Data access processing method and device for education platform
By setting up a multi-level data processing structure on the education platform, including identity authentication, randomized segmentation and encryption services, the data security and privacy protection issues of the education platform are solved, and efficient and secure data management and sharing are achieved.
Patent Information
- Application Number
- CN202510414513.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-18
AI Technical Summary
Education platforms lack effective security protection mechanisms in data storage and management, and there is a risk of data leakage and privacy violations, and there are imperfect authentication and authorization management, and there are problems with encryption algorithms and key management methods.
The internal communication layer, business logic layer, encryption service layer, identity verification layer and data storage layer are set up on the education platform. Through authentication, data randomization segmentation and encryption processing, data encryption is combined with user private keys to realize secure storage and management of data.
It improves the efficiency and security of data access processing of the education platform, ensures user privacy, and improves the sharing and collaboration of learning experience and educational resources.
Smart Images

Figure CN120337253A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a data access processing method, device and electronic device for an education platform. Background Art
[0002] With the rapid development of information technology, the education industry has embraced the wave of digital transformation, and various education platforms have emerged like mushrooms after rain. These education platforms cover various functions such as online course publishing, learning interaction, exam evaluation, etc., providing learners with more convenient and rich learning resources and learning methods. However, with the continuous increase in the number of users of education platforms and the increasing richness of course resources, data processing has become an important challenge faced by education platforms.
[0003] Education platforms have accumulated a large amount of course data and user behavior data, including course systems, knowledge point association data, user learning records, course evaluations, etc. These data not only have important value for optimizing course content and improving teaching quality, but also can provide personalized learning recommendations for users and enhance the learning experience of users. Therefore, how to efficiently and securely process and manage these data has become a key issue in the development of education platforms.
[0004] The data of education platforms contains a large amount of sensitive information, such as users' personal identity information, learning achievements, etc. However, the existing data storage and management methods often lack effective security protection mechanisms, which are prone to data leakage and privacy infringement. For example, some education platforms may store users' passwords in plain text, and once the database is attacked, sensitive information such as users' passwords will be directly exposed.
[0005] In terms of data access, existing education platforms often lack perfect identity authentication and authorization mechanisms. Some platforms may only use simple usernames and passwords for identity authentication, which are easy to be cracked and cannot effectively guarantee the security of data. At the same time, in terms of authorization management, there is a lack of fine control over different user roles and permissions, resulting in chaotic data access permissions and possible unauthorized access.
[0006] In order to protect the security and privacy of data, education platforms need to encrypt sensitive data. However, existing encryption algorithms and key management methods often have some problems. For example, some platforms may use outdated encryption algorithms, which are easy to be cracked; in terms of key management, there is a lack of effective key generation, storage and distribution mechanisms, resulting in a relatively high risk of key leakage.
[0007] The above problems have become technical problems that need to be solved. Summary of the Invention
[0008] In view of this, an embodiment of the present invention provides a data access processing method, device and electronic device for an education platform, which at least partially solve the problems existing in the prior art.
[0009] In a first aspect, an embodiment of the present invention provides a data access processing method for an education platform, comprising the following steps:
[0010] After encapsulating the course publishing model and course interaction model obtained from the outside, an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer and a data storage layer corresponding to the course publishing model and the course interaction model are set on the education platform;
[0011] Connect the course publishing model with the data storage layer of the education platform, and transfer the course system and knowledge point related data in the course publishing model to the data storage layer of the education platform through the internal communication layer for storage;
[0012] Integrate the course interaction model with the business logic layer. The integrated business logic layer generates course recommendation data based on user behavior data on the education platform.
[0013] When a data access requester initiates an access request to the education platform, the data access requester is authenticated through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data;
[0014] In the data storage layer, the course usage data is randomly segmented and merged with the anonymous identifier. In the encryption service layer, the merged data is encrypted using the user private key carried by the data access requester to form encrypted course data. The encrypted course data is published through the internal communication layer within the group to which the data access requester belongs.
[0015] According to a specific implementation of an embodiment of the present invention, the internal communication layer, business logic layer, encryption service layer, identity authentication layer and data storage layer corresponding to the course publishing model and the course interaction model are set on the education platform, including:
[0016] Set up the internal communication layer, business logic layer, encryption service layer, authentication layer and data storage layer in the architecture of the education platform to design functional boundaries and interaction interfaces;
[0017] Evaluate the communication performance of the education platform and, based on the evaluation results, set up transmission protocols and mechanisms for the internal communication layer that match the evaluation results;
[0018] Set business algorithms and processes in the business logic layer, and implement course management, user behavior analysis, and course recommendation functions according to the characteristics of the course release model and the course interaction model;
[0019] Configure the encryption algorithm and key management method of the encryption service layer to ensure the secure storage and distribution of keys;
[0020] Establish an authentication mechanism and authorization policy for the authentication layer, and perform authorization management on accessing users through multiple authentication methods according to user roles and permissions;
[0021] Deploy the database and storage devices of the data storage layer, select a matching database according to the data volume and access frequency stored in the education platform, and set data backup and recovery policies.
[0022] According to a specific implementation manner of an embodiment of the present invention, transmitting the course system and knowledge point association data in the course release model to the data storage layer of the education platform through the internal communication layer for storage includes:
[0023] Check and clean the format of the course system and knowledge point association data in the course release model, and remove invalid data and duplicate data;
[0024] Establish a data transmission channel in the internal communication layer, and encrypt the data using an encryption protocol to prevent the data from being stolen or tampered with during transmission;
[0025] Convert and map the course system and knowledge point association data according to the database structure of the data storage layer, and store the converted and mapped data in the database of the data storage layer.
[0026] According to a specific implementation manner of an embodiment of the present invention, integrating the course interaction model with the business logic layer, and the integrated business logic layer generates course recommendation data according to the behavior data of users on the education platform, including:
[0027] Collect and organize the behavior data of users on the education platform to establish a user behavior data set, and the user behavior data set includes the browsing records, learning records, and examination scores of users;
[0028] Analyze and understand the course interaction model, and extract the features and rules related to user behavior and course recommendation therein;
[0029] Integrate the course interaction model with the algorithms and processes of the business logic layer, and design a course recommendation algorithm according to the user behavior data set and the rules of the course interaction model;
[0030] Extract course data from the database of the education platform according to the course recommendation algorithm to form course recommendation data.
[0031] According to a specific implementation manner of an embodiment of the present invention, the authentication of the data access requester by the authentication layer includes:
[0032] When the data access requester initiates an access request, the authentication layer first extracts the identity identification information in the request, and according to the extracted identity identification information, looks up the corresponding user information in the authentication database to verify the validity and legality of the identity identification;
[0033] Monitor and audit the authentication process in real time, and record the time, result, and IP address information of the authentication;
[0034] If the authentication fails, the authentication layer returns an error message to the data access requester and restricts the number of access times of the data access requester according to a preset policy;
[0035] If the authentication is successful, the authentication layer generates a unique identity token and returns it to the data access requester for subsequent data access authorization.
