user information through multiple channels, and realizes the collection and integration of customer information based on multiple channels.

[0016] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0018] Figure 1 A schematic diagram showing an exemplary system architecture to which the data encryption method or multi-channel data processing method according to an embodiment of the present disclosure can be applied.

[0019] Figure 2 A flow chart of a data encryption method according to an embodiment of the present disclosure is shown.

[0020] Figure 3 A flow chart of a data encryption method according to another embodiment of the present disclosure is shown.

[0021] Figure 4 A schematic diagram of a method for processing multi-channel data in an embodiment of the present disclosure is shown.

[0022] Figure 5 A schematic diagram showing multi-channel acquisition of data to be processed in an embodiment of the present disclosure.

[0023] Figure 6 A schematic diagram of a data encryption device in an embodiment of the present disclosure is shown.

[0024] Figure 7 A schematic diagram of a multi-channel data processing device in an embodiment of the present disclosure is shown.

[0025] Figure 8 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown.

[0026] Fig. 9 A schematic diagram of a computer-readable storage medium provided in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0027] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0028] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0029] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0030] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0031] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0032] For ease of understanding, several terms involved in the present disclosure are explained below:

[0033] APP (Application) usually refers to a software that can run on devices such as smartphones, tablets, and computers.

[0034] The clue middle-office system is mainly used to distribute leads to sales personnel. It supports the formulation of rules for distributing leads, configuration of distribution sales personnel lists, rules for collecting leads, etc. Among them, the leads collected by the first application (for example, Boss Cloud APP) are one of the data sources of the clue middle-office system.

[0035] The Sensors Tracking System is a data collection tool for mobile applications. It tracks user behaviors and events in the first application (for example, the Boss Cloud APP) by adding code snippets to the page within the first application, collects this data, and displays it visually.

[0036] Producer: The party that sends data.

[0037] Consumer: Responsible for subscribing to the topic in the message middleware and pulling messages from the subscribed topic. For example, the consumer can be a receiving device of the present disclosure (such as the clue middleware system).

[0038] Message middleware: It can be a distributed message middleware. It has the characteristics of low latency, high reliability, scalability, and ease of use. Producers write messages to the queue, and consumers take messages from the queue to perform business logic.

[0039] Media platform: An application program used on an electronic device. For example, media platforms may include Baidu, Tencent, Zhihu, Kuaishou Short Video, Douyin Short Video, etc.

[0040] In the field of data processing technology, with the continuous development of the information society, data security has become an important issue that all walks of life need to pay attention to, especially in areas such as personal privacy, financial transactions, and medical health. In order to prevent the leakage of sensitive data and ensure the privacy and integrity of information, data encryption technology has been widely used.

[0041] The inventors have found that each time sensitive data is encrypted, a new set of keys needs to be generated to prevent data leakage after the keys are cracked by brute force. Although this approach can increase security, it increases the consumption of computing resources.

[0042] In addition, the existing technology has problems such as limited data acquisition channels and the inability to simply, efficiently and in real time process multi-channel data in a unified manner.

[0043] Based on at least one of the above problems, the embodiment of the present disclosure provides a data encryption method, which can be applied to the scenario of data encryption. Exemplarily, it can be applied to the scenario of confidential storage or transmission of enterprise data. According to the technical solution provided by the embodiment of the present disclosure, by obtaining the data to be encrypted and the first key, the first key is a key that has not reached the usage limit, and according to the data to be encrypted, the security level of the data to be encrypted is determined; when the security level is the first security level, metadata is obtained, and the first key is partially expanded according to the metadata to obtain the second key, and the data to be encrypted is encrypted using the second key to obtain encrypted transmission data. In the case where the security level is the first security level, the present disclosure partially expands the first key through metadata (not regenerating a new key) to obtain the second key, and encrypts the data to be encrypted (sensitive data) through the second key. The present disclosure can increase the difficulty of cracking the second key by partially expanding the key, thereby saving computing resources while ensuring security.

[0044] Figure 1 A schematic diagram showing an exemplary system architecture to which the data encryption method or multi-channel data processing method according to an embodiment of the present disclosure can be applied.

[0045] like Figure 1 As shown, the system architecture may include a server 101, a network 102 and a terminal device 103. The network 102 is used to provide a medium for a communication link between the terminal device 103 and the server 101. The network 102 may include various connection types, such as wired, wireless communication links or optical fiber cables.

[0046] In an exemplary embodiment, the terminal device 103 for data transmission with the server 101 may include but is not limited to mobile devices such as smart phones, tablet computers, and laptop computers, as well as terminal devices with specific functions or forms such as smart speakers, digital assistants, AR (Augmented Reality) devices, VR (Virtual Reality) devices, and smart wearable devices. Alternatively, the terminal device 103 may also be a personal computer, such as a laptop computer and a desktop computer. Optionally, the operating system running on the electronic device may include but is not limited to Android, IOS, Linux, Windows, etc.

[0047] Server 101 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. In some practical applications, server 101 can also be a server of a network platform, which can be, for example, a trading platform, a live broadcast platform, a social platform, or an audio platform, etc., which is not limited in the embodiments of the present disclosure. Among them, the server can be a single server or a cluster formed by multiple servers, and the present disclosure does not limit the specific architecture of the server. In an embodiment of the present invention, the server 101 can be the Boss Cloud APP management backend.

[0048] In some embodiments of the present disclosure, the process of data encryption by server 101 (such as the Boss Cloud APP management backend) may be: obtaining the data to be encrypted and a first key, where the first key is a key that has not reached the usage limit; determining the security level of the data to be encrypted based on the data to be encrypted; when the security level is the first security level, obtaining metadata; partially expanding the first key based on the metadata to obtain a second key; and encrypting the data to be encrypted using the second key to obtain encrypted transmission data.

[0049] In some embodiments of the present disclosure, the processing process of multi-channel data by server 101 (such as the Boss Cloud APP management backend) may be: obtaining the data to be processed through multiple data collection channels, wherein the data to be processed includes data to be encrypted and non-encrypted data; extracting the data to be encrypted; encrypting the data to be encrypted according to the first key or the second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached the usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; storing the encrypted transmission data in the database of the first application; in response to the log changes of the storage clue table of the database, adopting the real-time stream processing mode, the database change data is transmitted to the message middleware, so that the downstream receiving device receives it according to the resource usage.

