Business compliance evaluation method and device, electronic equipment and storage medium
By configuring the private key and performing SSL offload operations, encrypted data transmission between the application server and the password server, identifying sensitive data and comparing it with the compliance library, the compliance and security of encrypted data transmission in the existing technology are solved, and the compliance and security of data transmission are achieved.
Patent Information
- Application Number
- CN202510224586.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-17
AI Technical Summary
The prior art is difficult to monitor and judge the compliance of sensitive data in encrypted data transmission between the application server and the cryptographic server, especially in the case of encrypted channels and encrypted content.
By configuring the network communication private key between the application server and the password server and performing SSL uninstallation operations, obtaining the data to be encrypted. Then, identify the sensitive data and its type and compare it with the pre-established compliance library to determine whether it is compliant. If it is not compliant, compare the packets of the password server with the product message library to determine the product type and make rectifications.
It realizes monitoring of data transmission between application servers and password servers, identification and compliance judgment of sensitive data, and ensuring compliance and security of data processing and product operations.
Smart Images

Figure CN120166048A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data processing, and in particular, to a method, device, electronic device and storage medium for business compliance assessment. Background Art
[0002] When outputting data in cooperation with customers, it is necessary to comply with national laws, regulations and company rules and regulations, and data that is clearly prohibited from being output shall not be output externally. In enterprises that attach importance to network security and data security, encrypted channels are often used to transmit data, and the content of sensitive items is encrypted.
[0003] Traditional conventional monitoring means based on network traffic focus on the exit position of the network boundary, that is, the gateway server. It mainly targets the total gateway for network traffic to enter and exit the enterprise network, but it is powerless against encrypted channels and encrypted content. For example, the location of the router or firewall where the internal network of the enterprise is connected to the external Internet mainly monitors the inflow and outflow of the overall network traffic, focusing on the macro-level network access control and traffic situation perception, and it is difficult to deeply understand the detailed interaction between the internal specific application and the cryptographic device; it is impossible to determine which specific application service interacts with the cryptographic device to generate these data, and the specific processing situation of these data at the cryptographic level. Summary of the Invention
[0004] In view of this, the purpose of the present application is to provide a method, device, electronic device and storage medium for business compliance assessment, which can realize the monitoring of data transmission between the application server and the cryptographic server, the identification of sensitive data, and ensure the compliance of the operating products.
[0005] In the first aspect, an embodiment of the present application provides a method for business compliance assessment, and the method includes the following steps:
[0006] Configure the network communication private key between the application server and the cryptographic server, and after the private key configuration is completed, perform an SSL offloading operation to obtain the data to be encrypted sent by the application server to the cryptographic server;
[0007] Identify sensitive data and its type from the obtained data to be encrypted, and compare it with a pre-established compliance library to determine whether it is compliant; wherein, the compliance library stores various compliance standards for various types of sensitive data.
[0008] If it is determined that it is not compliant, compare the corresponding message requesting the cryptographic server with the product message library, determine the product type, and rectify the product; wherein, the product message library stores various message examples of various products interacting with the cryptographic server.
[0009] In some embodiments, the steps for configuring the private key for network communication between the configuration application server and the password server are as follows:
[0010] Select a target encryption algorithm and generate a key pair using the target encryption algorithm; the key pair includes a private key and its corresponding public key;
[0011] Configure the generated private key to the application server for SSL communication; and configure the generated public key to the password server for SSL communication verification.
[0012] In some embodiments, the SSL offloading operation is performed in the following manner, including the following steps:
[0013] Deploy an SSL offloading device on the network path between the application server and the password server;
[0014] Configure an SSL offloading policy in the SSL offloading device;
[0015] Perform an SSL offloading operation based on the SSL offloading policy configured in the SSL offloading device to intercept and decrypt the request initiated by the application server to the password server, and obtain the data to be encrypted.
[0016] In some embodiments, the steps for identifying sensitive data and its type from the obtained data to be encrypted and comparing it with a pre-established compliance library to determine compliance are as follows:
[0017] Perform feature analysis on the obtained data to be encrypted, and identify different types of sensitive data based on various preset data features; among them, different types of sensitive data have different digital formats or encoding formats;
[0018] For each type of sensitive data identified, compare it one by one with each compliance standard in the pre-established compliance library. If there is a non-compliance standard item, it is determined to be non-compliant.
[0019] In some embodiments, the compliance standard items include one or more of the processing method, storage status, and transmission conditions of sensitive data.