[0036] According to a specific implementation manner of an embodiment of the present invention, the binding operation of the course recommendation data and the data access requester in the data storage layer to generate course usage data includes:
[0037] According to the identity token returned by the authentication layer, look up the corresponding user information and course recommendation data in the data storage layer;
[0038] Screen and sort the course recommendation data, and select the course recommendation information suitable for the user according to the user's historical behavior and preferences;
[0039] Associate the screened course recommendation data with the user information of the data access requester to establish a mapping relationship between the course recommendation data and the user;
[0040] Create a course usage data record in the data storage layer, and store the course recommendation data, user information, and access time information in the record;
[0041] Encrypt and protect the course usage data, use a symmetric encryption algorithm to encrypt sensitive information, and establish an index and association relationship in the data storage layer for querying and statistical analysis of the course usage data.
[0042] According to a specific implementation manner of an embodiment of the present invention, in the data storage layer, perform a randomized segmentation process on the course usage data and fuse the segmented data with an anonymous identifier, including:
[0043] Perform feature analysis on the course usage data to determine the fields and data ranges that need to be segmented;
[0044] Use a randomization algorithm to split the course usage data into multiple small chunks, with each chunk containing different features and data information;
[0045] Generate a unique anonymous identifier for each split data chunk, where the anonymous identifier is generated using a hashing algorithm or a random number generator;
[0046] Associate the split data chunks with their corresponding anonymous identifiers to ensure a one-to-one correspondence between the data chunks and the anonymous identifiers;
[0047] Reorganize and integrate the fused data by recombining the associated anonymous identifiers and data chunks into a new data structure, and back up and store the fused data in the data storage layer.
[0048] According to a specific implementation manner of an embodiment of the present invention, encrypting the fused data using the user private key carried by the data access requester in the encryption service layer to form encrypted course data, including:
[0049] Obtain the fused data and the user private key information of the data access requester from the data storage layer;
[0050] After verifying the legitimacy of the user private key, encrypt the fused data using the user private key;
[0051] Return the encrypted course data to the internal communication layer for publication and sharing within the group to which the data access requester belongs.
[0052] In a second aspect, an embodiment of the present invention also provides a data access processing device for an educational platform, including:
[0053] A setting module that encapsulates the course release model and the course interaction model obtained from the outside, and sets an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer, and a data storage layer corresponding to the course release model and the course interaction model on the educational platform;
[0054] A storage module that docks the course release model with the data storage layer of the educational platform, and transmits the course system and knowledge point association data in the course release model to the data storage layer of the educational platform for storage through the internal communication layer;
[0055] A generation module that fuses the course interaction model with the business logic layer, and the fused business logic layer generates course recommendation data based on the behavior data of the user on the educational platform;
[0056] The verification module, when the data access requester initiates an access request to the education platform, authenticates the data access requester through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data;
[0057] The execution module randomly segments the course usage data at the data storage layer and merges the segmented data with the anonymous identifier. At the encryption service layer, the merged data is encrypted using the user private key carried by the data access requester to form encrypted course data, and the encrypted course data is published through the internal communication layer within the group to which the data access requester belongs.
[0058] In a third aspect, an embodiment of the present invention further provides an electronic device, the electronic device comprising:
[0059] at least one processor; and,
[0060] a memory communicatively connected to the at least one processor; wherein,
[0061] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method described in any of the first aspects or any of the implementations of the first aspect.
[0062] In a fourth aspect, an embodiment of the present invention further provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the method described in the first aspect or any implementation of the first aspect.
[0063] In the fifth aspect, an embodiment of the present invention further provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer executes the method described in the first aspect or any implementation of the first aspect.
[0064] The present invention realizes efficient storage, management and processing of data by encapsulating the course publishing model and the course interaction model, setting multiple layers such as internal communication layer, business logic layer, encryption service layer, identity authentication layer and data storage layer; generates personalized course recommendation data by integrating the course interaction model and the business logic layer; ensures the security of data access by improving the identity authentication and authorization mechanism; and protects the security and privacy of data by adopting advanced encryption algorithms and privacy protection technologies. The implementation of the present invention will help improve the data access processing efficiency and quality of the education platform, enhance the user's learning experience, and promote the sharing and collaboration of educational resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0066] Figure 1 It is a schematic flowchart of a data access processing method for an education platform provided by an embodiment of the present invention;
[0067] Figure 2 It is a schematic flowchart of another data access processing method for an education platform provided by an embodiment of the present invention;
[0068] Figure 3 It is a schematic structural diagram of a data access processing device for an education platform provided by an embodiment of the present invention;
[0069] Figure 4 It is a schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0070] The embodiments of the present invention will be described in detail below with reference to the drawings.
[0071] Refer to Figure 1 and Figure 2 , an embodiment of the present invention provides a data access processing method for an education platform, which includes the following steps:
[0072] S101, after encapsulating the course release model and the course interaction model obtained from the outside, an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer, and a data storage layer corresponding to the course release model and the course interaction model are set on the education platform.
[0073] The course release model and the course interaction model can be obtained from external data sources, such as cooperative education content providers, academic institutions, etc.
[0074] Adopting the encapsulation idea of object-oriented programming, the relevant attributes and methods of the course release model and the course interaction model are packaged. Create specific classes or data structures for the models, hide the internal implementation details of the models, and only provide necessary interfaces externally. For example, for the course release model, functions such as course creation, editing, and release can be encapsulated in a class and called through specific function interfaces for subsequent operations, which can improve the security and maintainability of the models.
[0075] According to the overall architecture of the education platform, plan the topology of the internal communication layer. If the platform adopts a distributed architecture, the communication layer needs to support efficient data transmission between multiple nodes. Select a suitable communication protocol, such as the TCP / IP protocol, to ensure the reliability of data transmission.
[0076] Develop communication interfaces adapted to the course release model and the course interaction model. For example, design an interface for the course release model to transmit course system update information, and design an interface for the course interaction model to receive the reporting of user behavior data. The interfaces should have good compatibility and scalability, so that when subsequent model upgrades or new functions are added, there is no need to modify the communication layer code on a large scale.
[0077] Based on the business processes of the education platform, sort out the logic related to course release and interaction. Divide the business logic into multiple modules, such as the course management module (responsible for the logic of course review, online / offline, etc. related to the course release model), and the user behavior analysis module (processing data such as user learning trajectories and evaluations based on the course interaction model).
[0078] Integrate various algorithms in the business logic layer, such as the course recommendation algorithm (used to combine the course interaction model and user behavior data to generate recommended content), and the course quality assessment algorithm (assisting the course release model to quantitatively evaluate the quality of course content). These algorithms need to be fully tested and optimized to ensure high efficiency and accuracy under a large amount of data processing.
[0079] Evaluate and select encryption algorithms suitable for the data security requirements of the education platform, such as AES (Advanced Encryption Standard) for symmetric encryption of data, and RSA for asymmetric encryption scenarios, such as the generation and data encryption / decryption of user private keys and public keys. The encryption algorithm should have high-intensity security and reasonable computational complexity, balancing the encryption effect and system performance.
[0080] Build a key management system responsible for generating, storing, distributing, and updating encryption keys. For user private keys, adopt a secure storage method, such as encrypted storage in a dedicated key library, and set strict access control permissions. Regularly update the keys to reduce the risk of key leakage and ensure the security of data encryption.
