Asset data encryption method, device and system, equipment and medium
By obtaining and verifying the service types of customer asset data, extracting characteristic data and encrypting it, the problems of information asymmetry and tampering in financial services are solved, the security and accuracy of data are achieved, the risk of tampering is reduced, and resource waste is avoided.
Patent Information
- Application Number
- CN202510873226.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-06-27
AI Technical Summary
The prior art has problems in financial services such as information asymmetry, information fraud and information being tampered with when sharing information, resulting in an increase in the chance of errors or tampering with customer asset data, reducing security and privacy, and causing data redundancy and waste of resources.
By obtaining the data service type of customer asset data, data verification and processing are carried out, business services matching customer permissions are extracted, characteristic data is extracted and encryption is carried out according to the encryption method, data accuracy is ensured, and encrypted, and encrypted storage is used using blockchain technology and distributed storage areas.
It improves the security and accuracy of information, reduces the probability of being tampered with, avoids data redundancy and resource waste, and improves the efficiency of data management.
Smart Images

Figure CN120408684A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data encryption processing, and particularly to an encryption method, device, system, equipment and medium for asset data. Background Art
[0002] With the continuous advancement of the informatization process of enterprises, data has become an important part of enterprises. Data is generally divided into two categories, one is the data of the enterprise itself, and the other is the relevant data of the enterprise's service objects. For example, financial service enterprises provide asset allocation services for customers and need to protect the private asset information of customers. To effectively manage this data, data asset management technology has emerged.
[0003] To ensure the security of various asset data and information of customers, one commonly used encryption method is: using blockchain technology, encrypting the various asset data of customers and linking them in sequence in the form of blocks to form a continuously growing and immutable record chain to ensure its security, integrity and availability.
[0004] However, the currently commonly used methods have the following technical problems: there are problems such as information asymmetry, information falsification and tampering when sharing information in traditional financial services. As the business services participated by customers increase, the asset data of customers becomes more complex, and the probability of errors or tampering also increases. Encrypting with incorrect data not only reduces security and privacy, but also causes data redundancy and wastes management resources. Summary of the Invention
[0005] In view of the above problems, the present application is proposed to provide an encryption method, device, system, equipment and medium for asset data that overcomes the above problems or at least partially solves the above problems, including: An encryption method for asset data, the method includes: Obtain the asset data to be processed by the customer and the corresponding data service type of the asset data; Perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; When the processing result of the data verification processing is passed, extract feature data from the asset data, where the feature data includes: data corresponding to asset location features, business features and time features; After determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the feature data.
[0006] In a possible implementation, the data service type includes: asset transaction type, and the encryption method includes: transaction encryption method; The encrypting the asset data according to the encryption method and the feature data includes: If the encryption method is the transaction encryption method, look up the transaction data chain corresponding to the customer in a preset database and find the connection node corresponding to the transaction encryption method in the transaction data chain; Construct an encryption signature using the feature data, and construct a transaction encryption key using the encryption signature and a convention preset by the customer; After converting the transaction encryption key and the asset data into function values, bind the function values to the connection node to obtain an encrypted data chain; Store the encrypted data chain in a preset distributed storage area, and perform area encryption on the preset distributed storage area.
[0007] In a possible implementation, the data service type includes: asset update type, and the encryption method includes: update encryption method; The encrypting the asset data according to the encryption method and the feature data includes: If the encryption method is the update encryption method, look up the historical data corresponding to the customer in a preset database; Determine the difference value between the historical data and the asset data according to the data items of the historical data; After constructing an update encryption key using the value of the feature data and the difference value, encrypt the asset data using the update encryption key.
[0008] In a possible implementation, the data verification processing of the asset data based on the data service type includes: Search for a number of business services in a preset permission list based on the data service type, where the preset permission list is a list constructed using multiple services corresponding to customer permissions; Obtain the text content corresponding to each business service to get multiple service texts and obtain the description text of each item of data of the asset data; After manually proofreading each description text, calculate the text matching degree according to the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, determine that the processing result of the data verification processing is passed.
[0009] In a possible implementation, after the step where the processing result of the data verification processing is passed, the method further includes: Calculate the business level value of the customer using the asset data; If the service level value is different from the customer's historical level value, then search for several push services according to the service level value; Construct a business graph using the service information of the several push services and display the business graph to the customer.
[0010] In a possible implementation manner, after the step of performing data verification processing on the asset data based on the data service type, the method further includes: When the processing result of the data verification processing fails, determine the number of business anomalies of the customer within a preset time period, where the number of business anomalies is the number of times the processing result of the data verification processing fails; Perform dynamic alarm processing according to the number of business anomalies.
