Data encryption method and system, electronic equipment and medium

By determining the access type with the access server and the login server combined with the IP address, a function permission list is generated, which solves the problem of complex and high cost of internal and external network function permission control in the prior art, and realizes flexible data encryption and permission management.

CN120110705APending Publication Date: 2025-06-06中国航空油料有限责任公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411965270.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing permission control policies are independently carried out in the basic platform layer and the application layer, and functional permission control cannot be directly carried out for the internal and external networks, resulting in high costs for development and subsequent maintenance adjustment.

Method used

The access server determines the access type based on the client's IP address, and attaches an access type identifier to the login request. The login server generates a functional permission list based on the access type and sends it to the client for data encryption.

Benefits of technology

It reduces the development cost and subsequent maintenance adjustment cost during data encryption, and realizes flexible control of internal and external network functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110705A_ABST
    Figure CN120110705A_ABST
Patent Text Reader

Abstract

The invention provides a data encryption method and system, electronic equipment and a medium, and the method comprises the steps: receiving a login request for a target service system, and obtaining an IP address of a client which sends the login request from the login request, the login request comprising a user name; determining an access type corresponding to the IP address, wherein the access type comprises an intranet access type and an extranet access type; adding an access type identifier corresponding to the access type to the login request, and forwarding the login request to the login server; and receiving a function permission list corresponding to the access type and the user name returned by the login server, and sending the function permission list to the client to complete data encryption. By adopting the data encryption method and system, the electronic equipment and the medium, the problems of high development cost and high subsequent maintenance and adjustment cost during data encryption are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and more specifically, to a data encryption method, system, electronic device and medium. Background Art

[0002] Permission control is a basic means to ensure the security of information systems. In information systems, permission control mainly grants or restricts the use of some functions and access to some data based on the user name, role and status of the user logging in. In daily work, there is often a need to access the company's internal system through the Internet, but for security reasons, some functions or important and sensitive data are not allowed to be accessed through the external network, which requires permission control for these functions and data. In the prior art, external network data is usually encrypted based on IP whitelists, blacklists, etc. in the basic platform layer. This method can open or deny access to certain services or addresses, while the control of the scope of access content is completed at the application layer. As for the control of internal and external network access rights, either users are prohibited from accessing the external network, or a different service can only be redeveloped, and the scope of permissions can be restricted in different services. When the user logs in, it is routed to different services according to the user's IP address to achieve permission control.

[0003] However, in the existing permission control strategy, the IP control strategy and the username control strategy are implemented independently in the basic platform layer and the application layer respectively, and it is impossible to directly perform functional permission control on the internal and external networks. Although functional permission control of the internal and external networks can be achieved by developing independent services, this method is complicated to implement and requires the redevelopment of new login services. In addition, the code is relatively rigid, resulting in high subsequent maintenance and adjustment costs. Summary of the invention

[0004] In view of this, the purpose of this application is to provide a data encryption method, system, electronic device and medium to solve the problems of high development cost and subsequent maintenance and adjustment cost when performing data encryption.

[0005] In a first aspect, an embodiment of the present application provides a data encryption method, which is applied to an access server, including:

[0006] Receive a login request for a target business system, and obtain an IP address of a client sending the login request from the login request, wherein the login request includes a user name;

[0007] Determine the access type corresponding to the IP address, which includes intranet access type and extranet access type;

[0008] Attaching the access type identifier corresponding to the access type to the login request and forwarding it to the login server;

[0009] Receive the function permission list corresponding to the access type and user name returned by the login server, and send the function permission list to the client to complete data encryption.

[0010] Optionally, determining the access type corresponding to the IP address includes: obtaining a preset intranet address list, the intranet address list including intranet IP address segments; determining whether the IP address is in the intranet IP address segment; if it is in the intranet IP address segment, determining that the IP address is an intranet address, and the access type is an intranet access type; if it is not in the intranet IP address segment, determining that the IP address is an external network address, and the access type is an external network access type.