[0081] Select multiple authentication methods, such as the combination of username and password, digital certificate verification, third-party authentication (such as WeChat login, QQ login, etc.), and integrate them into the education platform. For username and password verification, store passwords using methods such as salted hashing to prevent the leakage of password plaintext. For digital certificate verification, a certificate verification environment needs to be built to ensure the legality and validity of the certificates.
[0082] Establish a management system based on user roles and permissions. According to the user types of the education platform, such as students, teachers, administrators, etc., different permissions are assigned to different roles. For example, students only have the permissions for course learning and evaluation, teachers can not only teach but also publish and manage courses, and administrators have the highest permissions for system configuration and global management. Through the association of the permission table and the user table, user permissions are verified simultaneously during authentication to ensure the security and compliance of data access.
[0083] According to factors such as the data scale, data type, and access frequency of the education platform, select a suitable database management system. For example, the relational database MySQL is used to store structured course information and user information, and the non-relational database MongoDB is used to store unstructured or semi-structured user behavior data, course document materials, etc. Design the database table structure to match the course publishing model and the course interaction model. For example, create a course table to store the basic course information in the course publishing model, a knowledge point table to store the associated knowledge point data, and a user behavior record table to store the user operation behavior data in the course interaction model.
[0084] Adopt optimization means such as data indexing and caching mechanisms to improve data storage and retrieval efficiency. For frequently queried course information, establish appropriate indexes in the database, such as course name indexes and course category indexes. Introduce caching technologies, such as Redis caching, to cache popular course data, common user permission information, etc., reduce the direct access pressure on the database, and improve the system response speed.
[0085] The internal communication layer is responsible for data transmission and interaction between different components and modules within the education platform. It is the bridge for communication between different layers of the platform. Through specific communication protocols and interfaces, it ensures that data is accurately and efficiently transmitted between different layers. For example, it can timely transmit the course update information in the course publishing model to the data storage layer for storage, and at the same time transmit the behavior data generated by users in the course interaction model to the business logic layer for analysis.
[0086] The business logic layer is the layer that bears the core business rules and logic of the education platform. It processes and analyzes the obtained data according to the business requirements of the platform to achieve various business functions. For example, by combining the course interaction model with user behavior data and using course recommendation algorithms to generate personalized course recommendation data to meet the diverse learning needs of users, it is the key to the platform to achieve educational service functions.
[0087] The encryption service layer focuses on data encryption and decryption operations to ensure the security of platform data during storage and transmission. By selecting appropriate encryption algorithms and building a key management system, sensitive data is encrypted to prevent data from being stolen or tampered with. For example, user private keys, sensitive teaching materials in courses, etc. are encrypted for storage and transmission, and only authorized users can decrypt and obtain the data with the correct key.
[0088] The authentication layer is used to verify the identity of data access requesters and allocate corresponding permissions according to their identities. It adopts multiple authentication methods and constructs a perfect permission management system to ensure that only legitimate users can access platform data, and users can only operate within their permitted scope. For example, it prevents students from accessing teachers' course management functions beyond their authority, maintaining the data security and operation order of the platform.
[0089] The data storage layer is responsible for storing various types of data generated and used by the education platform, including data related to the course release model and the course interaction model. By reasonably selecting the database and optimizing the storage structure, efficient data storage and fast retrieval are achieved. For example, structured data such as the course system and knowledge point association data are stored in a relational database for complex query and data association operations; unstructured data such as user behavior data are stored in a non-relational database to adapt to the flexible data format characteristics.
[0090] S102, interface the course release model with the data storage layer of the education platform, and through the internal communication layer, transmit the course system and knowledge point association data in the course release model to the data storage layer of the education platform for storage.
[0091] The course system and knowledge point association data in the course release model may have specific data formats, while the database used by the data storage layer has its own supported standard formats. Therefore, data format adaptation and conversion are required first. For example, if the course system is described in XML format in the course release model and the data storage layer uses the relational database MySQL, then a data conversion script needs to be written to parse and convert the XML data into a format suitable for the MySQL table structure. Technologies such as XSLT (Extensible Stylesheet Language Transformations) can be used to convert XML data into CSV (Comma-Separated Values) format that conforms to the database table structure for subsequent import into the database.
[0092] During the conversion process, special attention should be paid to the integrity and accuracy of the data. For key information such as the hierarchical relationship in the course system and the dependency relationship between knowledge points, it is necessary to ensure that they can be correctly mapped to the table structure of the database after conversion. For example, the chapter and sub-chapter relationship in the course system can be represented by creating parent and child tables in the database and using foreign keys for association.
[0093] Before transmitting the associated data of the curriculum system and knowledge points to the data storage layer, communication parameters need to be configured, such as setting the timeout for data transmission, buffer size, etc. For example, set a reasonable timeout of 30 seconds to prevent long waits for data transmission due to network latency or other reasons. At the same time, adjust the buffer size according to the size of the data. If the data volume is large, the buffer can be appropriately increased to improve data transmission efficiency.
[0094] Use the interfaces developed by the internal communication layer to construct a data transmission request. For the curriculum system update information in the curriculum release model, according to the interface specifications, encapsulate the curriculum system data into a specific data structure, such as a JSON-formatted data packet. Add necessary meta-information to the data packet, such as the data source identifier (indicating that it is data from the curriculum release model), data version number, etc., so that the data storage layer can perform verification and processing when receiving the data.
[0095] Start the data transmission task. The internal communication layer establishes a connection with the data storage layer according to the configured communication protocol (such as TCP / IP) and sends the encapsulated data. During the transmission process, adopt a reliable transmission mechanism, such as using the confirmation and retransmission mechanism of the TCP protocol, to ensure that the data arrives at the data storage layer accurately and without error. At the same time, monitor the data transmission progress in real time. The real-time status of data transmission can be displayed to the administrator on the management interface of the education platform by recording the ratio of the number of bytes of data already transmitted to the total number of data bytes.
[0096] After the data storage layer receives the data from the internal communication layer, it first performs data integrity verification. According to the previously added meta-information, such as the data version number, check whether the data is the latest version to prevent receiving expired data. At the same time, use the hash value of the data (generated at the sending end and transmitted with the data) to verify whether the data has been tampered with during transmission. For example, use the MD5 or SHA-256 hash algorithm to recalculate the hash value of the received data and compare it with the hash value provided by the sending end.
[0097] Insert the associated data of the curriculum system and knowledge points into the corresponding database tables according to the pre-designed database table structure. For curriculum system data, it can be inserted into relevant tables such as the curriculum table and chapter table. During the insertion process, use the transaction mechanism of the database to ensure data consistency. For example, if the curriculum system data involves insert operations in multiple tables, place these operations in a single transaction. If any one of the insert operations fails, the entire transaction will roll back to ensure that the data does not show inconsistent situations where only part of the data is inserted successfully.
[0098] Establish necessary indexes for the curriculum system and knowledge point association data to improve the efficiency of subsequent data query and retrieval. For example, in the course schedule, establish an index for the course name field to facilitate quick query of course information based on the course name; in the knowledge point table, establish a composite index for the knowledge point ID and the affiliated course ID to facilitate quick query of all knowledge points under a certain course and their association relationships.