[0011] An encryption device for asset data, the system includes: An acquisition module, configured to acquire the asset data to be processed by the customer and the data service type corresponding to the asset data; A verification module, configured to perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; An extraction module, configured to, when the processing result of the data verification processing passes, extract feature data from the asset data, where the feature data includes: data corresponding to asset location features, business features, and time features; An encryption module, configured to, after determining the encryption method corresponding to the data service type, perform encryption processing on the asset data according to the encryption method and the feature data.
[0012] An encryption system for asset data, the system includes: an online management platform and multiple business terminals, and the online management platform is respectively communicatively connected to the multiple business terminals; The online management platform is applicable to the encryption method of asset data as described above.
[0013] A device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor, where when the computer program is executed by the processor, the steps of encrypting the asset data as described above are implemented.
[0014] A computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of encrypting the asset data as described above are implemented.
[0015] This application has the following advantages: In an embodiment of the present application, the present application obtains asset data to be processed by a customer and a data service type corresponding to the asset data; performs data verification processing on the asset data based on the data service type; when the processing result of the data verification processing passes, extracts feature data from the asset data; after determining the encryption method corresponding to the data service type, encrypts the asset data according to the encryption method and the feature data. By performing data verification processing on the asset data according to the data service type, the present application can ensure the accuracy of information before encryption, improve the security of information, avoid encrypting with incorrect data, thereby avoiding data redundancy and waste of management resources; at the same time, the encryption process is encrypted according to a specific business type, which can further improve the security level and reduce the probability of being tampered with. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] To more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings required for the description of the present application. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 is a flowchart of the steps of an encryption method for asset data provided by an embodiment of the present application; Figure 2 is a structural block diagram of an encryption device for asset data provided by an embodiment of the present application; Figure 3 is a structural block diagram of an encryption system for asset data provided by an embodiment of the present application; Figure 4 is a schematic structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the drawings and specific embodiments. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application.
[0019] With the continuous advancement of the informatization process of enterprises, data has become an important part of enterprises. Data is generally divided into two categories, one is the data of the enterprise itself, and the other is the relevant data of the enterprise's service objects. For example, financial service enterprises provide asset allocation services for customers and need to protect the private asset information of customers. To effectively manage this data, data asset management technology has emerged.
[0020] To ensure the security of various asset data and information of customers, one commonly used encryption method is: using blockchain technology, encrypting the customer's various asset data and then linking them in sequence in the form of blocks to form a continuously growing and immutable record chain to ensure its security, integrity, and availability.
[0021] However, the commonly used methods currently have the following technical problems: there are problems such as information asymmetry, information falsification, and tampering when sharing information in traditional financial services. As the business services participated by customers continue to increase, the customer's asset data becomes more complex, and the probability of errors or tampering also increases accordingly. Encrypting using incorrect data not only reduces security and privacy, but also causes data redundancy and wastes management resources.
[0022] To solve the above technical problems, referring to Figure 1 , a step flowchart of an encryption method for asset data provided by an embodiment of the present application is shown; In one embodiment, the encryption method for asset data is applicable to the enterprise's management system or business processing system. In an application scenario, the management system can be an online management platform of a financial service enterprise, encrypting the asset data recorded by customers in the enterprise through the online management platform to improve data security and protect customer privacy.
[0023] Among them, by way of example, the encryption method for asset data may include: S11. Obtain the asset data to be processed by the customer and the data service type corresponding to the asset data.
[0024] In one embodiment, the customer may be a newly added customer of the business service or a previously registered customer. After the business personnel negotiate with the customer, they can obtain the customer's asset data and upload it to the online management platform, so that the online management platform can obtain the asset data to be processed by the customer. At the same time, the business personnel can upload the information corresponding to the business service negotiated this time to the online management platform, so that the online management platform can determine the data service type corresponding to the asset data.
[0025] Among them, the asset data may be related data such as the customer's financial management, insurance, deposits, property information, vehicles, etc.
[0026] Among them, the customer may be a newly added customer, and the uploaded asset data may be the data entered for the first time. After obtaining the asset data, business services are provided for it. Common business services include asset management, asset trading, information change, etc. For different business services, there are different data processing corresponding to data service types.
[0027] S12. Perform data verification and processing on the asset data based on the data service type, where the data verification and processing is a process of matching the asset data with the business services of the customer's permissions.
[0028] In addition to the enterprise's own processing, different business services may also involve the participation of different third parties. To ensure that data and information are not tampered with, so as to avoid encrypting with incorrect information and reducing the security of information, after obtaining the data service type, the asset data can be subjected to data verification and processing according to the data service type.
