Micro-service-based retail credit full-stage data flow control system
Through a full-stage retail credit data flow risk control system based on microservices, text and image data are dynamically encrypted, dynamic encryption keys are generated and blockchain storage is used, which solves the problem of easy cracking of keys and single encryption of data types in the existing technology, and realizes comprehensive security protection of data.
Patent Information
- Application Number
- CN202510678348.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-07-11
AI Technical Summary
The existing data flow risk control protection technology has the problem of easy cracking through fixed key encryption and insufficient security and comprehensiveness of encryption of a single type of data, especially in credit platforms, image information is not effectively protected.
The retail credit full-stage data flow risk control system based on microservices is adopted. By generating dynamic encryption keys, text and image data are dynamically encrypted, and encoding to be calculated and dynamically encrypted. The blockchain is used to store secure ciphertexts to ensure the security of data during transmission and storage.
It improves the security of encryption keys and comprehensive data protection, enhances the security and effectiveness of data flow risk control protection, and is difficult to crack through dynamic encryption and storage technology to ensure the security of data during transmission and storage.
Smart Images

Figure CN120301694A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data flow risk control and protection, and specifically to a data flow risk control system for the whole stage of retail credit based on microservices. Background Art
[0002] The data flow risk control and protection technology refers to the technology for controlling and protecting the security risks of data flow during the transmission and storage processes. Its core is to ensure the security of data during the entire stage of data acquisition, transmission, and storage, and prevent data leakage during any process.
[0003] Existing data flow risk control and protection technologies usually obtain fixed ciphertexts through fixed key encryption. However, both the fixed key and the fixed ciphertext have deficiencies in security. It is easy for others to find the encryption rule through a large number of operations, resulting in the cracking of the encryption process. Moreover, if the key is stolen or leaked, all ciphertexts will also be cracked and leaked. At the same time, the information in the credit platform contains a lot of user image information, and existing data flow risk control technologies usually only perform data protection on a single type of text data or image data, lacking versatility. For example, in the Chinese patent with the application publication number CN111698252A, a data encryption transmission method and system for a cloud platform are disclosed. This solution only encrypts a single type of text data and does not consider the image data in the cloud platform. Existing data flow risk control and protection technologies also have problems such as encrypting plaintext with a fixed key and only encrypting a single type of data, resulting in insufficient data security and comprehensiveness of data protection, and easy data leakage. Summary of the Invention
[0004] The present invention aims to solve at least one of the technical problems in the existing technology to some extent. By obtaining the data in the data flow of the whole stage of retail credit, naming it credit data, generating an encryption key and dynamically updating the encryption key, then converting the text data into a calculation code to be encrypted, and at the same time converting the image data into a calculation code to be encrypted, then dynamically encrypting the calculation code with the encryption key to obtain a dynamic secure ciphertext, and then restoring and re-encrypting the secure ciphertext according to the dynamic transformation of the encryption key, securely transmitting the secure ciphertext, and securely storing the secure ciphertext, to solve the problems that existing data flow risk control and protection technologies still encrypt plaintext with a fixed key and only encrypt a single type of data, resulting in insufficient data security and comprehensiveness of data protection, and easy data leakage.
[0005] To achieve the above object, in a first aspect, the present application provides a risk control system for the entire stage data stream of retail credit based on microservices, including a credit data acquisition module, a dynamic key update module, a data dynamic encryption module, a data secure transmission module, and a data secure storage module; the credit data acquisition module, the dynamic key update module, the data secure transmission module, and the data secure storage module are respectively connected to the data dynamic encryption module in terms of data; The credit data acquisition module is used to acquire data in the entire stage data stream of retail credit and name it credit data; The dynamic key update module is used to generate an encryption key and dynamically update the encryption key; The data dynamic encryption module is used to dynamically encrypt the credit data. First, the credit data is subjected to complex transformation to obtain a to-be-calculated code, and then the to-be-calculated code is dynamically encrypted through the encryption key to obtain a dynamic secure ciphertext. At the same time, after the encryption key is updated, the secure ciphertext is restored to the to-be-calculated code and re-encrypted; The data secure transmission module is used to securely transmit the secure ciphertext; The data secure storage module is used to securely store the secure ciphertext.