[0020] In some embodiments, the steps for comparing the corresponding message requesting the password server with the product message library and determining the product type are as follows:
[0021] Obtain the message of the request initiated by the application server to the password server;
[0022] Extract keywords and message structures from the said message; wherein, the keywords include one or more of product names, version numbers, and business process related terms, and the message structure includes the number of data fields and their arrangement order.
[0023] Preliminarily screen out a set of message examples from the product message library that contain all the extracted keywords.
[0024] Match the extracted message structure with the structure of each message example in the set of message examples, find the target message example that is consistent, and determine the product type corresponding to the target message example.
[0025] In some embodiments, rectifying the product includes reviewing the code logic of the product, adjusting the way of interacting with the password server, or optimizing the sensitive data processing process involved in the product.
[0026] In a second aspect, an embodiment of the present application provides a business compliance assessment device, and the device includes:
[0027] An unloading module, configured to configure the network communication private key between the application server and the password server, and after the private key is completed, perform an SSL unloading operation to obtain the data to be encrypted sent by the application server to the password server.
[0028] A judgment module, configured to identify sensitive data and its type from the obtained data to be encrypted, and compare it with a pre-established compliance library to judge whether it is compliant; wherein, the compliance library stores various compliance standards for various types of sensitive data.
[0029] A determination module, configured to, if it is judged non-compliant, compare the corresponding message requesting the password server with the product message library, determine the product type, and rectify the product; wherein, the product message library stores various message examples of various products interacting with the password server.
[0030] In a third aspect, an electronic device provided by an embodiment of the present application includes: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the business compliance assessment method according to any one of the first aspects are executed.
[0031] In a fourth aspect, a computer-readable storage medium provided by an embodiment of the present application stores a computer program. When the computer program is run by a processor, the steps of the business compliance assessment method according to any one of the first aspects are executed.
[0032] A method, apparatus, electronic device, and storage medium for business compliance assessment according to the present application configure a network communication private key between an application server and a password server, and after completing the private key, perform an SSL offloading operation to obtain the data to be encrypted sent by the application server to the password server; identify sensitive data and its type from the obtained data to be encrypted, and compare it with a pre-established compliance library to determine whether it is compliant; wherein, the compliance library stores various compliance standards for each type of sensitive data; if it is determined to be non-compliant, compare the corresponding message requesting the password server with a product message library, determine the product type, and rectify the product; wherein, the product message library stores various message examples of various products interacting with the password server. Thus, it is possible to systematically monitor the data transmission between the application server and the password server, identify sensitive data and judge its compliance, and take corresponding treatment measures in a timely manner when violations occur, ensuring the compliance and security of data processing and product operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0034] Figure 1 Shows a flowchart of the business compliance assessment method described in the embodiments of the present application;
[0035] Figure 2 Shows a flowchart of identifying sensitive data and its type from the obtained data to be encrypted and comparing it with a pre-established compliance library to determine whether it is compliant in the embodiments of the present application;
[0036] Figure 3 Shows a schematic structural diagram of the business compliance assessment apparatus described in the embodiments of the present application;
[0037] Figure 4 Shows a block diagram of the structure of the electronic device described in the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. It should be understood that the accompanying drawings in this application are only for the purposes of illustration and description, and are not used to limit the protection scope of this application. Additionally, it should be understood that the schematic drawings are not drawn to actual scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of this application. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without a logical context relationship may be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of this application.
[0039] Furthermore, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. The components of the embodiments of this application usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents the selected embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.
[0040] It should be noted that the term "including" will be used in the embodiments of this application to indicate the existence of the features stated thereafter, but does not exclude the addition of other features.
[0041] In view of the technical problems proposed in the background art, this application provides a method, device, electronic device, and storage medium for business compliance assessment, which can achieve the monitoring of data transmission between the application server and the password server, the identification of sensitive data, and ensure the compliance of the operating products.
[0042] See the attached Figure 1 of the specification. A method for business compliance assessment provided by the embodiments of this application includes the following steps:
[0043] S1. Configure the network communication private key between the application server and the password server, and after the private key configuration is completed, perform an SSL offloading operation to obtain the data to be encrypted sent by the application server to the password server;
[0044] S2. Identify the sensitive data and its type from the obtained data to be encrypted, and compare it with a pre-established compliance library to determine whether it is compliant; wherein, the compliance library stores the compliance standards for various types of sensitive data.
[0045] S3. If it is determined that it does not comply with the regulations, compare the corresponding message requesting the password server with the product message library, determine the product type, and rectify the product; wherein, the product message library stores various message examples of various products interacting with the password server.
