A data processing system, method, device and medium

Through a chain encryption and a modular design data processing system, the security problems in the data transmission process are solved, the secure transmission and storage of data are realized, and data security and transmission efficiency are improved.

CN120074961BActive Publication Date: 2025-07-18SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510542965.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-18
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

How to improve data security during data transmission and prevent data leakage, tampering or illegal access.

Method used

The chain encryption method is used to segment and encrypt the data block, use the combination of the MD5 value of the data block and the target key as the encryption key, and authenticate and securely transmit it through a modularly designed data processing system.

Benefits of technology

It improves security during data transmission, prevents data leakage and tampering, reduces bandwidth consumption, improves transmission efficiency, and supports a variety of data sources and output targets, with good scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074961B_ABST
    Figure CN120074961B_ABST
Patent Text Reader

Abstract

The present application discloses a data processing system, method, device and medium, relating to the technical fields of artificial intelligence and cloud computing. The system includes a data processing module on the server side, which is used to split target data into several data blocks and chain-encrypt the several data blocks to obtain an encrypted data packet including several encrypted data blocks; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data of the previous data block and the target key of the current data block; a secure transmission module on the server side, which is used to send the encrypted data packet to the client; a client verification and reception module of the client, which is used to perform identity verification between the client and the server; an encryption processing engine of the client, which is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the identity verification; a secure output and storage module of the client, which is used to store the processed data at a specified location. It can improve the data security during data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of artificial intelligence and cloud computing, and particularly relates to a data processing system, method, device and medium. Background Art

[0002] In the digital age, with the rapid development of information technology, the demand for secure data transmission by enterprises and individuals is increasing day by day. As the core asset of an enterprise, the security of data is directly related to the stable operation of the enterprise, the protection of business secrets, and the privacy rights and interests of users. Therefore, how to ensure the security of data during transmission, prevent data leakage, tampering or illegal access has become an urgent problem to be solved.

[0003] In summary, how to improve the data security during data transmission is an urgent problem to be solved currently. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a data processing system, method, device and medium that can improve the data security during data transmission. The specific solutions are as follows:

[0005] In a first aspect, the present application discloses a data processing system, including a data processing module and a secure transmission module on the server side, as well as a client verification and reception module, an encryption processing engine and a secure output and storage module on the client side. Among them,

[0006] The data processing module is used to split target data into several data blocks, and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block;

[0007] The secure transmission module is used to send the encrypted data packet to the client;

[0008] The client verification and reception module is used to perform identity verification between the client and the server;

[0009] The encryption processing engine is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the identity verification;

[0010] The secure output and storage module is used to store the processed data at a specified location.

[0011] Optionally, the encryption processing engine is configured to, after authentication, receive the encrypted data packet, decrypt the encrypted data using the encryption key pre-obtained from the data processing module to obtain decrypted data, process the decrypted data, and encrypt the processed data using the encryption key to obtain processed data.

[0012] Optionally, the data processing module includes:

[0013] A data compression module, configured to compress the several data blocks to obtain several compressed data blocks;

[0014] A data encryption module, configured to perform an encryption operation on the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks.

[0015] Optionally, the data encryption module is specifically configured to select a target encryption method and the target key corresponding to each of the encrypted data blocks from a preset key library; and perform an encryption operation on the several compressed data blocks based on the target key and the target encryption method to obtain an encrypted data packet including several encrypted data blocks.

[0016] Optionally, the data processing module is further configured to update the target encryption method and the target key in the preset key library according to a preset update time.

[0017] Optionally, the data compression module is specifically configured to use a lossless compression technique to compress the several data blocks to obtain several compressed data blocks.

[0018] Optionally, the arrangement order of the several data blocks is the data block cutting order;

[0019] Wherein, the data processing module is specifically configured to perform an encryption operation on the several data blocks in accordance with the data block cutting order to obtain an encrypted data packet including several encrypted data blocks.