[0050] In addition, it should be noted that Figure 1 What is shown is merely one application environment of the data encryption method or multi-channel data processing method provided by the present disclosure. Figure 1The number of terminal devices 103, networks 102 and servers 101 is merely illustrative, and any number of terminal devices, networks and servers may be provided according to actual needs.

[0051] Figure 2 A flow chart of a data encryption method according to an embodiment of the present disclosure is shown. Figure 2 The execution subject of the method provided in the embodiment may be any electronic device, such as Figure 1 The server 101 in the embodiment is also as follows Figure 1 The terminal device 103 in Figure 1 The server 101 and the terminal device 103 in the embodiment jointly implement the data encryption method, but the present disclosure is not limited thereto. Figure 2 , the data encryption method provided by the embodiment of the present disclosure includes S201 to S203.

[0052] S201, obtaining data to be encrypted and a first key, where the first key is a key that has not reached a usage limit.

[0053] In the disclosed embodiment, the data to be encrypted is sensitive data that needs to be encrypted, for example, sensitive data is data such as a user's ID number, mobile phone number, or company name.

[0054] In the disclosed embodiment, if the current encryption is the first encryption, the first key may be a newly generated key; if the current encryption is not the first encryption, the first key may be the key used for the last encryption.

[0055] It should be noted that the present disclosure configures a usage limit for each key in the database, and each time the key is used (for example, encrypted once using the first key), the corresponding usage limit is increased by 1.

[0056] S202: Determine the security level of the data to be encrypted according to the data to be encrypted.

[0057] In the embodiments of the present disclosure, the present disclosure does not specifically limit how to determine the security level of the data to be encrypted. For example, the security level of the data to be encrypted may be determined according to the importance of the data to be encrypted or the required confidentiality level.

[0058] S203, when the security level is the first security level, obtain metadata; partially expand the first key according to the metadata to obtain a second key; encrypt the data to be encrypted using the second key to obtain encrypted transmission data; wherein the metadata at least includes a creation time and / or a data channel mark.

[0059] In the embodiment of the present disclosure, metadata may be data describing the content, source, format, structure, etc. of the data. For example, metadata may include creation time, data channel mark, etc. In the embodiment of the present disclosure, the first key is partially extended through metadata, and there is no need to generate new data to extend the first key, which can further save computing resources while ensuring security.

[0060] It should be noted that the first security level is a higher security level and requires a higher degree of confidentiality. In order to improve security, the disclosed embodiment can also use preset data instead of metadata to partially expand the first key. The preset data can be data set according to actual application scenarios or specific application experience, or data generated by a random number generator.

[0061] In the disclosed embodiment, the second key is obtained by partially expanding the first key according to the metadata. That is, the second key is obtained by partially modifying the first key, and is by no means a regenerated key or round key in the prior art, thereby reducing computing power and speeding up encryption.

[0062] In the embodiment of the present disclosure, when the security level is the first security level, the first key is partially expanded through metadata to obtain the second key, and the encrypted data is encrypting with the second key, thereby saving computing resources while ensuring security.

[0063] How to obtain the second key is described below through exemplary embodiments.

[0064] In an exemplary embodiment, in the data encryption method provided by the present invention, the first key is partially expanded according to the metadata, and obtaining the second key can be achieved in the following three ways. It should be noted that the preset position is the position on the first key for storing the first extended data, the second extended data or the metadata.

[0065] In one embodiment, a hash operation is performed on the metadata to obtain first extended data, and the first extended data is inserted into a preset position of the first key to obtain the second key.

[0066] In the embodiments of the present disclosure, the present disclosure does not limit which hash algorithm is used for hash operation, and can be selected according to actual application scenarios and specific application experience. For example, the hash algorithm is FNV (Fowler-Noll-Vo). For another example, the hash algorithm is CRC32.

[0067] The disclosed embodiment performs a hash operation on the metadata and inserts it into a preset position of the first key, thereby further increasing the difficulty of cracking the second key and improving the security of the data to be encrypted.

[0068] In another embodiment, the metadata is encoded to obtain second extended data, and the second extended data is inserted into a preset position of the first key to obtain the second key.

[0069] In the embodiments of the present disclosure, the present disclosure does not limit which encoding method is used for encoding processing, and can be selected according to actual application scenarios and specific application experience. For example, the encoding method is one of ASCII (American Standard Code for Information Interchange, American Standard Information Interchange Code) encoding, binary encoding, and Unicode encoding.

[0070] The disclosed embodiment encodes the metadata and inserts it into the preset position of the first key, thereby further increasing the difficulty of cracking the second key and improving the security of the data to be encrypted.

[0071] In yet another embodiment, the metadata may also be directly inserted into a preset position of the first key to obtain the second key.

[0072] Exemplarily, the metadata is inserted into a preset position of the first key, that is, the metadata is directly inserted into the first key as a byte array of the first key, thereby obtaining the second key.

[0073] The disclosed embodiment inserts metadata into a preset position of the first key, and the second key can be obtained without regenerating a new key, thereby saving computing power and improving encryption speed without reducing security.

[0074] Exemplarily, in the scenario where the symmetric encryption algorithm AES is used to encrypt the data to be encrypted (such as field information) at a high security level (such as the first security level), the round key of the previous round (such as the first key) cannot be directly used for simple encryption. The round key of the previous round needs to be partially expanded (not the regeneration of the round key in the prior art to reduce computing power and speed up encryption), such as using metadata such as creation time and data channel mark to expand part of the round key of the previous round. The expansion can introduce corresponding metadata at the preset position of the round key of the previous round for expansion to form a new round key (such as the second key) to encrypt the field information at a high security level. Specifically, some positions can be preset in advance for storing extended information (such as the first extended data, the second extended data and metadata), and it is ensured that these positions will not affect the original structure and function of the round key. The selected metadata is processed in some way (such as encoding, using a hash function for hashing), and the processed metadata is inserted into the preset position of the first key, or the metadata is directly inserted into the preset position of the first key as a byte array. The key can be inserted at the start, middle or end of the round key, depending on the design of the encryption algorithm. For example, starting from the first encryption (such as partial extension), the preset position can be set to the 40 bits before the beginning of the first key (starting position), and when the second encryption requires partial extension, the preset position is determined to be the middle 40 bits of the first key (middle position), and when the third encryption requires extension, the preset position is determined to be the last 40 bits of the first key (end position)... The preset position is determined repeatedly in sequence.

