Encrypted storage method and device applied to distributed micro-service system
By using the encryption server to encrypt and store the encryption fields in the distributed microservice system, the problem of encryption key leakage in the distributed service terminal is solved, and data security and storage efficiency are improved.
Patent Information
- Application Number
- CN202510218135.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-06-24
AI Technical Summary
Distributed service terminals have security vulnerabilities in the encryption storage process, resulting in encryption key leakage and increasing the risk of data decryption leakage.
In the distributed microservice system, the data encryption request of the target microservice is obtained through the encryption server, the encryption field is encrypted based on the preset key, and the encrypted fields are stored in the preset storage space to avoid direct encryption on the microservice and reduce the risk of key leakage.
By storing the encryption fields on the encrypted server and isolating them from the micro-server, the resource usage and code volume of the micro-server are reduced, data security is improved, and the possibility of data leakage is reduced.
Smart Images

Figure CN120200779A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of distributed services. Specifically, it relates to an encryption storage method and device applied to a distributed microservice system. Background Art
[0002] In a network information environment, using distributed service technology to upload and store data has become one of the commonly used data storage methods.
[0003] In related technologies, in order to improve the storage security of data, a distributed service terminal usually encrypts the data using a pre-set encryption key and then stores the data, so as to achieve the purpose of improving the storage security of the data.
[0004] However, with the continuous upgrading of Internet technology, many security vulnerabilities have emerged in the distributed service terminal. If the encryption key in the distributed service terminal is leaked, the risk of the data uploaded by users being decrypted and leaked will be greatly increased. Therefore, how to improve the security of user data has become an urgent problem to be solved. Summary of the Invention
[0005] To solve the above technical problems, embodiments of this application provide an encryption storage method and device applied to a distributed microservice system.
[0006] According to one aspect of the embodiments of this application, there is provided an encryption storage method applied to a distributed microservice system. The distributed microservice system includes a plurality of microservice terminals and an encryption service terminal. The method is executed by the encryption service terminal, and the method includes: obtaining a data encryption request sent by a target microservice terminal; encrypting the to-be-encrypted field carried in the data encryption request based on a preset key, and storing the encrypted field obtained by encryption in a preset storage space; where the preset key and the preset storage space are the key and storage space allocated by the encryption service terminal for the target microservice terminal; returning a first notification message indicating successful encryption storage to the target microservice terminal, so that the target microservice terminal deletes the stored to-be-encrypted field based on the first notification message.
[0007] According to one aspect of the embodiments of the present application, there is provided an encrypted storage device applied to a distributed microservice system. The distributed microservice system includes multiple microservice servers and an encryption server. The device includes: a first receiving module configured to obtain a data encryption request sent by a target microservice server; an encrypted storage module configured to encrypt the fields to be encrypted carried in the data encryption request based on a preset key and store the encrypted fields obtained by encryption in a preset storage space, where the preset key and the preset storage space are the key and storage space allocated by the encryption server for the target microservice server; a first sending module configured to return a first notification message indicating successful encrypted storage to the target microservice server, so that the target microservice server deletes and stores the fields to be encrypted based on the first notification message.
[0008] In some embodiments of the present application, based on the foregoing solution, the encrypted storage device applied to the distributed microservice system further includes: a second receiving module configured to obtain an encryption permission application request sent by the target microservice server before obtaining the data encryption request sent by the target microservice server; a permission allocation module configured to allocate a corresponding preset key and a preset storage space to the target microservice server based on the encryption permission application request; a second sending module configured to, if the allocation is completed, return a second notification message indicating successful application to the target microservice server, so that the target microservice server sends a data encryption request for encrypting the fields to be encrypted to the encryption server based on the second notification message.
[0009] In some embodiments of the present application, based on the foregoing solution, the encrypted storage device applied to the distributed microservice system further includes: a third receiving module configured to obtain a data retrieval request sent by the target microservice server after storing the encrypted fields obtained by encryption in the preset storage space; an encrypted retrieval module configured to encrypt the retrieval fields carried in the data retrieval request based on the preset key to obtain encrypted retrieval fields; a decryption module configured to determine target encrypted fields associated with the encrypted retrieval fields in the preset storage space and decrypt the target encrypted fields through the preset key to obtain the target field plaintext; a third sending module configured to send the target field plaintext to the target microservice server, so that the target microservice server displays the target field plaintext.
[0010] In some embodiments of the present application, based on the foregoing solution, the encrypted retrieval module is further configured to perform word segmentation processing on the retrieval fields to obtain a retrieval word sequence; and encrypt the retrieval word sequence using the preset key to obtain the encrypted retrieval fields.
[0011] In some embodiments of the present application, based on the foregoing solution, when the encrypted field includes the field ciphertext and the encryption index, and the first notification message includes the encryption index, the third sending module is further configured to, before sending the target field plaintext to the target microservice, obtain the target encryption index corresponding to the target field plaintext; send the target encryption index and the target field plaintext to the target microservice, so that after the target microservice determines that the target encryption index is the same as the encryption index in any historical first notification message, the target microservice displays the target field plaintext, where the historical first notification message represents the first notification message received by the target microservice before sending the data retrieval request.
[0012] In some embodiments of the present application, based on the foregoing solution, the encryption storage module is further configured to obtain the encryption method of the field to be encrypted; if the encryption method is the first encryption method, encrypt the field plaintext and the index field in the field to be encrypted respectively based on the preset key to obtain the field ciphertext and the encryption index; if the encryption method is the second encryption method, perform word segmentation processing on the field plaintext in the field to be encrypted to obtain an index word sequence, and encrypt the field plaintext and the index word sequence respectively based on the preset key to obtain the field ciphertext and the encryption index.