[0029] Among them, the data verification and processing can be a process of matching and proofreading the asset data with the business services of the customer's permissions, determining whether the asset data matches the business services corresponding to the customer's permissions in the enterprise, and at the same time reviewing whether the content of the asset data is incorrect. After determining that the customer's asset data is correct through the verification and processing, then encrypt it to ensure data security.
[0030] In an optional embodiment, different business services need to be determined for different data service types. Among them, as an example, the performing data verification and processing on the asset data based on the data service type may include the following sub-steps: S121. Search for several business services in a preset permission list based on the data service type, where the preset permission list is a list constructed using multiple services corresponding to the customer's permissions.
[0031] S122. Obtain the text content corresponding to each of the business services to obtain multiple service texts and obtain the description text of each item of the asset data.
[0032] S123. After manually proofreading each of the description texts, calculate the text matching degree according to the description texts and the multiple service texts, and when the text matching degree is greater than a preset threshold, determine that the processing result of the data verification and processing is passed.
[0033] S124. When the manual proofreading fails or the text matching degree is less than the preset threshold, determine that the processing result of the data verification and processing is not passed.
[0034] In an operation mode, different business services correspond to different data service types. For example, if the customer is conducting asset trading, its data service type can be the asset trading type. Another example is that if the customer changes its asset allocation (changing the a-class insurance of xx assets to b-class insurance), its data service type can be the asset update type.
[0035] Different data service types have different business services. Several business services can be searched within a preset permission list based on the data service type. Among them, the preset permission list is a list constructed using multiple services corresponding to customer permissions.
[0036] Different customers have different levels in the enterprise. For example, customers with more deposits have a higher level and greater permissions. Conversely, customers with a lower level have smaller permissions. Another example is that customers with a longer tenure have a higher level and greater permissions. Conversely, customers with a lower level have smaller permissions.
[0037] Different permissions have different business services or different permissions have different service terms in the same business service.
[0038] To match the customer's permissions, after determining the customer's permissions, multiple corresponding business service information can be searched according to their permissions, and a list can be constructed using the multiple searched business service information to obtain the preset permission list.
[0039] For example, referring to the above example, assume that the customer's data service type can be the asset trading type, and the business services corresponding to its permissions include deposit delivery service, signing service, supervision service, loan service, etc. A list can be constructed using the information of the above several business services to obtain the preset permission list.
[0040] Next, the corresponding text content can be obtained from the information of each business service to get multiple service texts. At the same time, the description text of each item of asset data can also be obtained.
[0041] In one operation mode, the information can be recognized by calling a text recognition model to extract the corresponding text content.
[0042] It should be noted that customers and business personnel generally upload their asset data through their smart terminals. The smart terminal can set a form for data filling, and then let the customer or business personnel fill in their asset data. After reading the form, the description information of each column and the content within the column can be read to obtain the description text.
[0043] After obtaining the description text, each description text can be transmitted to the technical personnel in the review department for them to conduct manual proofreading on each description text. Through manual proofreading, it can be determined whether the asset data to be encrypted is incorrect. If incorrect data is used for encryption, it will not only cause redundant stored data but also waste storage and management resources.
[0044] When the manual proofreading is passed, the text matching degree can be calculated based on the description text and multiple service texts. When the text matching degree is greater than the preset threshold, it is determined that the processing result of data verification and processing is passed.
[0045] Conversely, if the manual proofreading fails or the text matching degree is less than the preset threshold, it is determined that the processing result of the data verification process fails.
[0046] Since there are several description texts and multiple service texts, in an operation mode, in order to calculate the matching degree between the two types of texts, the similarity between each description text and each service text can be calculated one by one, and then multiple similarities corresponding to each description text can be obtained; then, the average value of the multiple similarities is calculated to obtain the text matching degree of each description text. When the text matching degree of each description text is greater than the preset threshold, it is determined that the processing result of the data verification process passes. Conversely, if any text matching degree is less than the preset threshold, it is determined that the processing result of the data verification process fails.
[0047] In another operation mode, each description text may be the description content of different assets, corresponding to different business services, so that each description text can correspond to a service text, and the similarity between each description text and its corresponding service text can be calculated to obtain the text matching degree of each description text. When the text matching degree of each description text is greater than the preset threshold, it is determined that the processing result of the data verification process passes. Conversely, if any text matching degree is less than the preset threshold, it is determined that the processing result of the data verification process fails.