[0099] S103. Integrate the course interaction model with the business logic layer. The integrated business logic layer generates course recommendation data based on the behavior data of users on the education platform.
[0100] It is possible to deeply analyze the structure and functions of the course interaction model, clarify various types of user interaction data it covers, such as the viewing duration of course videos, the number of clicks on the details of knowledge points, and the frequency of participating in discussions in the discussion area. Master the definitions and data recording methods of the model for different interaction behaviors, laying a foundation for subsequent integration.
[0101] Examine the existing architecture and modules of the business logic layer to determine which parts are related to course interaction data processing and course recommendation. For example, check the user information management module, the course information management module, and the data analysis and processing module to ensure that they can be smoothly docked with the course interaction model.
[0102] Develop interfaces that adapt to the course interaction model and the business logic layer. For various types of data output by the course interaction model, design corresponding input interfaces to ensure that the data can enter the business logic layer accurately. At the same time, for the data output after being processed by the business logic layer, design interfaces that are compatible with subsequent processes, such as interfaces with the data storage layer or the user display layer.
[0103] Connect the real-time or near-real-time user interaction data generated by the course interaction model to the business logic layer. Using the designed interfaces, integrate the data scattered in different interaction scenarios into the data processing process of the business logic layer. For example, aggregate the operation data of users on different course pages into a unified data structure for subsequent analysis.
[0104] In the business logic layer, organically integrate the logic related to course interaction with the original business logic. For example, in the user behavior analysis module, combine the user behavior analysis rules in the course interaction model with the existing user portrait construction logic in the business logic layer. When a user completes a course viewing behavior, not only update the viewing duration data in the course interaction model but also update the activity index of the user portrait in the business logic layer.
[0105] Introduce and integrate algorithms suitable for course recommendation into the business logic layer. For example, collaborative filtering algorithms can predict courses that users may be interested in based on the similarities between users and their interactive behaviors on courses. Use the user interest preference data in the course interaction model as the input of the collaborative filtering algorithm, and combine it with the existing user basic information, historical learning records and other data in the business logic layer to optimize the algorithm and improve the accuracy of recommendations.
[0106] Continuously collect user behavior data on the education platform, including but not limited to course learning progress, test answering, collection and sharing of course resources, etc. Clean the collected data to remove duplicate, erroneous or invalid data. For example, filter out abnormal click behavior data caused by network fluctuations. Then standardize the data and convert different types of behavior data into a unified numerical range to facilitate subsequent analysis and calculation.
[0107] The course recommendation calculation is performed using the fused course interaction model and the algorithms and data of the business logic layer. For example, based on the user's historical course interaction data, their interest preferences are analyzed. If it is found that the user frequently watches programming courses and actively speaks in related discussion forums, it can be judged that the user has a high interest in the programming field. Combined with the consideration of factors such as course popularity and update time in the business logic layer, high-quality programming courses that meet the user's interests are selected from the course library as recommendation candidates.
[0108] The recommended candidate courses are ranked, taking into account a variety of factors, such as the match between the course and the user's interests, the course rating and reputation, and the timeliness of course updates. According to the preset recommendation strategy, the ranked courses are screened to determine the course recommendation data that will be finally displayed to the user. For example, the upper limit of the recommended number is set to 10 courses, and the first 10 courses are selected from the ranked results as the final results recommended to the user, and these data are organized in a specific format so that they can be displayed to the user on the education platform later.
[0109] S104, when the data access requester initiates an access request to the education platform, the data access requester is authenticated through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data.
[0110] When a data access requester initiates an access request to the education platform, the authentication layer first captures the request. Authentication-related information is extracted from the request, such as username, password, digital certificate, or third-party authentication token. For example, if the user chooses to log in with a username and password, the authentication layer extracts the corresponding username and password fields from the login form data of the request.
[0111] Based on multiple authentication methods preset by the platform, determine which method to use to authenticate the requester. If it is the username and password method, compare the extracted username and password with the corresponding records stored in the user information database. Before the comparison, the password needs to be encrypted and matched with the encrypted password stored in the database to prevent security risks caused by the transmission and storage of plaintext passwords. If digital certificate authentication is adopted, the authentication layer will verify the legitimacy of the digital certificate, including whether the certificate is issued by a trusted certificate authority (CA), whether the certificate is within the valid period, and whether the public key of the certificate matches the relevant information provided by the requester. For third-party authentication (such as WeChat login), the authentication layer will interact with the third-party authentication platform, verify the validity of the third-party authentication token, and obtain the relevant identity information of the user on the third-party platform.
[0112] If the authentication is successful, the authentication layer generates a unique identity identifier (such as a token), which will be used to identify the requester's identity in subsequent operations. At the same time, record the relevant information of the successful authentication, such as the authentication time, the IP address of the requester, etc., for subsequent security audits. If the authentication fails, the authentication layer returns an error message to the requester, indicating the reason for the authentication failure, such as incorrect username or password, invalid certificate, etc., and according to the platform security policy, it may take restrictive access measures against requesters who fail the authentication continuously for multiple times, such as temporarily blocking the IP address for a period of time.
[0113] After the authentication is successful, according to the generated identity identifier, obtain the corresponding course recommendation data of the requester from the data storage layer. The course recommendation data was previously generated by integrating the course interaction model and the business logic layer, and may include information such as a list of recommended courses and the matching score between the courses and the user's interests. At the same time, confirm the unique identifier information of the data access requester, such as the user ID, for accurate binding operations.
[0114] In the data storage layer, establish an association relationship between the course recommendation data and the data access requester. For example, create a new course usage data association table in the database, which contains the user ID of the requester, the ID of the recommended course, and other relevant information, such as the recommendation time and the source of the course recommendation. Record the obtained course recommendation data and the corresponding user ID of the requester in this table to complete the binding operation. Through this binding, the association between each user and the recommended courses can be clearly traced, providing a data basis for subsequent analysis of the user's usage of the recommended courses.
[0115] During the binding operation, utilize the transaction mechanism of the database to ensure data integrity and consistency. If the binding operation involves updates or insertions to multiple database tables, execute these operations within a single transaction. If any one of the operations fails, the entire transaction is rolled back to avoid inconsistent situations where some data is successfully bound while others are not. For example, when inserting a course usage data association record, simultaneously update the usage status of the course recommendation data (such as marking it as received by a certain user). If the status update fails, roll back the operation of inserting the association record to ensure data accuracy and integrity.
[0116] Integrate the bound course recommendation data with the requester information to generate course usage data. In addition to the basic association of user ID and course ID, other information can be added as needed, such as the user's first access time to the recommended course, the user's initial stay time on the course page, etc. This information helps to further analyze the user's course usage behavior. Perform necessary processing on the integrated data, such as standardizing the time format to unify time data from different sources into the time format used internally by the platform.
[0117] Store the generated course usage data in the corresponding location in the data storage layer. Select an appropriate storage method based on the data scale and access frequency, such as a relational database or a non-relational database. In a relational database, create a dedicated course usage data table and design a reasonable table structure to store the course usage data. During the storage process, ensure data accuracy and security. Measures such as data backup and data encryption can be adopted to prevent data loss or unauthorized access. At the same time, record relevant information about data storage, such as storage time and storage location, for convenient subsequent query and management.
