Government affair data sharing method and storage medium
By configuring user information and encryption technology, the problem of inaccurate data leakage and update in government data sharing is solved, data permission control and transmission security is realized, and the accuracy and completeness of government data sharing is ensured.
Patent Information
- Application Number
- CN202510353922.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-03-25
AI Technical Summary
In the prior art, government data sharing methods cannot effectively prevent users with access permission from uploading data to unauthorized departments, resulting in data leakage and cannot ensure the accuracy of data updates and data integrity during transmission.
Ensure the security and accuracy of data transmission by configuring user information, including departments and ranks, querying similar government data, analyzing upload permissions and data updates, and using digital signatures and parity sorting encryption.
It realizes precise control of data permissions, avoids data leakage, ensures the accuracy of data updates and the integrity of transmission, and improves the security and reliability of government data sharing.
Smart Images

Figure CN120277716A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a government affairs data sharing method and a storage medium. Background Art
[0002] Government affairs data sharing is of extremely important significance in modern government governance and social development. It can not only improve the efficiency and transparency of the government, but also promote social innovation, economic development and the improvement of the quality of public services.
[0003] In government affairs data sharing, the sharable data does not necessarily mean that it can be shared with all departments and all personnel. Often, some sharable data is only limited to be shared with designated departments. In the existing technology, only by setting different access permissions for different users for each data, it cannot be avoided that users in other departments with access permissions upload the obtained data to the sharing platform through their own user terminals after obtaining the data, resulting in leakage to departments without access permissions. Summary of the Invention
[0004] In order to solve the technical problems existing in the prior art, the present invention provides a government affairs data sharing method, including the following steps:
[0005] Configuration step: Configure the user information of each user, including department information and rank;
[0006] Data upload step:
[0007] S1. Obtain the government affairs data to be uploaded, and query whether there is similar government affairs data corresponding to the government affairs data to be uploaded in the sharing platform. If it exists, execute S2; if not, upload the government affairs data to be uploaded to the sharing platform and set access permission information;
[0008] S2. Obtain the user information of the uploading user to which the similar government affairs data belongs, and compare it with the user information of the current uploading user, and analyze whether the current uploading user has the uploading permission for the government affairs data to be uploaded. If so, execute S3;
[0009] S3. Analyze whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data. If so, send the uploaded government affairs data to the uploading user to which the corresponding similar government affairs data belongs for confirmation of whether to update. If it is confirmed to update, upload the uploaded government affairs data to the sharing platform to update the corresponding similar government affairs data, and the access permission information of the uploaded government affairs data is the same as that of the corresponding similar government affairs data;
[0010] Data access steps: The sharing platform obtains the access instruction of the current user, and determines whether the user information of the current access user conforms to the access permission information of the government affairs data to be accessed. If it conforms, the sharing platform encrypts and encapsulates the government affairs data to be accessed into a data packet and then transmits it to the user terminal of the current access user. The user terminal of the current access user decrypts the data packet to obtain the government affairs data to be accessed.
[0011] Further, to query whether there is similar government affairs data corresponding to the government affairs data to be uploaded in the sharing platform, specifically:
[0012] Obtain the preset content tags and data collection information of the government affairs data to be uploaded, and compare them with the government affairs data in the sharing platform respectively. If the corresponding preset content tags and data collection information are the same as those of the government affairs data to be uploaded, the corresponding government affairs data is the similar government affairs data corresponding to the government affairs data to be uploaded.
[0013] Further, to analyze whether the current uploading user has the uploading permission for the government affairs data to be uploaded, specifically:
[0014] When the department information of the uploading user to which the similar government affairs data belongs is consistent with the department information of the current uploading user, and the rank of the current uploading user is greater than or equal to the rank of the uploading user to which the similar government affairs data belongs, then the current uploading user has the uploading permission for the government affairs data to be uploaded.
[0015] Further, to analyze whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data, specifically:
[0016] Compare the values of the main data items of the government affairs data to be uploaded with the values of the main data items of the corresponding similar government affairs data respectively, and analyze whether there are main data items with different values. If so, it is determined that the uploaded government affairs data is the updated data of the corresponding similar government affairs data.
[0017] Further, the access permission information includes the permitted access department and the corresponding permitted access rank.
[0018] Further, to determine whether the user information of the current access user conforms to the access permission information of the government affairs data to be accessed, specifically:
[0019] If the department information of the current access user belongs to the permitted access department, and the rank of the current access user belongs to the corresponding permitted access rank in the corresponding permitted access department, then the user information of the current access user conforms to the access permission information of the government affairs data to be accessed.