[0020] In a second aspect, the present application discloses a data processing method, which is applied to a data processing system. The system includes a data processing module and a secure transmission module on the server side, and a client verification and reception module, an encryption processing engine, and a secure output and storage module on the client side. The method includes:

[0021] The target data is segmented by the data processing module to obtain several data blocks, and an encryption operation is performed on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block;

[0022] Send the encrypted data packet to the client through the security transmission module;

[0023] Perform authentication between the client and the server through the client verification and reception module;

[0024] After passing the authentication through the encryption processing engine, receive the encrypted data packet and process the encrypted data packet to obtain processed data;

[0025] Store the processed data in a specified location through the security output and storage module.

[0026] In a third aspect, the present application discloses an electronic device, including:

[0027] A memory for storing a computer program;

[0028] A processor for executing the computer program to implement the data processing method disclosed above.

[0029] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the data processing method disclosed above is implemented.

[0030] It can be seen that the data processing module of the present application is used to split target data into several data blocks, and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block; the security transmission module is used to send the encrypted data packet to the client; the client verification and reception module is used to perform authentication between the client and the server; the encryption processing engine is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the authentication; the security output and storage module is used to store the processed data in a specified location. Thus, the present application proposes a data chain encryption method using a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block as the encryption key. In addition, MD5 has uniqueness, and for different plaintext data, the MD5 value is different. Moreover, MD5 is irreversible, and the original data cannot be directly restored from the MD5 value, thereby improving the security of data during transmission; in addition, through modular design, the overall server system of the present application has good scalability. Description of the Drawings

[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.

[0032] Figure 1 Schematic diagram of a data processing system disclosed in the present application;

[0033] Figure 2 Flowchart of a data processing method disclosed in the present application;

[0034] Figure 3 Schematic diagram of a data processing flow disclosed in the present application;

[0035] Figure 4 Structural diagram of an electronic device disclosed in the present application. Detailed implementation manners

[0036] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0037] In the digital age, with the rapid development of information technology, the demand for secure data transmission by enterprises and individuals is increasing day by day. As the core asset of an enterprise, the security of data is directly related to the stable operation of the enterprise, the protection of business secrets, and the privacy rights and interests of users. Therefore, how to ensure the security of data during transmission, prevent data leakage, tampering, or illegal access has become an urgent problem to be solved.

[0038] For this reason, the embodiments of the present application propose a data processing solution that can improve the data security during data transmission.

[0039] The embodiments of the present application disclose a data processing system. Refer to Figure 1 As shown, the system includes a data processing module 11 and a secure transmission module 12 of the server 10, and a client verification and reception module 21, an encryption processing engine 22, and a secure output and storage module 23 of the client 20. Among them,

[0040] The data processing module 11 is used to split the target data into several data blocks, and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block;

[0041] The secure transmission module 12 is used to send the encrypted data packet to the client 20;

[0042] The client verification and reception module 21 is used to perform identity verification between the client 20 and the server 10;

[0043] The encryption processing engine 22 is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the identity verification;

[0044] The secure output and storage module is used to store the processed data at a specified location.

[0045] In this embodiment, the data processing module 11 is used to split the target data into several data blocks. Specifically, the data processing module 11 is used to preprocess the target data, and split the preprocessed data into several data blocks; wherein, the preprocessing of the target data is specifically to perform preprocessing operations such as data cleaning and formatting on the data to ensure the integrity and consistency of the data.

[0046] In this embodiment, the target data supports multiple data sources, including file systems, databases, network streams, etc.; splitting the preprocessed data can split the overall data into data blocks of 1MB in size, and less than 1MB is a data block.

[0047] In this embodiment, the MD5 (Message-Digest Algorithm 5) value is the result calculated by a hash algorithm, which is used to verify the integrity of a file. The MD5 algorithm maps input data of any length to a hash value of a fixed length (128 bits, i.e., 16 bytes). This hash value is usually represented as a 32-bit hexadecimal number. MD5 is inherently unique. For different input data, the MD5 value is almost always different. MD5 is irreversible, and the original data cannot be directly restored from the MD5 value.