[0048] In another operation mode, each description text may be the description content of the same asset, corresponding to the same business service, so that each description text corresponds to the same service text. The similarity between each description text and the corresponding service text can be calculated, and then the average value of the multiple similarities is calculated to obtain the text matching degree. When the text matching degrees are all greater than the preset threshold, it is determined that the processing result of the data verification process passes. Conversely, when the text matching degree is less than the preset threshold, it is determined that the processing result of the data verification process fails.
[0049] It should be noted that the neural network or the conventional calculation method of text similarity can be called for calculation, and this application does not make any limitations here.
[0050] In one of the embodiments, when the processing result of the data verification process passes, the enterprise can provide corresponding business services for the customers. According to the previous analysis, each customer has a corresponding level, which may change with the number of services, the asset price or the service life. In order to be able to push the corresponding business services to the customers in time when the business level of the customers changes, so as to enhance the customers' favorability towards the enterprise. Among them, as an example, after the step where the processing result of the data verification process passes, the method may further include the following steps: S21. Calculate the business level value of the customer by using the asset data.
[0051] S22. If the service level value is different from the customer's historical level value, search for several push services according to the service level value.
[0052] S23. Construct a business map using the service information of the several push services and display the business map to the customer.
[0053] In an operation mode, if the data service type is an asset transaction type, the amount of this transaction can be obtained from the asset data and the number of transactions of the customer can be counted. The customer's service level value is determined according to the size of the amount of this transaction and the number of transactions. For example, if the transaction amount is 0 - 100,000, it is level A; if the transaction amount is 100,000 - 500,000, it is level B; if the transaction amount is 500,000 - 1,000,000, it is level C, and so on. Then adjust the level according to the number of transactions. For example, for a level A customer, if the number of transactions within one year is 0 - 10 times, it is level A1; if the number of transactions within one year is 10 - 20 times, it is level A2; if the number of transactions within one year is 20 - 30 times, it is level A3, and so on.
[0054] In another operation mode, if the data service type is an asset update type and the customer changes the asset configuration within the enterprise, the asset value of the assets stored by the customer in the enterprise can be obtained from the asset data, and the customer's service level value is determined according to the size of the asset value. For example, if the asset is 0 - 100,000, it is level 1; if the asset is 100,000 - 500,000, it is level 2; if it is 500,000 - 1,000,000, it is level 3, and so on.
[0055] Next, it can be determined whether the service level value is the same as the customer's historical level value. The historical level value is the level value of the customer before obtaining the asset data to be processed. The service level value is the level value of the customer after obtaining the asset data to be processed and determining that business services can be provided according to the asset data. If the service level value is different from the customer's historical level value, it means that the customer's service level needs to be adjusted after completing this business service, and at the same time, the business services that can be provided to the customer may also be different. In order to match the customer's level, several push services can be searched according to the service level value.
[0056] Among them, the several push services are the business services that can be newly added after the customer adjusts from the historical level value to the service level value.
[0057] Furthermore, in order to facilitate the customer to view multiple different newly added services, a business map can be constructed using the service information of the several push services, and then the business map is transmitted to the customer's intelligent terminal, so that the intelligent terminal can display the business map to the customer.
[0058] In one operation mode, in order to construct a knowledge graph, relevant vocabulary of the knowledge graph ontology model can be extracted from the service information of the push service, and the vocabulary is organized in the form of a relational network including several connection lines to form an initial model of the knowledge graph; the initial model is imported into a graph database for storage.
[0059] Among them, the vocabulary related to the knowledge graph ontology model can be element information related to business services, including business handling materials, completed materials, business content, parties, rules, labels, benefits, etc. The relational network diagram of several connection lines is the reference relationship between the elements of the business service; According to the above initial model, each content of the business service is combined, and an icon of the business service is added to form a business knowledge graph. Subsequently, customers can determine whether they need to adjust their business services by viewing the business knowledge graph.
[0060] In one of the embodiments, data verification may go wrong or the verification result is not passed. In order to correct and adjust the error situation, as an example, after the step of performing data verification processing on the asset data based on the data service type, the method may further include the following steps: S31. When the processing result of the data verification processing is not passed, determine the number of business anomalies of the customer within a preset time period, where the number of business anomalies is the number of times that the processing result of the data verification processing is not passed.
[0061] S32. Perform dynamic alarm processing according to the number of business anomalies.
[0062] The information filled in by the customer this time may be incorrect, resulting in the processing result of the data verification processing not being passed. In order to allow the customer to fill in the information again, the number of business anomalies of the customer within a preset time period can be determined, where the number of business anomalies is the number of times that the processing result of the data verification processing is not passed. For example, it can be the number of times that the processing result of the data verification processing of the customer's asset data is not passed within one day or ten days.