[0013] In some embodiments of the present application, based on the foregoing solution, the encryption storage module is further configured to determine that the first encryption method is the encryption method of the field to be encrypted if the field to be encrypted does not support fuzzy query; determine that the second encryption method is the encryption method of the field to be encrypted if the field to be encrypted supports fuzzy query.
[0014] According to one aspect of the embodiments of the present application, there is provided a computer-readable storage medium, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor of a computer, the computer is caused to execute the encryption storage method applied to a distributed microservice system as described in the foregoing embodiments.
[0015] According to one aspect of the embodiments of the present application, there is provided an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the electronic device is caused to implement the encryption storage method applied to a distributed microservice system as described in the foregoing embodiments.
[0016] In the technical solution of the embodiment of the present application, first obtain a data encryption request sent by the target microservice, then encrypt the fields to be encrypted carried in the data encryption request based on a preset key, and store the encrypted fields obtained by encryption in a preset storage space, so as to prevent the target microservice used by the user from directly encrypting the fields to be encrypted, reduce the risk of key leakage of the target microservice, and enable the target microservice to not participate in the encrypted storage of the fields to be encrypted, reduce the code amount and resource occupancy of the target microservice, thereby reducing the configuration cost of the target microservice, and also isolate the encrypted fields from the target microservice, improve the security of the data stored by the user, and then return a first notification message indicating successful encrypted storage to the target microservice, so that the target microservice deletes the stored fields to be encrypted based on the first notification message, further reducing the possibility of the target microservice leaking the data stored by the user, thereby improving the security of the data stored by the user. Description of the Drawings
[0017] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. In the drawings:
[0018] Figure 1 is a schematic diagram of the architecture of a distributed microservice system shown in an exemplary embodiment of the present application;
[0019] Figure 2 is a flowchart of an encrypted storage method applied to a distributed microservice system shown in an exemplary embodiment of the present application;
[0020] Figure 3 is Figure 2 a flowchart in an exemplary embodiment before step S210 in the shown embodiment;
[0021] Figure 4 is a flowchart of an encrypted storage method applied to a distributed microservice system shown in another exemplary embodiment of the present application;
[0022] Figure 5 is Figure 4 a flowchart in an exemplary embodiment of step S440 in the shown embodiment;
[0023] Figure 6 is Figure 2 a flowchart in an exemplary embodiment of step S220 in the shown embodiment;
[0024] Figure 7It is a flowchart of an encryption storage method applied to a distributed microservices system shown in another exemplary embodiment of the present application;
[0025] Figure 8 It is a flowchart of an encryption storage method applied to a distributed microservices system shown in another exemplary embodiment of the present application;
[0026] Figure 9 It is a block diagram of an encryption storage device applied to a distributed microservices system shown in an exemplary embodiment of the present application;
[0027] Figure 10 It is a schematic structural diagram of an electronic device shown in an exemplary embodiment of the present application. Detailed implementation manners
[0028] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0029] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be used. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.
[0030] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0031] The flowcharts shown in the drawings are only exemplary illustrations and do not necessarily include all the content and operations / steps, nor do they necessarily have to be executed in the described order. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0032] It should be noted that: "multiple" mentioned in this article refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the front and back associated objects.
[0033] First of all, it should be noted that the embodiments of this application relate to distributed service technology. Distributed service technology is to provide different services distributedly according to different application environments and business requirements in a network information environment. Each service is responsible for completing a specific function, and each service is allowed to be independently extended and upgraded to adapt to different application environments and business requirements. Simply put, distributed service technology is a form of service operation distributed at different locations, and each service is equivalent to an independent service terminal.
[0034] In the related art, when a user uploads and stores data using distributed service technology, in order to improve the storage security of the data, the distributed service terminal usually encrypts the data using a pre-set encryption key and then stores the data. However, with the continuous upgrade of Internet technology, many security vulnerabilities have occurred in the distributed service terminal. If the encryption key in the distributed service terminal is leaked, the risk of the user's uploaded data being decrypted and leaked will be greatly increased. Therefore, how to improve the security of user data has become an urgent problem to be solved.
[0035] To solve the problems existing in the prior art, the technical solution of this application provides an encryption storage solution applied to a distributed microservice system. Please refer to Figure 1 , Figure 1 is a schematic diagram of the architecture of an exemplary distributed microservice system. As Figure 1 shown, the distributed microservice system 100 includes multiple microservice terminals 110 and an encryption service terminal 120. Each part will be introduced one by one below.
[0036] The microservice terminal 110 is used to provide services to users. Different microservice terminals can provide corresponding services according to different application environments and business requirements, and each microservice terminal can be independently extended and upgraded to improve the service ability of the microservice terminal.
[0037] The encryption server 120 is communicatively connected to multiple microservice servers and is used to enhance the security of user data uploaded to the microservice servers. Specifically, by implementing the technical solution of the embodiment of the present application, when the encryption server obtains a data encryption request sent by a microservice server, it encrypts the fields to be encrypted carried in the data encryption request based on the key allocated for the microservice server, and stores the encrypted fields obtained by encryption in the storage space allocated for the microservice server, thereby preventing the microservice server from directly encrypting the user-uploaded data, and at the same time isolating the stored encrypted data from the microservice server, thus greatly improving the security of user data.
[0038] It should be understood that Figure 1 is only a schematic diagram of the architecture of an exemplary distributed microservice system and does not represent a limitation on the architecture of the distributed microservice system. In an actual application scenario, the distributed microservice system may include components different from the Figure 1 architecture shown, such as including more or fewer components than the Figure 1 architecture shown, which is not limited herein.