[0075] It should be noted that when the symmetric encryption algorithm AES is used to encrypt the data to be encrypted, the first key is a round key, that is, the second key is obtained by expanding the first key, that is, the second key can also include multiple keys, and each round of encryption uses a round key in the first key or a key corresponding to the round in the second key for encryption. The present disclosure has the same partial expansion method for the key for each round of encryption.

[0076] The above describes how to obtain the second key. The following describes how to determine the preset position.

[0077] In an exemplary embodiment, in the case of a stream encryption scenario, the preset position is the starting position of the first key.

[0078] In the embodiment of the present disclosure, the starting position is the position starting from the 1st character position of the first key and ending at the i-th character position, where i is an integer greater than or equal to 1, and the 1st character position to the i-th character position are at least one reserved position included in the starting position.

[0079] In the disclosed embodiment, in a stream encryption scenario, since data flows continuously, inserting metadata into the starting position of the first key can ensure instant encryption of the data to be encrypted, which is very important for data streams that require fast response and high security.

[0080] The disclosed embodiment can insert extended information (such as first extended data, second extended data and metadata) into the starting position of the first key in a stream encryption scenario, so that each encrypted data block will be immediately affected by the extended information, thereby enhancing security.

[0081] In another exemplary embodiment, when an asymmetric encryption algorithm is used for encryption and resources are not limited, the preset position is a middle position of the first key.

[0082] In the disclosed embodiment, the middle position is the position starting from the jth character position of the first key and ending at the kth character position, wherein j is an integer greater than i, and k is an integer greater than or equal to j. The middle position includes at least one reserved position starting from the jth character position to the kth character position.

[0083] When using an asymmetric encryption algorithm, such as the RSA (Rivest-Shamir-Adleman) algorithm for digital signature, the impact of extended information on the encryption result needs to be more dispersed. In this scenario, the embodiment of the present disclosure can insert the extended information into the middle position of the first key, which can increase the complexity of the signature, thereby improving the integrity and authentication of the data, and helping to balance security and performance.

[0084] In yet another exemplary embodiment, in a scenario where resources are limited, the preset position is the end position of the first key.

[0085] In the embodiment of the present disclosure, the termination position is the position from the nth character position to the last character position, where n is an integer greater than K. The termination position includes at least one reserved position from the nth character position to the last character position.

[0086] It should be noted that each time the extended information is encrypted and inserted, the system should automatically record the specific reserved position inserted for subsequent decryption.

[0087] In resource-constrained scenarios, asymmetric encryption algorithms such as ECC (Elliptic Curve Cryptography) algorithms can be used to insert extended information into the end position of the first key to reduce the demand for computing resources while maintaining high security. Alternatively, in resource-constrained scenarios, key agreement protocols (such as Diffie-Hellman) can be used to insert extended information into the end position of the first key, which can increase the diversity and security of the key without changing the core mechanism of the protocol; or, in resource-constrained scenarios, quantum key distribution (QKD) can be used to insert extended information into the end position of the first key as a supplementary measure to ensure the security of information encoded in quantum states during transmission. This process does not require the re-execution of the key reconstruction and generation process, saving computing resources and time, and improving security.

[0088] The above is an explanation of determining the preset position, and the following is an explanation of the case where the security level is the second security level.

[0089] Figure 3 A flowchart of a data encryption method according to another embodiment of the present disclosure is shown. Figure 3 The execution subject of the method provided in the embodiment may be any electronic device, such as Figure 1 The server 101 in the embodiment is also as follows Figure 1 The terminal device 103 in Figure 1 The server 101 and the terminal device 103 in the embodiment jointly implement the data encryption method, but the present disclosure is not limited thereto. Figure 3 , the data encryption provided by the embodiment of the present disclosure also includes S301.

[0090] S301, when the security level is the second security level, using the first key to encrypt the data to be encrypted to obtain encrypted transmission data, and the second security level is lower than the first security level.

[0091] In the disclosed embodiment, the second security level is lower than the first security level. For example, the first security level is a high security level (or high sensitivity), and the second security level is a low security level (or low sensitivity).

[0092] In one embodiment, the data encryption method provided by the embodiment of the present disclosure may include: encrypting the data to be encrypted based on a symmetric encryption algorithm.

[0093] For example, encrypting the data to be encrypted using the first key to obtain encrypted transmission data may include: encrypting the data to be encrypted using the first key based on a symmetric encryption algorithm to obtain encrypted transmission data.

[0094] For another example, using the second key to encrypt the data to be encrypted to obtain the encrypted transmission data may include: based on a symmetric encryption algorithm, using the second key to encrypt the data to be encrypted to obtain the encrypted transmission data.

[0095] It should be noted that no matter whether the data to be encrypted is encrypted using the first key or the second key, the symmetric encryption algorithm AES can be used for encryption, and the use of AES for encryption can further improve the security of the data.

[0096] Exemplarily, the data to be encrypted includes sensitive information such as mobile phone number, company name and ID card number, and the data to be encrypted is encrypted using the improved AES.

[0097] For example, in the scenario where the first key is used to encrypt the data to be encrypted, a key (AES key) in the first key is first generated or obtained from the key library. The first key will be used for the entire encryption process, and its length can be 128 bits, 192 bits, or 256 bits. It should be noted that during the first encryption, a key expansion algorithm (such as the Rijndael key expansion algorithm in AES) is used to generate a series of round keys (other keys in the first key). These round keys will be used for subsequent encryption rounds. The data to be encrypted is XORed with the first round key (AES key), and then each round of encryption is performed in turn, and each round uses the corresponding round key to perform the AES encryption operation. After all rounds of encryption, the last round key is used to perform the final encryption operation to complete the entire encryption process.

[0098] In practical applications, the present disclosure can be implemented by caching the results of key expansion, so that when processing multiple data blocks, only one key expansion is required, and subsequent encryption can directly use the cached round key, thereby improving data processing efficiency.