[0020] Further, the access instruction includes the public key of the current accessing user and the access time, and the access time includes the current access time and the last historical access time;
[0021] The sharing platform encrypts and encapsulates the government affairs data to be accessed into a data packet and then transmits it to the user side of the current accessing user, which specifically includes:
[0022] X11. The sharing platform calculates and obtains the original digital signature of the government affairs data to be accessed by using its own private key;
[0023] X12. The sharing platform slices the government affairs data to be accessed to form multiple first data blocks, and sorts them in sequence to form a data block sequence;
[0024] X13. The sharing platform randomly generates a symmetric session key, encrypts each first data block into a first ciphertext block, and forms an initial ciphertext block sequence according to the sorting of the data block sequence;
[0025] X14. Respectively judge the parity of the current access time and the last historical access time;
[0026] X15. According to the parity of the last historical access time, extract the ciphertext blocks at odd / even positions in the initial ciphertext block sequence, and arrange them at the end of the sequence in turn to form a first ciphertext block sequence. Then, according to the parity of the current access time, extract the ciphertext blocks at odd / even positions in the first ciphertext block sequence, and arrange them at the end of the sequence in turn to form a final ciphertext block sequence;
[0027] X16. The sharing platform uses the public key of the current accessing user to perform asymmetric encryption on the symmetric session key to obtain a second ciphertext;
[0028] X17. The sharing platform encapsulates the original digital signature, the public key of the sharing platform, the final ciphertext block sequence and the second ciphertext into a data packet and transmits it to the user side of the current accessing user.
[0029] Further, the step of respectively judging the parity of the current access time and the last historical access time specifically is:
[0030] If among the readings of each item of the current access time, the readings of even numbers are the most, then the current access time is even, otherwise it is odd; if among the readings of each item of the last historical access time, the readings of even numbers are the most, then the current access time is even, otherwise it is odd; the readings include year reading, month reading, day reading, hour reading, minute reading and second reading.
[0031] Further, when the client of the current accessing user decrypts the data packet to obtain the government affairs data to be accessed, it includes restoring the final ciphertext block sequence to the first ciphertext block sequence according to the parity of the current access time, and then restoring the first ciphertext block sequence to the initial ciphertext block sequence according to the parity of the historical last access time. Specifically:
[0032] Obtain the number of ciphertext blocks n in the final ciphertext block sequence;
[0033] If n is even:
[0034] In the final ciphertext block sequence, if the current access time is even, use the first ciphertext block of the first n / 2 ciphertext blocks as the first block of the sequence, and insert the last n / 2 ciphertext blocks into the spaces in front of the first n / 2 ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is odd, use the first ciphertext block of the last n / 2 ciphertext blocks as the first block of the sequence, and insert the first n / 2 ciphertext blocks into the spaces behind the last n / 2 ciphertext blocks in turn to restore the first ciphertext block sequence;
[0035] In the first ciphertext block sequence, if the historical last access time is even, use the first ciphertext block of the first n / 2 ciphertext blocks as the first block of the sequence, and insert the last n / 2 ciphertext blocks into the spaces in front of the first n / 2 ciphertext blocks in turn to restore the initial ciphertext block sequence. If the historical last access time is odd, use the first ciphertext block of the last n / 2 ciphertext blocks as the first block of the sequence, and insert the first n / 2 ciphertext blocks into the spaces behind the last n / 2 ciphertext blocks in turn to restore the initial ciphertext sequence;
[0036] If n is odd:
[0037] In the final ciphertext block sequence, if the current access time is even, use the first ciphertext block of the first ((n + 1) / 2 ciphertext blocks as the first block of the sequence, and insert the last ((n - 1) / 2 ciphertext blocks into the spaces in front of the first ((n + 1) / 2 ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is odd, use the first ciphertext block of the last ((n + 1) / 2 ciphertext blocks as the first block of the sequence, and insert the first ((n - 1) / 2 ciphertext blocks into the spaces behind the last ((n + 1) / 2 ciphertext blocks in turn to restore the first ciphertext block sequence;
[0038] In the first ciphertext block sequence, if the historical last access time is even, use the first ciphertext block of the first ((n + 1) / 2 ciphertext blocks as the first block of the sequence, and insert the last ((n - 1) / 2 ciphertext blocks into the spaces in front of the first ((n + 1) / 2 ciphertext blocks in turn to restore the initial ciphertext block sequence. If the historical last access time is odd, use the first ciphertext block of the last ((n + 1) / 2 ciphertext blocks as the first block of the sequence, and insert the first ((n - 1) / 2 ciphertext blocks into the spaces behind the last ((n + 1) / 2 ciphertext blocks in turn to restore the initial ciphertext sequence.
