End-to-end data secure transmission method and device based on field importance and medium

By dynamically determining the encryption algorithm based on the field importance score and the number of data blocks, and using encryption algorithms of different security levels to encrypt the data blocks, the problem that a single encryption algorithm cannot balance security and efficiency is solved, and efficient and secure data transmission within the expected time of users is achieved.

CN120358081AActive Publication Date: 2025-07-22TIANJIN TIANHE DIGITAL IND TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510821658.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-22
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

In the prior art, a single encryption algorithm is used to encrypt all data in the data table, which cannot balance data security and encryption efficiency, affecting the user experience.

Method used

According to the importance score of the target field name and the number of data blocks, the first data block and the second data block are dynamically determined, and they are encrypted using symmetric encryption algorithms with different security levels. The first data block uses an encryption algorithm with a high security level, and the second data block uses an encryption algorithm with a low security level.

Benefits of technology

When meeting the user's expectations, balance data security and encryption efficiency and improve user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358081A_ABST
    Figure CN120358081A_ABST
Patent Text Reader

Abstract

The invention provides an end-to-end data secure transmission method and device based on field importance and a medium, and relates to the technical field of data transmission, and the method can obtain target data blocks, obtain a judgment threshold value based on an expected duration determined by a user and the number of the target data blocks corresponding to a target field name, and send the judgment threshold value to a server. According to the method, the first data block and the second data block are dynamically determined, and the first data block and the second data block are encrypted by using different symmetric encryption algorithms; a first symmetric encryption algorithm with a high security level is used to encrypt a target data block corresponding to a target field name with a high importance score, and a second symmetric encryption algorithm with a low security level is used to encrypt a target data block corresponding to a target field name with a low importance score. The data security and the encryption efficiency can be well balanced, and the user experience can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and particularly to an end-to-end data secure transmission method, device and medium based on field importance. Background Art

[0002] For data stored in a data table, when performing data transmission, in order to prevent the data from being stolen, tampered with or forged during the transmission process, it is usually necessary to encrypt the data to ensure the security of the data; in the prior art, encrypting the data mainly relies on encryption algorithms, and usually a single encryption algorithm is used to encrypt all the data in the data table.

[0003] However, the above method also has the following technical problems: The security levels corresponding to different encryption algorithms are different, and the encryption speeds are also different. The higher the security level of the encryption algorithm, the slower its corresponding encryption speed, the longer the encryption duration. Using an encryption algorithm with a fast encryption speed to encrypt the data cannot meet the requirements of high security, and using an encryption algorithm with a slow encryption speed cannot meet the requirements of high encryption efficiency. Therefore, using a single encryption algorithm to encrypt all the data in the data table cannot balance data security and encryption efficiency, which will affect the user experience. Summary of the Invention

[0004] In view of the above technical problems, the technical solution adopted by the present invention is as follows: According to the first aspect of the present invention, an end-to-end data secure transmission method based on field importance is provided. The method is applied to a client, and the method includes the following steps: S1. Obtain a target field name list A = {A1, A2,..., A i ,..., A m}, where A i is the i-th target field name, the value of i ranges from 1 to m, m is the number of target field names, and the target field names are the field names in the target data table; the importance score corresponding to A i is not less than the importance score corresponding to A i+1 .

[0005] S2. Based on the number B i of target data blocks corresponding to A i and the expected duration T determined by the user, obtain a judgment threshold a, where the target data block corresponding to A i is a data block obtained by dividing all the field values corresponding to A i according to a preset data volume, and a meets the following conditions: a×t1+((∑ m i=1 B i-a)×t2=T - T 0 where t1 is the time required to encrypt data of a preset data volume using the first symmetric encryption algorithm S1, t2 is the time required to encrypt data of a preset data volume using the second symmetric encryption algorithm S2, T 0 is the data transmission time required to transfer all target data blocks to the server, and the security level of S1 is higher than that of S2; t1 > t2; T > T 0 .

[0006] S3. If B1 + B2 + … + B i-1 < a and B1 + B2 + … + B i ≥ a, then take the target data blocks corresponding to A1, A2, …, A i as the first data blocks, and take the target data blocks corresponding to A i+1 , A i+2 , …, A m as the second data blocks.