[0118] S105, In the data storage layer, perform a randomized segmentation process on the course usage data, and fuse the segmented data with an anonymous identifier. Use the user private key carried by the data access requester in the encryption service layer to encrypt the fused data to form encrypted course data, and publish the encrypted course data through the internal communication layer within the group to which the data access requester belongs.
[0119] In the data storage layer, determine the randomized segmentation strategy for the course usage data according to data security and privacy protection requirements. For example, set a certain ratio (such as 30%, 30%, 40%) to divide the data into different parts, or perform random grouping according to the time sequence of data records, certain characteristic values of the data (such as course category, user activity level, etc.). Assume that based on the course category, the course usage data for programming courses is grouped into one group, and the course usage data for humanities and social science courses is grouped into another group, etc.
[0120] Perform the splitting operation: Write a data processing program to actually split the course usage data according to the determined splitting strategy. If the course usage data is stored in a relational database, the random extraction and grouping of data can be achieved through SQL query statements combined with random functions (such as the RAND() function in MySQL). For example, use the following SQL statement to randomly extract 30% of the data from the course usage data table:
[0121] SELECT*FROM course_usage_data
[0122] ORDER BY RAND()
[0123] LIMIT(SELECT COUNT(*)FROM course_usage_data)*0.3;
[0124] Store the extracted data into different data structures or temporary storage locations respectively to complete the random splitting of the data.
[0125] To protect the privacy of the data subject, a specific algorithm is used to generate an anonymous identifier. For example, use a hash function (such as SHA-256) to process the unique identifier of the user (such as the user ID) or other information that can distinguish different users to generate an anonymous identifier with a fixed length and irreversibility. Due to the characteristics of the hash function, the anonymous identifiers obtained after hashing the identifiers of different users are unique and difficult to reverse back to the original user information.
[0126] Associate and integrate the generated anonymous identifier with the split course usage data. At the data storage layer, a new data table can be created or a field can be added to an existing data table to store the corresponding relationship between the anonymous identifier and the split data. For example, for each group of split data records, add an anonymous identifier field to the new data table and fill in the corresponding anonymous identifier. In this way, the integration of the course usage data and the anonymous identifier is achieved, so that in subsequent processing, even if the data is obtained, it cannot be directly associated with a specific user.
[0127] At the encryption service layer, first obtain the user private key carried in the request information of the data access requester. Before encrypting with the private key, verify the legality of the private key to ensure that the private key has not been tampered with and belongs to the data access requester. It can be verified by comparing with the public-private key pair information pre-stored in the secure key management system or using the relevant information in the digital certificate.
[0128] Select encryption algorithm and encryption operation: Select a suitable encryption algorithm (such as RSA asymmetric encryption algorithm) to encrypt the fused data. The RSA algorithm uses a public key to encrypt data, and only the corresponding private key can decrypt it, ensuring the security of the data. Through the above operations, the encryption of the fused data is completed to form encrypted course data.
[0129] Within the group to which the data access requester belongs, the encrypted course data is published using the internal communication layer. First, determine the group information to which the data access requester belongs, which can be obtained through the user's role, permission, or specific group identification field. For example, student users may belong to different class groups, and teacher users may belong to different subject teaching and research groups. Then, based on the internal communication architecture of the education platform, determine the path and method for communicating with other members in the group.
[0130] Using the interface and communication protocol provided by the internal communication layer, the encrypted course data is sent to other members of the group to which the data access requester belongs. For example, if the internal communication layer is implemented based on the message queue mechanism, the encrypted course data is sent as the message content to the message queue of the corresponding group, and the members of the group obtain the encrypted course data by subscribing to the message queue. During the publishing process, the integrity and reliability of data transmission can be ensured by using message confirmation and retransmission mechanisms. At the same time, relevant information about data publishing, such as publishing time, recipient group, etc., is recorded for subsequent data tracking and management.
[0131] At the same time, participate Figure 2 The embodiment of the present invention further provides a security verification method for authenticating the data access requester in step S104, comprising:
[0132] S1041: The business logic layer processes the access request through an authentication algorithm.
[0133] When the requester initiates an access request to the course data in the data storage layer, the business logic layer calls the authentication algorithm to process the request.
[0134] The business logic layer is in a key position in the software system architecture, and is mainly responsible for processing business rules and logic. It receives requests from the presentation layer (usually the interface for users to interact with the system), calls the corresponding business logic components for processing according to the preset business rules, and finally returns the processing results to the presentation layer. In this education platform scenario, the business logic layer focuses on processing various operations related to course data, such as identifying whether the access request is legal and generating course recommendations based on user behavior.
[0135] An authentication algorithm is an algorithm specifically used to verify and identify the identity or permissions of data access requesters. By analyzing and verifying various information provided by the requester, such as username, password, digital certificate, etc., it determines whether the requester has the permission to access specific course data. Authentication methods include verifying the authenticity of the user's identity, checking whether their permission level is sufficient, verifying the validity of digital signatures, etc.
[0136] S1042: Business logic layer mining node determination and blockchain recording operation.
[0137] The data owner develops a mining node determination algorithm in the business logic layer. Based on the course usage data and in accordance with the course usage rules, mining nodes are selected. In the blockchain network, there are numerous nodes, and each node has a certain computing and storage capacity. The role of the mining node determination algorithm is to select appropriate nodes from these nodes to be responsible for mining and processing the course usage data. This algorithm usually comprehensively considers multiple factors, such as the computing power of the node, the storage capacity, the relevance to the course data, etc. Through these rules and conditions, a most suitable node is finally determined to execute the mining task.
[0138] In the blockchain, data is summarized and verified through hashing. The obtained root hash value, timestamp, hash value of the previous block, anonymous identifier, and average course usage value result are recorded in the block header of the new block.
[0139] In the Merkle tree structure of the blockchain, the course usage data forms leaf nodes after hashing. By performing layer-by-layer hashing calculations on these leaf nodes, the hash value at the top of the tree, which is the root hash value, is finally obtained. The root hash value can uniquely identify the entire data set. As long as any data in the data set changes, the root hash value will change, so that it can quickly detect whether the data has been tampered with.
[0140] The blockchain is a chain formed by connecting blocks in chronological order. Each block contains the hash value of the previous block. In this way, an immutable chain structure is formed, ensuring the integrity and traceability of the blockchain. Once a certain previous block is modified, its hash value will change, and then the hash value referenced in the subsequent blocks will not match, resulting in the failure of the entire chain verification.
[0141] An anonymous identifier is an identifier used to identify the data subject without revealing their true identity. In scenarios that pay attention to user privacy protection, anonymous identifiers are very important. For example, in course usage data, anonymous identifiers are used to distinguish the behavior data of different users, but sensitive information such as the user's name and ID number will not be directly displayed. In this way, user data can be tracked and processed while protecting user privacy.
[0142] The average course usage value is an important indicator obtained through statistical analysis of course usage data, which is used to reflect the average usage of courses by users. This indicator may incorporate information from multiple dimensions, such as the learning duration of the course, the number of visits, the completion of assignments, etc. By calculating the average course usage value, one can understand the user's participation and learning effect in the course, providing a reference for course optimization and recommendation.