[0099] In the case of the second security level, the embodiment of the present disclosure uses the same key to reduce repeated calculations of key expansion in a series of encryption or decryption operations to achieve lightweight and optimization of the AES encryption algorithm.

[0100] In another embodiment, the data encryption method provided by the present invention uses a first key to encrypt data to be encrypted to obtain encrypted transmission data, which may include: when the number of times the first key is used has not reached a usage limit, using the first key to encrypt the data to be encrypted, and the number of uses is increased by 1; when the number of times the first key is used has reached the usage limit, selecting any key whose number of uses has not reached the usage limit from the key library as a new first key, and using the new first key to encrypt the data to be encrypted to obtain encrypted transmission data.

[0101] In the embodiment of the present disclosure, the usage limit is set according to the actual application scenario and specific application experience. The embodiment of the present disclosure does not limit the specific value of the usage limit.

[0102] In order to improve the security of the data to be encrypted at a low security level, the embodiment of the present invention can set a usage limit for the first key. Each time the first key is used, the usage count is increased by 1 until the usage count equals the usage limit. The first key whose usage count equals the usage limit is deleted (invalidated), a key whose usage count is less than the usage limit is selected from the key library as a new first key, and the data to be encrypted is encrypted using the new first key to obtain encrypted transmission data.

[0103] The embodiment of the present invention divides the security levels (or sensitivity) of different fields into low security levels (or low sensitivity) and high security levels (or high sensitivity), and partially expands the first key according to metadata for the high security level (or high sensitivity) to obtain the second key; and uses the second key to encrypt the data to be encrypted to obtain encrypted transmission data. For the low security level (or low sensitivity), the first key is used to encrypt the data to be encrypted to obtain encrypted transmission data. It can be seen that the embodiment of the present invention can adopt different encryption processing methods for field information of different levels, that is, introduce a dynamic encryption strategy to dynamically adjust the encryption strength.

[0104] For example, for the data to be encrypted at a low security level, the first key of the previous round is directly used for simple encryption to save computing resources; the first key that can be used directly needs to be a round key that has not reached the usage limit. The usage limit can be configured for the generated round key in the previous key preparation and key expansion stages. Each time it is reused, the number of uses is increased by 1 until the usage limit is reached, and the first key is invalidated. If the first key of the previous round has reached the usage limit, the most recent round key that has not reached the usage limit can be found to directly encrypt the data to be encrypted at a low security level.

[0105] The disclosed embodiment configures a usage limit for the first key. When the first key is used up to the usage limit, any key that has not been used up to the usage limit is selected from the key library as a new first key, and the new first key is used to encrypt the data to be encrypted. This can further improve security while saving resources and computing power.

[0106] In another embodiment, the length of the first key is 128 bits, 192 bits or 256 bits; when the security level is the first security level, the length of the first key is 192 bits or 256 bits; when the security level is the second security level, the length of the first key is 128 bits.

[0107] For example, the mobile phone number is at the first security level, and the company name is at the second security level. The security level of the mobile phone number is higher than that of the company name. The first key used to encrypt the mobile phone number is 256 bits, and it is necessary to obtain a new round key (second key) by means of partially extending the key as described above for encryption; while the company name can be encrypted using a 128-bit first key, and the most recent 128-bit first key that has not reached the upper limit of use is directly selected for encryption. It should be noted that the encrypted data of the first security level can also be encrypted by obtaining a new round key by means of partially extending the key.

[0108] The disclosed embodiment dynamically adjusts the length of the first key, and at a lower security level, using a first key with fewer bits can save computing power and increase encryption speed. At a higher security level, using a first key with more bits can further increase security.

[0109] The dynamic adjustment processing method disclosed in the present invention is described below.

[0110] In an exemplary embodiment, the data encryption method provided by the present disclosure may also include: in response to the system security assessment coefficient being lower than the security alarm threshold, using the second key to encrypt the data to be encrypted; in response to the system load value being equal to or greater than the load alarm threshold, using the first key to encrypt the data to be encrypted.

[0111] In the embodiments of the present disclosure, both the security alarm threshold and the load alarm threshold can be set as needed. The embodiments of the present disclosure do not specifically limit how to obtain the security assessment coefficient and the system load value. For example, the management background of the first application (such as the Boss Cloud APP) can perform security assessment and system load detection in real time to obtain the values ​​of the security assessment coefficient and the system load.

[0112] In the disclosed embodiment, when the security assessment coefficient is as low as the security alarm threshold, it indicates that the data security is low, and it is necessary to encrypt all the data to be encrypted (i.e., regardless of the security level) to improve the data security. When the system load value is equal to or greater than the load alarm threshold, it indicates that the system computing load is too large, and it is necessary to reduce the system load. The first key is used to encrypt all the data to be encrypted (i.e., regardless of the security level), which can reduce the system load.

[0113] For example, if the security assessment coefficient is as low as the security alarm threshold, triggering an alarm, all data to be encrypted are encrypted using a partial expansion method to ensure data security. If the system load value is equal to or greater than the load alarm threshold, triggering an alarm, all data to be encrypted are encrypted using a low security level information processing method to ensure that the system platform will not crash due to increased computing power.

[0114] The management backend of the first application in the disclosed embodiment can dynamically adjust the encryption method according to real-time security assessment or system load to balance performance and security.

[0115] In another exemplary embodiment, the data encryption method provided by the present disclosure may further include: regularly deleting keys in the key library whose creation time is greater than a time threshold.

[0116] In the embodiment of the present disclosure, the specific value of the duration threshold is not specifically limited in the embodiment of the present disclosure. For example, the duration threshold is any value between 90 and 500 days. For example, the duration threshold is 360 days.

[0117] Exemplarily, the management background of the first application will also dynamically adjust the key library, regularly deleting keys created more than 360 days ago, or keys with 0 remaining uses, thereby reducing storage space, reducing costs, and increasing data processing speed.

[0118] Based on the same inventive concept, a method for processing multi-channel data is also provided in the embodiments of the present disclosure, as described in the following embodiments. Since the principle of solving the problem in the embodiment of the method is similar to that in the above-mentioned data encryption method embodiment, the implementation of the embodiment of the method can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.

[0119] Figure 4 A schematic diagram of a method for processing multi-channel data in an embodiment of the present disclosure is shown. Figure 4 As shown, the method includes the following S401 to S405.