[0007] S4. Encrypt the first data blocks using S1 to obtain first encrypted data blocks, and encrypt the second data blocks using S2 to obtain second encrypted data blocks.

[0008] S5. Transmit the first encrypted data blocks and the second encrypted data blocks to the server through a secure channel.

[0009] According to a second aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing a computer program, which is loaded and executed by a processor to implement the foregoing method.

[0010] According to a third aspect of the present invention, there is provided an electronic device, including: a processor, a memory, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the foregoing method is implemented.

[0011] The present invention has at least the following beneficial effects: The present invention provides a method, device and medium for secure end-to-end data transmission based on field importance. The method can obtain a target field name list, obtain a judgment threshold based on an expected duration determined by a user and the number of target data blocks corresponding to the target field name, determine a first data block and a second data block based on the judgment threshold and the target data block, encrypt the first data block using a first symmetric encryption algorithm to obtain a first encrypted data block, and encrypt the second data block using a second symmetric encryption algorithm to obtain a second encrypted data block, wherein the security level of the first symmetric encryption algorithm is higher than that of the second symmetric encryption algorithm, the encryption duration of the first symmetric encryption algorithm is longer than that of the second symmetric encryption algorithm, and the first encrypted data block and the second encrypted data block are encrypted by security. Full channel transmission to the server; it can be seen that the present invention can obtain the target data block, obtain the judgment threshold based on the expected duration determined by the user and the number of target data blocks corresponding to the target field name, dynamically determine the first data block and the second data block, and use different symmetric encryption algorithms to encrypt the first data block and the second data block. While satisfying the expected duration determined by the user as much as possible, the first symmetric encryption algorithm with a higher security level is used to encrypt the target data block corresponding to the target field name with a higher importance score, and the second symmetric encryption algorithm with a lower security level is used to encrypt the target data block corresponding to the target field name with a lower importance score. This can better balance data security and encryption efficiency, which is beneficial to improving user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0013] Figure 1 A flowchart of an end-to-end data security transmission method based on field importance is provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0014] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0015] It should be noted that the terms "first", "second", etc. in the specification, claims and the above-mentioned drawings of the present invention are used to distinguish similar tasks and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0016] An embodiment of the present invention provides an end-to-end data security transmission method based on field importance. The method is applied to a client, as Figure 1 shown. The method includes the following steps: S1. Obtain a list A = {A1, A2,..., A i ,..., A m} of target field names, where A i is the i-th target field name, and the value of i ranges from 1 to m, where m is the number of target field names.

[0017] Specifically, the target field names are the field names in the target data table. The target data table includes several field names, and each field name corresponds to several field values. Among them, the target data table is a data table preselected by those skilled in the art according to actual needs, which will not be elaborated here.

[0018] Specifically, the greater the importance score corresponding to the target field name, the higher the importance degree of the target field name and its corresponding field value.

[0019] Specifically, the importance score corresponding to A i is not less than the importance score corresponding to A i+1 , and A i+1 is the (i + 1)-th target field name.

[0020] Furthermore, when the importance score corresponding to A i is equal to the importance score corresponding to A i+1 , the data volume corresponding to A i is not less than the data volume corresponding to A i+1 .

[0021] Specifically, the data volume corresponding to the target field name is the total number of bytes of all the field values corresponding to the target field name, and the unit of the total number of bytes is byte.

[0022] Through the above steps, the higher the importance score corresponding to the target field name, the higher its corresponding importance level. When the importance scores are the same, the larger the amount of data corresponding to the target field name, the higher the importance level corresponding to the target field name, which can clearly reflect the importance level of the target field name. According to the number of target data blocks corresponding to each target field name and the judgment threshold, the first data block and the second data block can be determined, which can more conveniently determine the first data block and the second data block and is beneficial to improving the efficiency of determining the first data block and the second data block.