[0039] The following elaborates in detail on various implementation details of the technical solution of the embodiment of the present application:
[0040] Please refer to Figure 2 shown in Figure 2 is a flowchart of an encryption storage method applied to a distributed microservice system proposed by the technical solution of the embodiment of the present application. This method can be executed by the encryption server. This method includes at least steps S210 to S230, which are introduced in detail as follows:
[0041] In step S210, a data encryption request sent by the target microservice server is obtained.
[0042] In the implementation manner of the present application, if each microservice server in the distributed microservice system needs to encrypt and store the user-uploaded data, it needs to send a data encryption request to the encryption server so that after the encryption server obtains the data encryption request sent by the microservice server, it provides encryption storage services for the microservice server. Among them, the target microservice server represents the microservice server in the distributed microservice system that requests encryption storage services.
[0043] In step S220, the fields to be encrypted carried in the data encryption request are encrypted based on a preset key, and the encrypted fields obtained by encryption are stored in a preset storage space.
[0044] Among them, the preset key and the preset storage space are the key and storage space allocated by the encryption server for the target microservice server.
[0045] In an embodiment of the present application, after obtaining a data encryption request sent by a target microservice, the to-be-encrypted field carried in the data encryption request can be encrypted based on a preset key, and the encrypted field obtained by encryption is stored in a preset storage space, so that the target microservice does not need to participate in the encrypted storage of the to-be-encrypted field. On the one hand, the code amount and resource occupancy of the target microservice can be reduced. On the other hand, the to-be-encrypted field can be isolated from the target microservice, thereby reducing the risk of user data leakage from the target microservice and further improving the security of user data.
[0046] For example, in a distributed microservice system, there are a first microservice and a second microservice. The key and storage space allocated to the first microservice in the encryption server are the first key and the first storage disk respectively, and the key and storage space allocated to the second microservice are the second key and the second storage disk respectively. When the encryption server obtains a data encryption request sent by the second microservice, the second microservice is the target microservice. Correspondingly, the process of encrypting the to-be-encrypted field carried in the data encryption request based on a preset key and storing the encrypted field obtained by encryption in a preset storage space is to encrypt the to-be-encrypted field carried in the data encryption request based on the second key and store the encrypted field obtained by encryption in the second storage disk, so as to achieve the purpose of encrypting and storing the data uploaded by the user through the microservice in the distributed microservice system.
[0047] In step S230, a first notification message indicating successful encrypted storage is returned to the target microservice, so that the target microservice deletes the stored to-be-encrypted field based on the first notification message.
[0048] In an embodiment of the present application, after encrypting the to-be-encrypted field carried in the data encryption request based on a preset key and storing the encrypted field obtained by encryption in a preset storage space, it indicates that the encryption server has completed the encrypted storage of the to-be-encrypted field uploaded by the target microservice. A first notification message indicating successful encrypted storage can be returned to the target microservice, so that the target microservice deletes the stored to-be-encrypted field based on the first notification message, thereby reducing the possibility of the target microservice leaking the data stored by the user, improving the security of the data, and at the same time further reducing the resource occupancy of the target microservice, and further reducing the configuration cost of the microservice.
[0049] In addition, the target microservice can also feedback information indicating that the encrypted storage of the to-be-encrypted field carried in the data encryption request is completed to the user based on the first notification message, so that the user knows that the to-be-encrypted field has completed encrypted storage.
[0050] Through the above implementation, first obtain the data encryption request sent by the target microservice, then encrypt the fields to be encrypted carried in the data encryption request based on a preset key, and store the encrypted fields obtained by encryption in a preset storage space, so as to prevent the target microservice used by the user from directly encrypting the fields to be encrypted, reduce the risk of leakage of the target microservice key, and enable the target microservice not to participate in the encrypted storage of the fields to be encrypted, reduce the code volume and resource occupancy of the target microservice, thereby reducing the configuration cost of the target microservice, and also isolating the encrypted fields from the target microservice, improving the security of the data stored by the user. Then, return a first notification message indicating successful encrypted storage to the target microservice, so that the target microservice deletes the stored fields to be encrypted based on the first notification message, further reducing the possibility of the target microservice leaking the data stored by the user, thereby improving the security of the data.
[0051] See Figure 3 , Figure 3 is a flowchart of an encrypted storage method applied to a distributed microservice system shown according to another exemplary embodiment. As Figure 3 shown, before step S210 in the Figure 2 embodiment shown, the method may further include steps S310 to S330, which are introduced in detail as follows:
[0052] In step S310, obtain an encryption permission application request sent by the target microservice.
[0053] It should be noted that if each microservice in the distributed microservice system needs to encrypt and store the data uploaded by the user through the encryption server, it needs to first apply for encryption permission in the encryption server. Therefore, in the implementation of this application, the target microservice can send an encryption permission application request to the encryption server, and the encryption server will receive the encryption permission application request sent by the target microservice to identify the target microservice, so as to provide encrypted storage services for the target microservice safely.
[0054] In step S320, allocate corresponding preset keys and preset storage spaces to the target microservice based on the encryption permission application request.
[0055] In the implementation of this application, after obtaining the encryption permission application request sent by the target microservice, corresponding preset keys and preset storage spaces can be allocated to the target microservice based on the encryption permission application request, so as to encrypt and store the fields to be encrypted after the target microservice uploads the fields to be encrypted to the encryption server.