[0120] S401, obtaining data to be processed through multiple data collection channels, where the data to be processed includes data to be encrypted and non-encrypted data.

[0121] In one embodiment, the data to be processed is collected by the management background of the first application or through the Sensors tracking system.

[0122] For example, part of the data to be processed can be realized by adding code (such as management background) in the first application (such as Boss Cloud APP), and part of the data can be realized by using a third-party tool, Sensors Point Tracking System, or it can be realized by adding more complex code and monitoring technology completely through the Boss Cloud APP system without using the Sensors Point Tracking System. This disclosure does not limit this.

[0123] The present invention collects the data to be processed directly through the management background, or collects the data to be processed through the Sensors tracking system, and transmits the collected data to be processed to the management background. The two methods of collecting the data to be processed can increase the comprehensiveness of the data to be processed, prepare for the subsequent accurate determination of the user's preferences and interests, and improve the accuracy of recommending projects to users.

[0124] In another embodiment, the data to be processed includes data to be encrypted and unencrypted data; wherein, before extracting the data to be encrypted from the data to be processed, the data encryption method provided by the present disclosure may also include: classifying the data to be processed according to user behavior, user attributes, time dimension, and user intention, and storing the classified data to be processed in the database of the first application.

[0125] In the disclosed embodiment, classification is performed from multiple angles and dimensions such as user behavior, user attributes, time dimension, and user intention. Through the classification of the above multiple dimensions, the user's behavior patterns and intentions can be fully understood, thereby providing strong support for subsequent data analysis, personalized recommendations, and marketing strategy formulation. This classification not only helps to improve user experience, but also helps companies better understand market demand and optimize resource allocation.

[0126] The disclosed embodiments provide multi-level and multi-dimensional security protection measures to ensure the security of network data during transmission.

[0127] The disclosed embodiments can collect data to be processed from multiple channels through the management background or the Sensors tracking system, so as to obtain more comprehensive data to be processed. By inferring user preferences through the comprehensive data to be processed, the accuracy of recommending items to users can be increased.

[0128] S402: extracting data to be encrypted.

[0129] In the embodiments of the present disclosure, the method for extracting the data to be encrypted is not limited in the embodiments of the present disclosure. For example, the data to be encrypted may be extracted according to the field attributes of the data to be processed.

[0130] S403, encrypt the data to be encrypted according to the first key or the second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached the usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key through metadata, and the second security level is lower than the first security level.

[0131] The embodiments of the present disclosure have described in the above embodiments how to encrypt the data to be encrypted by using the first key and the second key, which will not be repeated here.

[0132] S404, storing the encrypted transmission data in a database of the first application.

[0133] In the embodiment of the present disclosure, the type of the database of the first application is not specifically limited. For example, the database is a MySQL database of the management background of the first application. It should be noted that the MySQL database is used in conjunction with the message queue, and the encrypted transmission data and non-encrypted data of the present disclosure can be stored in the message queue or in the local file system. For example, the encrypted transmission data is stored in HDFS (Hadoop Distributed File System).

[0134] It should be noted that message queue refers to the use of efficient and reliable message transmission mechanism for data exchange. By providing message transmission and message queuing models, it can provide application decoupling, elastic scaling, redundant storage, traffic peak shaving, asynchronous communication, data synchronization and other functions in a distributed environment. Message queues include but are not limited to Apache Kafka, RabbitMQ, ApacheActiveMQ, RocketMQ, and Apache Pulsar.

[0135] S405, in response to the log changes of the storage clue table of the database, adopt the real-time stream processing mode to transmit the changed data of the database to the message middleware, so that the downstream receiving device receives it according to the resource usage.

[0136] In the embodiment of the present disclosure, the embodiment of the present disclosure does not specifically limit how to monitor the log changes of the storage clue table of the database. For example, the above monitoring is achieved through the flink CDC tool (a tool that captures database changes in real time and streams them).

[0137] Exemplarily, the flink CDC tool is used to monitor the changes in the binlog (Binary Log) of the clue table stored in the MySQL database used by the management background of the first application (such as the Boss Cloud APP), and a real-time stream processing mode is adopted to transmit the change data (such as user and intention behavior information) to the message middleware (such as the distributed message queue middleware Kafka). The message middleware acts as a buffer and is received by the downstream receiving device (clue middleware system) according to resource usage.

[0138] It should be noted that when the processing mode is real-time stream processing, the data collection results will be abstracted into several data streams, and then the data streams will be divided into multiple data partitions. Then, based on the flink CDC tool, multiple working nodes are used to process the data partitions in parallel to achieve parallel data processing; and the degree of correlation between variables in the data partitions is identified, and then the data partitions with data correlation are analyzed and processed to obtain the changed data. In other words, the flink CDC tool can capture the changed data of the database and output these changed data in the form of streams.

[0139] Exemplarily, part of the data to be processed is directly collected by the Boss Cloud APP management background, and part is collected through the Sensors tracking system. The Sensors tracking system collects some user behaviors (such as users forwarding project information, users entering the live broadcast room, and users staying on the project page). These behavior information is reported to the Kafka of the Sensors tracking system, that is, the producer sends the message. The clue middle-office system consumes some behaviors that need to be reported (such as users forwarding project information, users watching live broadcasts for more than 1 minute, and users staying on the project page for more than 20 seconds). After the behavior is stored in the clue middle-office system, it is available for distribution and use.

[0140] The disclosed embodiment solves the problems of limited data acquisition channels and lack of personal information location in the prior art by establishing a method for collecting and processing multi-channel customer information, and realizes the collection and integration of multi-channel customer information.

[0141] The following four embodiments illustrate how to obtain the data to be processed. Figure 5 As shown, ①, ②, ③ and ④ represent four channels for obtaining the data to be processed, and 1, 2, 3 and 4 represent the order in which each channel obtains the data to be processed.

[0142] In one embodiment, a first propagation information is sent to a second application via a third application, so that a user can jump to the first application by viewing the first propagation information on the second application; and data to be processed on the first application is obtained, where the data to be processed is the user's intended behavior information.

[0143] In the embodiment of the present disclosure, the first propagation information is information for users to read and forward and can jump to the first application program. For example, the first propagation information can be news, conference activity information, etc.