[0143] S1043: Perform privacy protection operations during data transmission.
[0144] During the process of data transmission to the blockchain, differential privacy technology is integrated at the smart contract layer. The smart contract layer is the layer in the blockchain system specifically used for deploying and executing smart contracts. Smart contracts exist in the form of code and will automatically execute corresponding operations once the preset conditions are met, without the need for third-party intervention. In the scenario of this educational platform, the smart contract layer is used to implement functions such as privacy protection during data transmission, execution of access control policies, and monitoring of digital certificates.
[0145] During the process of data sharing and analysis, it is necessary to obtain valuable information while protecting the privacy of data subjects. Differential privacy technology perturbs the original data by adding noise to the data, so that even if an attacker obtains part of the data, it is difficult to accurately infer the sensitive information of individuals.
[0146] In the scenario of this course data, the distribution characteristics of course usage data can be analyzed through clustering technology. For example, users can be classified according to learning behaviors, interests, etc., and users with similar learning habits and the same preference for course types can be grouped into one category. This helps to better understand the structure and rules of the data, providing a basis for subsequent privacy protection and data processing.
[0147] Use the Laplace mechanism to generate noise and add it to the model parameters by weighted average. The working principle of the Laplace mechanism is to add noise that follows the Laplace distribution to the original data. By controlling the magnitude of the added noise, a balance can be found between protecting privacy and ensuring data availability. Specifically, the Laplace mechanism will determine the scale of the added noise based on the sensitivity of the data and the privacy budget, effectively protecting data privacy while minimizing the impact on data availability.
[0148] S1044: The data owner constructs an access control policy and encrypts the data.
[0149] The data owner constructs an access control policy based on the shared requirements in the business logic layer using the public parameter K provided by the key management center. In an encryption system, the key is the crucial information for encrypting and decrypting data, and its security and availability are of vital importance. The key management center is responsible for generating, storing, distributing, and updating keys. In the scenario of this education platform, the key management center provides the public parameter K for the data owner, and this public parameter K will be used to construct the access control policy and encrypt the data to ensure the security of the data during transmission and storage.
[0150] An access control policy is a set of rules that define which users or roles can access specific resources and in what manner. Access control policies are usually formulated based on factors such as the identity, permissions, and roles of users, and are used to protect the security and confidentiality of data. In this scenario, the data owner constructs an access control policy suitable for course data based on the shared requirements and the public parameter K provided by the key management center to restrict access to course data.
[0151] After the policy is constructed, the data is encrypted in the encryption service layer to obtain the ciphertext. The encryption service layer is the layer in the system specifically responsible for data encryption and decryption. In this step, the encryption service layer encrypts the course data according to the access control policy constructed by the data owner and the key provided by the key management center. The purpose of encryption is to convert the original data into ciphertext, so that even if the data is illegally obtained during data transmission and storage, the attacker cannot directly interpret the content, thereby protecting the security and privacy of the data.
[0152] S1045: The smart contract layer processes data access requests.
[0153] When a data access requester initiates an access request, in the smart contract layer, the policy enforcement point smart contract forwards the access request to the attribute authority.
[0154] The policy enforcement point smart contract is an important component in the smart contract, mainly responsible for performing the specific operations of the access control policy. When a data access requester initiates a request, the policy enforcement point smart contract accurately forwards the request to the attribute authority smart contract for further processing.
[0155] In the attribute-based access control model, the attribute authority is the entity responsible for managing and providing user attribute information, storing various user attribute information such as identity, permissions, and roles. The attribute authority smart contract will provide the corresponding attribute information according to the request of the policy enforcement point smart contract, providing a basis for subsequent access decisions.
[0156] After the Attribute Authority Smart Contract receives the request forwarded by the Policy Enforcement Point Smart Contract, it will collect the attribute information related to the requester from its own "information repository". This information will serve as an important basis for determining whether the requester has the right to access the data.
[0157] After the Policy Enforcement Point Smart Contract obtains the attribute information provided by the Attribute Authority, it will construct an attribute-based access request based on this information. This request includes the attribute information of the requester and the access target, etc., and then submits it to the Policy Decision Point Smart Contract for decision-making.
[0158] The Policy Decision Point Smart Contract determines whether the attribute set of the data access requester conforms to the access policy based on comprehensive information. The Policy Decision Point Smart Contract is the core decision-making component in the smart contract. The Policy Decision Point Smart Contract will judge whether the attribute set of the data access requester conforms to the pre-set access policy according to the attribute-based access request submitted by the Policy Enforcement Point Smart Contract and the relevant comprehensive information. If it conforms, the requester is allowed to access the data; if it does not conform, the access is refused.
[0159] If it conforms, the data owner generates a decryption key at the business logic layer and transmits it to the data access requester through the internal communication layer.
[0160] When the Policy Decision Point Smart Contract determines that the attribute set of the requester conforms to the access policy, the data owner will generate a decryption key at the business logic layer according to the relevant information of the key management center. Then, the decryption key is securely transmitted to the data access requester through the internal communication layer, enabling the requester to decrypt and access the encrypted course data.
[0161] S1046: Digital certificate monitoring operation in the smart contract layer.
[0162] Set up a digital certificate monitoring module in the smart contract layer to monitor digital certificates that follow the X.509 standard format. A digital certificate is an electronic document used to prove identity or permissions. Digital certificates usually follow the X.509 standard format and contain information such as the identity information of the certificate holder, public key, validity period, issuing authority, etc. In network communication, digital certificates are used to verify the identities of both communication parties and ensure data security.
[0163] The X.509 standard is a digital certificate standard jointly developed by the International Telecommunication Union (ITU-T) and the International Organization for Standardization (ISO). It defines the format, content, and verification methods of digital certificates, etc., making digital certificates that follow the X.509 standard have wide compatibility and interoperability and are widely used in various network security scenarios.
[0164] The digital certificate monitoring module is a specialized module in the smart contract layer, used for real-time monitoring of digital certificates. By monitoring information such as the validity and integrity of digital certificates, potential security risks can be detected in a timely manner to ensure the security of the system.
[0165] Extract the core content from the digital certificate and process the core content using the hash algorithm embedded in the certificate to obtain a first digest. In a digital certificate, the hash algorithm embedded in the certificate processes the core content of the certificate to generate a unique digest, that is, the first digest. This digest is used to verify the integrity and authenticity of the certificate.
[0166] Extract the digest signature from the certificate and decrypt the signature in the encryption service layer using the public key provided by the root certificate to obtain a second digest. The digest signature is the result of the certificate authority digitally signing the digest of the digital certificate. The certificate authority uses its own private key to sign the digest of the certificate, which can ensure the integrity and authenticity of the certificate. The data recipient can confirm whether the certificate has been tampered with and the legitimacy of the certificate authority by verifying the digest signature.
[0167] The root certificate is the highest-level certificate in the digital certificate system and is issued by an authoritative certificate authority. The root certificate contains the public key of the certificate authority. Using the public key provided by the root certificate, the digest signature can be decrypted in the encryption service layer to obtain a second digest.