[0039] The present invention also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described in any one of the above.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0041] The present invention queries similar government affairs data corresponding to the to-be-uploaded government affairs data, compares the user information of the uploading user to which the similar government affairs data belongs with the user information of the current uploading user, and analyzes whether the current uploading user has the uploading permission for the to-be-uploaded government affairs data, so as to prevent a user from uploading restricted shared data of other departments through their own user terminal, thereby causing the leakage of the data to unauthorized departments.
[0042] After analyzing whether the uploaded government affairs data is updated data of the corresponding similar government affairs data, the present invention sends it to the uploading user to which the corresponding similar government affairs data belongs for confirmation of whether to update, so as to obtain two-way verification, avoid the correct similar government affairs data being overwritten by incorrect to-be-uploaded government affairs data, and ensure the accuracy of the shared data.
[0043] The present invention verifies the integrity and source of data through digital signatures, prevents data from being tampered with or forged during transmission, and ensures the integrity and accuracy of the accessed data.
[0044] By respectively judging the parity of the readings of the user's current access time and the historical last access time, using the parity to sort and reorganize the divided ciphertext blocks, disrupting the original sorting, and restoring the sequence through the parity of the user's current access time and the historical last access time during decryption, the security of the data is further improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0047] Figure 1 is a flowchart of the data uploading step in a government affairs data sharing method of the present invention;
[0048] Figure 2 is a flowchart of data encryption in the data access step of a government affairs data sharing method of the present invention.
[0049] Figure 3 It is the flowchart of data decryption in the data access step of a government affairs data sharing method of the present invention. Specific implementation manners
[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0051] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative position relationship and movement conditions between components in a specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.
[0052] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0053] Embodiment 1
[0054] Refer to Figure 1 As shown, a government affairs data sharing method provided by the present invention specifically includes the following steps:
[0055] Configuration step: Configure the user information of each user, including department information and rank;
[0056] Data upload step:
[0057] S1. Obtain the government affairs data to be uploaded, and query whether there is similar government affairs data corresponding to the government affairs data to be uploaded in the sharing platform. If it exists, execute S2; if not, upload the government affairs data to be uploaded to the sharing platform and set access permission information;
[0058] S2. Obtain the user information of the uploading user to which the similar government affairs data belongs, compare it with the user information of the current uploading user, analyze whether the current uploading user has the uploading permission for the to-be-uploaded government affairs data. If so, execute S3;
[0059] S3. Analyze whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data. If so, send the uploaded government affairs data to the uploading user to which the corresponding similar government affairs data belongs for confirmation of whether to update. If it is confirmed to update, upload the uploaded government affairs data to the shared platform to update the corresponding similar government affairs data, and the access permission information of the uploaded government affairs data is the same as that of the corresponding similar government affairs data;
[0060] Data access step: The shared platform obtains the access instruction of the current user, determines whether the user information of the current accessing user conforms to the access permission information of the to-be-accessed government affairs data. If it conforms, the shared platform encrypts and encapsulates the to-be-accessed government affairs data into a data packet and then transmits it to the user terminal of the current accessing user, and the user terminal of the current accessing user decrypts the data packet to obtain the to-be-accessed government affairs data.
[0061] In step S1, to query whether there is similar government affairs data corresponding to the to-be-uploaded government affairs data in the shared platform, specifically:
[0062] Obtain the preset content label and data collection information of the to-be-uploaded government affairs data, and compare them with the government affairs data in the shared platform respectively. If the corresponding preset content label and data collection information are both the same as those of the to-be-uploaded government affairs data, the corresponding government affairs data is the similar government affairs data corresponding to the to-be-uploaded government affairs data.
[0063] The data collection information includes the collection date and the collection location.
[0064] Government affairs data is various information and data generated by government departments in the process of performing their functions. Generally speaking, the functions of each department are different, and the content of its government affairs data is also different, such as economic data, population data, environmental data, etc. Environmental data can be further divided into air quality data, water quality data, soil pollution data, etc. According to the specific content, corresponding preset content labels are set for each government affairs data. Combining with the data collection information of the data, the present invention realizes a fast and accurate query of whether there is similar government affairs data corresponding to the to-be-uploaded government affairs data in the shared platform. For example, when a user uploads the air quality data of Area A collected on December 24, 2024, and it is recognized that there is already air quality data of Area A collected on December 24, 2024 in the shared platform, it can automatically make an analysis and judgment on whether to update the data subsequently or avoid repeated uploads, improve the data upload efficiency, and avoid wasting communication resources.