[0144] For example, Figure 5As shown, the forwarding person (such as a company employee) forwards the first dissemination information (such as news, articles, project information, conference activity information) to the second application 52 (such as WeChat friends, WeChat Moments) through the third application 51 (such as the Boss Helper APP). If the user views these news, articles, project information, and conference activity information, the page will jump to the first application 53 (Boss Cloud APP). After the user browses, registers and submits the information, it is stored in the MySQL database of the Boss Cloud APP management background 54.

[0145] For example, corporate employees forward consultations, articles, project information, and conference event information in the Boss Helper APP to their WeChat friends and WeChat Moments. When a user opens the information forwarded by the corporate employee, the page jumps to the Boss Cloud APP, and the intention behavior information generated is obtained based on the user's browsing of project information, browsing of news, and submission of conference event registration information. The management backend of the Boss Cloud APP stores the user's intention behavior information in the MySQL database of the management backend of the Boss Cloud APP according to the classification. These categories include: project attention, meeting attendance, IM consultation, obtaining project information, interest in projects, and event registration. Record the time when the behavior information is generated, application type (Android, IOS), user ID (Identification), and other information.

[0146] It should be noted that the management backend 54 of the first application can directly crawl the data to be processed from the first application 53, and can also crawl the data to be processed from the first application 53 through the Sensors tracking system 55, and send the crawled data to be processed to the management backend 54. The management backend 54 extracts the data to be encrypted from the data to be processed, and encrypts the data to be encrypted using the above-mentioned data encryption method.

[0147] In another embodiment, the data to be processed is obtained through the first application, and the data to be processed is the user's intended behavior information.

[0148] For example, Figure 5 As shown, users can browse project information, news, live broadcast rooms and conference activities directly on the first application 53, so that the management background 54 or the Sensors tracking system 55 can collect the data to be processed from the first application 53.

[0149] For example, the first application 53 is the Boss Cloud APP, which can be directly searched and installed in the application market. After the user installs the Boss Cloud APP and registers and logs in, he can search for projects, information, browse all project information, watch project live broadcasts, etc. Users share the Boss Cloud APP with colleagues and friends, and invite them to register for the Boss Cloud APP. In marketing activities, corporate APP promoters guide users to download and install the Boss Cloud APP. The content of the Boss Cloud APP is updated by the company's marketing personnel to provide users with project matching services, industry information services, consulting services, etc. In other words, users log in to the Boss Cloud APP, search for projects of interest, follow projects, obtain project information, contact service personnel by phone, sign up for meetings and activities, and generate intended behaviors. The management background 54 or the Shen Ce point-burying system 55 collects data to be processed from the first application 53.

[0150] In yet another embodiment, all user information is obtained, and users are screened based on all user information and preset delivery strategies to obtain target users, and push information is sent to the target users on the media platform through a fourth application. The target users jump to the first application by viewing the push information on the media platform; and the data to be processed on the first application is obtained, and the data to be processed is the user's intended behavior information, wherein the target users are users with the same characteristics and who are reached by the media platform.

[0151] In the disclosed embodiment, the preset delivery strategy is a strategy for screening out users with the same characteristics (such as interest preferences). Users with the same characteristics and reached by the media platform delivery are determined as target users. The media platform may include multiple applications. For example, the media platform includes applications such as Xiaohongshu, Baidu, Tencent, Zhihu, Kuaishou Short Video, and Douyin Short Video.

[0152] For example, Figure 5 As shown, the receiving device 56 (such as the clue middle-office system) receives all user information (such as data stored in the database) of the management background 54 of the first application, and the receiving device 56 sends all user information to the fourth application 57. The fourth application 57 screens users based on all user information and preset delivery strategies to obtain target users, so that push information can be sent to the target users on the media platform 58 through the fourth application 57.

[0153] For example, the enterprise media platform delivery personnel query the target users to be delivered in the fourth application 57 (Natural Selection System), such as male users who are interested in new energy. These target user characteristics are transmitted to the media platform 58, and the media platform 58 is set to push the project page (push information) to the target user, or to attract the user to retain information (push information). Let the user know more about the project and conference activities, and generate intentional behavior.

[0154] For another example, the enterprise media platform delivery personnel use the fourth application 57 to screen the characteristics of the target users according to the preset delivery strategy, determine the users reached by the media platform delivery, determine the media platform and the push information that the media platform wants to push to these users. The push information (such as users and pushed content) is transmitted to the designated media platform 58. After the user logs in to the designated media platform 58, the media platform 58 pushes content to these users. When the user clicks and browses the content, he will jump to the first application (Boss Cloud APP), where he can view more detailed project information, conference activity information, consulting projects, etc. to generate intentional behavior.

[0155] In another embodiment, a second dissemination information is sent on a media platform through a corporate account, so that the user can jump to the first application by viewing the second dissemination information; and the data to be processed on the first application is obtained, and the data to be processed is the user's intended behavior information.

[0156] In the embodiment of the present disclosure, the second propagation information is information for users to read and forward and can jump to the first application.

[0157] For example, Figure 5 As shown, the enterprise has an enterprise account on some media platforms 58, and the media platform 58 can be a platform supported by the fourth application 57. The enterprise media platform operator publishes the second dissemination information (such as project information, conference activity information, etc.) through the enterprise account in a form supported by the media platform 58. When the user browses the content on the media platform 58, he may browse the content published by the enterprise account, submit user personal information to participate in the conference activity, and jump to the first application (Boss Cloud APP). In the Boss Cloud APP, continue to view more detailed project information, conference information, consult projects, etc. to generate intentional behavior.

[0158] For example, the enterprise operator publishes content (secondary communication information) in the enterprise account of the media platform 58. After the content is browsed by the users of the media platform, the users will be directed to jump to the Boss Cloud APP. If the users have not installed the Boss Cloud APP, they need to download and install it first and then register to become Boss Cloud APP users before they can browse all the project information, conference activities and other information in the Boss Cloud APP, as well as telephone consultation and IM (Information Management) consultation project (information management consultation project) information.

[0159] In summary, the data to be processed finally collected by the data collection channels of the above four embodiments will enter the first application, thereby realizing the aggregation of user data from different channels on the first application and realizing data integration.