[0006] Further, the credit data includes in-bank data, external data, and behavior data. Among them, the in-bank data includes customer basic information, transaction flow, and historical credit records. The external data includes credit investigation data, industrial and commercial data, judicial data, tax data, and social security data. The behavior data includes online consumption records and geographical locations. The credit data as a whole can be divided into two categories, namely text data and image data.
[0007] Further, the dynamic key update module is configured with a dynamic key update policy, and the dynamic key update policy includes: Create a key element pool, and the key element pool includes all numbers, capital letters, lowercase letters, and punctuation marks; Create a key queue with a first number of digits, number the characters in the key queue in order from left to right, and represent them through the symbol PW n where n is a non-zero natural number and n is the serial number of PW, and 1 ≤ n ≤ the first number; For each PW n Assign a value. Each time a value is assigned, a character is randomly selected from the key element pool for assignment, and the finally assigned PW n is arranged and combined in ascending order of n to obtain an encryption key; The encryption key will become invalid and be randomly generated again every first update period.
[0008] Further, the data dynamic encryption module includes a text data transcoding unit, an image data transcoding unit, a data encryption unit, and a dynamic encryption unit; The text data transcoding unit is used to convert text data into a to-be-calculated code that can be encrypted; The image data transcoding unit is used to convert image data into a to-be-calculated code that can be encrypted; The data encryption unit is used to dynamically encrypt the to-be-calculated code with an encryption key to obtain a dynamic secure ciphertext; The dynamic encryption unit is used to restore and re-encrypt the secure ciphertext according to the dynamic transformation of the encryption key.
[0009] Further, the text data transcoding unit is configured with a text data transcoding strategy, and the text data transcoding strategy includes: Obtain text data, convert each character in the text data into a hexadecimal digit combination according to Unicode encoding, and mark it as C m , where m is a non-zero natural number and m is the serial number of C; Preset a conversion code, mark it as A, calculate C m / A, and mark the calculation result as B1 m , and at the same time calculate C m %A, and mark the calculation result as B2 m , where % is the modulo operator; Place B1 m before B2 m and form a new digit combination, mark it as D m , for all C m Calculate D m ; All D m are composed of four digits. Replace the first digit and the third digit in D m to obtain E m ; Calculate E m / A, and mark the calculation result as B3 m , and at the same time calculate E m %A, and mark the calculation result as B4 m ; Place B3 m before B4 m and form a new digit combination, mark it as F m , for all E m Calculate F m , and arrange and combine F m in ascending order of m to obtain the to-be-calculated code.
[0010] Further, the image data transcoding unit is configured with an image data transcoding strategy, and the image data transcoding strategy includes: Obtain the RGB color of the pixel at the i-th row and j-th column in the image data, and mark it as P(i, j), where both i and j are non-zero natural numbers and (i, j) is the serial number of P. The RGB color includes R color, G color, and B color, which are respectively marked as CA, CG, and CB; Mark CA, CG, and CB of P(i, j) as CA(i, j), CG(i, j), and CB(i, j) respectively, and ensure that all CA(i, j), CG(i, j), and CB(i, j) are three-digit numbers. If the number is less than three digits, pad zeros at the first digit to convert it to a three-digit number; Combine them in the order of CA(i, j), CG(i, j), and CB(i, j) and convert them into a hexadecimal number. Name the obtained number combination as the first encoding, and mark the first encoding of P(i, j) as H(i, j); Combine the H(i, j) with equal i in ascending order of j to obtain the encoding to be calculated. Each row of pixel points in the image data corresponds to an encoding to be calculated.
