A method, device, system, equipment and medium for encrypting asset data

By obtaining the data service type of customer asset data to perform data verification and feature data extraction, and combining encryption to process the asset data, the problem of customer asset data being prone to errors or tampering is solved, and data security and resource utilization efficiency are improved.

CN120408684BActive Publication Date: 2025-09-19SHENZHEN TUOBAO SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510873226.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-09-19
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

In traditional financial services, customer asset data is prone to errors or tampering, resulting in reduced security and privacy, data redundancy and waste of resources.

Method used

By obtaining the data service type of customer asset data, data verification is performed to match customer permissions, feature data is extracted, and asset data is encrypted according to the encryption method, including transaction encryption and update encryption.

Benefits of technology

Ensure the accuracy of asset data encryption, improve security, reduce the probability of tampering, and avoid data redundancy and resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408684B_ABST
    Figure CN120408684B_ABST
Patent Text Reader

Abstract

The present application provides an asset data encryption method, apparatus, system, equipment and medium, including: obtaining the client's asset data to be processed and the data service type corresponding to the asset data; performing data verification processing on the asset data based on the data service type; when the processing result of the data verification processing is passed, extracting feature data from the asset data; after determining the encryption method corresponding to the data service type, encrypting the asset data according to the encryption method and the feature data. The present application performs data verification processing on the asset data according to the data service type, which can ensure that the information is accurate before encryption, improve the security of the information, avoid using wrong data for encryption, and thus avoid data redundancy and waste of management resources; at the same time, the encryption process is encrypted according to the specific business type, which can further improve the security and reduce the probability of tampering.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data encryption processing, and in particular to an asset data encryption method, apparatus, system, equipment and medium. Background Art

[0002] As enterprises continue to advance in informatization, data has become a crucial component. Data is generally categorized into two main types: the enterprise's own data and the data related to its service recipients. For example, financial services companies providing asset allocation services to clients need to protect their private asset information. To effectively manage this data, data asset management technologies have emerged.

[0003] In order to ensure the security of various types of customer asset data and information, one of the commonly used encryption methods is to use blockchain technology to encrypt the customer's various asset data and link them sequentially in the form of blocks to form a growing, tamper-proof record chain to ensure its security, integrity and availability.

[0004] However, currently used methods suffer from technical issues: traditional financial services are subject to information asymmetry, information falsification, and tampering during information sharing. As customers engage in more and more business services, their asset data becomes more complex, increasing the likelihood of errors or tampering. Using erroneous data for encryption not only reduces security and privacy, but also creates data redundancy and wastes management resources. Summary of the Invention

[0005] In view of the above problems, the present application is proposed to provide an asset data encryption method, apparatus, system, device and medium that overcomes the above problems or at least partially solves the above problems, including:

[0006] A method for encrypting asset data, the method comprising:

[0007] Obtain the client's asset data to be processed and the data service type corresponding to the asset data;

[0008] Performing data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer's authority;

[0009] When the result of the data verification process is passed, feature data is extracted from the asset data, the feature data including: data corresponding to asset location features, business features, and time features;

[0010] After determining the encryption method corresponding to the data service type, the asset data is encrypted according to the encryption method and the characteristic data.

[0011] In a possible implementation, the data service type includes: an asset transaction type, and the encryption method includes: a transaction encryption method;

[0012] The encrypting the asset data according to the encryption method and the characteristic data includes:

[0013] If the encryption method is a transaction encryption method, searching the transaction data chain corresponding to the customer from a preset database and searching the connection node corresponding to the transaction encryption method in the transaction data chain;

[0014] Constructing an encrypted signature using the characteristic data, and constructing a transaction encryption key using the encrypted signature and a convention preset by the customer;

[0015] After converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain;

[0016] The encrypted data chain is stored in a preset distributed storage area, and the preset distributed storage area is regionally encrypted.

[0017] In a possible implementation, the data service type includes: asset update type, and the encryption mode includes: update encryption mode;

[0018] The encrypting the asset data according to the encryption method and the characteristic data includes:

[0019] If the encryption method is an update encryption method, the historical data corresponding to the customer is searched from a preset database;

[0020] determining, based on data items of the historical data, a difference value between the historical data and the asset data;

[0021] After constructing an updated encryption key using the numerical value of the feature data and the difference value, the asset data is encrypted using the updated encryption key.