[0011] Optionally, the access type identifier corresponding to the access type is attached to the login request, including: if it is an intranet access type, the intranet access type identifier is attached to the request header of the login request; if it is an extranet access type, the extranet access type identifier is attached to the request header of the login request.

[0012] In a second aspect, an embodiment of the present application further provides a data encryption system, the system comprising: a client, an access server and a login server;

[0013] The client is used to send a login request to the access server;

[0014] An access server, used to execute the above data encryption method;

[0015] The login server is used to receive a login request of an additional access type, verify the login request, generate a function permission list if the login request passes the verification, and send the function permission list to the client.

[0016] Optionally, the login server is used to generate a function permission list through the following processing: obtaining an initial function permission list corresponding to the user name in the login request from the function permission table; for each function in the initial function permission list, determining the allowed access type corresponding to the function; determining whether the access type in the login request meets the requirements of the allowed access type; if it meets the requirements of the allowed access type, including the function in the function permission list.

[0017] Optionally, the allowed access types include allowing intranet access type, allowing extranet access type, and allowing both internal and external network access type; the login server is used to determine whether the access type in the login request meets the requirements of the allowed access type through the following processing: if the access type in the login request is an intranet access type, and the allowed access type is allowing intranet access type or allowing both internal and external network access type, it is determined that the requirements of the allowed access type are met; if the access type in the login request is an extranet access type, and the allowed access type is allowing extranet access type or allowing both internal and external network access type, it is determined that the requirements of the allowed access type are met.

[0018] Optionally, the login server is further configured to perform the following processing: in response to an allowed access type configuration instruction, determine an allowed access type corresponding to each function.

[0019] The list sending module is used to receive the function permission list corresponding to the access type and the user name returned by the login server, and send the function permission list to the client to complete data encryption.

[0020] In a fourth aspect, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps of the data encryption method as described above are performed.

[0021] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data encryption method as described above are executed.

[0022] The embodiments of the present application bring the following beneficial effects:

[0023] A data encryption method, system, device, electronic device and medium provided in the embodiments of the present application can determine the access type of the IP address according to the IP address of the client, determine different function permission lists for different access types, and use the function permission lists to encrypt data. Compared with the data encryption method in the prior art, it solves the problems of high development cost and high subsequent maintenance and adjustment cost when performing data encryption.

[0024] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0026] Figure 1 A flow chart of a data encryption method provided in an embodiment of the present application is shown;

[0027] Figure 2 A schematic diagram showing the structure of a data encryption system provided in an embodiment of the present application is shown;

[0028] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown;

[0029] Figure 4 One of the structural schematic diagrams of the electronic device provided in the embodiment of the present application is shown. DETAILED DESCRIPTION

[0030] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, each other embodiment obtained by those skilled in the art without making creative work belongs to the scope of protection of the present application.

[0031] It is worth noting that before this application was proposed, permission control was a basic means to ensure the security of information systems. In information systems, permission control is mainly based on the user name, role and status of the user's login, granting or restricting the use of some functions and access to some data. In daily work, there is often a need to access the company's internal system through the Internet, but for security reasons, some functions or important and sensitive data are not allowed to be accessed through the external network, which requires permission control for these functions and data. In the prior art, external network data encryption is usually performed in the basic platform layer based on IP whitelists, blacklists, etc. This method can open or deny access to certain services or addresses, while the control of the scope of access content is completed at the application layer. As for the control of internal and external network access rights, either users are prohibited from accessing the external network, or a different service can only be redeveloped, and the scope of permission is restricted in different services. When the user logs in, it is routed to different services according to the user's IP address to achieve permission control. However, in the existing permission control strategy, the IP control strategy and the username control strategy are implemented independently in the basic platform layer and the application layer respectively, and it is impossible to directly perform functional permission control on the internal and external networks. Although functional permission control of the internal and external networks can be achieved by developing independent services, this method is complicated to implement and requires the redevelopment of new login services. In addition, the code is relatively rigid, resulting in high subsequent maintenance and adjustment costs.

[0032] Based on this, an embodiment of the present application provides a data encryption method to reduce the development cost and subsequent maintenance and adjustment costs when performing data encryption.