[0023] S2. Based on A i The number B of corresponding target data blocks i and the expected duration T determined by the user, obtain the judgment threshold a, where A i The corresponding target data blocks are data blocks obtained by dividing all field values corresponding to A according to a preset data volume, and a meets the following conditions: i a×t1 + ((∑ a×t1+((∑ m i=1 B i ) - a)×t2 = T - T 0 , t1 is the duration required to encrypt data with a size of the preset data volume using the first symmetric encryption algorithm S1, t2 is the duration required to encrypt data with a size of the preset data volume using the second symmetric encryption algorithm S2, T 0 is the data transmission duration required to transmit all target data blocks to the server, and the security level of S1 is higher than that of S2.

[0024] Specifically, t1 > t2.

[0025] Specifically, T > T 0 Specifically, the preset data volume is the number of bytes preset by those skilled in the art according to actual needs. For example: 102,400 bytes (100 KB), which will not be elaborated here.

[0026] In a specific embodiment, in the process of dividing all field values corresponding to A i according to the preset data volume to obtain data blocks, if the total number of bytes of the remaining several field values is less than the preset data volume, then the remaining several field values are used as an independent data block; for example: if dividing A according to 102,400 bytes iAfter dividing all the corresponding field values into 8 data blocks, there are still several field values remaining. The total number of bytes of the remaining several field values is 81,920 bytes. Then, taking the remaining several field values as a data block can avoid dividing the field values corresponding to different target field names into the same data block and can also avoid missing some field values during the division process.

[0027] Specifically, before step S2, it further includes: presenting to the user a preset data processing duration range [T 1 , T 2 , and receiving T determined by the user according to the preset data processing duration range [T 1 , T 2 . Here, T 1 is the minimum data processing duration, T 2 is the maximum data processing duration, and T 1 and T 2 respectively meet the following conditions: T 1 = (∑ m i=1 B i ) × t2 + T 0 ; T 2 = (∑ m i=1 B i ) × t1 + T 0 , where T 1 ≤ T ≤ T 2 .

[0028] Specifically, T 0 < T 1 .

[0029] Optionally, S1 is the AES encryption algorithm.

[0030] Optionally, S2 is the ChaCha20 encryption algorithm; as is known to those skilled in the art, the algorithms corresponding to S1 and S2 above are only examples and are not specific limitations of the protection scope of the present invention.

[0031] Through the above steps, the preset data processing time interval is displayed to the user, and the expected time determined by the user according to the preset data processing time interval is received. The judgment threshold is obtained according to the expected time determined by the user, the number of target data blocks corresponding to each target field name, the time required for encrypting data with a preset data size using the first symmetric encryption algorithm, and the time required for encrypting data with a preset data size using the second symmetric encryption algorithm. Further, the first data block and the second data block are determined so that the first data block is encrypted using the first symmetric encryption algorithm with a higher security level, and the second data block is encrypted using the second symmetric encryption algorithm with a lower security level while satisfying the expected time determined by the user as much as possible. This can better balance data security and encryption efficiency, and is conducive to improving user experience.

[0032] S3, if B1+B2+…+B i-1 <a and B1+B2+…+B i ≥a, then A1, A2, …, A i The corresponding target data block is taken as the first data block, and A i+1 , A i+2 , …, A m The corresponding target data block is used as the second data block, B i-1 A i-1 The number of corresponding target data blocks, A i-1 is the i-1th target field name, A i+2 The name of the i+2th target field.

[0033] Through the above steps, if B1+B2+…+B i-1 <a and B1+B2+…+B i ≥a, then A1, A2, …, A i The corresponding target data block is taken as the first data block, and A i+1 , A i+2 , …, A m The corresponding target data block is used as the second data block, and all target data blocks corresponding to the same target field name are used as the first data block, or all target data blocks corresponding to the same target field name are used as the second data block, so as to avoid dividing the equally important field values into two categories, thereby ensuring the rationality of the classification of the first data block and the second data block.

[0034] S4. Use S1 to encrypt the first data block to obtain a first encrypted data block, and use S2 to encrypt the second data block to obtain a second encrypted data block.

[0035] Specifically, the encryption process in step S4 is serial encryption, that is, only one data block can be encrypted each time; it can be understood that only one first data block can be encrypted each time, or only one second data block can be encrypted each time.