[0056] Among them, the manner of allocating corresponding preset keys and preset storage spaces to the target microservice based on the encryption permission application request can be flexibly set according to needs. In one example, the key and storage space can be directly allocated to the target microservice in response to the encryption permission application request, and the key and storage space are used as the corresponding preset key and preset storage space of the target microservice.
[0057] In another example, the information of the target microservice carried in the encryption permission application request can be authenticated. If the authentication is passed, the corresponding preset key and preset storage space are allocated to the target microservice, so as to ensure that the target microservice meets the requirements for calling the encryption server to encrypt and store the fields to be encrypted.
[0058] Among them, the information of the target microservice includes but is not limited to network address, version model, hardware information, etc.
[0059] In step S330, if the allocation is completed, a second notification message indicating successful application is returned to the target microservice, so that the target microservice sends a data encryption request for encrypting the fields to be encrypted to the encryption server based on the second notification message.
[0060] In the implementation manner of this application, during the process of the encryption server allocating the corresponding preset key and preset storage space to the target microservice, if the allocation is completed, it indicates that the target microservice can call the encryption server in the subsequent process to complete the encryption and storage of the fields to be encrypted, and then a second notification message indicating successful application can be returned to the target microservice, so that the target microservice sends a data encryption request for encrypting the fields to be encrypted to the encryption server based on the second notification message, thereby ensuring that the target microservice can send a data encryption request to encrypt and store the fields to be encrypted on the premise of calling the encryption server for encryption storage.
[0061] See Figure 4 , Figure 4 is a flowchart of an encryption storage method applied to a distributed microservice system shown according to another exemplary embodiment. As Figure 4 shown, after step S220 in the embodiment shown in Figure 2 , the method may further include steps S410 to S440, which are introduced in detail as follows:
[0062] In step S410, a data retrieval request sent by the target microservice is obtained.
[0063] In an embodiment of the present application, when each microservice end in a distributed microservice system needs to call data that was previously encrypted and stored in an encryption server for display, it needs to send a data retrieval request to the encryption server. After the encryption server receives the data retrieval request sent by the microservice end, it sends the required data to the microservice end, facilitating the microservice end for display.
[0064] In step S420, encrypt the retrieval fields carried in the data retrieval request based on a preset key to obtain encrypted retrieval fields.
[0065] In an embodiment of the present application, after receiving the data retrieval request sent by the target microservice end, the retrieval fields carried in the data retrieval request can be encrypted based on a preset key to obtain encrypted retrieval fields, so that the retrieval fields are converted to the encryption environment of the encrypted fields, facilitating the acquisition of encrypted fields that meet the data retrieval request.
[0066] Among them, the method of encrypting the retrieval fields carried in the data retrieval request based on a preset key can be flexibly set according to needs. In one example, the retrieval fields carried in the data retrieval request can be directly encrypted using the preset key corresponding to the target microservice end to obtain encrypted retrieval fields.
[0067] In another example, the retrieval fields can be segmented first to obtain a sequence of retrieval words, and then the sequence of retrieval words can be encrypted using a preset key to obtain encrypted retrieval fields, thereby expanding the retrieval ability of the encrypted retrieval fields under the influence of the sequence of retrieval words.
[0068] In step S430, determine the target encrypted fields associated with the encrypted retrieval fields in the preset storage space, and decrypt the target encrypted fields using the preset key to obtain the plaintext of the target fields.
[0069] Among them, the plaintext of the fields is the fields to be encrypted that have not been encrypted with a key.
[0070] In an embodiment of the present application, after obtaining the encrypted retrieval fields, the target encrypted fields associated with the encrypted retrieval fields in the preset storage space can be determined to ensure that the data retrieved by the encrypted retrieval fields are all the data uploaded by the target microservice end, and then the target encrypted fields are decrypted using the preset key to obtain the plaintext of the target fields.
[0071] The method of determining the target encrypted fields associated with the encrypted retrieval fields in the preset storage space can be flexibly set according to needs. In one example, the encrypted field with the highest similarity to the encrypted retrieval field in the preset storage space can be determined, and the determined encrypted field can be used as the target encrypted field associated with the encrypted retrieval field.
[0072] In another example, the similarity between each encrypted field and the encrypted search field in the preset storage space can be determined first to identify the encrypted fields with a similarity higher than the preset similarity threshold, and then the identified encrypted fields can be used as the target encrypted fields associated with the encrypted search field, thereby expanding the search scope on the premise that the target encrypted fields are related to the encrypted search field.
[0073] In step S440, the plaintext of the target field is sent to the target microservice server so that the target microservice server can display the plaintext of the target field.
[0074] In the implementation manner of the present application, after obtaining the plaintext of the target field through the preset key and the target encrypted field, the plaintext of the target field can be sent to the target microservice server so that the target microservice server can display the plaintext of the target field, thereby achieving the purpose that the target microservice server can call the data encrypted and stored in the encryption server before for display.
[0075] Through the above implementation manner, first obtain the data retrieval request sent by the target microservice server, then encrypt the search field carried in the data retrieval request based on the preset key to obtain the encrypted search field, so as to facilitate retrieving the encrypted field based on the data retrieval request in the encrypted environment, then determine the target encrypted field associated with the encrypted search field in the preset storage space, and decrypt the target encrypted field through the preset key to obtain the plaintext of the target field, and then send the plaintext of the target field to the target microservice server, so that the target microservice server can display the plaintext of the target field, and further achieve the purpose that the target microservice server can call the data encrypted and stored in the encryption server before for display.