[0065] It should be noted that when there is no similar government affairs data corresponding to the to-be-uploaded government affairs data in the sharing platform, it means that the to-be-uploaded government affairs data is collected by the department where the current uploading user is located. It is the data of the department where the current uploading user is located. Therefore, it can be directly uploaded to the sharing platform, and there is no situation where the current uploading user uploads the shared data of other departments through their own user terminal.
[0066] In step S2, analyze whether the current uploading user has the uploading permission for the to-be-uploaded government affairs data. Specifically:
[0067] When the department information of the uploading user to which the similar government affairs data belongs is consistent with the department information of the current uploading user, and the rank of the current uploading user is greater than or equal to the rank of the uploading user to which the similar government affairs data belongs, then the current uploading user has the uploading permission for the to-be-uploaded government affairs data.
[0068] In the sharing of government affairs data among departments, not all uploaded and shared government affairs data are shared with all departments. There will be some data that can only be shared with certain departments. In order to prevent these departments from accidentally uploading and sharing this restricted shared data after obtaining it, resulting in all departments being able to obtain it and causing data leakage, the present invention uses the method of comparing the user information of the current uploading user with the user information of the uploading user to which the similar government affairs data corresponding to the to-be-uploaded government affairs data belongs, restricting the uploading permission of the to-be-uploaded government affairs data, and well avoiding data leakage caused by incorrect operations on this restricted shared data by other departments or lower-rank personnel in the sharing platform.
[0069] In step S3, analyze whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data. Specifically:
[0070] Compare the values of the main data items of the to-be-uploaded government affairs data with the values of the main data items of the corresponding similar government affairs data, and analyze whether there are main data items with different values. If so, determine that the uploaded government affairs data is the updated data of the corresponding similar government affairs data.
[0071] For the uploaded similar government affairs data, there may be data errors that need to be corrected and updated. Therefore, the present invention compares the values of the main data items of the government affairs data to be uploaded with the values of the corresponding main data items of the similar government affairs data, and determines whether the main data items of the government affairs data to be uploaded have changed compared to the corresponding main data items of the corresponding similar government affairs data. If there are changes, the data to be updated, that is, the government affairs data to be uploaded, is first sent to the corresponding uploading user of the similar government affairs data for confirmation and then updated to obtain two-way verification, avoiding the situation where the similar government affairs data is correct but the government affairs data to be uploaded is incorrect, thereby causing incorrect updates. On the one hand, it ensures the accuracy of data updates, and on the other hand, it prevents the incorrect modification of correct data.
[0072] The access permission information includes the permitted access department and the corresponding permitted access rank;
[0073] The judgment of whether the user information of the current access user conforms to the access permission information of the government affairs data to be accessed is specifically as follows:
[0074] If the department information of the current access user belongs to the permitted access department and the rank of the current access user belongs to the corresponding permitted access rank in the corresponding permitted access department, then the user information of the current access user conforms to the access permission information of the government affairs data to be accessed.
[0075] The access instruction includes the public key of the current access user and the access time, and the access time includes the current access time and the historical last access time;
[0076] Refer to Figure 2 As shown, the sharing platform encrypts and encapsulates the government affairs data to be accessed into a data packet and then transmits it to the user terminal of the current access user, specifically including:
[0077] X11. The sharing platform calculates and obtains the original digital signature of the government affairs data to be accessed by using its own private key;
[0078] X12. The sharing platform slices the government affairs data to be accessed to form a plurality of first data blocks, and sorts them in sequence to form a data block sequence;
[0079] X13. The sharing platform randomly generates a symmetric session key, encrypts each first data block into a first ciphertext block, and forms an initial ciphertext block sequence according to the sorting of the data block sequence;
[0080] X14. Respectively judge the parity of the current access time and the historical last access time, specifically as follows:
[0081] If among the readings of various information at the current access time, the number of readings with even values is the largest, then the current access time is of even parity; otherwise, it is of odd parity. Judging the parity of the last historical access time is the same as judging the parity of the current access time. The information readings include year reading, month reading, day reading, hour reading, minute reading, and second reading.
[0082] For example, if the current access time is 11:39:28 on December 30, 2024, then there are 4 readings with even values and 2 readings with odd values. Therefore, the current access time is of even parity.
[0083] X15. According to the parity of the last historical access time, extract the ciphertext blocks at odd / even positions in the initial ciphertext block sequence and arrange them at the end of the sequence in turn to form the first ciphertext block sequence. Then, according to the parity of the current access time, extract the ciphertext blocks at odd / even positions in the first ciphertext block sequence and arrange them at the end of the sequence in turn to form the final ciphertext block sequence.