[0046] Specifically, in step S1, first configure a dedicated private key for the network communication between the application server and the password server. Among them, the private key plays a crucial role in the SSL (Secure Sockets Layer) communication mechanism. It is one of the key elements for realizing data encryption, decryption, and authentication. By reasonably configuring the private key, a secure and reliable communication channel can be established between the application server and the password server, ensuring the confidentiality and integrity of data during transmission.
[0047] After completing the private key configuration, perform the SSL offloading operation. Among them, SSL offloading is a technical means of transferring the SSL encryption and decryption processing tasks originally borne by the server to a dedicated device. Through such an offloading operation, the data to be encrypted sent by the application server to the password server can be directly obtained. This step enables the subsequent processing and analysis of data to be carried out closer to the data source, laying a foundation for further sensitive data identification and compliance judgment.
[0048] In one embodiment, first determine a suitable encryption algorithm and use professional encryption tools to generate a key pair, such as the commonly used asymmetric encryption algorithms RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography). Among them, the generated key pair includes a private key and its corresponding public key. Then install the generated private key on the application server for SSL communication; and install the public key corresponding to the private key on the password server for verifying messages from the application server.
[0049] After completing the private key configuration, select a dedicated SSL offloading device and deploy it on the network path between the application server and the password server, and configure specific offloading policies for the SSL offloading device, which includes specifying the SSL protocol version, cipher suite to be offloaded, and how to handle the traffic after offloading. For example, configure the traffic of the TLSv1.3 protocol to be offloaded, and the decrypted plaintext traffic can be transmitted to the password server using the unencrypted HTTP protocol or other custom internal protocols. After configuring the offloading policy, enable the SSL offloading function. When the application server initiates an SSL connection to the password server, the SSL offloading device will intercept the connection request, perform the SSL handshake process, and then decrypt the subsequent encrypted data to obtain the data to be encrypted sent by the application server to the password server.
[0050] Through step S1, the configuration of the dedicated private key between the application server and the password server and the SSL offloading operation can be completed, thereby realizing a secure and easily monitored data communication environment.
[0051] See the attached Figure 2 In step S2, identifying sensitive data and its type from the obtained data to be encrypted and comparing it with a pre-established compliance library to determine compliance includes the following steps:
[0052] S201. Perform feature analysis on the obtained data to be encrypted, and identify different types of sensitive data based on various preset data features; among them, different types of sensitive data have different digital formats or encoding formats;
[0053] S202. For each type of identified sensitive data, compare it one by one with each compliance standard in the pre-established compliance library. If there is a non-compliance standard item, it is judged as non-compliant.
[0054] Specifically, in step S201, a special sensitive data identification module can be used to comprehensively analyze the features of the obtained data to be encrypted, and it will identify different types of sensitive data according to various preset data feature patterns. For example, for sensitive data such as credit card numbers, they usually have a specific digital format (generally 16 digits, and the first few digits correspond to specific card-issuing institution codes); another example is that for ID card numbers, they have a fixed length (18 digits) and specific encoding rules (including date of birth, area code, etc.). The sensitive data identification module will initially judge whether there may be credit card number data or ID card numbers by identifying this digital format feature.
[0055] In other embodiments, a neural network model in deep learning can also be used. After being trained with a large number of labeled sensitive data samples, the model can learn the complex features and patterns of various sensitive data, so as to more accurately identify new data. These models can be continuously updated and optimized to adapt to newly emerging sensitive data types and changing business scenarios.
[0056] In step S202, different types of sensitive data are classified in the pre-established compliance library, and various compliance standards are formulated for each type of sensitive data, including compliance requirements for the processing method, storage status, transmission conditions, etc. of various types of sensitive data. For example, the encryption intensity, access control, etc. requirements of payment-related sensitive data such as credit card numbers during network transmission are clearly specified.
[0057] Once a sensitive data type is identified, it will be matched with the data types in the compliance library. For example, if the identified data type is a credit card number, the relevant compliance standards for credit card numbers will be searched in the compliance library. Once the data type matching is completed, for the identified sensitive data, its actual situation such as the current processing method, storage status, and transmission conditions will be compared one by one with the compliance conditions specified in the compliance library. For example, for the identified credit card number data, if the compliance library stipulates that the AES-256 encryption algorithm must be used for encryption during network transmission, but the actual situation is that the AES-128 encryption algorithm is used, then it is determined to be non-compliant.