[0048] It should be noted that when a user illegally brute-forces to crack the compressed package, the time of the compressed package will change, indirectly causing the MD5 value to change. When the MD5 changes, the subsequent compressed package cannot be decrypted, thus realizing the security of encryption.

[0049] In this embodiment, the data processing module 11 is configured to perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks. Specifically, the data processing module 11 includes: a data compression module configured to compress the several data blocks to obtain several compressed data blocks; and a data encryption module configured to perform an encryption operation on the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks.

[0050] It should be noted that the compression algorithm corresponding to the compression operation may be an efficient compression algorithm such as LZ4 or Zstandard. These algorithms achieve a good balance between the compression ratio and the compression speed. Specifically, the data compression module is specifically configured to use lossless compression technology to compress the several data blocks to obtain several compressed data blocks. Specifically, using lossless compression technology, the statistical redundancy of the data is compressed, and the compressed data can be completely restored to the original data without losing any information. Common compression algorithms include but are not limited to lossless compressions such as Huffman coding, Lempel-Ziv-Welch (LZW), Run-Length Encoding (RLE), Burrows-Wheeler Transform (BWT), Arithmetic Coding, LZ77 and LZ78, and DEFLATE; in addition, the user is allowed to adjust the compression level according to specific requirements to balance the compression efficiency and the compression ratio.

[0051] In this embodiment, the data encryption module is configured to perform an encryption operation on the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks. Specifically, the data encryption module is specifically configured to select a target encryption method and the target key corresponding to each of the encrypted data blocks from a preset key library; and perform an encryption operation on the several compressed data blocks based on the target key and the target encryption method to obtain an encrypted data packet including several encrypted data blocks.

[0052] It should be noted that the encryption algorithm corresponding to the target encryption method may be a strong encryption algorithm such as AES-256-GCM. This algorithm combines the high security of AES (Advanced Encryption Standard) and the authenticated encryption characteristics of GCM (Galois / Counter Mode); in addition, an appropriate encryption mode can be selected for the target encryption method, which may be CBC (Cipher Block Chaining), CFB (Cipher Feed Back), ECB (Electronic Codebook Book), etc. However, considering the integrity verification function of GCM, the GCM mode is usually recommended.

[0053] It should be noted that, based on the target key and the target encryption method, each compressed data block and the metadata corresponding to the compressed data block (such as IV (Initialization Vector), MAC (Message Authentication Code) tag) are encapsulated and encrypted to obtain an encrypted data block, so as to obtain an encrypted compressed package.

[0054] In this embodiment, the arrangement order of the several data blocks is the data block cutting order; wherein, the data processing module 11 is specifically configured to perform an encryption operation on the several data blocks according to the data block cutting order to obtain an encrypted data packet including several encrypted data blocks.

[0055] It should be noted that the encrypted compressed package (encrypted data packet) may include multiple encrypted data blocks or a single data block. Each data block has its own IV and MAC tag to enhance the independence and security of the data. Each complete data includes a set of data compressed packages or multiple data compressed packages. Each compressed package is arranged in a certain order, and the arrangement order is the order of cutting the data to avoid confusion.

[0056] In this embodiment, the data processing module 11 is further configured to update the target encryption method and the target key in the preset key library according to a preset update time. Specifically, a key management system (KMS) is used to generate, store, and manage keys. The keys can be randomly generated and replaced regularly to enhance security. It should be noted that keys are generated regularly and the key library is updated for use when encrypting the compressed package. Considering the complexity and time length of encryption, the key length is 128 bits; when encrypting the data compressed package, the encryption process is chain encryption, that is, the md5 of the plaintext data of the previous compressed package plus the key together constitute this chain encryption strategy.