[0084] For example: If the initial ciphertext block sequence is ABCDE, if the last historical access time is of odd parity, then the first ciphertext block sequence is BDACE. If the current access time is of even parity, then the final ciphertext block sequence is BAEDC.
[0085] X16. The sharing platform uses the public key of the current access user to encrypt the symmetric session key to obtain the second ciphertext.
[0086] X17. The sharing platform encapsulates the original digital signature, the sharing platform public key, the final ciphertext block sequence, and the second ciphertext into a data packet and transmits it to the user terminal of the current access user.
[0087] The sharing platform calculates and obtains the original digital signature of the government affairs data to be accessed by using its own private key. Specifically:
[0088] After the sharing platform calculates the original hash value of the government affairs data to be accessed through a preset hash function, it encrypts the original hash value with its own private key to obtain the original digital signature.
[0089] Refer to Figure 3 As shown, the user terminal of the current access user decrypts the data packet to obtain the government affairs data to be accessed. Specifically including:
[0090] X21. The user terminal of the current access user uses its own private key to decrypt the second ciphertext to obtain the symmetric session key.
[0091] X22. According to the parity of the current access time, restore the final ciphertext block sequence to the first ciphertext block sequence, and then according to the parity of the last historical access time, restore the first ciphertext block sequence to the initial ciphertext block sequence. Specifically:
[0092] Obtain the number of ciphertext blocks \(n\) in the final ciphertext block sequence;
[0093] If \(n\) is even:
[0094] In the final ciphertext block sequence, if the current access time is even, use the first ciphertext block of the first \(n / 2\) ciphertext blocks as the first block of the sequence, and insert the latter \(n / 2\) ciphertext blocks into the spaces in front of the first \(n / 2\) ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is odd, use the first ciphertext block of the latter \(n / 2\) ciphertext blocks as the first block of the sequence, and insert the first \(n / 2\) ciphertext blocks into the spaces behind the latter \(n / 2\) ciphertext blocks in turn to restore the first ciphertext block sequence;
[0095] In the first ciphertext block sequence, if the historical last access time is even, use the first ciphertext block of the first \(n / 2\) ciphertext blocks as the first block of the sequence, and insert the latter \(n / 2\) ciphertext blocks into the spaces in front of the first \(n / 2\) ciphertext blocks in turn to restore the initial ciphertext block sequence. If the historical last access time is odd, use the first ciphertext block of the latter \(n / 2\) ciphertext blocks as the first block of the sequence, and insert the first \(n / 2\) ciphertext blocks into the spaces behind the latter \(n / 2\) ciphertext blocks in turn to restore the initial ciphertext sequence;
[0096] If \(n\) is odd:
[0097] In the final ciphertext block sequence, if the current access time is even, use the first ciphertext block of the first \((n + 1) / 2\) ciphertext blocks as the first block of the sequence, and insert the latter \((n - 1) / 2\) ciphertext blocks into the spaces in front of the first \((n + 1) / 2\) ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is odd, use the first ciphertext block of the latter \((n + 1) / 2\) ciphertext blocks as the first block of the sequence, and insert the first \((n - 1) / 2\) ciphertext blocks into the spaces behind the first \((n + 1) / 2\) ciphertext blocks in turn to restore the first ciphertext block sequence;
[0098] In the first ciphertext block sequence, if the historical last access time is even, use the first ciphertext block of the first \((n + 1) / 2\) ciphertext blocks as the first block of the sequence, and insert the latter \((n - 1) / 2\) ciphertext blocks into the spaces in front of the first \((n + 1) / 2\) ciphertext blocks in turn to restore the initial ciphertext block sequence. If the historical last access time is odd, use the first ciphertext block of the latter \((n + 1) / 2\) ciphertext blocks as the first block of the sequence, and insert the first \((n - 1) / 2\) ciphertext blocks into the spaces behind the first \((n + 1) / 2\) ciphertext blocks in turn to restore the initial ciphertext sequence;
[0099] For example, according to the example in step X15 above, since the current access time is even, the final ciphertext block sequence is BAEDC, and n = 5 is odd. Then, using the first ciphertext block (i.e., B) of the first 3 ciphertext blocks (i.e., BAE) as the first block of the sequence, insert the last 2 ciphertext blocks (i.e., DC) into the first 3 ciphertext blocks in turn to restore the first ciphertext block sequence BDACE. Since the historical last access time is odd, using the first ciphertext block (i.e., A) of the last 3 ciphertext blocks (i.e., ACE) as the first block of the sequence, insert the first 2 ciphertext blocks (i.e., BD) into the last 3 ciphertext blocks in turn to restore the initial ciphertext sequence ABCDE.