[0036] In a specific embodiment, the encryption process in step S4 is parallel encryption, that is, d data blocks can be encrypted each time, and d is the number of parallel encryption processes; when the encryption process in step S4 is parallel encryption, a, T 1 and T 2 Meet the following conditions respectively: (a×t1+((∑ m i=1 B i )-a)×t2) / d=TT 0 ; T 1 =(∑ m i=1 B i )×t2 / d+T 0 ; T 2 =(∑ m i=1 B i )×t1 / d+T 0 .

[0037] S5. Transmit the first encrypted data block and the second encrypted data block to the server through a secure channel.

[0038] Through the above steps, a target field name list is obtained, a judgment threshold is obtained based on the expected duration determined by the user and the number of target data blocks corresponding to the target field name, a first data block and a second data block are determined based on the judgment threshold and the target data block, the first data block is encrypted using a first symmetric encryption algorithm to obtain a first encrypted data block, and the second data block is encrypted using a second symmetric encryption algorithm to obtain a second encrypted data block, wherein the security level of the first symmetric encryption algorithm is higher than that of the second symmetric encryption algorithm, and the encryption duration of the first symmetric encryption algorithm is longer than the encryption duration of the second symmetric encryption algorithm, and the first encrypted data block and the second encrypted data block are transmitted to the server through a secure channel, and the target data blocks corresponding to the target field names with higher importance scores can be encrypted using the first symmetric encryption algorithm with a higher security level while satisfying the expected duration determined by the user as much as possible, and the target data blocks corresponding to the target field names with lower importance scores can be encrypted using the second symmetric encryption algorithm with a lower security level, which can better balance data security and encryption efficiency, and is conducive to improving user experience.

[0039] Specifically, before step S5, the following steps are also included: S01. Encrypt the first key and the second key using the received public key to obtain the first encrypted key corresponding to the first key and the second encrypted key corresponding to the second key.

[0040] Specifically, before step S01, it further includes: sending a data transmission request to the server, and when the server responds to the data transmission request, sending the public key generated by a preset asymmetric encryption algorithm to the client.

[0041] In a specific embodiment, at fixed time intervals, new public and private keys generated by a preset asymmetric encryption algorithm are used to replace the old public and private keys. Regularly updating the public and private keys is beneficial to improving data security.

[0042] Specifically, the first key is the key generated for S1, and the second key is the key generated for S2.

[0043] S02. Send the first encrypted key and the second encrypted key to the server through a secure channel.

[0044] Specifically, when the server receives the first encrypted key and the second encrypted key, it decrypts the first encrypted key and the second encrypted key using the private key generated by a preset asymmetric encryption algorithm to obtain the first key and the second key.

[0045] Optionally, the preset asymmetric encryption algorithm is the RSA encryption algorithm; as known to those skilled in the art, the algorithm corresponding to the preset asymmetric encryption algorithm is only an example and is not a specific limitation of the protection scope of the present invention.

[0046] Through the above steps, encrypt the first key and the second key using the received public key to obtain the first encrypted key corresponding to the first key and the second encrypted key corresponding to the second key, and send the first encrypted key and the second encrypted key to the server through a secure channel to complete the synchronization of the first key and the second key, which can avoid and ensure the security of the first key and the second key.

[0047] Specifically, after step S5, it further includes: when all the first encrypted data blocks and all the second encrypted data blocks are transmitted, destroy the first key and the second key, which can prevent the leakage of the first key and the second key and is beneficial to improving data security.

[0048] In a specific embodiment, when encrypting the first data block with S1 to obtain the first encrypted data block, calculate the MD5 hash value of the first data block at the same time, and when encrypting the second data block with S2 to obtain the second encrypted data block, calculate the MD5 hash value of the second data block at the same time.

[0049] Specifically, while transmitting the first encrypted data block and the second encrypted data block to the server through a secure channel, the MD5 hash value of the first data block corresponding to the first encrypted data block and the MD5 hash value of the second data block corresponding to the second encrypted data block are also transmitted to the server through the secure channel.