[0011] Further, the data encryption unit is configured with a data encryption strategy, and the data encryption strategy includes: When calculating for any encoding to be calculated, name the corresponding encoding to be calculated as the initial encoding; Convert the encryption key into a hexadecimal number according to the ASCII encoding, and name it the key encoding; Number each character in the key encoding in the order from left to right, and represent it by the symbol R1 t , where t is a non-zero natural number and t is the serial number of R1. Add one to R1 t to get R2 t ; Mark the initial encoding as Q. Starting from t = 1, calculate Q / R2 t , and mark the calculation result as K1 t , calculate Q%R2 t , and mark the calculation result as K2 t , arrange K1 t in front of K2 t to get a new encoding and mark it as Q again. Determine whether t is the maximum value of t. If so, output a calculation termination signal; otherwise, output a calculation continuation signal; If a calculation continuation signal is output, add one to t and calculate Q again to update Q until a calculation termination signal is output; If a calculation termination signal is output, name the finally obtained Q as the intermediate encoding and mark it as S; Number the characters in S in order from left to right, represented by the symbol Y h where h is a non-zero natural number and h is the serial number of Y; For each Y h , randomly generate a single-digit number, denoted as L1, L1 is a hexadecimal number and not 0, set the number L2 such that (L1 + L2) % f = Y h , where f is a hexadecimal number, and L1 + L2 is actually a multiple of f plus Y h , the L2 that satisfies the condition is not unique, take the minimum value as L2, L1 will be randomly changed again every first time period, and L2 will be recalculated at the same time; Place L1 in front of L2 to get a new number group, denoted as X h , and combine X h in ascending order of h to obtain the secure ciphertext.
[0012] Furthermore, the dynamic encryption unit is configured with a dynamic encryption policy, and the dynamic encryption policy includes: When the encryption key is updated, restore the secure ciphertext to the encoding to be calculated; Perform dynamic encryption on the encoding to be calculated with the new encryption key.
[0013] Furthermore, the data security transmission module is used to securely transmit the secure ciphertext by constructing a secure transmission channel through secure transmission technology and transmitting the secure ciphertext.
[0014] Furthermore, the data security storage module is used to securely store the secure ciphertext by securely storing the secure ciphertext through blockchain storage technology.
[0015] The beneficial effects of the present invention: The present invention obtains the data in the full-stage data stream of retail credit, names it credit data, generates an encryption key and dynamically updates the encryption key. The advantage is that dynamically updating the encryption key can effectively prevent the encryption key from being leaked, and the encryption key only exists inside the platform and there is no record anywhere, improving the security of the encryption key and the security of the ciphertext when encrypting the plaintext with the dynamic encryption key; The present invention converts text data into a calculation - to - be - encoded data that can be encrypted, and at the same time converts image data into a calculation - to - be - encoded data that can be encrypted. Then, the calculation - to - be - encoded data is dynamically encrypted by an encryption key to obtain a dynamic secure ciphertext. Then, the secure ciphertext is restored and re - encrypted according to the dynamic transformation of the encryption key, the secure ciphertext is securely transmitted, and the secure ciphertext is securely stored. The advantages are that through the conversion, both text data and image data are converted into the same type of calculation - to - be - encoded data, and then the calculation - to - be - encoded data is uniformly encrypted. Moreover, the calculation - to - be - encoded data is obtained through complex transformations and has its own security protection ability. Through further dynamic encryption, a secure ciphertext is obtained, and the secure ciphertext is data that changes in real time, and each character changes in real time, increasing the difficulty of cracking and improving the security and effectiveness of the data stream risk control protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic block diagram of the system of the present invention; Figure 2 is a flowchart of the steps for converting text data into a calculation - to - be - encoded data of the present invention; Figure 3 is a flowchart of the steps for calculating the secure ciphertext of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0018] It should be noted that the terms used herein are only for describing the specific embodiments and are not intended to limit the exemplary embodiments according to the present invention.