[0057] It should be noted that a key vault is a storage facility for storing encryption keys and certificates, mainly used to prove the identities of servers and clients in SSL encrypted communication. It can be a file, a hardware device, or a software component, used to securely store and manage key materials and prevent unauthorized access. When data needs to be encrypted, a key and an encryption method can be selected from the key vault, and the key is returned according to the encryption method, and this key is used to encrypt the data. In addition, access mechanisms should be strictly controlled to ensure that only authorized users can access the key vault. Provide secure key generation algorithms and storage mechanisms to ensure the randomness and security of keys, and rotate and update keys regularly to prevent keys from being cracked or leaked. Record all access and operation logs of the key vault to detect and respond to potential security threats in a timely manner; include a disaster recovery mechanism to ensure that data in the key vault can be restored in the event of a system failure or attack.

[0058] It should be noted that the transport protocol in the sending process of the secure transport module 12 is selected as follows: for Web (World Wide Web) data transmission, the HTTPS protocol (Secure Hypertext Transfer Protocol) is used, and encrypted transmission is carried out through SSL (Secure Sockets Layer) / TLS (Transport Layer Security). Specifically, a secure TLS / SSL connection is established between the client and the server, and mutual authentication and key negotiation are ensured through certificate exchange and handshake protocols. The encrypted compressed package is protected during transmission to prevent man-in-the-middle attacks and data leakage.

[0059] It should be noted that the data transmission protocol is recommended to use HTTPS. HTTPS uses SSL / TLS encryption technology to encrypt the transmitted data to ensure that the data is not stolen or tampered with during transmission. This encryption mechanism effectively protects the security of users' sensitive information. HTTPS is mainly composed of the HTTP protocol (Hypertext Transfer Protocol) and the SSL / TLS protocol. The HTTP protocol is used to transmit hypertext data, while the SSL / TLS protocol is responsible for encrypted communication and authentication.

[0060] It should be noted that the client uses digital certificates and private keys for device authentication. Before the device accesses the system, it needs to submit valid certificates and signature information to the authentication server. The authentication server verifies the validity of the certificates, the integrity of the signatures, and the permissions of the devices to ensure that only authorized devices (authorized clients) can receive and process the encrypted compressed package.

[0061] In this embodiment, the encrypted data obtained by the client is data that cannot be manually decrypted, and a unique client needs to be used in combination to operate the data. The client is a data processing client provided by the data issuer for subsequent processing of the data.

[0062] In this embodiment, the encryption processing engine 22 is configured to, after passing the authentication, receive the encrypted data packet and decrypt the encrypted data using the encryption key pre-obtained from the data processing module 11 to obtain decrypted data, process the decrypted data, and encrypt the processed data using the encryption key to obtain processed data.

[0063] It should be noted that after the verification passes, the device receives the encrypted compressed package through a secure channel and stores it in the encrypted storage area of the device. When storing, the encrypted compressed package may undergo further encapsulation or encryption processing to enhance security on the device. It should be noted that for data that needs to be stored for a long time, it is stored in a secure storage medium, such as an encrypted hard disk, cloud storage, etc. When storing, consider using redundant storage and backup mechanisms to prevent data loss and damage. Subsequently, strict access control policies can also be set to limit the access rights to the stored data and prevent unauthorized access and tampering.

[0064] It should be noted that the data can be transmitted back to the server 10 using the https technology in the same way as it is transmitted back to the server 10 (such as a data center or a storage center, etc.).

[0065] In summary, this application encrypts the compressed data by integrating an efficient encryption algorithm (such as AES-256-GCM), ensuring the confidentiality and integrity of the data during transmission and storage, and effectively preventing the risks of data leakage and tampering; by adopting an efficient compression algorithm, this system can significantly reduce the volume of the data, thereby reducing the bandwidth consumption and transmission time during transmission and improving the overall efficiency of data transmission; this application supports multiple data sources and output targets and can be seamlessly integrated into the existing IT infrastructure; this application provides an intuitive and easy-to-use operation interface and a simple operation process, enabling users to easily complete operations such as data encryption, compression, transmission, and storage, reducing the operation difficulty and complexity; in terms of data backup and recovery, this application ensures the reliability and availability of the data through encrypted storage and efficient transmission, providing strong guarantee for the business continuity of enterprises. Even in case of an accident, the data can be quickly restored and the business operation can be resumed; this application helps enterprises comply with relevant regulatory requirements and avoid potential risks by providing comprehensive data encryption and privacy protection functions.