[0076] Based on the technical solution of the foregoing embodiment, in an embodiment of the present application, on the premise that the encrypted field includes the field ciphertext and the encryption index, and the first notification message includes the encryption index Figure 4 Before step S440 in the illustrated embodiment, that is, before sending the plaintext of the target field to the target microservice server, steps S510 to S520 may further be included, so as to improve the security when the microservice server calls the data encrypted and stored in the encryption server before for display, specifically refer to Figure 5 as shown.
[0077] In step S510, obtain the target encryption index corresponding to the plaintext of the target field.
[0078] It should be noted that the encryption index is obtained after the encryption server encrypts the index field in the field to be encrypted using the key.
[0079] The manner of obtaining the target encryption index corresponding to the plaintext of the target field can be flexibly set according to needs. In one example, the target encryption index can be directly obtained from the target encrypted field corresponding to the plaintext of the target field.
[0080] In another example, an encryption index associated with the target field ciphertext of the target encryption field can be obtained from a preset storage space, and the obtained encryption index can be used as the target encryption index corresponding to the target field plaintext. That is to say, during the process of storing the encryption field, the encryption server can separately store the field ciphertext and the encryption index included in the encryption field in an associated manner, so as to facilitate separately decrypting and restoring the field ciphertext with a key, thereby reducing the decryption time of the field ciphertext in the encryption field.
[0081] In step S520, the target encryption index and the target field plaintext are sent to the target microservice server, so that after the target microservice server determines that the target encryption index is the same as the encryption index in any historical first notification message, the target field plaintext is displayed.
[0082] In an embodiment of the present application, after obtaining the target encryption index, the target encryption index and the target field plaintext can be sent to the target microservice server, so that after the target microservice server determines that the target encryption index is the same as the encryption index in any historical first notification message, the target field plaintext is displayed, where the historical first notification message represents the first notification message received by the target microservice server before sending the data retrieval request, so as to display the target field plaintext on the premise of ensuring that the target microservice server has uploaded the target field plaintext, and further achieve the purpose of improving the security when the microservice server displays the data encrypted and stored in the encryption server before calling.
[0083] For example, after the target microservice server sends a data encryption request carrying the first field to be encrypted to the encryption server, the encryption server can use a preset key to encrypt the first field to be encrypted to obtain the field ciphertext and the encryption index in the encryption field, then store the encryption field in the preset storage space, and at the same time return a target first notification message including the encryption index of the first field to be encrypted to the target microservice server.
[0084] After the target microservice server sends a data retrieval request for obtaining the first field to be encrypted to the encryption server, the encryption server can obtain the corresponding target field plaintext based on the data retrieval request, then obtain the target encryption index corresponding to the target field plaintext, and at the same time send the target field plaintext and the target encryption index to the target microservice server. Since the target microservice server uploaded the first field to be encrypted to the encryption server before, that is, the target microservice server has received the target first notification message, so that in the process of determining whether the target encryption index is the same as the encryption index in any historical first notification message, the target microservice server can determine that the target encryption index is the same as the encryption index of the target first notification message in the historical first notification message, and then display the target field plaintext.
[0085] However, when the target microservice sends a data retrieval request for obtaining the second field to be encrypted to the encryption server, or the plaintext of the target field obtained by the encryption server based on the data retrieval request is not decrypted from the encrypted field corresponding to the first field to be encrypted, the target microservice cannot determine that the target encryption index is the same as the encryption index in any historical first notification message. In order to ensure that the encrypted data is not easily leaked, the target microservice may not display the obtained plaintext of the target field, thereby improving the security when the microservice displays encrypted data.
[0086] Based on the technical solution of the foregoing embodiment, in an embodiment of the present application, in order to obtain the field ciphertext and the encryption index included in the encrypted field, Figure 2 In step S220 of the embodiment shown, the process of encrypting the field to be encrypted carried in the data encryption request based on the preset key may further include steps S610 to S630, specifically as follows Figure 6 shown.
[0087] Step S610, obtain the encryption method of the field to be encrypted;
[0088] Step S620, if the encryption method is the first encryption method, encrypt the field plaintext and the index field in the field to be encrypted based on the preset key respectively to obtain the field ciphertext and the encryption index;
[0089] Step S630, if the encryption method is the second encryption method, perform word segmentation processing on the field plaintext in the field to be encrypted to obtain an index word sequence, and encrypt the field plaintext and the index word sequence based on the preset key respectively to obtain the field ciphertext and the encryption index.
[0090] In the implementation manner of the present application, the process of obtaining the encryption method of the field to be encrypted can be flexibly set according to needs. In one example, the encryption method of the field to be encrypted can be directly obtained from the data encryption request corresponding to the field to be encrypted. That is to say, when generating the data encryption request, the target microservice can add the encryption method of the field to be encrypted to the data encryption request, so that the encryption server can obtain the encryption method of the field to be encrypted through the data encryption request.
[0091] For example, the target microservice side can add identification characters before the position of the field to be encrypted in the data encryption request to characterize the encryption method of the field to be encrypted. Specifically, if the encryption requirement of the target microservice side for the character to be encrypted is the first encryption method, the target microservice side can adjust the identification characters in the data encryption request to 00, so that after the encryption server obtains the data encryption request, based on the 00 shown by the identification characters, it can determine that the encryption method of the field to be encrypted corresponding to the data encryption request is the first encryption method; correspondingly, if the encryption requirement of the target microservice side for the character to be encrypted is the second encryption method, the target microservice side can adjust the identification characters in the data encryption request to 11, so that after the encryption server obtains the data encryption request, based on the 11 shown by the identification characters, it can determine that the encryption method of the field to be encrypted corresponding to the data encryption request is the second encryption method.