[0019] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0020] Embodiment 1. Please refer to Figure 1 As shown, the present application provides a retail credit full - stage data stream risk control system based on microservices, including a credit data acquisition module, a dynamic key update module, a data dynamic encryption module, a data secure transmission module, and a data secure storage module; the credit data acquisition module, the dynamic key update module, the data secure transmission module, and the data secure storage module are respectively connected to the data dynamic encryption module for data connection; The credit data acquisition module is used to acquire data in the full-stage data stream of retail credit and name it credit data; the credit data includes in-bank data, external data, and behavioral data. Among them, the in-bank data includes customer basic information, transaction records, and historical credit records, the external data includes credit investigation data, industrial and commercial data, judicial data, tax data, and social security data, and the behavioral data includes online consumption records and geographical locations. The credit data as a whole can be divided into two categories, namely text data and image data; In practical applications, the credit data includes various types of data, but the data presentation forms are usually divided into two categories: text data and image data. Moreover, the credit data usually contains the personal identity information of the borrower. Therefore, it is necessary to perform full-stage data protection on it.
[0021] The dynamic key update module is used to generate an encryption key and dynamically update the encryption key; The dynamic key update module is configured with a dynamic key update policy, and the dynamic key update policy includes: Create a key element pool, which includes all numbers, uppercase letters, lowercase letters, and punctuation marks; Create a key queue with a first number of digits, number the characters in the key queue in order from left to right, and use the symbol PW n to represent, where n is a non-zero natural number and n is the serial number of PW, 1≤n≤the first number; Assign a value to each PW n Each time a value is assigned, randomly select a character from the key element pool for assignment, and arrange and combine the finally assigned PW n in ascending order of n to obtain the encryption key; The encryption key will become invalid and be randomly generated again every first update period; In practical applications, the punctuation marks in the key element pool only include the symbols that exist in the ASCII encoding table, rather than including all special symbols. The first number is usually set by the platform administrator, and the first number can take a certain range so that it also changes once every first update period. The first update period is also set by the platform administrator. In this embodiment, the first number is set to be from 10 to 18, which means that each time the encryption key needs to be updated, a random number will be drawn from 10 to 18 as the first number. The first update period is set to 7 days, that is, the encryption key is changed once a week; assume that the current first number is 10, that is, obtain PW n , 1≤n≤10, and the encryption key obtained by assigning a value to each PW n is ".f4Sd6fn;F", excluding the outermost quotation marks. The outermost quotation marks are only used to limit the components of the encryption key to prevent confusion with other punctuation marks or text content in this embodiment.
[0022] The data dynamic encryption module is used to perform dynamic encryption on credit data. First, the credit data is subjected to complex transformation to obtain the encoding to be calculated, and then the encoding to be calculated is dynamically encrypted with an encryption key to obtain a dynamic secure ciphertext. At the same time, after the encryption key is updated, the secure ciphertext is restored to the encoding to be calculated and encrypted again. The data dynamic encryption module includes a text data transcoding unit, an image data transcoding unit, a data encryption unit, and a dynamic encryption unit; The text data transcoding unit is used to convert text data into the encoding to be calculated that can be encrypted; The text data transcoding unit is configured with a text data transcoding strategy, and the text data transcoding strategy includes: Obtain the text data, convert each character of the text data into a hexadecimal digital combination according to