[0063] Then, dynamic alarm processing can be performed according to different numbers of business anomalies. For example, when the number of business anomalies is within 2 times, a warning can be sent to the business personnel to remind the business personnel to pay attention; when the number of business anomalies is within 3 - 5 times, an information error message can be sent to the customer's family members and the business processing can be suspended; when the number of business anomalies exceeds 5 times, the customer's information is blocked and an alarm is triggered.
[0064] The specific alarm operation can also be adjusted according to actual needs. This application does not make any limitations here.
[0065] S13. When the processing result of the data verification and processing passes, extract feature data from the asset data. The feature data includes: data corresponding to the asset location feature, business feature, and time feature.
[0066] When the processing result of the data verification and processing passes, determine that the customer conducts the corresponding business service. At this time, in order to ensure that information such as relevant operations (including transactions and updates) of the business service will not be stolen, feature data can be extracted from the asset data. The feature data includes: data corresponding to the asset location feature, business feature, and time feature. Subsequently, the feature data is used for encryption.
[0067] Among them, the asset location feature can be the specific location of the asset. For physical assets, it can be its location coordinates. For virtual assets or intangible assets, it can be the storage location of the virtual asset. The business feature can be the business number, label number, etc. The time feature can be the time of business processing.
[0068] S14. After determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the feature data.
[0069] In one embodiment, there may be multiple types of the customer's business services, and different business service types have different encryption methods. The encryption method corresponding to its data service type can be determined, and then the asset data is encrypted using the feature data according to the encryption method to ensure the security of its data.
[0070] In one of the embodiments, the data service type includes: the asset transaction type, which provides services for customers to conduct asset transactions; correspondingly, the encryption method of the data service type is the transaction encryption method. Among them, as an example, the encrypting the asset data according to the encryption method and the feature data may include the following sub-steps: S41. If the encryption method is the transaction encryption method, search for the transaction data chain corresponding to the customer in the preset database and search for the connection node corresponding to the transaction encryption method in the transaction data chain.
[0071] S42. Construct an encryption signature using the feature data, and use the encryption signature and the convention preset by the customer to construct a transaction encryption key.
[0072] S43. After converting the transaction encryption key and the asset data into a function value, bind the function value to the connection node to obtain an encrypted data chain.
[0073] S44. Store the encrypted data chain in the preset distributed storage area, and perform area encryption on the preset distributed storage area.
[0074] In an operation mode, if the encryption method is a transaction encryption method, the transaction data chain corresponding to the customer is searched from a preset database, and the connection node corresponding to the transaction encryption method is searched in the transaction data chain.
[0075] Among them, the transaction data chain is a blockchain constructed by the customer for transactions in this enterprise. Each data block of the blockchain is the relevant data of the customer's previous transactions. In order to connect the current transaction with the previous transactions to form the customer's own blockchain, the connection node corresponding to the transaction encryption method can be searched in the transaction data chain, and this connection node is the address at the end of the transaction data chain.
[0076] Next, a cryptographic signature can be constructed using the feature data, and a transaction encryption key can be constructed using the cryptographic signature and the convention preset by the customer.
[0077] Among them, the method of constructing the cryptographic signature can be to extract a value from the feature data and simultaneously obtain the personal number of the customer, which is the identification number of the enterprise. Then, the value of the feature data is hashed to generate a hash value H(M). Among them, H(M) is the hash value, and hi(mi) represents the result of hashing the i-th part of the value of the feature data, and ⊕ represents the bitwise exclusive OR operation.
[0078] The hash value H(M) is digitally signed using the identification number to generate a cryptographic signature S. Among them, S is the cryptographic signature, and N is the modulus in the RSA algorithm.
[0079] The generated digital signature S is appended with the convention preset by the customer to form an encrypted key with a signature. Then, after converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain.
[0080] At the same time, in order to protect the information and data of each customer and distinguish the information and data of each customer, the encrypted data chain can be stored in a preset distributed storage area, and the preset distributed storage area is encrypted.
[0081] Among them, the preset distributed storage area is the area allocated after the customer creates an account. When encrypting the preset distributed storage area, it can also be encrypted using the cryptographic signature. Each time data is extracted, the cryptographic signature generated last time needs to be used for verification. Only after passing the verification can the encrypted data chain be extracted, and the encrypted data chain is used as the transaction data chain for the next encryption and used for the next processing.
[0082] Through the encryption of data and the encryption of the storage area, the information security can be greatly ensured, and the risk of information being stolen can be reduced.