[0033] See also Figure 1 , Figure 1 This is a flow chart of a data encryption method provided by an embodiment of the present application. Figure 1 As shown, the data encryption method provided in the embodiment of the present application is applied to the access server, including:

[0034] Step S101: receiving a login request for a target business system, and obtaining an IP address of a client sending the login request from the login request.

[0035] In this step, the target business system may refer to an internal system that the target user logs into. For example, the target business system may be an internal business system of an aviation fuel company.

[0036] The login request may refer to a request for logging into a target business system, and the login request includes but is not limited to: a user name, a login password, and an IP address of a client.

[0037] In the embodiment of the present application, the target user enters the domain name of the target business system through the client in the intranet or extranet, and after being resolved by the intranet or extranet domain name server, it is routed to the internal access server to display the website content corresponding to the target business system. The target user enters the user name and login password in the target business system, clicks the login button and sends a login request. The access server receives the login request and determines the IP address corresponding to the client that initiated the access request from the login request. Among them, the intranet refers to the company's internal network, and the extranet refers to the external network.

[0038] Step S102: determine the access type corresponding to the IP address.

[0039] In this step, the access type may refer to the type of the IP address of the client. The access type is used to determine the access rights. The access type includes an intranet access type and an extranet access type.

[0040] In an optional embodiment, determining the access type corresponding to the IP address includes: obtaining a preset intranet address list, the intranet address list including an intranet IP address segment; determining whether the IP address is in the intranet IP address segment; if it is in the intranet IP address segment, determining that the IP address is an intranet address and the access type is an intranet access type; if it is not in the intranet IP address segment, determining that the IP address is an extranet address and the access type is an extranet access type.

[0041] Specifically, an intranet address list may be pre-set, which lists all IP address segments used in the company's intranet, namely, the intranet IP address segments, which are used to represent the IP address range of the intranet, for example: 192.0.0.0-192.0.0.255.

[0042] When a login request is received, it is determined whether the login request is an intranet address or an extranet address based on the client IP address in the login request. Taking the above example, assuming that the client IP address sending the login request is 192.0.0.116, it is in the intranet IP address segment, indicating that the login is through the intranet, then the access type of the login request is determined to be the intranet access type, otherwise the access type of the login request is determined to be the extranet access type.

[0043] Step S103: attach the access type identifier corresponding to the access type to the login request and forward it to the login server.

[0044] In this step, the access type identifier may refer to a unique identifier of the access type, and the access type identifier is used to distinguish the access types.

[0045] Access types include intranet access type and extranet access type.

[0046] Exemplarily, the access type identifier may be a number or a character.

[0047] As an example, the intranet access type is true and the extranet access type is false, or the intranet access type is 1 and the extranet access type is 0.

[0048] In an optional embodiment, the access type identifier corresponding to the access type is attached to the login request, including: if it is an intranet access type, the intranet access type identifier is attached to the request header of the login request; if it is an extranet access type, the extranet access type identifier is attached to the request header of the login request.

[0049] Specifically, if it is determined that the IP address of the client sending the access request is an intranet IP address, the access type is assigned a value in the request header of the login request, for example: access type = true. If it is determined that the IP address of the client sending the access request is an extranet IP address, the access type is assigned a value in the request header of the login request, for example: access type = false.

[0050] Step S104, receiving the function permission list corresponding to the access type and the user name returned by the login server, and sending the function permission list to the client to complete data encryption.

[0051] In this step, the function permission list may refer to a list of functions that can be used by the target user, and the function permission list is used to determine the function use permission of the target user.

[0052] Exemplary functions that can be used include querying aircraft refueling orders, querying invoices, querying orders, etc.

[0053] As an example, the function permission list includes function identification, function name, function description, and function type.

[0054] In an embodiment of the present application, after the login server receives a login request with an access type identifier attached, it first verifies the username and password in the login request. If the verification passes, it queries the pre-set function permission list to see whether there is a target username that matches the username. If there is a matching target username, the function list corresponding to the target username is used as the initial function permission list.