[0100] X23. Decrypt each ciphertext block of the initial ciphertext block sequence using the symmetric session key, and splice them according to the sorting of the initial ciphertext block sequence to obtain the government affairs data to be accessed. At the same time, decrypt the original digital signature using the public key of the shared platform to obtain the original hash value.
[0101] X24. Calculate the hash value of the decrypted government affairs data to be accessed using the same hash function as the shared platform. If it is the same as the original hash value, trust the decrypted government affairs data to be accessed.
[0102] The present invention verifies the integrity and source of data through digital signature, prevents data from being tampered with or forged during transmission, and ensures the integrity and accuracy of the accessed data.
[0103] The uniqueness and irreversibility of the hash function ensure that any modification to the data will result in a change in the hash value. Therefore, if the data is tampered with, the recalculated hash value will be different from the verified hash value, thus detecting the tampering.
[0104] In some embodiments, in step X16, the shared platform encrypts the symmetric session key using the public key of the current access user to obtain a second ciphertext, and further includes:
[0105] The shared platform processes the public key of the current access user using cascaded Chebyshev mapping to generate a first pseudo-random chaotic sequence.
[0106] Use a preset first LSTM neural network model to generate a first scrambling matrix according to the first pseudo-random chaotic sequence.
[0107] Use the scrambling matrix to perform scrambling encryption on the symmetric session key to obtain a second ciphertext.
[0108] Before decrypting each ciphertext block of the initial ciphertext block sequence using the symmetric session key in step X23, it includes:
[0109] The client uses a cascaded Chebyshev map to process the public key of the current user itself, generating a second pseudo-random chaotic sequence. The mapping control parameters of the cascaded Chebyshev map processing by the client are the same as those of the cascaded Chebyshev map processing by the shared platform;
[0110] The second LSTM neural network model is used to generate a second scrambling matrix according to the second pseudo-random chaotic sequence. The second LSTM neural network model is obtained in advance through digital twin technology according to the preset first LSTM neural network model;
[0111] The second scrambling matrix is used to perform an inverse scrambling operation on the second ciphertext to obtain the symmetric session key.
[0112] In this embodiment, a pseudo-random chaotic sequence is generated through a cascaded Chebyshev map. Since the public keys of each user are different, each user will generate a unique pseudo-random chaotic sequence according to the preset cascaded Chebyshev map, and then obtain a unique scrambling matrix according to the preset LSTM neural network model, ensuring the communication independence and security of each user. At the same time, the client establishes a cascaded Chebyshev map and an LSTM neural network model with the same parameters as the shared platform in advance through digital twin, and can generate a pseudo-random chaotic sequence and a scrambling matrix consistent with the shared platform, reducing the data transmission of the pseudo-random chaotic sequence and the scrambling matrix, so as to ensure the data security of the symmetric session key.
[0113] In some other embodiments, in step X16, the shared platform can directly use the public key of the currently accessing user to asymmetrically encrypt the symmetric session key to obtain a second ciphertext.
[0114] In some embodiments, the shared platform transmits the data packet to the client of the currently accessing user and uses a secure communication protocol such as TLS / SSL for transmission.
[0115] Embodiment 2
[0116] The present invention also provides an electronic device, including: a processor, a sending device, an input device, an output device, and a memory. The processor can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit, or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application. The memory can be implemented in forms such as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc., and is used to store computer program codes. The computer program codes include computer instructions. When the processor executes the computer instructions, the electronic device executes the method in any of the above possible implementation manners.
[0117] Embodiment III
[0118] The present invention also provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by the processor of the electronic device, the processor is caused to execute the method in any of the above possible implementation manners.
[0119] The beneficial effects of the present invention are as follows:
[0120] The present invention queries similar government affairs data corresponding to the to-be-uploaded government affairs data, compares the user information of the uploading user to which the similar government affairs data belongs with the user information of the current uploading user, and analyzes whether the current uploading user has the uploading permission for the to-be-uploaded government affairs data, so as to prevent the user from uploading restricted shared data of other departments through their own user terminal, thereby causing the data to be leaked to unauthorized departments.
[0121] After analyzing whether the uploaded government affairs data is updated data of the corresponding similar government affairs data, the present invention sends it to the uploading user to which the corresponding similar government affairs data belongs for confirmation of whether to update, obtaining two-way verification, avoiding the correct similar government affairs data being overwritten by incorrect to-be-uploaded government affairs data, and ensuring the accuracy of the shared data.