the Unicode encoding, and mark it as C m , where m is a non-zero natural number and m is the serial number of C; Preset the conversion code, marked as A, and calculate C m / A, and mark the calculation result as B1 m , and at the same time calculate C m %A, and mark the calculation result as B2 m , where % is the modulo operator; Place B1 m before B2 m and form a new digital combination, marked as D m , for all C m Calculate D m ; All D m are composed of four-digit numbers. Replace the first digit and the third digit in D m to obtain E m ; Calculate E m / A, and mark the calculation result as B3 m , and at the same time calculate E m %A, and mark the calculation result as B4 m ; Place B3 m before B4 m and form a new digital combination, marked as F m , for all E m Calculate F m , and arrange and combine F m in ascending order of m to obtain the encoding to be calculated; In practical applications, to further illustrate the process of converting text data into the encoding to be calculated and to briefly express the results of each calculation stage in this embodiment, only a small amount of text data is used as an example in this embodiment. For example, the text data is "borrower's mobile phone number" (without quotation marks). After conversion according to the text, C1 to C6 are respectively 501f, 8d37, 4eba, 624b, 673a, and 53f7, and the conversion code A is set to ff. Since ff + 1 is 100, setting the conversion code to ff can ensure that the calculated B1 m and B2 m are both at most two-digit numbers. If they are less than two digits, zero can be filled in the first digit. For example, when analyzing and calculating C1, the calculated B11 and B21 are respectively 50 and 6f, and D1 is obtained as 506f. Then, after replacement, E1 is 605f. Then, the calculated B31 and B41 are respectively 60 and bf, and the combination gives F1 as 60bf. Similarly, F2 to F6 are calculated to be ce52, 0f58, a310, a809, and 449f in sequence. Finally, the encoding to be calculated is "605fce520f58a310a809449f" (without quotation marks); The image data transcoding unit is used to convert image data into the encoding to be calculated that can perform data encryption; The image data transcoding unit is configured with an image data transcoding strategy, and the image data transcoding strategy includes: Obtain the RGB color of the pixel point at the i-th row and j-th column in the image data, and mark it as P(i, j), where both i and j are non-zero natural numbers and (i, j) is the serial number of P. The RGB color includes R color, G color, and B color, which are respectively marked as CA, CG, and CB; Mark CA, CG, and CB of P(i, j) as CA(i, j), CG(i, j), and CB(i, j) respectively, and it is necessary to ensure that all CA(i, j), CG(i, j), and CB(i, j) are three-digit numbers. If they are less than three digits, they can be converted to three-digit numbers by filling zero in the first digit; Combine them in the order of CA(i, j), CG(i, j), and CB(i, j) and convert them into hexadecimal numbers. Name the obtained number combination as the first encoding, and mark the first encoding of P(i, j) as H(i, j); Combine the H(i, j) with equal i in ascending order of j to obtain the encoding to be calculated. Each row of pixel points in the image data corresponds to a encoding to be calculated; In practical applications, a microservices architecture is adopted in this embodiment, which can simultaneously convert the pixel points in each row of the image data to obtain the encoding to be calculated for each row, and can simultaneously perform dynamic encryption on the encoding to be calculated for each row. Assuming that there are 3 pixel points in the first row of the image data, namely P(1,1), P(1,2), and P(1,3), and CA(1,1), CG(1,1), and CB(1,1) are 210, 144, and 158 respectively, CA(1,2), CG(1,2), and CB(1,2) are 213, 145, and 156 respectively, and CA(1,3), CG(1,3), and CB(1,3) are 204, 155, and 142 respectively. Taking P(1,1) as an example, the combined H(1,1) is 210144158, which is converted to hexadecimal as c868b9e. When converting to hexadecimal, ensure that H(i,j) has seven digits, and for those with insufficient digits, still fill zeros at the first place. Only by limiting each CA(i,j), CG(i,j), and CB(i,j) to three digits and H(i,j) to seven digits can the corresponding value of each color value be found during restoration. Therefore, it is necessary to perform zero-padding operations on CA(i,j), CG(i,j), and CB(i,j) with insufficient three digits. Finally, the encoding to be calculated is "c868b9ecb45644c2b2906", without quotes. The data encryption unit is used