[0092] In another example, the encryption method of the field to be encrypted can be determined by judging whether the field to be encrypted supports fuzzy query, that is, if the field to be encrypted does not support fuzzy query, it means that the encryption level of the field to be encrypted is relatively high or the field to be encrypted is not suitable for improving the retrieval convenience by means of word segmentation, and the first encryption method can be determined as the encryption method of the field to be encrypted, so as to directly encrypt the field plaintext and the index field in the field to be encrypted based on the preset key, thereby obtaining the field ciphertext and the encrypted index.
[0093] If the field to be encrypted supports fuzzy query, it means that the field to be encrypted is suitable for improving the retrieval convenience by means of word segmentation and the encryption level is relatively low, and the second encryption method can be determined as the encryption method of the encrypted field, so as to perform word segmentation processing on the field plaintext in the field to be encrypted to obtain an index word sequence, and encrypt the field plaintext and the index word sequence respectively based on the preset key to obtain the field ciphertext and the encrypted index, so as to further improve the content matching degree corresponding to the encrypted index of the field to be encrypted, and further achieve the purpose of improving the retrieval convenience.
[0094] See Figure 7 as shown. Figure 7 is a flowchart of an encryption storage method applied to a distributed microservice system shown in an embodiment of the present application. As Figure 7 shown, the method at least includes steps S710 to S760, which are introduced in detail as follows:
[0095] Step S710, obtain a data encryption request sent by the target microservice side.
[0096] Step S720, obtain the encryption method of the field to be encrypted carried in the data encryption request.
[0097] Among them, the process of obtaining the encryption method of the fields to be encrypted carried in the data encryption request can be determined by identifying the identification characters carried in the data encryption request or by determining whether the fields to be encrypted support fuzzy query. The specific implementation process can refer to the above embodiments and will not be elaborated here.
[0098] Step S730, if the encryption method is the first encryption method, encrypt the field plaintext and the index field in the field to be encrypted respectively based on a preset key to obtain the field ciphertext and the encrypted index included in the encrypted field.
[0099] Among them, the preset key is the key allocated by the encryption server based on the encryption permission application request sent by the target microservice.
[0100] Step S740, if the encryption method is the second encryption method, perform word segmentation processing on the field plaintext in the field to be encrypted to obtain an index word sequence, and encrypt the field plaintext and the index word sequence respectively based on a preset key to obtain the field ciphertext and the encrypted index included in the encrypted field.
[0101] Step S750, store the encrypted field obtained by encryption in a preset storage space.
[0102] Among them, the preset storage space is the storage space allocated by the encryption server based on the encryption permission application request sent by the target microservice.
[0103] Step S760, return a first notification message including the encrypted index to the target microservice, so that the target microservice deletes the stored fields to be encrypted based on the first notification message.
[0104] Through the above implementation, first obtain the data encryption request sent by the target microservice, and then obtain the encryption method of the fields to be encrypted carried by the data encryption request, so as to improve the retrieval convenience of the fields to be encrypted on the premise of ensuring the security of the fields to be encrypted. That is, when the encryption method is the first encryption method, it indicates that the required encryption level of the fields to be encrypted is relatively high, and then encrypt the field plaintext and index fields in the fields to be encrypted respectively based on the preset key to obtain the field ciphertext and encrypted index included in the encrypted field; while when the encryption method is the second encryption method, it indicates that the required encryption level of the fields to be encrypted is relatively low and it is suitable to improve the retrieval convenience by means of word segmentation. Then, the field plaintext in the fields to be encrypted can be segmented to obtain an index word sequence, and the field plaintext and the index word sequence are encrypted respectively based on the preset key to obtain the field ciphertext and encrypted index included in the encrypted field. After that, the encrypted fields obtained by encryption are stored in the preset storage space, so as to avoid the target microservice directly encrypting the fields to be encrypted used by the user, thereby reducing the risk of leakage of the target microservice key, and enabling the target microservice not to participate in the encrypted storage of the fields to be encrypted, reducing the code volume and resource occupancy of the target microservice, and also isolating the encrypted fields from the target microservice, improving the security of the data stored by the user. Then, a first notification message is returned to the target microservice, so that the target microservice deletes the stored fields to be encrypted based on the first notification message, further reducing the possibility of the target microservice leaking the data stored by the user and improving the security of the data stored by the user.
[0105] See Figure 8 as shown. Figure 8 is a flowchart of an encryption storage method applied to a distributed microservice system shown in another embodiment of the present application. As Figure 8 shown, the method at least includes steps S810 to S860, which are introduced in detail as follows:
[0106] Step S810, obtain a data retrieval request sent by the target microservice.
[0107] Among them, the data retrieval request indicates that the target microservice needs to retrieve and display the previously encrypted and stored data from the encryption server.
[0108] Step S820, segment the retrieval fields carried by the data retrieval request to obtain a retrieval word sequence.
[0109] Among them, the retrieval fields indicate the relevant information of the data that the target microservice needs to display. For example, information such as keywords, dates, uploaders, directories, etc.
[0110] Step S830, encrypt the retrieval word sequence using the preset key to obtain an encrypted retrieval field.
[0111] Step S840, determine a target encrypted field associated with the encrypted retrieval field in the preset storage space, and decrypt the target encrypted field with a preset key to obtain the plaintext of the target field.
[0112] Step S850, obtain a target encrypted index corresponding to the plaintext of the target field.
[0113] Step S860, send the target encrypted index and the plaintext of the target field to the target microservice end, so that after the target microservice end determines that the target encrypted index is the same as the encrypted index in any historical first notification message, it displays the plaintext of the target field.