[0022] In a possible implementation, performing data verification processing on the asset data based on the data service type includes:

[0023] Searching for a plurality of business services in a preset permission list based on the data service type, wherein the preset permission list is a list constructed using a plurality of services corresponding to the customer's permissions;

[0024] Obtaining the text content corresponding to each of the business services to obtain multiple service texts and obtaining the description text of each item of the asset data;

[0025] After manually proofreading each of the description texts, a text matching degree is calculated based on the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, the processing result of the data verification process is determined to be passed.

[0026] In a possible implementation, after the step of checking that the data verification process has passed, the method further includes:

[0027] Calculating a customer's service level value using the asset data;

[0028] If the service level value is different from the customer's historical level value, searching for several push services according to the service level value;

[0029] A business map is constructed using the service information of the several push services, and the business map is displayed to customers.

[0030] In a possible implementation, after the step of performing data verification processing on the asset data based on the data service type, the method further includes:

[0031] When the result of the data verification process is failure, the number of business anomalies of the customer within a preset time period is determined, and the number of business anomalies is the number of times the result of the data verification process is failure;

[0032] Dynamic alarm processing is performed based on the number of business anomalies.

[0033] An asset data encryption device, the system comprising:

[0034] An acquisition module is used to obtain the client's asset data to be processed and the data service type corresponding to the asset data;

[0035] A verification module, configured to perform data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer authority;

[0036] an extraction module, configured to extract feature data from the asset data when the result of the data verification process is passed, the feature data including data corresponding to asset location features, business features, and time features;

[0037] The encryption module is used to determine the encryption method corresponding to the data service type and then encrypt the asset data according to the encryption method and the characteristic data.

[0038] An asset data encryption system, comprising: an online management platform and a plurality of business terminals, wherein the online management platform is communicatively connected to the plurality of business terminals respectively;

[0039] The online management platform is suitable for the asset data encryption method described above.

[0040] A device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the steps of encrypting asset data as described above when executed by the processor.

[0041] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of encrypting asset data as described above.

[0042] This application has the following advantages:

[0043] In an embodiment of the present application, the present application obtains the client's asset data to be processed and the data service type corresponding to the asset data; performs data verification processing on the asset data based on the data service type; when the processing result of the data verification processing is passed, extracts feature data from the asset data; after determining the encryption method corresponding to the data service type, encrypts the asset data according to the encryption method and feature data. The present application performs data verification processing on the asset data according to the data service type, which can ensure that the information is accurate before encryption, improve the security of the information, avoid using incorrect data for encryption, and thus avoid data redundancy and waste of management resources; at the same time, the encryption process is encrypted according to the specific business type, which can further improve security and reduce the probability of tampering. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for the description of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0045] Figure 1 This is a flowchart of a method for encrypting asset data provided by an embodiment of the present application;

[0046] Figure 2 This is a structural block diagram of an asset data encryption device provided by an embodiment of the present application;

[0047] Figure 3 This is a structural block diagram of an asset data encryption system provided by an embodiment of the present application;

[0048] Figure 4 It is a structural diagram of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0049] To make the objectives, features, and advantages of this application more readily apparent, the present application is further described below in conjunction with the accompanying drawings and specific embodiments. It is apparent that the embodiments described are only a portion of the embodiments of this application, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments in this application without inventive effort are also within the scope of protection of this application.

[0050] As enterprises continue to advance in informatization, data has become a crucial component. Data is generally categorized into two main types: the enterprise's own data and the data related to its service recipients. For example, financial services companies providing asset allocation services to clients need to protect their private asset information. To effectively manage this data, data asset management technologies have emerged.

[0051] In order to ensure the security of various types of customer asset data and information, one of the commonly used encryption methods is to use blockchain technology to encrypt the customer's various asset data and link them sequentially in the form of blocks to form a growing, tamper-proof record chain to ensure its security, integrity and availability.

[0052] However, currently used methods suffer from technical issues: traditional financial services are subject to information asymmetry, information falsification, and tampering during information sharing. As customers engage in more and more business services, their asset data becomes more complex, increasing the likelihood of errors or tampering. Using erroneous data for encryption not only reduces security and privacy, but also creates data redundancy and wastes management resources.

[0053] In order to solve the above technical problems, refer to Figure 1 , showing a flowchart of the steps of an asset data encryption method provided by an embodiment of the present application;

[0054] In one embodiment, the asset data encryption method is applicable to an enterprise's management system or business processing system. In one application scenario, the management system may be an online management platform for a financial services company. The online management platform encrypts the asset data recorded by customers at the company to enhance data security and protect customer privacy.