[0058] In step S3, when it is determined that there is a non-compliant situation through the sensitive data identification in step S2 and comparison with the compliance library, further in-depth analysis needs to be carried out on the message requesting the password server. First, it is necessary to ensure that the complete message content of the application server's request to the password server can be accurately obtained. In one embodiment, the message information is extracted from the relevant device or system logs that obtained data during the previous SSL offloading operation to ensure the integrity and accuracy of the message data for subsequent effective comparative analysis.
[0059] In this application, after obtaining the message of the application server's request to the password server, keywords and message structures are extracted from the message; then a set of message examples containing all the extracted keywords is preliminarily screened from the product message library, and then the extracted message structure is matched with the structure of each message example in the set of message examples, and a target message example that is consistent is found, and the product type corresponding to the target message example is determined. The product message library is a sample library of messages for the interaction between various products and the password server that is collected and sorted in advance, which contains typical message examples of different products and their corresponding product type information.
[0060] In one embodiment, key words, phrases, etc. are mainly extracted from the message as the key words for analysis. The key words extracted from the message requesting the password server include product name, version number, specific function code, business process related vocabulary, etc. For example, if it involves a financial product, keywords related to the product's business such as "online banking transfer" and "payment password verification" may appear in the message. At the same time, similar keyword extraction operations are also performed on each message example in the product message library, and the words that can reflect the product characteristics are sorted out to form a keyword set corresponding to each product. Furthermore, the keywords extracted from the message requesting the password machine are compared one by one with the keyword sets of each product in the product message library. Through this comparison, a message example set containing all the keywords is initially screened out. For example, if the keywords "online banking transfer" and "payment password verification" appear in the message requesting the password server, and these keywords also happen to be in the keyword set of a certain message example in the product message library, then it initially indicates that this request may be related to the financial product corresponding to this message example;
[0061] Perform a structural analysis on the message to determine the composition method, data format, and logical relationship between each part such as the message header, message body, and message tail. For example, analyze the information contained in the message header such as source IP address, destination IP address, protocol version, etc.; the arrangement order of data and the definition of data fields in the message body; the information such as checksum that may be contained in the message tail. And similarly, a detailed structural analysis is also performed on each message example in the product message library to sort out their respective structural characteristics and form a message structure template corresponding to each product. Furthermore, the structure of the message from the request password server is matched and judged with the message structure template corresponding to the message example set initially screened out in the product message library to check whether they are the same in terms of the overall structure, composition of each part, and logical relationship. For example, if the message structure of the request password server is the same as the message structure template corresponding to a certain message example in the initially screened out message example set in terms of the number and arrangement order of data fields, etc., then this message example is determined as the target message example, and then the financial product corresponding to this target message example is found.
[0062] After determining the product type, promptly notify the relevant product managers, for example, through enterprise internal communication tools (such as instant messaging software, emails, etc.). The notification content should detail the non-compliance situation this time, including the violation details analyzed in the previous steps (such as the specific manifestations of non-compliance in sensitive data processing), and the determined product type. After receiving the notification, the product manager can carry out specific rectification work for the responsible product, such as reviewing and modifying the product code, adjusting the process of the product interacting with the cryptographic machine, and improving the product's sensitive data processing mechanism, etc., to ensure that the product can meet the relevant compliance requirements during subsequent operation.
[0063] It can be seen that for a business compliance assessment method provided by this application, by setting the monitoring point on the communication link between the application server and the cryptographic server, it can accurately capture the details of sensitive data processing and transmission, realize the identification and compliance judgment of sensitive data, and take corresponding handling measures in a timely manner when violations occur, ensuring the compliance and security of data processing and product operation.
[0064] Based on the same inventive concept, an embodiment of this application also provides a business compliance assessment device. Since the principle of solving problems by the device in the embodiment of this application is similar to that of the above-mentioned business compliance assessment method, device, electronic device, and storage medium in the embodiment of this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0065] As shown in the attached Figure 3 description of the specification, this application also provides a business compliance assessment device, and the device includes:
[0066] An uninstallation module 301, configured to configure the network communication private key between the application server and the cryptographic server, and after completing the private key, perform an SSL uninstallation operation to obtain the data to be encrypted sent by the application server to the cryptographic server;
[0067] A judgment module 302, configured to identify sensitive data and its type from the obtained data to be encrypted, and compare it with a pre-established compliance library to judge whether it is compliant; wherein, the compliance library stores various compliance standards for various types of sensitive data;
[0068] A determination module 303, configured to, if the judgment is non-compliant, compare the corresponding message requesting the cryptographic server with the product message library, determine the product type, and rectify the product; wherein, the product message library stores various message examples of various products interacting with the cryptographic server.