[0160] The disclosed embodiment establishes four channels to collect data to be processed, thereby solving the problems of limited data acquisition channels and lack of personal information positioning in the prior art, and realizing the collection and integration of multi-channel customer information.

[0161] Based on the same inventive concept, the present disclosure also provides a data encryption device in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0162] Figure 6 A schematic diagram of a data encryption device in an embodiment of the present disclosure is shown. Figure 6 As shown, the device includes: a first acquisition module 61, a level determination module 62 and a first encryption module 63. The first acquisition module 61 can be used to obtain the data to be encrypted and the first key, the first key is a key that has not reached the usage limit; the level determination module 62 can be used to determine the security level of the data to be encrypted according to the data to be encrypted; the first encryption module 63 can be used to obtain metadata when the security level is the first security level; partially expand the first key according to the metadata to obtain the second key; encrypt the data to be encrypted using the second key to obtain encrypted transmission data; wherein the metadata at least includes the creation time and / or the data channel mark.

[0163] In one embodiment, the first encryption module 63 can also be used to perform a hash operation on the metadata to obtain first extended data, and insert the first extended data into the preset position of the first key to obtain a second key; or, encode the metadata to obtain second extended data, and insert the second extended data into the preset position of the first key to obtain the second key; or, insert the metadata into the preset position of the first key to obtain the second key; wherein the preset position is a position on the first key for storing the first extended data, the second extended data or the metadata.

[0164] In one embodiment, in the case of a stream encryption scenario, the preset position is the starting position of the first key; when an asymmetric encryption algorithm is used for encryption and in a non-resource-constrained situation, the preset position is the middle position of the first key; in a resource-constrained scenario, the preset position is the end position of the first key.

[0165] In one embodiment, the first encryption module 63 may also be used to encrypt the data to be encrypted using the first key to obtain encrypted transmission data when the security level is the second security level, and the second security level is lower than the first security level.

[0166] In one embodiment, the first encryption module 63 can also be used to encrypt the encrypted data using the first key when the number of times the first key is used has not reached the usage limit, and the number of uses is increased by 1; when the number of times the first key is used reaches the usage limit, select any key whose number of uses has not reached the usage limit from the key library as a new first key, and use the new first key to encrypt the encrypted data to obtain encrypted transmission data.

[0167] In one embodiment, the first encryption module 63 may also be used to encrypt the data to be encrypted based on a symmetric encryption algorithm.

[0168] In one embodiment, the first encryption module 63 can also be used to encrypt the encrypted data using the second key in response to the system security assessment coefficient being lower than the security alarm threshold; and to encrypt the encrypted data using the first key in response to the system load value being equal to or greater than the load alarm threshold.

[0169] The data encryption device disclosed in the embodiment of the present disclosure partially expands the first key through metadata to obtain the second key when the security level is the first security level, and encrypts the encrypted data with the second key, thereby saving computing resources while ensuring security.

[0170] Based on the same inventive concept, the present disclosure also provides a multi-channel data processing device, as described in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0171] Figure 7 A schematic diagram of a multi-channel data processing device in an embodiment of the present disclosure is shown. Figure 7As shown, the device may include: a second acquisition module 71, an extraction module 72, a second encryption module 73, a storage module 74 and a transmission module 75. The second acquisition module 71 may be used to acquire data to be processed through multiple data collection channels, and the data to be processed includes data to be encrypted and non-encrypted data; the extraction module 72 may be used to extract the data to be encrypted; the second encryption module 73 may be used to encrypt the data to be encrypted according to the first key or the second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached the usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; the storage module 74 may be used to store the encrypted transmission data in the database of the first application; the transmission module 75 may be used to respond to the log changes of the storage clue table of the database, adopt the real-time stream processing mode, and transmit the change data of the database to the message middleware, so that the downstream receiving device receives it according to the resource usage.

[0172] In one embodiment, the second acquisition module 71 can be used to send the first propagation information to the second application through the third application, so that the user can jump to the first application by viewing the first propagation information on the second application; obtain the data to be processed on the first application, where the data to be processed is the user's intended behavior information; or, obtain the data to be processed through the first application, where the data to be processed is the user's intended behavior information; or, obtain all user information, and screen the users according to all user information and preset delivery strategies to obtain target users, and send push information to the target users on the media platform through the fourth application, and the target users jump to the first application by viewing the push information on the media platform; obtain the data to be processed on the first application, where the data to be processed is the user's intended behavior information, wherein the target users are users with the same characteristics and are reached by the media platform; or, send the second propagation information on the media platform through the corporate account, so that the user can jump to the first application by viewing the second propagation information; obtain the data to be processed on the first application, where the data to be processed is the user's intended behavior information.

[0173] The multi-channel data processing device disclosed in the embodiment of the present disclosure establishes a multi-channel customer information collection and processing method, which solves the problems of limited data acquisition channels and lack of personal information positioning in the prior art, and realizes the collection and integration of multi-channel customer information.

[0174] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".

[0175] Refer to the following Figure 8 The electronic device 800 according to this embodiment of the present disclosure is described. Figure 8 The electronic device 800 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0176] like Figure 8 As shown, the electronic device 800 is in the form of a general computing device. The components of the electronic device 800 may include but are not limited to: at least one processing unit 810, at least one storage unit 820, and a bus 830 connecting different system components (including the storage unit 820 and the processing unit 810).

[0177] The storage unit stores program codes, which can be executed by the processing unit 810, so that the processing unit 810 executes the steps described in the above “exemplary method” section of this specification according to various exemplary embodiments of the present disclosure.

[0178] The storage unit 820 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 8201 and / or a cache memory unit 8202 , and may further include a read-only memory unit (ROM) 8203 .

[0179] The storage unit 820 may also include a program / utility 8204 having a set (at least one) of program modules 8205, such program modules 8205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0180] Bus 830 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0181] The electronic device 800 may also communicate with one or more external devices 840 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 800, and / or communicate with any device that enables the electronic device 800 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 850. Furthermore, the electronic device 800 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 860. As shown, the network adapter 860 communicates with other modules of the electronic device 800 via a bus 830. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0182] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0183] Based on the same inventive concept, a computer-readable storage medium is also provided in an embodiment of the present disclosure. The computer-readable storage medium may be a readable signal medium or a readable storage medium. Fig. 9 A schematic diagram of a computer-readable storage medium in an embodiment of the present disclosure is shown. Fig. 9 As shown, the computer-readable storage medium 900 stores a program product capable of implementing the above method of the present disclosure.