[0122] The present invention verifies the integrity and source of the data through digital signatures, prevents the data from being tampered with or forged during the transmission process, and ensures the integrity and accuracy of the accessed data.
[0123] By respectively judging the parity of the readings of the user's current access time and the historical last access time, using the parity to sort and reorganize the segmented ciphertext blocks, disrupting the original sorting, and restoring the sequence through the parity of the user's current access time and the historical last access time during decryption, the security of the data is further improved.
[0124] In the description of the specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0125] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. And the foregoing storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memories (ROM for short), random access memories (RAM for short), magnetic disks, or optical discs.
[0126] The above is only the specific implementation manner of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for sharing government affairs data, characterized in that, It includes the following steps: Configuration step: Configure the user information of each user, including department information and job level; Data upload step: S1. Obtain the government affairs data to be uploaded, and query whether there is similar government affairs data corresponding to the government affairs data to be uploaded in the sharing platform. If it exists, execute S2; if not, upload the government affairs data to be uploaded to the sharing platform and set the access permission information; S2. Obtain the user information of the uploading user to which the similar government affairs data belongs, and compare it with the user information of the current uploading user to analyze whether the current uploading user has the uploading permission for the government affairs data to be uploaded. If so, execute S3; S3. Analyze whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data. If so, send the uploaded government affairs data to the uploading user to which the corresponding similar government affairs data belongs for confirmation of whether to update. If it is confirmed to be updated, upload the uploaded government affairs data to the sharing platform to update the corresponding similar government affairs data, and the access permission information of the uploaded government affairs data is the same as that of the corresponding similar government affairs data; Data access step: The sharing platform obtains the access instruction of the current user, and judges whether the user information of the current accessing user conforms to the access permission information of the government affairs data to be accessed. If it conforms, the sharing platform encrypts and encapsulates the government affairs data to be accessed into a data packet and then transmits it to the user terminal of the current accessing user. The user terminal of the current accessing user decrypts the data packet to obtain the government affairs data to be accessed.
2. The government affairs data sharing method according to claim 1, wherein The query of whether there is similar government affairs data corresponding to the government affairs data to be uploaded in the sharing platform is specifically: Obtain the preset content label and data collection information of the government affairs data to be uploaded, and compare them with the government affairs data in the sharing platform respectively. If the corresponding preset content label and data collection information are both the same as those of the government affairs data to be uploaded, the corresponding government affairs data is the similar government affairs data corresponding to the government affairs data to be uploaded.
3. The government affairs data sharing method according to claim 1, wherein The analysis of whether the current uploading user has the uploading permission for the government affairs data to be uploaded is specifically: When the department information of the uploading user to which the similar government affairs data belongs is consistent with the department information of the current uploading user, and the job level of the current uploading user is greater than or equal to the job level of the uploading user to which the similar government affairs data belongs, then the current uploading user has the uploading permission for the government affairs data to be uploaded.
4. The government affairs data sharing method according to claim 1, wherein The analysis of whether the uploaded government affairs data is the updated data of the corresponding similar government affairs data is specifically: Compare the values of the main data items of the government affairs data to be uploaded with the values of the main data items of the corresponding similar government affairs data respectively, and analyze whether there are main data items with different values. If so, determine that the uploaded government affairs data is the updated data of the corresponding similar government affairs data.
5. The government affairs data sharing method according to claim 1, wherein The access permission information includes the permitted access department and the corresponding permitted access job level.
6. The government affairs data sharing method according to claim 5, characterized in that, The judgment of whether the user information of the current accessing user conforms to the access permission information of the government affairs data to be accessed is specifically: If the department information of the current accessing user belongs to the permitted access department, and the rank of the current accessing user belongs to the corresponding permitted access rank in the corresponding permitted access department, then the user information of the current accessing user conforms to the access permission information of the government affairs data to be accessed.