[0069] In some embodiments, the offloading module 301 configures the network communication private key between the application server and the password server, including: selecting a target encryption algorithm and generating a key pair using the target encryption algorithm; the key pair includes a private key and its corresponding public key; configuring the generated private key to the application server for SSL communication; and configuring the generated public key to the password server for SSL communication verification.
[0070] In some embodiments, the offloading module 301 performs an SSL offloading operation, including: deploying an SSL offloading device on the network path between the application server and the password server, and configuring an SSL offloading policy in the SSL offloading device; wherein, the configured SSL offloading policy includes the IP addresses of the application server and the password server; performing an SSL offloading operation based on the SSL offloading policy configured in the SSL offloading device to intercept and decrypt the request initiated by the application server to the password server, and obtain the data to be encrypted.
[0071] In some embodiments, the judging module 302 identifies sensitive data and its type from the obtained data to be encrypted, and compares it with a pre-established compliance library to judge whether it is compliant, including: performing feature analysis on the obtained data to be encrypted, and identifying different types of sensitive data according to various preset data features; wherein, different types of sensitive data have different digital formats or encoding formats; for each type of sensitive data identified, comparing it one by one with each compliance standard in the pre-established compliance library, and if there is a non-compliant standard item, judging it as non-compliant. Among them, the compliance standard items include one or more of the processing method, storage state, and transmission condition of the sensitive data.
[0072] In some embodiments, the determining module 303 compares the corresponding message for requesting the password server with the product message library and determines the product type, including: obtaining the message of the request initiated by the application server to the password server; extracting keywords and message structure from the message; wherein, the keywords include one or more of the product name, version number, business process related vocabulary, and the message structure includes the number of data fields and their arrangement order; preliminarily screening out a set of message examples in the product message library that contain all the extracted keywords; matching the extracted message structure with the structure of each message example in the set of message examples, and finding a consistent target message example, and determining the product type corresponding to the target message example.
[0073] In some embodiments, the determining module 303 rectifies the product, including reviewing the code logic of the product, adjusting the interaction method with the password server, or optimizing the sensitive data processing process involved in the product.
[0074] A business compliance evaluation device provided by the present application configures the network communication private key between the application server and the password server through an offloading module, and after the private key is completed, performs an SSL offloading operation to obtain the data to be encrypted sent by the application server to the password server; the judgment module identifies sensitive data and its type from the obtained data to be encrypted, and compares it with a pre-established compliance library to judge whether it is compliant; wherein, the compliance library stores various compliance standards for various types of sensitive data; if it is judged to be non-compliant, the determination module compares the corresponding message requesting the password server with the product message library, determines the product type, and rectifies the product; wherein, the product message library stores various message examples of various products interacting with the password server. Thus, it can systematically monitor the data transmission between the application server and the password server, identify sensitive data and judge its compliance, and take corresponding treatment measures in a timely manner when violations occur, ensuring the compliance and security of data processing and product operation.
[0075] Based on the same inventive concept of the present invention, the accompanying Figure 4 As shown in the figure, the structure of an electronic device 400 provided by an embodiment of the present application, the electronic device 400 includes: at least one processor 401, at least one network interface 404 or other user interfaces 403, a memory 405, and at least one communication bus 402. The communication bus 402 is used to realize the connection and communication between these components. The electronic device 400 optionally includes a user interface 403, including a display (for example, a touch screen, an LCD, a CRT, a holographic imaging or a projector, etc.), a keyboard or a pointing device (for example, a mouse, a trackball, a touchpad or a touch screen, etc.).
[0076] The memory 405 may include a read-only memory and a random access memory, and provide instructions and data to the processor 401. A part of the memory 405 may also include a non-volatile random access memory (NVRAM).
[0077] In some embodiments, the memory 405 stores the following elements, which can protect modules or data structures, or subsets thereof, or extended sets thereof:
[0078] An operating system 4051, including various system programs, used to implement various basic services and process hardware-based tasks;
[0079] An application program module 4052, including various application programs, such as a launcher, a media player, a browser, etc., used to implement various application services.
[0080] In an embodiment of the present application, by invoking the programs or instructions stored in the memory 405, the processor 401 is configured to execute the steps in a business compliance evaluation method, apparatus, electronic device, and storage medium, and can implement the monitoring of data transmission between the application server and the password server and the identification of sensitive data, so as to ensure the compliance of the operating products.