[0055] As an example, the encryption method of the asset data may include:

[0056] S11. Obtain the client's asset data to be processed and the data service type corresponding to the asset data.

[0057] In one embodiment, the customer may be a newly added customer for the business service or a previously registered customer. After the business personnel completes the negotiation with the customer, they can obtain the customer's asset data and upload it to the online management platform, allowing the online management platform to obtain the customer's pending asset data. At the same time, the business personnel can upload information corresponding to the business service negotiated to the online management platform, allowing the online management platform to determine the data service type corresponding to the asset data.

[0058] Among them, asset data can be customer's financial management, insurance, deposits, property information, vehicles and other related data.

[0059] The customer can be a newly added customer, and the uploaded asset data can be data entered for the first time. Business services are provided after acquiring the asset data. Common business services include asset management, asset trading, and information changes. Different data processing types correspond to different business services.

[0060] S12. Perform data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching the asset data with the business service of the customer's authority.

[0061] In addition to the company's own processing, different business services may also involve the participation of different third parties. In order to ensure that data and information are not tampered with and to avoid using incorrect information for encryption, which reduces information security, after obtaining the data service type, the asset data can be verified and processed according to the data service type.

[0062] Data verification involves matching and verifying asset data with the business services for which the customer has authority. This process verifies whether the asset data matches the business services corresponding to the customer's authority within the enterprise and checks the asset data for errors. Once the customer's asset data is verified to be correct, it is encrypted to ensure data security.

[0063] In an optional embodiment, different business services need to be determined for different data service types. As an example, performing data verification on the asset data based on the data service type may include the following sub-steps:

[0064] S121. Search for several business services in a preset permission list based on the data service type, wherein the preset permission list is a list constructed using multiple services corresponding to customer permissions.

[0065] S122: Obtain the text content corresponding to each business service to obtain multiple service texts and obtain the description text of each item of asset data.

[0066] S123. After manually proofreading each of the description texts, a text matching degree is calculated based on the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, the processing result of the data verification process is determined to be passed.

[0067] S124: When the manual proofreading fails or the text matching degree is less than a preset threshold, the processing result of the data verification process is determined to be failed.

[0068] In one operation mode, different business services correspond to different data service types. For example, if a customer is trading assets, the data service type might be asset transaction. Another example is if a customer is changing their asset configuration (changing insurance type A for asset XX to insurance type B), the data service type might be asset update.

[0069] Different data service types have different business services. Based on the data service type, you can search for several business services in the preset permission list. The preset permission list is a list constructed using multiple services corresponding to customer permissions.

[0070] Different customers have different ranks within the company. For example, customers with more deposits have higher ranks and greater authority, while customers with lower ranks have lower authority. Another example is that customers with longer service have higher ranks and greater authority, while customers with lower ranks have lower authority.

[0071] Different permissions have different business services, or different permissions have different service terms for the same business service.

[0072] In order to match the customer's permissions, after determining the customer's permissions, multiple corresponding business service information can be searched according to the permissions, and a list can be constructed using the multiple searched business service information to obtain a preset permission list.

[0073] For example, referring to the above example, suppose the customer's data service type is asset transaction type, and the business services corresponding to its permissions include deposit delivery service, contract service, supervision service, loan service, etc. The information of these business services can be used to construct a list to obtain a preset permission list.

[0074] Next, the corresponding text content can be obtained from the information of each business service to obtain multiple service texts, and the description text of each item of asset data can also be obtained.

[0075] In one operation mode, the information may be recognized by calling a text recognition model to extract the corresponding text content.

[0076] It should be noted that customers and business personnel generally upload their asset data through their smart terminals. The smart terminals can set up data filling forms and then let customers or business personnel fill in their asset data. After reading the form, they can read the description information of each column and the content in the column to obtain the description text.

[0077] After obtaining the description text, each description text can be transmitted to the technical staff of the audit department for manual proofreading. Manual proofreading can determine whether the asset data to be encrypted contains errors. If incorrect data is used for encryption, it will not only cause redundant data storage, but also waste storage and management resources.

[0078] When manual proofreading is passed, the text matching degree can be calculated based on the description text and multiple service texts, and when the text matching degree is greater than a preset threshold, the processing result of the data verification process is determined to be passed.