[0184] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0185] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0186] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0187] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0188] Based on the same inventive concept, a computer program product is also provided in an embodiment of the present disclosure, including a computer program product, including: a computer program or an instruction, wherein the computer program or the instruction implements the above method of the present disclosure when executed by a processor. Since the principle of solving the problem in the computer program product embodiment is similar to that in the above method embodiment, the implementation of the computer program product embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0189] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.

[0190] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.

[0191] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0192] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.

Claims

1. A data encryption method, characterized in that: include: Acquire data to be encrypted and a first key, where the first key is a key that has not reached a usage limit; Determining a security level of the data to be encrypted according to the data to be encrypted; When the security level is the first security level, obtaining metadata; partially expanding the first key according to the metadata to obtain a second key; The data to be encrypted is encrypted using the second key to obtain encrypted transmission data; wherein the metadata at least includes a creation time and / or a data channel mark.

2. The method according to claim 1, characterized in that The partially expanding the first key according to the metadata to obtain the second key includes: Performing a hash operation on the metadata to obtain first extended data, and inserting the first extended data into a preset position of the first key to obtain a second key; or, Encoding the metadata to obtain second extended data, and inserting the second extended data into a preset position of the first key to obtain a second key; or, Inserting the metadata into a preset position of the first key to obtain a second key; The preset position is a position on the first key for storing the first extended data, the second extended data or the metadata.

3. The method according to claim 2, characterized in that In the case of a stream encryption scenario, the preset position is the starting position of the first key; When an asymmetric encryption algorithm is used for encryption and resources are not limited, the preset position is the middle position of the first key; In a scenario where resources are limited, the preset position is the termination position of the first key.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: In a case where the security level is a second security level, the data to be encrypted is encrypted using the first key to obtain the encrypted transmission data, and the second security level is lower than the first security level.

5. The method according to claim 4, characterized in that The step of encrypting the data to be encrypted using the first key to obtain the encrypted transmission data includes: If the usage count of the first key does not reach the usage limit, the first key is used to encrypt the data to be encrypted, and the usage count is increased by 1; When the first key is used a limited number of times, any key whose usage number has not reached the limited number of times is selected from the key library as a new first key, and the data to be encrypted is encrypted using the new first key to obtain the encrypted transmission data.

6. The method according to claim 4, characterized in that The method further includes: encrypting the data to be encrypted based on a symmetric encryption algorithm.

7. The method according to claim 4, characterized in that The method further comprises: In response to the system security assessment coefficient being lower than a security alarm threshold, encrypting the data to be encrypted using the second key; In response to the system load value being equal to or greater than a load alarm threshold, the to-be-encrypted data is encrypted using the first key.

8. A method for processing multi-channel data, characterized in that: The method comprises: Acquire the data to be processed through multiple data collection channels, wherein the data to be processed includes encrypted data and non-encrypted data; Extracting the data to be encrypted; The data to be encrypted is encrypted according to the first key or the second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached a usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; storing the encrypted transmission data in a database of the first application; In response to the log changes of the storage clue table of the database, the real-time stream processing mode is adopted to transmit the changed data of the database to the message middleware, so that the downstream receiving device receives it according to the resource usage.

9. The method according to claim 8, characterized in that The method of obtaining the data to be processed through multiple data collection channels includes: Sending first propagation information to a second application through a third application, so that a user can jump to the first application by viewing the first propagation information on the second application; obtaining the data to be processed on the first application, where the data to be processed is the user's intended behavior information; or, Acquire the data to be processed through the first application, where the data to be processed is the user's intended behavior information; or, Obtain all user information, and screen users according to all user information and preset delivery strategies to obtain target users, and send push information to the target users on the media platform through a fourth application, so that the target users jump to the first application by viewing the push information on the media platform; obtain the data to be processed on the first application, where the data to be processed is the user's intended behavior information, wherein the target users are users with the same characteristics and who are reached by the media platform delivery; or, Send a second dissemination information on the media platform through a corporate account, so that the user can jump to the first application by viewing the second dissemination information; obtain the data to be processed on the first application, and the data to be processed is the user's intended behavior information.

10. A data encryption device, characterized in that: include: A first acquisition module, used to acquire data to be encrypted and a first key, where the first key is a key that has not reached a usage limit; A level determination module, used to determine the security level of the data to be encrypted according to the data to be encrypted; A first encryption module is used to obtain metadata when the security level is the first security level; and partially expand the first key according to the metadata to obtain a second key; The data to be encrypted is encrypted using the second key to obtain encrypted transmission data.

11. A multi-channel data processing device, characterized in that: include: A second acquisition module is used to acquire the data to be processed through multiple data acquisition channels, wherein the data to be processed includes encrypted data and non-encrypted data; An extraction module, used for extracting the data to be encrypted; a second encryption module, configured to encrypt the data to be encrypted according to the first key or the second key to obtain encrypted transmission data, wherein, when the security level is the second security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the first key, and the first key is a key that has not reached a usage limit; when the security level is the first security level, the encrypted transmission data is obtained by encrypting the data to be encrypted with the second key, and the second key is obtained by partially extending the first key by metadata, and the second security level is lower than the first security level; A storage module, used for storing the encrypted transmission data in a database of the first application; The transmission module is used to respond to the log changes of the storage clue table of the database, adopt a real-time stream processing mode, and transmit the changed data of the database to the message middleware, so that the downstream receiving device can receive it according to the resource usage.

12. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to perform the method of any one of claims 1 to 9 by executing the executable instructions.

13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Patent Citations

  • Method, system and server for pushing data

    CN103209188A

  • Media data transmission system, method and device, and storage medium

    CN108965302A

  • Communication method for bus dispatching system and bus dispatching system

    CN113114621A

  • Vehicle monitoring method and device and storage medium

    CN115225673A

  • Data processing method and device, equipment and medium

    CN116415268A

Cited By

  • Agricultural material platform ledger system based on multi-source data

    CN120632922A

  • Agricultural material platform account system based on multi-source data

    CN120632922B