[0050] Specifically, when the server receives the first encrypted data block, it decrypts the first encrypted data block using the first key to obtain the first data block and calculates the MD5 hash value of the first data block to perform integrity verification on the first data block. Among them, if the calculated MD5 hash value is the same as the MD5 hash value transmitted by the client received, it indicates that the verification is successful and the data block is complete; otherwise, it indicates that the verification fails and the data block is incomplete. When the verification fails, the data transmission is terminated and the first key is destroyed.

[0051] Specifically, when the server receives the second encrypted data block, it decrypts the second encrypted data block using the second key to obtain the second data block and calculates the MD5 hash value of the second data block to perform integrity verification on the second data block. Among them, if the calculated MD5 hash value is the same as the MD5 hash value transmitted by the client received, it indicates that the verification is successful and the data block is complete; otherwise, it indicates that the verification fails and the data block is incomplete. When the verification fails, the data transmission is terminated and the second key is destroyed.

[0052] Specifically, when the server obtains all the first data blocks and the second data blocks, the first key and the second key are immediately destroyed; it can be understood that when the data transmission is completed, the first key and the second key are immediately destroyed.

[0053] In a specific embodiment, before each data transmission, a new first key is generated using S1, and a new second key is generated using S2. The first key and the second key are updated before each data transmission, which is beneficial to improving the security of the data.

[0054] Specifically, the following steps are also included before step S1: S11. Obtain the initial field name list C = {C1, C2,..., C j ,..., C n}, where C j is the field name of the jth field in the target data table, and the value of j ranges from 1 to n, and n is the number of fields in the target data table.

[0055] Specifically, n = m.

[0056] S12. If C j contains a preset keyword, then use the preset keyword in C j as C jThe corresponding keyword to obtain C j The corresponding keyword list D j ={D j1 , D j2 , …, D je , …, D jf(j)}, D je is the e-th keyword corresponding to C j , where the value of e ranges from 1 to f(j), and f(j) is the number of keywords corresponding to C j . The preset key words are the words preset by those skilled in the art according to actual needs, which will not be elaborated here.

[0057] S13. Obtain the preset importance score mapping list E = {E1, E2, …, E g , …, E h}, E g =(E g1 , E g2 ), E g is the preset importance score group corresponding to the g-th preset key word in E, where the value of g ranges from 1 to h, and h is the number of preset key words, E g1 is the g-th preset key word, E g2 is E g1 corresponding preset importance score.

[0058] Specifically, 0 < E g2 ≤1, the larger E g2 , the higher the importance of E g1 .

[0059] S14. When D je = E g1 , take E g2 as the key score F je corresponding to D je to obtain the key score list F j corresponding to D j ={F j1 , F j2 , …, F je , …, F jf(j)}.

[0060] S15. Take the maximum value among F j1 , F j2 , …, F je , …, F jf(j) as ZY j , ZY j is the importance score corresponding to C j .

[0061] Through the above steps, if the field name in the target data table contains a preset key word, obtain the keyword list corresponding to the field name, and obtain the key score corresponding to the keyword based on the preset importance score corresponding to the preset key word. The higher the preset importance score, the more important the corresponding preset key word is, and correspondingly, the higher the key score, the more important the corresponding keyword is, and the more important the field name corresponding to the keyword is. Therefore, take the maximum key score in the key scores corresponding to the keyword list corresponding to the field name in the target data table as the importance score corresponding to the field name, so that the higher the importance score, the higher the importance degree of the field name, which can reasonably represent the importance degree of the field name in the target data table and is beneficial to improving the accuracy of obtaining the importance score corresponding to the field name.

[0062] Specifically, after step S15, the following steps are further included: S10. If C j does not contain a preset key word, obtain C j corresponding target query statement list G j ={G j1 , G j2 , …, G jx , …, G jp(j)}, G jx is the x-th target query statement corresponding to C j , and the value range of x is from 1 to p(j), where p(j) is the number of target query statements corresponding to C j . The target query statement corresponding to C j is the query statement used to find the field value corresponding to C j in the historical time period.

[0063] S20. Obtain the query field name list corresponding to G jx . The query field name list includes several query field names, and the query field name is the field name corresponding to the field value returned in the query result corresponding to the target query statement.

[0064] Specifically, the historical time period is a time period preset by those skilled in the art according to actual needs, which will not be elaborated here.