to perform dynamic encryption on the encoding to be calculated through an encryption key to obtain a dynamic secure ciphertext. The data encryption unit is configured with a data encryption policy, and the data encryption policy includes: When calculating for any encoding to be calculated, name the corresponding encoding to be calculated as the initial encoding. Convert the encryption key to a hexadecimal number according to the ASCII encoding and name it the key encoding. Number each character in the key encoding in order from left to right, and represent it by the symbol R1 t where t is a non-zero natural number and t is the serial number of R1. Increment R1 t by one to get R2 t ; Mark the initial encoding as Q, start with t = 1, calculate Q / R2 t , mark the calculation result as K1 t , calculate Q%R2 t , mark the calculation result as K2 t , arrange K1 t in front of K2 t to get a new encoding and mark it as Q again. Determine whether t is the maximum value of t. If so, output a calculation termination signal; otherwise, output a calculation continuation signal. If the calculation continue signal is output, increment t by one and calculate Q again to update Q until the calculation termination signal is output; If the calculation termination signal is output, name the finally obtained Q as the intermediate code and mark it as S; In practical applications, the analysis and calculation processes for the encoding to be calculated are all the same, without difference between literal data and image data. Therefore, in this embodiment, only the encoding to be calculated "c868b9ecb45644c2b2906" is taken as the initial encoding as an example to illustrate the dynamic encryption process. The encryption key is converted to obtain the key code as 2E6634536436666E3B46, and numbered to get R11 to R1 20 , add one to R1 t Adding one is to prevent R1 t from being 0, resulting in an empty calculation result, while adding one to R1 t has a maximum of 10. When calculating, the remainder has a maximum of single-digit f, which can ensure that the remainder in each calculation process can be found during decryption. Q is c868b9ecb45644c2b2906, and the calculated K11 and K21 are 64345CF65A2B22615948 and 0 respectively. Combining them gives the new Q as 64345CF65A2B226159480. At this time, t is 1, not the maximum value of t. Increment t by one and calculate again, and so on. Finally, the intermediate code S obtained is 12C7E0BF4B85A7AE595692E5964D3; Number the characters in S in order from left to right, represented by the symbol Y h , where h is a non-zero natural number and h is the serial number of Y; For each Y h , randomly generate a single-digit number, marked as L1. L1 is a hexadecimal number and not 0. Set the number L2 such that (L1 + L2) % f = Y h , where f is a hexadecimal number. L1 + L2 is actually a multiple of f plus Y h . The L2 that satisfies the condition is not unique. Take the minimum value as L2. L1 will randomly change again every first time period, and L2 is recalculated at the same time; Place L1 in front of L2 to get a new number group, marked as X h , and combine X h in ascending order of h to obtain the secure ciphertext; In practical applications, through numbering, Y1 to Y 29 are obtained. Taking Y1 as an example, Y1 is 1. Randomly generate L1 as c. Set the number L2 such that (c + L2) % f = 1, that is, L2 is at least 4. Get X1 as c4. For each Y hAfter analysis and combination, the final secure ciphertext can be obtained; The dynamic encryption unit is used to restore and re-encrypt the secure ciphertext according to the dynamic transformation of the encryption key; The dynamic encryption unit is configured with a dynamic encryption policy, and the dynamic encryption policy includes: When the encryption key is updated, restore the secure ciphertext to the encoding to be calculated; Dynamically encrypt the encoding to be calculated with the new encryption key; In practical applications, the dynamic encryption unit actually restores and re-encrypts the secure ciphertext after the encryption key is updated.
[0023] The data security transmission module is used to securely transmit the secure ciphertext; the data security transmission module is used to securely transmit the secure ciphertext by constructing a secure transmission channel through secure transmission technology and transmitting the secure ciphertext; In practical applications, a secure transmission channel is constructed through existing secure transmission technologies to ensure the security of the data transmission of the secure ciphertext within the retail credit platform.