[0083] In one embodiment, the data service type includes: an asset update type, which can be a type for a customer to perform asset allocation update processing. The encryption method for the asset update type is an update encryption method; wherein, by way of example, encrypting the asset data according to the encryption method and the feature data may include the following sub-steps: S51. If the encryption method is the update encryption method, look up the historical data corresponding to the customer from a preset database.
[0084] S52. Determine the difference value between the historical data and the asset data according to the data items of the historical data.
[0085] S53. After constructing an update encryption key using the value of the feature data and the difference value, encrypt the asset data using the update encryption key.
[0086] In one operation mode, if the encryption method is the update encryption method, look up the historical data corresponding to the customer from a preset database. The historical data may be the asset data previously stored by the customer.
[0087] Then, the difference value between the historical data and the asset data can be determined according to the data items of the historical data. Among them, the data items may be items of different assets. For example, the customer's assets include aa wealth management, bb insurance, and cc fixed deposits.
[0088] The customer needs to reconfigure and update their three assets. The values of wealth management, insurance, and fixed deposits can be obtained from the historical data, and then the values of wealth management, insurance, and fixed deposits can be obtained from the asset data. Then calculate the difference value of wealth management, the difference value of insurance, and the difference value of fixed deposits respectively.
[0089] Then construct a key using the value of the feature data and the value of the difference value to obtain an update encryption key.
[0090] In one operation mode, the construction method may splice the value of the feature data to obtain a spliced value, and then add the values of several difference values to the spliced value at a preset character interval to obtain an update encryption key.
[0091] In another operation mode, a binary secret key value can be generated from the values of several feature data based on a quantum encryption algorithm and the value of the difference value can be converted into a binary value. The binary secret key value and the binary value are concatenated as a string, and then the string is photon polarized in a preset polarization direction to generate an encryption key.
[0092] Subsequently, encrypt the asset data using the update encryption key. The encryption method may be to compress the asset data using the encryption key as a file encryption password, and the specific encryption method can be adjusted according to actual needs.
[0093] In this embodiment, the embodiment of the present application provides an encryption method for asset data, and its beneficial effects are as follows: The present application obtains the asset data to be processed by the customer and the corresponding data service type of the asset data; performs data verification processing on the asset data based on the data service type; when the processing result of the data verification processing passes, extracts feature data from the asset data; after determining the encryption method corresponding to the data service type, encrypts the asset data according to the encryption method and the feature data. The present application performs data verification processing on the asset data according to the data service type, can ensure the accuracy of information before encryption, can improve the security of information, avoid encrypting with incorrect data, thereby avoiding data redundancy and waste of management resources; at the same time, the encryption process is encrypted according to a specific business type, which can further improve the security and reduce the probability of being tampered with.
[0094] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, refer to the partial description of the method embodiment.
[0095] Referring to Figure 2 , a structural block diagram of an encryption device for asset data provided by an embodiment of the present application is shown; Specifically, it includes: An acquisition module 201, configured to acquire the asset data to be processed by the customer and the corresponding data service type of the asset data; A verification module 202, configured to perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; An extraction module 203, configured to, when the processing result of the data verification processing passes, extract feature data from the asset data, where the feature data includes: data corresponding to asset location features, business features, and time features; An encryption module 204, configured to, after determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the feature data.
[0096] Optionally, the data service type includes: asset transaction type, and the encryption method includes: transaction encryption method; The encrypting the asset data according to the encryption method and the feature data includes: If the encryption method is a transaction encryption method, then search for the transaction data chain corresponding to the customer in a preset database and search for the connection node corresponding to the transaction encryption method in the transaction data chain; Construct an encrypted signature using the said feature data, and construct a transaction encryption key using the encrypted signature and a convention preset by the customer; After converting the transaction encryption key and the asset data into function values, bind the function values to the connection nodes to obtain an encrypted data chain; Store the encrypted data chain in a preset distributed storage area, and perform area encryption on the preset distributed storage area.
[0097] Optionally, the data service type includes: asset update type, and the encryption method includes: update encryption method; The encrypting and processing the asset data according to the encryption method and the feature data includes: If the encryption method is the update encryption method, look up the historical data corresponding to the customer from a preset database; Determine the difference value between the historical data and the asset data according to the data items of the historical data; After constructing an update encryption key using the value of the feature data and the difference value, encrypt the asset data using the update encryption key.
[0098] Optionally, the data verification processing of the asset data based on the data service type includes: Search for a number of business services in a preset permission list based on the data service type, where the preset permission list is a list constructed using multiple services corresponding to customer permissions; Obtain the text content corresponding to each of the business services to get multiple service texts and obtain the description text of each item of data of the asset data; After manually proofreading each of the description texts, calculate the text matching degree according to the description texts and the multiple service texts, and when the text matching degree is greater than a preset threshold, determine that the processing result of the data verification processing is passed.