[0168] S1047: Digital certificate verification and information recording.
[0169] Compare the first digest and the second digest. If the two are consistent, when the certificate is first added to the blockchain, record the validity period information of the certificate in a specific storage area of the blockchain ledger.
[0170] The blockchain ledger is the core data structure in blockchain technology, which records all transaction information and related data in a distributed manner. In the scenario of this education platform, the blockchain ledger is used to record the validity period information of digital certificates, as well as various operation and transaction records related to course data, to ensure the security and credibility of the data.
[0171] In the blockchain ledger, in order to facilitate the management and query of specific types of data, specific storage areas will be divided. For example, in order to record the validity period information of digital certificates, a specific storage area will be specially opened up to store this information according to certain formats and rules.
[0172] According to a specific implementation manner of an embodiment of the present invention, the setting of an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer, and a data storage layer corresponding to the course release model and the course interaction model on the education platform includes:
[0173] In the architecture of the education platform, set up an internal communication layer, a business logic layer, an encryption service layer, an authentication layer, and a data storage layer, and design the functional boundaries and interaction interfaces;
[0174] Evaluate the communication performance of the education platform. Based on the evaluation results, set up a transmission protocol and mechanism that match the evaluation results for the internal communication layer;
[0175] Set up business algorithms and processes in the business logic layer. According to the characteristics of the course release model and the course interaction model, implement functions such as course management, user behavior analysis, and course recommendation;
[0176] Configure the encryption algorithm and key management method of the encryption service layer to ensure the secure storage and distribution of keys;
[0177] Establish an authentication mechanism and authorization policy for the authentication layer. Through multiple authentication methods, authorize and manage the accessing users according to their user roles and permissions;
[0178] Deploy the database and storage devices of the data storage layer. Select a matching database according to the data volume and access frequency stored in the education platform, and set up data backup and recovery policies.
[0179] According to a specific implementation manner of an embodiment of the present invention, the course system and knowledge point association data in the course release model are transmitted to the data storage layer of the education platform through the internal communication layer for storage, including:
[0180] Check and clean the format of the course system and knowledge point association data in the course release model, and remove invalid data and duplicate data;
[0181] Establish a data transmission channel in the internal communication layer, and encrypt and transmit the data using an encryption protocol to prevent the data from being stolen or tampered with during the transmission process;
[0182] Convert and map the course system and knowledge point association data according to the database structure of the data storage layer, and store the converted and mapped data in the database of the data storage layer.
[0183] According to a specific implementation manner of an embodiment of the present invention, the course interaction model is integrated with the business logic layer, and the integrated business logic layer generates course recommendation data according to the behavior data of users on the education platform, including:
[0184] Collect and organize the behavior data of users on the education platform, and establish a user behavior data set, where the user behavior data set includes the browsing records, learning records, and exam scores of users;
[0185] Analyze and understand the course interaction model, and extract features and rules related to user behavior and course recommendations;
[0186] Integrate the course interaction model with the algorithms and processes of the business logic layer, and design a course recommendation algorithm based on the user behavior dataset and the rules of the course interaction model;
[0187] According to the course recommendation algorithm, course data is extracted from the database of the education platform to form course recommendation data.
[0188] According to a specific implementation of an embodiment of the present invention, the step of authenticating the data access requester through the identity authentication layer includes:
[0189] When a data access requester initiates an access request, the identity authentication layer first extracts the identity information in the request, and then searches for the corresponding user information in the identity authentication database based on the extracted identity information to verify the validity and legitimacy of the identity;
[0190] Monitor and audit the identity authentication process in real time, and record the time, results, and IP address information of identity authentication;
[0191] If the authentication fails, the authentication layer returns an error message to the data access requester and limits the number of accesses to the data access requester according to the preset policy;
[0192] If authentication is successful, the authentication layer generates a unique identity token and returns it to the data access requester for subsequent data access authorization.
[0193] According to a specific implementation of an embodiment of the present invention, the binding operation between the course recommendation data and the data access requester is performed at the data storage layer to generate the course usage data, including:
[0194] According to the identity token returned by the authentication layer, the corresponding user information and course recommendation data are searched in the data storage layer;
[0195] Filter and sort the course recommendation data, and select the course recommendation information suitable for the user based on the user's historical behavior and preferences;
[0196] Associating the filtered course recommendation data with the user information of the data access requester to establish a mapping relationship between the course recommendation data and the user;
[0197] Create course usage data records in the data storage layer and store course recommendation data, user information, and access time information in the records;
[0198] Encrypt and protect the course usage data, use symmetric encryption algorithm to encrypt sensitive information, and establish indexes and association relationships in the data storage layer for querying and statistical analysis of the course usage data.
[0199] According to a specific implementation manner of an embodiment of the present invention, in the data storage layer, perform randomized segmentation processing on the course usage data, and fuse the segmented data with an anonymous identifier, including:
[0200] Perform feature analysis on the course usage data to determine the fields and data ranges that need to be segmented;
[0201] Use a randomized algorithm to segment the course usage data, and divide the data into multiple small pieces, each small piece containing different features and data information;
[0202] Generate a unique anonymous identifier for each segmented data block, and the anonymous identifier is generated by using a hash algorithm or a random number generator;
[0203] Associate the segmented data blocks with the corresponding anonymous identifiers to ensure a one-to-one correspondence between the data blocks and the anonymous identifiers;
[0204] Recombine and integrate the fused data, recombine the associated anonymous identifiers and data blocks into a new data structure, and back up and store the fused data in the data storage layer.
[0205] According to a specific implementation manner of an embodiment of the present invention, in the encryption service layer, use the user private key carried by the data access requester to encrypt the fused data to form encrypted course data, including:
[0206] Obtain the fused data and the user private key information of the data access requester from the data storage layer;
[0207] After verifying the legality of the user private key, use the user private key to encrypt the fused data;
[0208] Return the encrypted course data to the internal communication layer for publishing and sharing within the group to which the data access requester belongs.
[0209] Corresponding to the above method embodiment, see Figure 3 , an embodiment of the present invention also discloses a data access processing device 30 for an education platform, including:
[0210] A setting module 301, after encapsulating the course release model and the course interaction model obtained from the outside, sets an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer, and a data storage layer corresponding to the course release model and the course interaction model on the education platform;
[0211] Storage module 302 connects the course publishing model with the data storage layer of the education platform, and transmits the course system and knowledge point related data in the course publishing model to the data storage layer of the education platform for storage through the internal communication layer;
[0212] The generation module 303 integrates the course interaction model with the business logic layer. The integrated business logic layer generates course recommendation data based on the user's behavior data on the education platform;
[0213] Verification module 304, when a data access requester initiates an access request to the education platform, the data access requester is authenticated through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data;
[0214] Execution module 305 randomly segments the course usage data at the data storage layer, and merges the segmented data with the anonymous identifier. At the encryption service layer, the merged data is encrypted using the user private key carried by the data access requester to form encrypted course data, and the encrypted course data is published through the internal communication layer within the group to which the data access requester belongs.