[0065] S30. Remove duplicates from all the query field names in G j1 , G j2 , …, G jx , …, G jp(j) to obtain the associated field name list H j corresponding to C j ={H j1 , H j2 , …, H jy , …, H jq(j)}, H jy is C j The y-th associated field name corresponding to it, where y ranges from 1 to q(j), and q(j) is the number of associated field names corresponding to C j The number of corresponding associated field names.

[0066] S40. If H jy includes a preset key word and the importance score corresponding to H jy is not less than the preset score, then H jy is used as the key field name corresponding to C j where the preset score is a score less than 1 and greater than 0 preset by those skilled in the art according to actual needs. For example: 0.6, 0.75, which will not be elaborated here.

[0067] S50. Based on p(j), q(j) and the number U j of the key field names corresponding to C j , obtain ZY j , where ZY j meets the following conditions: ZY j =(W1 × p(j) / p max + W2 × q(j) / q max + W3 × U j / U max ) / (W1 + W2 + W3), where W1 is the preset importance weight corresponding to the target query statement, W2 is the preset importance weight corresponding to the associated field name, W3 is the preset importance weight corresponding to the key field name, p max is the maximum value among p(1), p(2), …, p(j), …, p(n), q max is the maximum value among q(1), q(2), …, q(j), …, q(n), and U max is the maximum value among U1, U2, …, U j , …, U n in.

[0068] Specifically, the larger W1 is, the higher the importance of the target query statement.

[0069] Specifically, the larger W2 is, the higher the importance of the associated field name.

[0070] Specifically, the larger W3 is, the higher the importance of the key field name.

[0071] Optionally, W1 = W2 = W3 = 1, where when W1 = W2 = W3, it indicates that the importance of the target query statement, the associated field name, and the key field name is equally high.

[0072] Specifically, in a specific embodiment, an importance score is calculated each time before data transmission, so that the latest importance score can be obtained, which is beneficial to improving the accuracy of the importance score, and thus beneficial to improving the accuracy of obtaining the first data block and the second data block.

[0073] Specifically, in a specific embodiment, the importance score is calculated at fixed time intervals, without the need to calculate the importance score frequently, which is beneficial to saving resources and can improve the efficiency of obtaining the first data block and the second data block.

[0074] Through the above steps, if the field name in the target data table does not contain the preset key word, the target query statement corresponding to the field name and the list of query field names corresponding to the target query statement are obtained. Among them, the more target query statements corresponding to the field name in the target data table, the more times the field value corresponding to the field name is queried, and the more important the field name is. The duplicate removal process is performed on all query field names in the list of query field names corresponding to all target query statements corresponding to the field name in the target data table to obtain the list of associated field names corresponding to the field name. Among them, the more associated field names in the list of associated field names corresponding to the field name, the more the number of field names related to the field name, and the more important the field name is. Further, if the associated field name includes the preset key word and the corresponding importance score is not less than the preset score, the associated field name is used as the key field name corresponding to the field name. The more the number of key field names, the more the number of associated field names corresponding to it that include the preset key word and the corresponding importance score is not less than the preset score, and the more important the field name is. Therefore, based on the target query statements corresponding to all field names in the target data table that do not contain the preset key word, the number of associated field names, the number of key field names, and the preset importance weights corresponding to the target query statements, the preset importance weights corresponding to the associated field names, and the preset importance weights corresponding to the key field names, the importance score corresponding to the field name in the target data table is obtained, which can reasonably represent the importance degree of the field name in the target data table and comprehensively consider various influencing factors to obtain the importance score, which is beneficial to improving the accuracy of obtaining the importance score.

[0075] An embodiment of the present invention also provides a non-transitory computer-readable storage medium, which can be set in an electronic device to store a computer program related to a method in the method embodiment. The computer program is loaded and executed by the processor to implement the method provided in the above embodiment.

[0076] An embodiment of the present invention further provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method provided in the above embodiment when executing the computer program.

[0077] An embodiment of the present invention further provides a computer program product, which includes program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the method according to various exemplary embodiments of the present invention described above in this specification.