[0099] Optionally, the device further includes: A level module, configured to calculate a business level value of the customer using the asset data after the step where the processing result of the data verification processing is passed; A push module, configured to search for a number of push services according to the business level value if the business level value is different from the customer's historical level value; A graph module, configured to construct a business graph using the service information of the number of push services and display the business graph to the customer.
[0100] Optionally, the device further includes: A frequency module, configured to determine the number of business anomalies of a customer within a preset duration when the processing result of the data verification process is not passed after the step of performing data verification processing on the asset data based on the data service type, where the number of business anomalies is the number of times the processing result of the data verification process is not passed; An alarm module, configured to perform dynamic alarm processing according to the number of business anomalies.
[0101] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0102] Refer to Figure 3 , which shows a structural block diagram of an encryption system for asset data provided by an embodiment of the present application; Specifically, it includes: an online management platform and multiple business terminals, and the online management platform is respectively communicatively connected to the multiple business terminals; The online management platform is applicable to the encryption method for asset data as described in the above embodiment.
[0103] Refer to Figure 4 , which shows a computer device for an encryption method of asset data of the present application. Specifically, it may include the following: The above computer device 12 is presented in the form of a general computing device. The components of the computer device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).
[0104] The bus 18 represents one or more of several bus 18 structures, including a memory bus 18 or a memory controller, a peripheral bus 18, a graphics acceleration port, a processor, or a local bus 18 using any bus 18 structure in multiple bus 18 structures. For example, these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus 18, a Micro Channel Architecture (MAC) bus 18, an Enhanced ISA bus 18, a Video Electronics Standards Association (VESA) local bus 18, and a Peripheral Component Interconnect (PCI) bus 18.
[0105] The computer device 12 typically includes a variety of computer system-readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0106] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The computing device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 can be used for reading from and writing to non-removable, non-volatile magnetic media (commonly referred to as a "hard disk drive"). Although Figure 4 not shown in FIG. Figure 4 , a disk drive for reading from and writing to a removable, non-volatile magnetic disk (such as a "floppy disk"), and an optical disk drive for reading from and writing to a removable, non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical media) can be provided. In these instances, each drive can be connected to the bus 18 by one or more data media interfaces. The memory may include at least one program product having a set (at least one) of program modules 42 that are configured to carry out the functions of the embodiments of the present application.
[0107] A program / utility 40 having a set (at least one) of program modules 42 can be stored, for example, in the memory. Such program modules 42 include—but are not limited to—an operating system, one or more application programs, other program modules 42, and program data, and an implementation of a network environment may be included in each or some combination of these examples. The program modules 42 generally carry out the functions and / or methods in the embodiments described in the present application.
[0108] The computing device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, a camera, etc.), and can also communicate with one or more devices that enable a user to interact with the computing device 12, and / or with any device that enables the computing device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 22. Moreover, the computing device 12 can also communicate with one or more networks (such as a local area network (LAN)), a wide area network (WAN), and / or a public network (such as the Internet) through a network adapter 20. As shown, the network adapter 20 communicates with other modules of the computing device 12 through the bus 18. It should be understood that although Figure 4 not shown in FIG. Figure 4 , other hardware and / or software modules can be used in conjunction with the computing device 12, including but not limited to: microcode, device drivers, a redundant processing unit 16, an external disk drive array, a RAID system, a tape drive, and a data backup storage system 34, etc.
[0109] The processing unit 16 executes various functional applications and data processing by running the programs stored in the system memory 28, for example, implementing the encryption method for asset data provided in the embodiments of the present application.
[0110] That is, when the above-mentioned processing unit 16 executes the above-mentioned program, it realizes: Obtain the asset data to be processed by the customer and the data service type corresponding to the asset data; Perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; When the processing result of the data verification processing passes, extract feature data from the asset data, and the feature data includes: data corresponding to asset location features, business features, and time features; After determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the feature data.
[0111] In the embodiments of the present application, the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it realizes the encryption method for asset data provided in all embodiments of the present application.
[0112] That is, when the program is executed by the processor, it realizes: Obtain the asset data to be processed by the customer and the data service type corresponding to the asset data; Perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; When the processing result of the data verification processing passes, extract feature data from the asset data, and the feature data includes: data corresponding to asset location features, business features, and time features; After determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the feature data.