[0081] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps in the business compliance evaluation method.
[0082] Specifically, the storage medium can be a general storage medium, such as a removable disk, a hard disk, etc. When the computer program on the storage medium is run, it can execute the above-mentioned business compliance evaluation method.
[0083] In the embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the apparatus or unit can be in an electrical, mechanical or other form.
[0084] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0085] In addition, the functional units in the embodiments provided in the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0086] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0087] Finally, it should be noted that the above embodiments are only specific implementation manners of this application, used to illustrate the technical solutions of this application, rather than limiting it. The protection scope of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by this application can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application. All should be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A business compliance assessment method, characterized in that: The method comprises the following steps: Configure a network communication private key between the application server and the cryptographic server, and after completing the private key configuration, perform an SSL offloading operation to obtain the data to be encrypted sent by the application server to the cryptographic server; Identify sensitive data and its type from the acquired data to be encrypted, and compare with a pre-established compliance library to determine whether it is compliant; wherein the compliance library stores various compliance standards for various types of sensitive data; If it is judged to be non-compliant, the corresponding message requesting the cryptographic server will be compared with the product message library, and the product type will be determined, and the product will be rectified; wherein the product message library stores various message examples of various types of products interacting with the cryptographic server.
2. A business compliance assessment method according to claim 1, characterized in that: The configuration of the network communication private key between the application server and the password server includes the following steps: Selecting a target encryption algorithm and generating a key pair using the target encryption algorithm; the key pair includes a private key and a corresponding public key; The generated private key is configured to the application server for SSL communication; and the generated public key is configured to the cryptographic server for SSL communication verification.
3. A business compliance assessment method according to claim 2, characterized in that: The SSL offloading operation is performed in the following manner, including the following steps: Deploy SSL offloading devices on the network path between the application server and the cryptographic server; Configuring an SSL offloading policy in the SSL offloading device; An SSL unloading operation is performed based on the SSL unloading policy configured by the SSL unloading device to intercept and decrypt the request initiated by the application server to the cryptographic server to obtain the data to be encrypted.
4. A business compliance assessment method according to claim 3, characterized in that: The step of identifying sensitive data and its type from the acquired data to be encrypted, and comparing it with a pre-established compliance library to determine whether it is compliant, includes the following steps: Performing feature analysis on the acquired data to be encrypted, and identifying different types of sensitive data according to various preset data features; wherein different types of sensitive data have different digital formats or encoding formats; For each type of sensitive data identified, it is compared one by one with the compliance standards in the pre-established compliance library. If there are any non-compliant standard items, it is judged as non-compliant.
5. A business compliance assessment method according to claim 4, characterized in that: in, Compliance standard items include one or more of the processing methods, storage status, and transmission conditions of sensitive data.
6. A business compliance assessment method according to claim 5, characterized in that: The step of comparing the corresponding message of requesting the password server with the product message library and determining the product type comprises the following steps: Obtaining a message from the application server to initiate a request to the cryptographic server; Extracting keywords and message structures from the message; wherein the keywords include one or more of product names, version numbers, and business process-related words, and the message structure includes the number of data fields and their arrangement order; Preliminarily screening out a message sample set containing all the extracted keywords from the product message library; The extracted message structure is matched with the structure of each message example in the message example set, and a consistent target message example is found, and the product category corresponding to the target message example is determined.
7. A business compliance assessment method according to claim 6, characterized in that: in, Product rectification includes reviewing the product's code logic, adjusting the way it interacts with the password server, or optimizing the sensitive data processing process involved in the product.
8. A business compliance assessment device, characterized in that: The device comprises: An unloading module is used to configure a network communication private key between the application server and the cryptographic server, and after completing the private key configuration, perform an SSL unloading operation to obtain the data to be encrypted sent by the application server to the cryptographic server; A judgment module, used to identify sensitive data and its type from the acquired data to be encrypted, and compare it with a pre-established compliance library to determine whether it is compliant; wherein the compliance library stores various compliance standards for various types of sensitive data; The determination module is used to compare the corresponding message requesting the cryptographic server with the product message library if it is judged to be non-compliant, and determine the product type and rectify the product; wherein the product message library stores various message examples of various types of products interacting with the cryptographic server.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the business compliance assessment method as described in any one of claims 1 to 7 are performed.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the business compliance assessment method according to any one of claims 1 to 7 are executed.