[0066] It should be noted that in this application, the server functions are divided into an encryption and compression module 11 and a secure transmission module 12, and the client functions are divided into a client verification and reception module 21, an encryption processing engine 22, and a secure output and storage module 23. Thus, each detailed step is taken as a module, separated from other step modules. Through modular design, the overall server system also has good scalability and can be functionally extended and upgraded according to actual needs.

[0067] As can be seen, the data processing module described in this application is used to split target data into several data blocks and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks. Among them, the encryption operation is chain encryption. The chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block. The secure transmission module is used to send the encrypted data packet to the client. The client verification and reception module is used to perform authentication between the client and the server. The encryption processing engine is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the authentication. The secure output and storage module is used to store the processed data at a specified location. As can be seen, this application proposes a data chain encryption method that uses a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block as the encryption key. In addition, MD5 has uniqueness, and for different plaintext data, the MD5 value is different. Moreover, MD5 has irreversibility, and the original data cannot be directly restored from the MD5 value, thereby improving the security of data during transmission. In addition, through modular design, this application enables the overall server system to have good scalability.

[0068] Correspondingly, the embodiment of this application also discloses a data processing method. Refer to Figure 2 as shown, which is applied to a data processing system. The system includes a data processing module and a secure transmission module on the server side, and a client verification and reception module, an encryption processing engine, and a secure output and storage module on the client side. The method includes:

[0069] Step S11: Split the target data into several data blocks through the data processing module and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks. Among them, the encryption operation is chain encryption. The chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block.

[0070] In this embodiment, splitting the target data into several data blocks includes: preprocessing the target data and splitting the preprocessed data into several data blocks; wherein, the preprocessing of the target data specifically refers to preprocessing operations such as cleaning and formatting the data to ensure the integrity and consistency of the data.

[0071] In this embodiment, the target data supports multiple data sources, including file systems, databases, network streams, etc.; splitting the preprocessed data can split the overall data into data blocks of 1MB in size, and a data block less than 1MB is considered as one data block.

[0072] In this embodiment, the MD5 value is the result calculated by a hash algorithm, which is used to verify the integrity of a file. The MD5 algorithm maps input data of any length to a hash value of a fixed length (128 bits, i.e., 16 bytes). This hash value is usually represented as a 32-bit hexadecimal number. MD5 is inherently unique, and for different input data, the MD5 values are almost always different. MD5 is irreversible, and the original data cannot be directly restored from the MD5 value.

[0073] It should be noted that when a user illegally brute-forces a compressed package, the time of the compressed package will change, indirectly causing the MD5 value to change. When the MD5 changes, the subsequent compressed package cannot be decrypted, thus achieving the security of encryption.

[0074] In this embodiment, encrypting the several data blocks to obtain an encrypted data packet including several encrypted data blocks includes: compressing the several data blocks to obtain several compressed data blocks; encrypting the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks.

[0075] In this embodiment, encrypting the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks includes: selecting a target encryption method and the target key corresponding to each of the encrypted data blocks from a preset key library; encrypting the several compressed data blocks based on the target key and the target encryption method to obtain an encrypted data packet including several encrypted data blocks.

[0076] In this embodiment, the arrangement order of the several data blocks is the data block cutting order; wherein, encrypting the several data blocks to obtain an encrypted data packet including several encrypted data blocks includes: encrypting the several data blocks in accordance with the data block cutting order to obtain an encrypted data packet including several encrypted data blocks.

[0077] It should be noted that the encrypted compressed package (encrypted data packet) can contain multiple encrypted data blocks or a single data block. Each data block has its own IV and MAC tag to enhance the independence and security of the data. Each complete data contains a set of data compression packages or multiple data compression packages, and each compression package is arranged in a certain order, which is the order of the cut data to avoid confusion.