[0113] Any combination of one or more computer-readable media may be employed. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present document, a computer-readable storage medium may be any tangible medium that contains or stores a program which can be used by or in connection with an instruction execution system, apparatus, or device.
[0114] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take many forms, including - but not limited to - an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0115] The computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts among the various embodiments may be referred to each other.
[0116] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0117] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the said element.
[0118] The above has introduced in detail a method, device, system, equipment and medium for encrypting asset data provided by the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A method for encrypting asset data, characterized in that, The method includes: Obtaining the asset data to be processed by the customer and the corresponding data service type of the asset data; Performing data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; When the processing result of the data verification processing passes, extracting feature data from the asset data, where the feature data includes: data corresponding to asset location features, business features, and time features; After determining the encryption method corresponding to the data service type, encrypting the asset data according to the encryption method and the feature data.
2. The encryption method for asset data according to claim 1, characterized in that, The data service type includes: asset transaction type, and the encryption method includes: transaction encryption method; The encrypting the asset data according to the encryption method and the feature data includes: If the encryption method is the transaction encryption method, searching for the transaction data chain corresponding to the customer in a preset database and searching for the connection node corresponding to the transaction encryption method in the transaction data chain; Constructing an encryption signature using the feature data and constructing a transaction encryption key using the encryption signature and the convention preset by the customer; After converting the transaction encryption key and the asset data into function values, binding the function values to the connection node to obtain an encrypted data chain; Storing the encrypted data chain in a preset distributed storage area and performing area encryption on the preset distributed storage area.
3. The encryption method for asset data according to claim 1, characterized in that, The data service type includes: asset update type, and the encryption method includes: update encryption method; The encrypting the asset data according to the encryption method and the feature data includes: If the encryption method is the update encryption method, searching for the historical data corresponding to the customer in a preset database; Determining the difference value between the historical data and the asset data according to the data items of the historical data; After constructing an update encryption key using the value of the feature data and the difference value, encrypting the asset data using the update encryption key.
4. The encryption method for asset data according to claim 1, wherein The performing data verification processing on the asset data based on the data service type includes: Searching for several business services in a preset permission list based on the data service type, where the preset permission list is a list constructed using multiple services corresponding to the customer's permissions; Obtaining the text content corresponding to each business service to obtain multiple service texts and obtaining the description text of each item of data of the asset data; After manually proofreading each description text, calculating the text matching degree according to the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, determining that the processing result of the data verification processing passes.
5. The encryption method for asset data according to any one of claims 1 to 4, characterized in that After the step where the processing result of the data verification processing passes, the method further includes: Calculating the business level value of the customer using the asset data; If the business level value is different from the customer's historical level value, searching for several push services according to the business level value; Constructing a business map using the service information of the several push services and displaying the business map to the customer.
6. The encryption method for asset data according to any one of claims 1 to 4, characterized in that After the step of performing data verification processing on the asset data based on the data service type, the method further includes: When the processing result of the data verification processing fails, determine the number of business anomalies of the customer within a preset time period, where the number of business anomalies is the number of times the processing result of the data verification processing fails; Perform dynamic alarm processing according to the number of business anomalies.
7. An encryption device for asset data, characterized in that, The device includes: An acquisition module, configured to acquire the asset data to be processed by the customer and the data service type corresponding to the asset data; A verification module, configured to perform data verification processing on the asset data based on the data service type, where the data verification processing is a process of matching and proofreading the asset data with the business services of the customer's permissions; An extraction module, configured to, when the processing result of the data verification processing passes, extract feature data from the asset data, where the feature data includes: data corresponding to asset location features, business features, and time features; An encryption module, configured to, after determining the encryption method corresponding to the data service type, perform encryption processing on the asset data according to the encryption method and the feature data.
8. An encryption system for asset data, characterized in that, The system includes: an online management platform and multiple business terminals, and the online management platform is communicatively connected to the multiple business terminals respectively; The online management platform is applicable to the encryption method of the asset data as described in any one of claims 1-6.
9. An electronic device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the encryption method of the asset data as described in any one of claims 1-6 when executing the computer program.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer-executable program, and the computer-executable program is used to cause a computer to execute the encryption method of the asset data as described in any one of claims 1-6.
Citation Information
Patent Citations
Data encryption method and device, computing equipment and storage medium
CN116522358A
Vehicle insurance operation method and device based on block chain, equipment and storage medium
CN116630065A
Server-based financial service digital processing method and system
CN118797690A
Service authorization method and related device
CN119691723A
Cited By
Financial data storage method, device, system and equipment and medium
CN120951360A
A method, apparatus, system, device, and medium for storing financial data.
CN120951360B