[0114] Through the above implementation manner, first obtain a data retrieval request sent by the target microservice end, then perform word segmentation processing on the retrieval field carried in the data retrieval request to obtain a retrieval word sequence, so as to expand the retrieval range of the retrieval field based on the retrieval word sequence obtained from the retrieval field. After that, use a preset key to encrypt the retrieval word sequence to obtain an encrypted retrieval field, which is convenient for retrieving the encrypted field based on the data retrieval request in an encrypted environment. Then determine a target encrypted field associated with the encrypted retrieval field in the preset storage space, and decrypt the target encrypted field with a preset key to obtain the plaintext of the target field. Finally, obtain a target encrypted index corresponding to the plaintext of the target field, and send the target encrypted index and the plaintext of the target field to the target microservice end, so that after the target microservice end determines that the target encrypted index is the same as the encrypted index in any historical first notification message, it displays the plaintext of the target field, thereby displaying the plaintext of the target field on the premise of ensuring that the target microservice end has uploaded the plaintext of the target field, and further improving the security when the microservice end displays the data encrypted and stored in the encryption server before calling.
[0115] The following introduces the device embodiments of the present application, which can be used to execute the encrypted storage method applied to the distributed microservice system in the above embodiments of the present application. For the details not disclosed in the device embodiments of the present application, please refer to the embodiments of the encrypted storage method applied to the distributed microservice system in the above of the present application.
[0116] Figure 9 The block diagram of an encrypted storage device 900 applied to a distributed microservice system according to an embodiment of the present application is shown.
[0117] Refer to Figure 9As shown, an encryption storage device 900 applied to a distributed microservice system according to an embodiment of the present application, the distributed microservice system includes a plurality of microservice servers and an encryption server, and the device includes: a first receiving module 910 configured to obtain a data encryption request sent by a target microservice server; an encryption storage module 920 configured to encrypt a field to be encrypted carried in the data encryption request based on a preset key, and store the encrypted field obtained by encryption into a preset storage space; wherein, the preset key and the preset storage space are the key and storage space allocated by the encryption server for the target microservice server; a first sending module 930 configured to return a first notification message indicating successful encryption storage to the target microservice server, so that the target microservice server deletes the stored field to be encrypted based on the first notification message.
[0118] In some embodiments of the present application, based on the foregoing solution, an encryption storage device 100 applied to a distributed microservice system further includes: a second receiving module configured to obtain an encryption permission application request sent by the target microservice server before obtaining the data encryption request sent by the target microservice server; a permission allocation module configured to allocate a corresponding preset key and preset storage space to the target microservice server based on the encryption permission application request; a second sending module configured to, if the allocation is completed, return a second notification message indicating successful application to the target microservice server, so that the target microservice server sends a data encryption request for encrypting the field to be encrypted to the encryption server based on the second notification message.
[0119] In some embodiments of the present application, based on the foregoing solution, an encryption storage device 100 applied to a distributed microservice system further includes: a third receiving module configured to obtain a data retrieval request sent by the target microservice server after storing the encrypted field obtained by encryption into the preset storage space; an encryption retrieval module configured to encrypt a retrieval field carried in the data retrieval request based on the preset key to obtain an encrypted retrieval field; a decryption module configured to determine a target encrypted field associated with the encrypted retrieval field in the preset storage space, and decrypt the target encrypted field through the preset key to obtain a target field plaintext; a third sending module configured to send the target field plaintext to the target microservice server, so that the target microservice server displays the target field plaintext.
[0120] In some embodiments of the present application, based on the foregoing solution, the encryption retrieval module is further configured to perform word segmentation processing on the retrieval field to obtain a retrieval word sequence; encrypt the retrieval word sequence with the preset key to obtain an encrypted retrieval field.
[0121] In some embodiments of the present application, based on the foregoing solution, when the encrypted field includes the field ciphertext and the encryption index, and the first notification message includes the encryption index, the third sending module is further configured to obtain the target encryption index corresponding to the target field plaintext before sending the target field plaintext to the target microservice; send the target encryption index and the target field plaintext to the target microservice, so that the target microservice displays the target field plaintext after determining that the target encryption index is the same as the encryption index in any historical first notification message, where the historical first notification message represents the first notification message received by the target microservice before sending the data retrieval request.
[0122] In some embodiments of the present application, based on the foregoing solution, the encryption storage module 920 is further configured to obtain the encryption method of the field to be encrypted; if the encryption method is the first encryption method, encrypt the field plaintext and the index field in the field to be encrypted respectively based on the preset key to obtain the field ciphertext and the encryption index; if the encryption method is the second encryption method, perform word segmentation processing on the field plaintext in the field to be encrypted to obtain an index word sequence, and encrypt the field plaintext and the index word sequence respectively based on the preset key to obtain the field ciphertext and the encryption index.
[0123] In some embodiments of the present application, based on the foregoing solution, the encryption storage module 920 is further configured to determine the first encryption method as the encryption method of the field to be encrypted if the field to be encrypted does not support fuzzy query; determine the second encryption method as the encryption method of the field to be encrypted if the field to be encrypted supports fuzzy query.
[0124] It should be noted that the encryption storage device 900 applied to the distributed microservice system provided in the above embodiments and the encryption storage method applied to the distributed microservice system provided in the above embodiments belong to the same concept. The specific manners in which each module and unit perform operations have been described in detail in the method embodiments and will not be elaborated here.
[0125] An embodiment of the present application further provides an electronic device, including a processor and a memory, where a computer-readable instruction is stored on the memory, and when the computer-readable instruction is executed by the processor, the encryption storage method applied to the distributed microservice system as described above is implemented.
[0126] Figure 10 The structural schematic diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.