[0024] The data security storage module is used to securely store the secure ciphertext; the data security storage module is used to securely store the secure ciphertext by securely storing the secure ciphertext through blockchain storage technology; In practical applications, the secure ciphertext is securely stored through existing blockchain storage technologies, and when storing, the secure ciphertexts of text data and image data are stored separately. The secure ciphertexts of different rows of the same image data are separated by line breaks, while the secure ciphertexts of different image data are separated in the form of blank lines.
[0025] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc. These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, and the instruction device implements the functions specified in one process Figure 1 one process or multiple processes and / or boxes Figure 1 or the functions specified in multiple boxes or boxes.
[0026] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings, direct couplings, or communication connections between each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
Claims
1. A micro-service-based risk control system for the entire stage data flow of retail credit, characterized in that, It includes a credit data acquisition module, a dynamic key update module, a data dynamic encryption module, a data secure transmission module, and a data secure storage module; the credit data acquisition module, the dynamic key update module, the data secure transmission module, and the data secure storage module are respectively data-connected to the data dynamic encryption module; The credit data acquisition module is used to acquire data in the full-stage data stream of retail credit and name it credit data; The dynamic key update module is used to generate an encryption key and dynamically update the encryption key; The data dynamic encryption module is used to dynamically encrypt the credit data. First, the credit data is subjected to complex transformation to obtain a to-be-calculated code, and then the to-be-calculated code is dynamically encrypted through the encryption key to obtain a dynamic secure ciphertext. At the same time, after the encryption key is updated, the secure ciphertext is restored to the to-be-calculated code and re-encrypted; The data secure transmission module is used to securely transmit the secure ciphertext; The data secure storage module is used to securely store the secure ciphertext.
2. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 1, wherein The credit data includes in-bank data, external data, and behavior data. Among them, the in-bank data includes customer basic information, transaction records, and historical credit records. The external data includes credit investigation data, industrial and commercial data, judicial data, tax data, and social security data. The behavior data includes online consumption records and geographical locations. The credit data as a whole can be divided into two categories, namely text data and image data.
3. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 1, characterized in that The dynamic key update module is configured with a dynamic key update strategy, and the dynamic key update strategy includes: Create a key element pool, and the key element pool includes all numbers, capital letters, lowercase letters, and punctuation marks; Create a key queue having a first number of bits, number the characters in the key queue in order from left to right, and represent it by the symbol PW n where n is a non-zero natural number and n is the serial number of PW, and 1 ≤ n ≤ the first number; For each PW n Assign a value. Each time a value is assigned, a character is randomly selected from the key element pool for assignment. The PW after the final assignment n Is arranged and combined in ascending order of n to obtain the encryption key; The encryption key will become invalid and be randomly generated again every first update period.
4. The risk control system for the entire stage data flow of retail credit based on microservices according to claim 3, wherein, The data dynamic encryption module includes a text data transcoding unit, an image data transcoding unit, a data encryption unit, and a dynamic encryption unit; The text data transcoding unit is used to convert text data into a to-be-calculated code that can be encrypted; The image data transcoding unit is used to convert image data into a to-be-calculated code that can be encrypted; The data encryption unit is used to dynamically encrypt the to-be-calculated code through the encryption key to obtain a dynamic secure ciphertext; The dynamic encryption unit is used to restore and re-encrypt the secure ciphertext according to the dynamic transformation of the encryption key.
5. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 4, characterized in that The text data transcoding unit is configured with a text data transcoding strategy, and the text data transcoding strategy includes: Obtain text data, convert each character in the text data into a hexadecimal digit combination according to the Unicode encoding, and label it as C m , where m is a non-zero natural number and m is the serial number of C; Preset conversion code, labeled as A, calculate C m / A, label the calculation result as B1 m , and calculate C at the same time m %A, label the calculation result as B2 m , where % is the modulo operator; Place B1 m before B2 m and form a new numerical combination, labeled as D m , for all C m Calculate D m ; All D m are composed of four digits. Replace the first digit in D m with the third digit to obtain E m ; Calculate E m / A, and mark the calculation result as B3 m , and at the same time calculate E m %A, and mark the calculation result as B4 m ; Place B3 m before B4 m and form a new numerical combination, labeled as F m , and calculate F m for all E m , arrange the combinations of F m in ascending order of m to obtain the encoding to be calculated.