[0078] The present invention provides a method, device and medium for secure end-to-end data transmission based on field importance. The method can obtain a target field name list, obtain a judgment threshold based on an expected duration determined by a user and the number of target data blocks corresponding to the target field name, determine a first data block and a second data block based on the judgment threshold and the target data block, encrypt the first data block using a first symmetric encryption algorithm to obtain a first encrypted data block, and encrypt the second data block using a second symmetric encryption algorithm to obtain a second encrypted data block, wherein the security level of the first symmetric encryption algorithm is higher than that of the second symmetric encryption algorithm, the encryption duration of the first symmetric encryption algorithm is longer than that of the second symmetric encryption algorithm, and the first encrypted data block and the second encrypted data block are encrypted by security. Full channel transmission to the server; it can be seen that the present invention can obtain the target data block, obtain the judgment threshold based on the expected duration determined by the user and the number of target data blocks corresponding to the target field name, dynamically determine the first data block and the second data block, and use different symmetric encryption algorithms to encrypt the first data block and the second data block. While satisfying the expected duration determined by the user as much as possible, the first symmetric encryption algorithm with a higher security level is used to encrypt the target data block corresponding to the target field name with a higher importance score, and the second symmetric encryption algorithm with a lower security level is used to encrypt the target data block corresponding to the target field name with a lower importance score. This can better balance data security and encryption efficiency, which is beneficial to improving user experience.

[0079] Although some specific embodiments of the present invention have been described in detail by way of example, it should be understood by those skilled in the art that the above examples are only for illustration, not for limiting the scope of the present invention. It should also be understood by those skilled in the art that various modifications may be made to the embodiments without departing from the scope and spirit of the present invention.

Claims

1. An end-to-end data security transmission method based on field importance, characterized in that, The method is applied to a client, and the method includes the following steps: S1. Obtain the list of target field names A = {A1, A2, …, A i , …, A m}, where A i is the i-th target field name, i ranges from 1 to m, and m is the number of target field names. The target field names are the field names in the target data table; the importance score corresponding to A i is not less than the importance score corresponding to A i+1 . S2. Based on A i The number B of corresponding target data blocks i and the expected duration T determined by the user, obtain the judgment threshold a, where i The corresponding target data blocks are data blocks obtained by dividing all field values corresponding to A according to a preset data volume, and a meets the following conditions: i ​ a×t1+((∑ m i=1 B i )-a)×t2=T-T 0 , t1 is the duration required to encrypt data with a size of a preset data volume using the first symmetric encryption algorithm S1, t2 is the duration required to encrypt data with a size of a preset data volume using the second symmetric encryption algorithm S2, T 0 is the data transmission duration required to transfer all target data blocks to the server, and the security level of S1 is higher than that of S2; t1 > t2; T > T 0 ; S3. If B1 + B2 + … + B i-1 <a and B1 + B2 + … + B i ≥a, then take the target data blocks corresponding to A1, A2, …, A i as the first data blocks, and take the target data blocks corresponding to A i+1 , A i+2 , …, A m as the second data blocks; S4. Use S1 to encrypt the first data block to obtain a first encrypted data block, and use S2 to encrypt the second data block to obtain a second encrypted data block; S5. Transmit the first encrypted data block and the second encrypted data block to the server through a secure channel.

2. The end-to-end data security transmission method based on field importance according to claim 1, characterized in that T 0 <T 1 ≤T≤T 2 ,T 1 is the minimum data processing duration, T 2 is the maximum data processing duration, T 1 and T 2 respectively meet the following conditions: T 1 =(∑ m i=1 B i )×t2 + T 0 ; T 2 =(∑ m i=1 B i )×t1 + T 0 。 3. The end-to-end data security transmission method based on field importance according to claim 1, characterized in that Before step S1, the following steps are further included: S11. Obtain an initial list of field names C = {C1, C2, …, C j , …, C n}, where C j is the field name of the j-th field in the target data table, and the value range of j is from 1 to n, where n is the number of fields in the target data table; S12. If C j contains a preset key word, then use the preset key word in C j as the key word corresponding to C j to obtain the corresponding key word list D j ={D j , D j1 , …, D j2 , …, D je , …, D jf(j)}, where D je is the e-th key word corresponding to C j , and the value range of e is from 1 to f(j), where f(j) is the number of key words corresponding to C j ; S13. Obtain a preset importance score mapping list E = {E1, E2, …, E g , …, E h}, E g =(E g1 , E g2 ), E g is the preset importance score group corresponding to the g-th preset key word in E, where g ranges from 1 to h, h is the number of preset key words, E g1 is the g-th preset key word, E g2 is E g1 's corresponding preset importance score; S14. When D je = E g1 , take E g2 as the key score F je corresponding to D je to obtain the key score list F j corresponding to D j = {F j1 , F j2 , …, F je , …, F jf(j)}; S15. Take the maximum value among F j1 , F j2 , …, F je , …, F jf(j) as ZY j , and ZY j is the importance score corresponding to C j .