[0055] Then, for each function in the initial function permission list, determine the allowed access type corresponding to the function. Among them, the allowed access types are divided into three types, namely, the allowed intranet access type, the allowed extranet access type, and the allowed intranet and extranet access types. If the access type identifier in the login request is 1, and the allowed access type of a function is the allowed intranet access type, it means that the target user is allowed to use the function, and the function identifier and function name of the function are added to the function permission list; if the access type identifier in the login request is 1, and the allowed access type of a function is the allowed extranet access type, it means that the target user is not allowed to use the function, and the function identifier and function name of the function will not be added to the function permission list. If the allowed access type of a function is the allowed intranet and extranet access type, it means that regardless of whether the access type identifier in the login request is 1 or 0, the target user can use the function, and the function identifier and function name of the function are added to the function permission list.

[0056] Finally, when the username and password are verified, the login server sends the function permission list to the client through the access server to display the functions that the target user can use on the client and prompt the target user that the login is successful.

[0057] Compared with the data encryption method in the prior art, the present application can determine the access type of the IP address according to the IP address of the client, determine different function permission lists for different access types, and use the function permission lists to encrypt data, thereby solving the problems of high development costs and subsequent maintenance and adjustment costs when encrypting data.

[0058] See also Figure 2 , Figure 2 This is a schematic diagram of the structure of a data encryption system provided in an embodiment of the present application. Figure 2 As shown in , the data encryption system 200 includes: a client 210, an access server 220 and a login server 230;

[0059] The client 210 is used to send a login request to the access server 220;

[0060] Access server 220, used to execute the above data encryption method;

[0061] The login server 230 is used to receive a login request of an additional access type, verify the login request, generate a function permission list if the login request passes the verification, and send the function permission list to the client 210 .

[0062] In the embodiment of the present application, the client 210 is connected to the access server 220, and the access server 220 is connected to the login server 230. When the target user sends a login request for the target business system to the access server 220 through the client 210, the access server 220 receives the login request, obtains the IP address corresponding to the client 210 from the login request, and then determines the access type corresponding to the IP address; attaches the access type identifier corresponding to the access type to the request header of the login request, and forwards it to the login server 230.

[0063] After receiving the login request with an additional access type, the login server 230 verifies the login request. If the login request passes the verification, the initial function permission list corresponding to the user name in the login request is obtained from the function permission table, and the allowed access type corresponding to each function in the initial function permission list is determined, and whether the access type in the login request meets the requirements of the allowed access type corresponding to each function. If the access type meets the requirements of the allowed access type of a certain function, the function identifier and function name of the function are included in the function permission list to generate a function permission list corresponding to the access type and user name, and the function permission list is sent to the access server 220.

[0064] The access server 220 receives the function permission list corresponding to the access type and the user name returned by the login server 230, and sends the function permission list to the client 210. The client 210 displays the functions available to the target user according to the function permission list to complete data encryption.

[0065] In an optional embodiment, the login server 230 is used to generate a function permission list by the following processing: obtaining an initial function permission list corresponding to the user name in the login request from the function permission table; for each function in the initial function permission list, determining the allowed access type corresponding to the function; determining whether the access type in the login request meets the requirements of the allowed access type; if the requirements of the allowed access type are met, including the function in the function permission list.

[0066] In an optional embodiment, the allowed access type includes allowing intranet access type, allowing extranet access type, and allowing internal and external network access type; the login server 230 is used to determine whether the access type in the login request meets the requirements of the allowed access type through the following processing: if the access type in the login request is an intranet access type, and the allowed access type is allowing intranet access type or allowing internal and external network access type, it is determined that the requirements of the allowed access type are met; if the access type in the login request is an extranet access type, and the allowed access type is allowing extranet access type or allowing internal and external network access type, it is determined that the requirements of the allowed access type are met.

[0067] In an optional embodiment, the login server 230 is further configured to perform the following processing: in response to the allowed access type configuration instruction, determine the allowed access type corresponding to each function.