[0215] See also Figure 4 The embodiment of the present invention further provides an electronic device 60, the electronic device comprising:
[0216] at least one processor; and,
[0217] a memory communicatively connected to the at least one processor; wherein,
[0218] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data access processing method of the education platform in the aforementioned method embodiment.
[0219] An embodiment of the present invention further provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the aforementioned method embodiment.
[0220] An embodiment of the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, which, when executed by a computer, enable the computer to execute the data access processing method of the educational platform in the aforementioned method embodiment.
[0221] like Figure 4As shown, the electronic device 60 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage device 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 60 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through the bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0222] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, a pressure sensor, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 60 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 4 an electronic device 60 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0223] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for data access processing of an educational platform, characterized in that The following steps are involved: After encapsulating the course publishing model and course interaction model obtained from the outside, an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer and a data storage layer corresponding to the course publishing model and the course interaction model are set on the education platform; Connect the course publishing model with the data storage layer of the education platform, and transfer the course system and knowledge point related data in the course publishing model to the data storage layer of the education platform through the internal communication layer for storage; Integrate the course interaction model with the business logic layer. The integrated business logic layer generates course recommendation data based on user behavior data on the education platform. When a data access requester initiates an access request to the education platform, the data access requester is authenticated through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data; In the data storage layer, the course usage data is randomly segmented and merged with the anonymous identifier. In the encryption service layer, the merged data is encrypted using the user private key carried by the data access requester to form encrypted course data. The encrypted course data is published through the internal communication layer within the group to which the data access requester belongs.
2. The method according to claim 1, wherein The internal communication layer, business logic layer, encryption service layer, identity authentication layer and data storage layer corresponding to the course publishing model and the course interaction model are set on the education platform, including: Set up the internal communication layer, business logic layer, encryption service layer, authentication layer and data storage layer in the architecture of the education platform to design functional boundaries and interaction interfaces; Evaluate the communication performance of the education platform and, based on the evaluation results, set up transmission protocols and mechanisms for the internal communication layer that match the evaluation results; Set up business algorithms and processes in the business logic layer to implement course management, user behavior analysis, and course recommendation functions based on the characteristics of the course publishing model and course interaction model; Configure the encryption algorithm and key management method of the encryption service layer to ensure the secure storage and distribution of keys; Establish authentication mechanisms and authorization policies for the identity authentication layer, and manage access users based on their roles and permissions through multiple authentication methods; Deploy databases and storage devices at the data storage layer, select matching databases based on the amount of data stored and access frequency on the education platform, and set up data backup and recovery strategies.
3. The method according to claim 2, wherein The course system and knowledge point related data in the course publishing model are transmitted to the data storage layer of the education platform for storage through the internal communication layer, including: Check and clean the format of the course system and knowledge point related data in the course publishing model to remove invalid and duplicate data; Establish a data transmission channel in the internal communication layer and use encryption protocols to encrypt data for transmission to prevent data from being stolen or tampered with during transmission; The course system and knowledge point related data are converted and mapped according to the database structure of the data storage layer, and the converted and mapped data are stored in the database of the data storage layer.
4. The method according to claim 3, characterized in that, The course interaction model is integrated with the business logic layer. The integrated business logic layer generates course recommendation data based on the user's behavior data on the education platform, including: Collect and organize user behavior data on the education platform to establish a user behavior data set, which includes the user's browsing history, learning history and test scores; Analyze and understand the course interaction model, and extract features and rules related to user behavior and course recommendations; Integrate the course interaction model with the algorithms and processes of the business logic layer, and design a course recommendation algorithm based on the user behavior dataset and the rules of the course interaction model; According to the course recommendation algorithm, course data is extracted from the database of the education platform to form course recommendation data.
5. The method according to claim 4, wherein Authenticating the data access requester through the authentication layer includes: When a data access requester initiates an access request, the identity authentication layer first extracts the identity information in the request, and then searches for the corresponding user information in the identity authentication database based on the extracted identity information to verify the validity and legitimacy of the identity; Monitor and audit the identity authentication process in real time, and record the time, results, and IP address information of identity authentication; If the authentication fails, the authentication layer returns an error message to the data access requester and limits the number of accesses to the data access requester according to the preset policy; If authentication is successful, the authentication layer generates a unique identity token and returns it to the data access requester for subsequent data access authorization.
6. The method according to claim 5, wherein The binding operation of the course recommendation data and the data access requester at the data storage layer to generate the course usage data includes: According to the identity token returned by the authentication layer, the corresponding user information and course recommendation data are searched in the data storage layer; Filter and sort the course recommendation data, and select the course recommendation information suitable for the user based on the user's historical behavior and preferences; Associating the filtered course recommendation data with the user information of the data access requester to establish a mapping relationship between the course recommendation data and the user; Create course usage data records in the data storage layer and store course recommendation data, user information, and access time information in the records; Encrypt and protect course usage data, use symmetric encryption algorithms to encrypt sensitive information, and establish indexes and associations in the data storage layer for query and statistical analysis of course usage data.
7. The method according to claim 6, wherein In the data storage layer, the course usage data is randomly segmented and the segmented data is merged with the anonymous identifier, including: Conduct feature analysis on course usage data to determine the fields and data ranges that need to be segmented; A randomization algorithm is used to segment the course usage data into multiple small blocks, each of which contains different features and data information; Generate a unique anonymous identifier for each segmented data block, and the anonymous identifier is generated using a hash algorithm or a random number generator; Associating the segmented data blocks with the corresponding anonymous identifiers to ensure a one-to-one correspondence between the data blocks and the anonymous identifiers; The fused data is reorganized and integrated, the associated anonymous identifiers and data blocks are recombined into a new data structure, and the fused data is backed up and stored in the data storage layer.
8. The method according to claim 7, wherein The encrypted service layer uses the user private key carried by the data access requester to encrypt the merged data to form encrypted course data, including: Obtain the merged data and the user private key information of the data access requester from the data storage layer; After verifying the legitimacy of the user's private key, the fused data is encrypted using the user's private key; The encrypted course data is returned to the internal communication layer for publication and sharing within the group to which the data access requester belongs.
9. A data access processing device for an education platform, characterized in that, include: A setting module, after encapsulating the course publishing model and the course interaction model obtained from the outside, sets an internal communication layer, a business logic layer, an encryption service layer, an identity authentication layer and a data storage layer corresponding to the course publishing model and the course interaction model on the education platform; The storage module connects the course publishing model with the data storage layer of the education platform, and transmits the course system and knowledge point related data in the course publishing model to the data storage layer of the education platform for storage through the internal communication layer; The generation module integrates the course interaction model with the business logic layer. The integrated business logic layer generates course recommendation data based on the user's behavior data on the education platform; The verification module, when the data access requester initiates an access request to the education platform, authenticates the data access requester through the identity authentication layer. After the identity authentication is passed, the course recommendation data is bound to the data access requester in the data storage layer to generate course usage data; The execution module randomly segments the course usage data at the data storage layer and merges the segmented data with the anonymous identifier. At the encryption service layer, the merged data is encrypted using the user private key carried by the data access requester to form encrypted course data, and the encrypted course data is published through the internal communication layer within the group to which the data access requester belongs.
10. An electronic device, characterized in that, The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data access processing method of the education platform described in any one of claims 1 to 8.