[0078] In this embodiment, the target encryption method and the target key in the preset key library are updated according to the preset update time. Specifically, a key management system (KMS) is used to generate, store, and manage keys. The keys can be randomly generated and replaced regularly to enhance security. It should be noted that keys are generated and the key library is updated regularly for use when encrypting compressed packages. Considering the complexity and duration of encryption, the key length is 128 bits; when encrypting data compression packages, the encryption process is chain encryption, that is, the md5 of the plaintext data of the previous compression package plus the key together form this chain encryption strategy.

[0079] Step S12: Send the encrypted data packet to the client through the secure transmission module;

[0080] Step S13: Perform identity authentication between the client and the server through the client verification and reception module;

[0081] Step S14: After passing the identity authentication, receive the encrypted data packet through the encryption processing engine and process the encrypted data packet to obtain processed data;

[0082] In this embodiment, the step of receiving the encrypted data packet and processing the encrypted data packet to obtain processed data after passing the identity authentication includes: after passing the identity authentication, receiving the encrypted data packet and decrypting the encrypted data using the encryption key obtained in advance from the data processing module to obtain decrypted data, processing the decrypted data, and encrypting the processed data using the encryption key to obtain processed data.

[0083] Step S15: Store the processed data in a specified location through the secure output and storage module.

[0084] It can be seen that in this application, the data processing module divides the target data into several data blocks, and performs an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block; the encrypted data packet is sent to the client through the secure transmission module; the client verification and reception module is used for the identity verification between the client and the server; after passing the identity verification, the encrypted data packet is received by the encryption processing engine and processed to obtain processed data; the processed data is stored at a specified location through the secure output and storage module. Thus, this application proposes a data chain encryption method that uses a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block as the encryption key. In addition, MD5 has uniqueness, and for different plaintext data, the MD5 value is different. Moreover, MD5 is irreversible, and the original data cannot be directly restored from the MD5 value, thereby improving the security of data during transmission. In addition, through modular design, the overall server system of this application has good scalability.

[0085] See Figure 3 As shown, it is a schematic diagram of a data processing flow; in the figure, the original data (target data) is compressed and encrypted using the key in the key library, and then the compressed and encrypted data is transmitted to the client through https. Only authorized clients can receive the data and process it to obtain the final finished data set for storage. The specific detailed process will not be elaborated here. It should be noted that Figure 2 the data processing flow in is applicable to the collection and mining of big data, data training of large models, etc., which can use the device resources during the user's idle time; the data to be processed can include data collected from the network, official documents, articles, industry data, etc., and may include sensitive data, and these data may not be formatted or mined.

[0086] Furthermore, the embodiment of this application also provides an electronic device. Figure 4 It is a structural diagram of the electronic device 30 shown according to an exemplary embodiment, and the content in the figure should not be regarded as any limitation on the scope of use of this application.

[0087] Figure 4Schematic diagram of the structure of an electronic device 30 provided by an embodiment of the present application. The electronic device 30 may specifically include: at least one processor 31, at least one memory 32, a display screen 33, an input / output interface 34, a communication interface 35, a power supply 36, and a communication bus 37. Among them, the memory 32 is used to store a computer program, and the computer program is loaded and executed by the processor 31 to implement the relevant steps in the data processing method disclosed in any of the foregoing embodiments. In addition, the electronic device 30 in this embodiment may specifically be an electronic computer.

[0088] In this embodiment, the power supply 36 is used to provide operating voltage for each hardware device on the electronic device 30; the communication interface 35 can create a data transmission channel between the electronic device 30 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed thereon here; the input / output interface 34 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0089] In addition, as a carrier for resource storage, the memory 32 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include a computer program 321, and the storage method may be short-term storage or permanent storage. Among them, the computer program 321 may further include a computer program capable of completing other specific tasks in addition to the computer program capable of implementing the data processing method executed by the electronic device 30 disclosed in any of the foregoing embodiments.