6. The risk control system for the entire stage data flow of retail credit based on microservices according to claim 5, characterized in that, The image data transcoding unit is configured with an image data transcoding strategy, and the image data transcoding strategy includes: Obtain the RGB color of the pixel point at the i-th row and j-th column in the image data, and mark it as P(i,j), where both i and j are non-zero natural numbers and (i,j) is the serial number of P. The RGB color includes R color, G color, and B color, which are respectively marked as CA, CG, and CB; Mark the CA, CG, and CB of P(i,j) as CA(i,j), CG(i,j), and CB(i,j) respectively, and ensure that all CA(i,j), CG(i,j), and CB(i,j) are three-digit numbers. Those with less than three digits can be converted to three-digit numbers by padding zeros at the first digit; Combine them in the order of CA(i,j), CG(i,j) and CB(i,j) and convert them into hexadecimal numbers. Name the combined numbers the first encoding, and mark the first encoding of P(i,j) as H(i,j). Combine the H(i,j) with equal i in ascending order of j to obtain the encoding to be calculated. Each row of pixel points in the image data corresponds to an encoding to be calculated.
7. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 6, characterized in that, The data encryption unit is configured with a data encryption policy, and the data encryption policy includes: When calculating for any encoding to be calculated, name the corresponding encoding to be calculated the initial encoding; Convert the encryption key into a hexadecimal number according to the ASCII encoding, and name it the key encoding; Number each character in the key code in order from left to right, represented by the symbol R1 t where t is a non-zero natural number and t is the serial number of R1. Add one to R1 t to obtain R2 t ; Mark the initial code as Q, starting from t = 1, calculate Q / R2 t , mark the calculation result as K1 t , calculate Q%R2 t , mark the calculation result as K2 t , arrange K1 t in front of K2 t to obtain a new code and mark it as Q again, determine whether t is the maximum value of t. If so, output a calculation termination signal; otherwise, output a calculation continuation signal If the calculation continue signal is output, increment t by one and calculate Q again and update Q until the calculation termination signal is output; If the calculation termination signal is output, name the finally obtained Q the intermediate encoding and mark it as S; Number the characters in S in order from left to right, represented by the symbol Y h where h is a non-zero natural number and h is the serial number of Y; For each Y h , randomly generate a single-digit number, denoted as L1. L1 is a hexadecimal number and not 0. Set the number L2 such that (L1 + L2) % f = Y h , where f is a hexadecimal number, and L1 + L2 is actually a multiple of f plus Y h , the L2 that meets the condition is not unique. Take the minimum value among them as L2. L1 will be randomly changed again every first time period, and L2 will be recalculated simultaneously; Place L1 in front of L2 to obtain a new number group, marked as X h , and combine X h in ascending order of h to obtain the secure ciphertext.
8. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 7, characterized in that, The dynamic encryption unit is configured with a dynamic encryption policy, and the dynamic encryption policy includes: When the encryption key is updated, restore the secure ciphertext to the encoding to be calculated; Dynamically encrypt the encoding to be calculated with the new encryption key.
9. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 8, wherein The data security transmission module is used to securely transmit the secure ciphertext by constructing a secure transmission channel through secure transmission technology and transmitting the secure ciphertext.
10. The risk control system for the whole-stage data flow of retail credit based on microservices according to claim 9, characterized in that, The data security storage module is used to securely store the secure ciphertext by securely storing the secure ciphertext through blockchain storage technology.
Citation Information
Patent Citations
Cloud platform data encryption transmission method and system
CN111698252A