7. The government affairs data sharing method according to claim 1, wherein The access instruction includes the public key and access time of the current accessing user, and the access time includes the current access time and the last historical access time; The sharing platform encrypts and encapsulates the government affairs data to be accessed into a data packet and then transmits it to the user terminal of the current accessing user, specifically including: X11. The sharing platform calculates and obtains the original digital signature of the government affairs data to be accessed by using its own private key; X12. The sharing platform slices the government affairs data to be accessed to form multiple first data blocks, and sorts them in sequence to form a data block sequence; X13. The sharing platform randomly generates a symmetric session key, encrypts each first data block into a first ciphertext block, and forms an initial ciphertext block sequence according to the sorting of the data block sequence; X14. Respectively judge the parity of the current access time and the last historical access time; X15. According to the parity of the last historical access time, extract the ciphertext blocks at odd / even positions in the initial ciphertext block sequence, and arrange them at the end of the sequence in turn to form a first ciphertext block sequence. Then, according to the parity of the current access time, extract the ciphertext blocks at odd / even positions in the first ciphertext block sequence, and arrange them at the end of the sequence in turn to form a final ciphertext block sequence; X16. The sharing platform uses the public key of the current accessing user to perform asymmetric encryption on the symmetric session key to obtain a second ciphertext; X17. The sharing platform encapsulates the original digital signature, the public key of the sharing platform, the final ciphertext block sequence and the second ciphertext into a data packet and transmits it to the user terminal of the current accessing user.
8. The government affairs data sharing method according to claim 7, wherein The specific method for respectively judging the parity of the current access time and the last historical access time is as follows: If, among the readings of each item of the current access time, the readings of even numbers are the most, then the current access time is of even nature, otherwise it is of odd nature; if, among the readings of each item of the last historical access time, the readings of even numbers are the most, then the current access time is of even nature, otherwise it is of odd nature; the readings include annual readings, monthly readings, daily readings, hourly readings, minute readings and second readings.
9. The government affair data sharing method according to claim 7, wherein When the user terminal of the current accessing user decrypts the data packet to obtain the government affairs data to be accessed, it includes restoring the final ciphertext block sequence to the first ciphertext block sequence according to the parity of the current access time, and then restoring the first ciphertext block sequence to the initial ciphertext block sequence according to the parity of the last historical access time. Specifically: Obtain the number of ciphertext blocks n in the final ciphertext block sequence; If n is an even number: In the final ciphertext block sequence, if the current access time is of even nature, then use the first ciphertext block of the first n / 2 ciphertext blocks as the first block of the sequence, and insert the latter n / 2 ciphertext blocks into the spaces in front of the first n / 2 ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is of odd nature, then use the first ciphertext block of the latter n / 2 ciphertext blocks as the first block of the sequence, and insert the first n / 2 ciphertext blocks into the spaces behind the latter n / 2 ciphertext blocks in turn to restore the first ciphertext block sequence; In the first ciphertext block sequence, if the last historical access time is even, the first ciphertext block of the first n / 2 ciphertext blocks is used as the first block of the sequence, and the last n / 2 ciphertext blocks are inserted into the first n / 2 ciphertext blocks in turn to restore the initial ciphertext block sequence. If the last historical access time is odd, the first ciphertext block of the last n / 2 ciphertext blocks is used as the first block of the sequence, and the first n / 2 ciphertext blocks are inserted into the last n / 2 ciphertext blocks in turn to restore the initial ciphertext sequence; If n is odd: In the final ciphertext block sequence, if the current access time is even, the first ciphertext block of the first (n + 1) / 2 ciphertext blocks is used as the first block of the sequence, and the last (n - 1) / 2 ciphertext blocks are inserted into the first (n + 1) / 2 ciphertext blocks in turn to restore the first ciphertext block sequence. If the current access time is odd, the first ciphertext block of the last (n + 1) / 2 ciphertext blocks is used as the first block of the sequence, and the first (n - 1) / 2 ciphertext blocks are inserted into the last (n + 1) / 2 ciphertext blocks in turn to restore the first ciphertext block sequence; In the first ciphertext block sequence, if the last historical access time is even, the first ciphertext block of the first (n + 1) / 2 ciphertext blocks is used as the first block of the sequence, and the last (n - 1) / 2 ciphertext blocks are inserted into the first (n + 1) / 2 ciphertext blocks in turn to restore the initial ciphertext block sequence. If the last historical access time is odd, the first ciphertext block of the last (n + 1) / 2 ciphertext blocks is used as the first block of the sequence, and the first (n - 1) / 2 ciphertext blocks are inserted into the last (n + 1) / 2 ciphertext blocks in turn to restore the initial ciphertext sequence.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method according to any one of claims 1-9 is implemented.
Citation Information
Patent Citations
Two-way parity error detection for advanced encryption standard engines
CN107003911A
Enterprise information management system integrated platform
CN107977829A
Information resource sharing method, apparatus, readable storage medium, and electronic device
CN109389361A
Government affair data storage and query method and system based on block chain double-chain structure
CN110109930A
Cross-system and cross-department business cooperation information exchange method based on government affair field
CN113037471A