[0127] It should be noted that Figure 10 The computer system 1000 of the electronic device shown is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.
[0128] AsFigure 10 As shown in Figure 10 , the computer system 1000 includes a Central Processing Unit (CPU) 1001, which can perform various appropriate actions and processes according to the program stored in the Read-Only Memory (ROM) 1002 or the program loaded from the storage section 1008 into the Random Access Memory (RAM) 1003, such as executing the methods described in the above embodiments. In the RAM 1003, various programs and data required for system operation are also stored. The CPU 1001, ROM 1002, and RAM 1003 are connected to each other via a bus 1004. An Input / Output (I / O) interface 1005 is also connected to the bus 1004.
[0129] The following components are connected to the I / O interface 1005: an input section 1006 including a keyboard, a mouse, etc.; an output section 1007 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as needed so that a computer program read from it can be installed into the storage section 1008 as needed.
[0130] Specifically, according to the embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments of the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 1009, and / or installed from the removable medium 1011. When the computer program is executed by the Central Processing Unit (CPU) 1001, various functions defined in the system of the present application are executed.
[0131] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0132] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0133] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.
[0134] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the methods described in the above embodiments.
[0135] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0136] From the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of the present application.
[0137] After considering the specification and practicing the embodiments disclosed herein, those skilled in the art will readily conceive of other implementations of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application.
[0138] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. An encrypted storage method applied to a distributed microservice system, characterized in that: The distributed microservice system includes multiple microservice terminals and an encryption service terminal. The method is executed by the encryption service terminal, and the method includes: Get the data encryption request sent by the target microservice; Encrypting the to-be-encrypted field carried by the data encryption request based on a preset key, and storing the encrypted field obtained by encryption in a preset storage space; wherein the preset key and the preset storage space are the key and storage space allocated by the encryption server to the target microservice end; A first notification message indicating successful encrypted storage is returned to the target microservice end, so that the target microservice end deletes the stored field to be encrypted based on the first notification message.
2. The method according to claim 1, characterized in that Before obtaining the data encryption request sent by the target microservice end, the method further includes: Obtaining the encrypted permission application request sent by the target microservice end; Allocate a corresponding preset key and preset storage space to the target microservice end based on the encryption permission application request; If the allocation is completed, a second notification message indicating that the application is successful is returned to the target microservice end, so that the target microservice end sends a data encryption request for encrypting the field to be encrypted to the encryption service end based on the second notification message.
3. The method according to claim 1, characterized in that: After storing the encrypted field in the preset storage space, the method further includes: Obtaining a data retrieval request sent by the target microservice end; Encrypting the search field carried in the data search request based on the preset key to obtain an encrypted search field; Determine a target encrypted field associated with the encrypted search field in the preset storage space, and decrypt the target encrypted field using the preset key to obtain a target field plaintext; The target field plaintext is sent to the target microservice end, so that the target microservice end displays the target field plaintext.
4. The method according to claim 3, characterized in that The step of encrypting the search field carried by the data search request based on the preset key to obtain the encrypted search field includes: Performing word segmentation processing on the search field to obtain a search word sequence; The search word sequence is encrypted using the preset key to obtain the encrypted search field.
5. The method according to claim 3, characterized in that: The encrypted field includes a field ciphertext and an encrypted index, the first notification message includes the encrypted index, and the method further includes: Before sending the target field plaintext to the target microservice end, obtaining a target encryption index corresponding to the target field plaintext; The target encrypted index and the target field plaintext are sent to the target microservice end, so that the target microservice end displays the target field plaintext after determining that the target encrypted index is the same as the encrypted index in any historical first notification message, wherein the historical first notification message represents the first notification message received by the target microservice end before sending the data retrieval request.
6. The method according to claim 5, characterized in that The encrypting the to-be-encrypted field carried by the data encryption request based on a preset key includes: Obtaining the encryption method of the field to be encrypted; If the encryption method is the first encryption method, encrypting the field plaintext and the index field in the field to be encrypted respectively based on the preset key to obtain the field ciphertext and the encrypted index; If the encryption method is the second encryption method, the field plaintext in the field to be encrypted is segmented to obtain an index word sequence, and the field plaintext and the index word sequence are encrypted respectively based on the preset key to obtain the field ciphertext and the encrypted index.
7. The method according to claim 6, characterized in that The obtaining the encryption method of the field to be encrypted includes: If the field to be encrypted does not support fuzzy query, determining the first encryption method as the encryption method of the field to be encrypted; If the field to be encrypted supports fuzzy query, the second encryption method is determined as the encryption method of the field to be encrypted.
8. An encryption storage device applied to a distributed microservice system, characterized in that: The distributed microservice system includes multiple microservice terminals and an encryption service terminal, and the device includes: A first receiving module is configured to obtain a data encryption request sent by a target microservice end; An encryption storage module, configured to encrypt the to-be-encrypted field carried by the data encryption request based on a preset key, and store the encrypted field obtained by encryption in a preset storage space; wherein the preset key and the preset storage space are the key and storage space allocated by the encryption server to the target microservice end; The first sending module is configured to return a first notification message indicating successful encryption storage to the target microservice end, so that the target microservice end deletes the stored field to be encrypted based on the first notification message.
9. A computer-readable storage medium, characterized in that: Computer-readable instructions are stored thereon, and when the computer-readable instructions are executed by a processor of a computer, the computer is caused to execute the encryption storage method applied to a distributed microservice system as described in any one of claims 1-7.
10. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, enables the electronic device to implement the encryption storage method applied to a distributed microservice system as described in any one of claims 1 to 7.