4. The end-to-end data security transmission method based on field importance according to claim 3, wherein After step S15, the following steps are further included: S10. If C j does not contain the preset key words, obtain the target query statement list G j corresponding to C j ={G j1 , G j2 , …, G jx , …, G jp(j)}, where G jx is the x-th target query statement corresponding to C j , x ranges from 1 to p(j), p(j) is the number of target query statements corresponding to C j , and the target query statements corresponding to C j are the query statements used to find the field values corresponding to C j in the historical time period; S20. Obtain G jx The corresponding list of query field names, where the list of query field names includes several query field names, and the query field name is the field name corresponding to the field value returned in the query result corresponding to the target query statement; S30. Dedup all the query field names in G j1 to obtain the list H of associated field names corresponding to C j2 ={H jx , H jp(j) , …, H j , …, H j}, where H j1 is the y-th associated field name corresponding to C j2 , and the value range of y is from 1 to q(j), where q(j) is the number of associated field names corresponding to C jy ; jq(j)} jy is the y-th associated field name corresponding to C j , and the value range of y is from 1 to q(j), where q(j) is the number of associated field names corresponding to C j ; S40. If H jy includes the preset key words and the importance score corresponding to H jy is not less than the preset score, then H jy is used as the key field name corresponding to C j ; S50. Based on p(j), q(j), and C j The number U of corresponding key field names j , obtain ZY j , ZY j meets the following conditions: ZY j =(W1 × p(j) / p max + W2 × q(j) / q max + W3 × U j / U max ) / (W1 + W2 + W3), where W1 is the preset importance weight corresponding to the target query statement, W2 is the preset importance weight corresponding to the associated field name, W3 is the preset importance weight corresponding to the key field name, p max is the maximum value among p(1), p(2), …, p(j), …, p(n), q max is the maximum value among q(1), q(2), …, q(j), …, q(n), and U max is the maximum value among U1, U2, …, U j , …, U n in the set.

5. The end-to-end data security transmission method based on field importance according to claim 3, wherein n = m.

6. The end-to-end data security transmission method based on field importance according to claim 2, wherein Before step S2, the following steps are further included: Show a preset data processing duration interval [T 1 , T 2 to the user.

7. The end-to-end data security transmission method based on field importance according to claim 6, characterized in that After presenting a preset data processing duration range [T 1 , T 2 to the user, the following steps are further included: Receive T determined by the user according to the preset data processing duration range [T 1 , T 2 .

8. The end-to-end data security transmission method based on field importance according to claim 3, characterized in that 0<E g2 ≤1。 9. A non-transitory computer-readable storage medium, characterized in that, A computer program is stored in the storage medium, and the computer program is loaded and executed by a processor to implement the end-to-end data security transmission method based on field importance as described in any one of claims 1-8.

10. An electronic device, comprising: A processor, a memory, and a computer program stored on the memory and executable on the processor, wherein the processor implements the end-to-end data security transmission method based on field importance as described in any one of claims 1-8 when executing the computer program.

Citation Information

Patent Citations

  • Information security protection method and device based on data transmission

    CN116389138A

  • Encrypted information management system based on big data

    CN119004494A

  • Data privacy security encryption method and system for communication operator

    CN119052783A

  • Communication content security encryption method

    CN119071074A

  • Data processing system and method

    CN119892432A