[0079] On the contrary, if the manual proofreading fails or the text matching degree is less than a preset threshold, the processing result of the data verification process is determined to be failed.

[0080] Since there are multiple description texts and multiple service texts, in order to calculate the matching degree between the two types of text, in one operation mode, the similarity between each description text and each service text can be calculated one by one, thereby obtaining multiple similarities corresponding to each description text; then, the average of these multiple similarities is calculated to obtain the text matching degree of each description text. If the text matching degree of each description text is greater than a preset threshold, the data verification process is determined to have passed. Conversely, if any text matching degree is less than the preset threshold, the data verification process is determined to have failed.

[0081] In another operation mode, each description text may be a description of a different asset, corresponding to a different business service, such that each description text corresponds to a service text. The similarity between each description text and its corresponding service text can be calculated to obtain a text matching degree for each description text. If the text matching degree of each description text exceeds a preset threshold, the data verification process is determined to have passed. Conversely, if any text matching degree is less than the preset threshold, the data verification process is determined to have failed.

[0082] In another operation mode, each description text may be a description of the same asset and correspond to the same business service, so that each description text corresponds to the same service text. The similarity between each description text and the corresponding service text can be calculated, and then the average of multiple similarities can be calculated to obtain the text matching degree. If the text matching degree is greater than a preset threshold, the data verification process is determined to have passed. Conversely, if the text matching degree is less than the preset threshold, the data verification process is determined to have failed.

[0083] It should be noted that the calculation can be performed by calling a neural network or a conventional calculation method for text similarity, and this application does not limit this.

[0084] In one embodiment, when the result of the data verification process is passed, the enterprise can provide the corresponding business services to the customer. According to the above analysis, each customer has a corresponding level, and its level may change with the number of services, asset price or years. In order to push the corresponding business services to the customer in a timely manner when the customer's business level changes, so as to improve the customer's favorability towards the enterprise, as an example, after the step of passing the data verification process, the method may also include the following steps:

[0085] S21. Calculate the customer's service level value using the asset data.

[0086] S22: If the service level value is different from the customer's historical level value, search for several push services according to the service level value.

[0087] S23: Build a business map using the service information of the plurality of push services, and present the business map to the customer.

[0088] In one operation mode, if the data service type is asset transaction, the transaction amount and the number of transactions can be obtained from the asset data. The customer's service level can be determined based on the transaction amount and number of transactions. For example, a transaction amount of 0-100,000 is classified as A, a transaction amount of 100,000-500,000 is classified as B, a transaction amount of 500,000-1,000,000 is classified as C, and so on. The level is further adjusted based on the number of transactions. For example, an A-level customer with 0-10 transactions in a year is classified as A1, 10-20 transactions is classified as A2, 20-30 transactions is classified as A3, and so on.

[0089] In another operation mode, if the data service type is asset update, when a customer changes their asset configuration within the enterprise, the asset value of the customer's stored assets can be obtained from the asset data. The customer's service level value is determined based on the asset value. For example, assets between 0-100,000 are ranked as Level 1, assets between 100,000-500,000 are ranked as Level 2, 500,000-1,000,000 are ranked as Level 3, and so on.

[0090] Next, you can determine whether the service level value matches the customer's historical level value. The historical level value is the customer's level value before obtaining the asset data to be processed. The service level value is the customer's level value after obtaining the asset data to be processed and determining the business services that can be provided based on the asset data. If the service level value differs from the customer's historical level value, it means that the customer's service level needs to be adjusted after completing the current business service. At the same time, the business services that can be provided to the customer may also be different. To match the customer's level, you can search for several push services based on the service level value.

[0091] Among them, several push services are new business services that can be added after the customer adjusts from the historical level value to the business level value.

[0092] Furthermore, in order to facilitate customers to view multiple different new services, the service information of several push services can be used to construct a business map, and then the business map can be transmitted to the customer's smart terminal so that the smart terminal can display the business map to the customer.

[0093] In one operation mode, in order to construct a graph, vocabulary related to the graph ontology model can be extracted from the service information of the push service, and the vocabulary can be organized in the form of a relationship network containing several connecting lines to form an initial model of the graph; the initial model is imported into the graph database for storage.