[0090] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the data processing method disclosed above is implemented.

[0091] For the specific steps of this method, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0092] The various embodiments in this application book are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference may be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and reference may be made to the description in the method part for the relevant parts.

[0093] Those skilled in the art may further realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of function in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0094] The steps of the methods or algorithms described in connection with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0095] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variation thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0096] The above has introduced in detail a data processing system, method, device, and storage medium provided by this application. Specific examples are used herein to illustrate the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A data processing system, characterized in that, It includes a data processing module and a secure transmission module on the server side, as well as a client verification and reception module, an encryption processing engine, and a secure output and storage module on the client side. Among them, the data processing module is used to split the target data into several data blocks, and perform an encryption operation on the several data blocks to obtain an encrypted data packet including several encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block; wherein, the target key of each data block is regularly updated by the key management system and stored in a preset key library; the secure transmission module is used to send the encrypted data packet to the client; the client verification and reception module is used to perform identity verification between the client and the server; the encryption processing engine is used to receive the encrypted data packet and process the encrypted data packet to obtain processed data after passing the identity verification; the secure output and storage module is used to store the processed data at a specified location.

2. The data processing system according to claim 1, wherein the encryption processing engine is used to receive the encrypted data packet and decrypt the encrypted data with the encryption key obtained from the data processing module in advance after passing the identity verification to obtain decrypted data, process the decrypted data, and encrypt the processed data with the encryption key to obtain processed data.

3. The data processing system according to claim 1, wherein The data processing module includes: a data compression module, which is used to compress the several data blocks to obtain several compressed data blocks; a data encryption module, which is used to perform an encryption operation on the several compressed data blocks to obtain an encrypted data packet including several encrypted data blocks.

4. The data processing system according to claim 3, wherein the data encryption module is specifically used to select a target encryption method and the target key corresponding to each encrypted data block from a preset key library; and perform an encryption operation on the several compressed data blocks based on the target key and the target encryption method to obtain an encrypted data packet including several encrypted data blocks.

5. The data processing system according to claim 4, wherein the data processing module is further used to update the target encryption method and the target key in the preset key library according to a preset update time.

6. The data processing system according to claim 3, wherein the data compression module is specifically used to compress the several data blocks by using a lossless compression technique to obtain several compressed data blocks.

7. The data processing system according to claim 1, wherein The arrangement order of the several data blocks is the data block cutting order; wherein, the data processing module is specifically used to perform an encryption operation on the several data blocks in accordance with the data block cutting order to obtain an encrypted data packet including several encrypted data blocks.

8. A data processing method, characterized in that, Applied to a data processing system, the system includes a data processing module and a secure transmission module on the server side, and a client verification and reception module, an encryption processing engine, and a secure output and storage module on the client side. The method includes: The target data is segmented by the data processing module to obtain a number of data blocks, and the number of data blocks are encrypted to obtain an encrypted data packet including a number of encrypted data blocks; wherein, the encryption operation is chain encryption; the chain encryption means that the encryption key of the current data block is a combination of the MD5 value of the plaintext data corresponding to the previous data block and the target key corresponding to the current data block; wherein, the target key of each data block is periodically updated by the key management system and stored in a preset key library. The encrypted data packet is sent to the client through the secure transmission module. The client verification and reception module performs authentication between the client and the server. After passing the authentication, the encryption processing engine receives the encrypted data packet and processes the encrypted data packet to obtain processed data. The processed data is stored in a specified location through the secure output and storage module.

9. An electronic device, characterized in that, Includes: A memory for storing a computer program. A processor for executing the computer program to implement the data processing method as claimed in claim 8.

10. A computer-readable storage medium, characterized in that, For storing a computer program; wherein, the computer program, when executed by the processor, implements the data processing method as claimed in claim 8.

Citation Information

Patent Citations

  • Data transmission method, device and system, storage medium and electronic device

    CN112738117A

  • Data encryption method and device, data decryption method and device and electronic equipment

    CN117675189A