[0068] Specifically, a permitted access type table may be set for all functions, in which the function identifier is used as an index, and the permitted access type corresponding to each function is stored corresponding to the function identifier to determine the permitted access type corresponding to each function.

[0069] See also Figure 3 , Figure 3 This is a schematic diagram of the structure of a data encryption device provided in an embodiment of the present application. Figure 3 As shown in , the data encryption device 300 is applied to the access server, and includes:

[0070] The address acquisition module 301 is used to receive a login request for a target business system and obtain the IP address of the client sending the login request from the login request, wherein the login request includes a user name;

[0071] An access type determination module 302 is used to determine the access type corresponding to the IP address, where the access type includes an intranet access type and an extranet access type;

[0072] The request forwarding module 303 is used to attach the access type identifier corresponding to the access type to the login request and forward it to the login server;

[0073] The list sending module 304 is used to receive the function permission list corresponding to the access type and the user name returned by the login server, and send the function permission list to the client to complete data encryption.

[0074] The present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computer program can execute the above-mentioned Figure 1 The steps of the data encryption method in the method embodiment shown, the specific implementation method can be found in the method embodiment, and will not be repeated here.

[0075] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0076] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.

[0077] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0078] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0079] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0080] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-mentioned embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-mentioned embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.

Claims

1. A data encryption method, characterized in that: Applicable to access servers, including: Receiving a login request for a target business system, and obtaining an IP address of a client sending the login request from the login request, wherein the login request includes a user name; Determine the access type corresponding to the IP address, the access type including an intranet access type and an extranet access type; Adding the access type identifier corresponding to the access type to the login request and forwarding it to the login server; Receive the function permission list corresponding to the access type and the user name returned by the login server, and send the function permission list to the client to complete data encryption.

2. The method according to claim 1, characterized in that The determining the access type corresponding to the IP address includes: Obtain a preset intranet address list, wherein the intranet address list includes intranet IP address segments; Determine whether the IP address is in the intranet IP address segment; If it is in the intranet IP address segment, determine that the IP address is an intranet address and the access type is an intranet access type; If it is not in the intranet IP address segment, it is determined that the IP address is an extranet address and the access type is an extranet access type.

3. The method according to claim 1, characterized in that The step of attaching the access type identifier corresponding to the access type to the login request includes: If it is an intranet access type, appending the intranet access type identifier to the request header of the login request; If it is an external network access type, the external network access type identifier is appended to the request header of the login request.

4. A data encryption system, characterized in that: The system comprises: a client, an access server and a login server; The client is used to send a login request to the access server; The access server is used to execute the data encryption method described in any one of claims 1 to 3; The login server is used to receive a login request of an additional access type, verify the login request, generate a function permission list if the login request passes the verification, and send the function permission list to the client.

5. The system according to claim 4, characterized in that The login server is used to generate a function permission list through the following processing: Acquire an initial function permission list corresponding to the user name in the login request from the function permission table; For each function in the initial function permission list, determining the allowed access type corresponding to the function; Determining whether the access type in the login request meets the requirements of the allowed access type; If the requirements for the allowed access type are met, the function is included in the function permission list.

6. The system according to claim 5, characterized in that The allowed access types include allowed intranet access type, allowed extranet access type, and allowed intranet and extranet access type; The login server is used to determine whether the access type in the login request meets the requirement of the allowed access type by the following processing: If the access type in the login request is an intranet access type, and the allowed access type is an allowed intranet access type or an allowed intranet and extranet access type, it is determined that the requirements for the allowed access type are met; If the access type in the login request is an extranet access type, and the allowed access type is an allowed extranet access type or an allowed intranet and extranet access type, it is determined that the requirement for the allowed access type is met.

7. The system according to claim 4, characterized in that The login server is also used to perform the following processing: In response to the allowed access type configuration instruction, the allowed access type corresponding to each function is determined.

8. An electronic device, characterized in that: include: A processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the storage medium communicate through the bus, and the processor executes the machine-readable instructions to perform the steps of the data encryption method as described in any one of claims 1 to 3.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the data encryption method according to any one of claims 1 to 3 are executed.