[0094] Among them, the vocabulary related to the graph ontology model can be the element information related to business services, including business processing materials, completion materials, business content, parties, rules, labels, benefits, etc. The relationship network diagram with several connecting lines is the reference relationship between the elements of the business service;

[0095] Based on the initial model, the various business service components are combined and icons are added to form a business map. Customers can then review the business map to determine whether adjustments to their business services are necessary.

[0096] In one embodiment, a data verification error may occur or the audit result may be rejected. In order to correct and adjust the error, as an example, after the step of performing data verification on the asset data based on the data service type, the method may further include the following steps:

[0097] S31. When the processing result of the data verification process is failure, the number of business anomalies of the customer within a preset time period is determined, and the number of business anomalies is the number of times the processing result of the data verification process is failure.

[0098] S32. Perform dynamic alarm processing according to the number of business anomalies.

[0099] A customer may have entered incorrect information, resulting in a data verification failure. To allow the customer to re-enter the form, the system can determine the number of business anomalies the customer has experienced within a preset timeframe. This number of business anomalies is the number of times the data verification process has failed. For example, this could be the number of times the customer's asset data has failed data verification within a single day or ten days.

[0100] Then, dynamic alarm processing can be performed based on the number of different business anomalies. For example, if the number of business anomalies is less than 2, an early warning can be issued to business personnel to remind them to pay attention; if the number of business anomalies is within 3-5, an information error message will be sent to the customer's family and business processing will be suspended; if the number of business anomalies exceeds 5, the customer information will be blocked and an alarm will be triggered.

[0101] The specific alarm operation can also be adjusted according to actual needs. This application does not limit it here.

[0102] S13. When the result of the data verification process is passed, feature data is extracted from the asset data, where the feature data includes data corresponding to asset location features, business features, and time features.

[0103] If the data verification process passes, the customer is confirmed to have access to the corresponding business service. To prevent information related to business service operations (including transactions and updates) from being stolen, feature data is extracted from the asset data. This feature data includes data corresponding to asset location features, business features, and time features. This feature data is then encrypted.

[0104] The asset location feature can be the specific location of the asset. For physical assets, this can be its location coordinates. For virtual or intangible assets, this can be the storage location of the virtual asset. The business feature can be the business number or tag number, and the time feature can be the time when the business was processed.

[0105] S14: After determining the encryption method corresponding to the data service type, encrypt the asset data according to the encryption method and the characteristic data.

[0106] In one embodiment, a customer may have multiple business service types, and different business service types have different encryption methods. The encryption method corresponding to its data service type can be determined, and then the asset data can be encrypted using feature data according to the encryption method to ensure the security of its data.

[0107] In one embodiment, the data service type includes: an asset transaction type, which is to provide asset transaction services to customers; correspondingly, the encryption method of the data service type is a transaction encryption method.

[0108] As an example, the encrypting the asset data according to the encryption method and the characteristic data may include the following sub-steps:

[0109] S41. If the encryption method is a transaction encryption method, search for a transaction data chain corresponding to the customer from a preset database and search for a connection node corresponding to the transaction encryption method in the transaction data chain.

[0110] S42: Construct an encrypted signature using the characteristic data, and construct a transaction encryption key using the encrypted signature and a convention preset by the customer.

[0111] S43: After converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain.

[0112] S44: storing the encrypted data chain in a preset distributed storage area, and performing regional encryption on the preset distributed storage area.

[0113] In one operation mode, if the encryption mode is a transaction encryption mode, the transaction data chain corresponding to the customer is searched from a preset database and a connection node corresponding to the transaction encryption mode is searched in the transaction data chain.

[0114] The transaction data chain is a blockchain constructed by customers conducting transactions with the company. Each data block on the blockchain contains data related to the customer's previous transactions. To connect the current transaction with previous transactions to form the customer's own blockchain, the transaction data chain can be searched for the connection node corresponding to the transaction encryption method. This connection node is the address at the end of the transaction data chain.

[0115] Next, the characteristic data can be used to construct an encrypted signature, and the encrypted signature and the customer's preset convention can be used to construct a transaction encryption key.

[0116] The cryptographic signature can be constructed by extracting a numerical value from the feature data and simultaneously obtaining the customer's personal number, which serves as the company's identification code. The numerical value of the feature data is then hashed to generate a hash value H(M). H(M) is the hash value, and hi(mi) represents the result of hashing the i-th portion of the numerical value of the feature data, representing a bitwise exclusive OR operation.

[0117] Use the number code to digitally sign the hash value H(M) to generate an encrypted signature S. Where S is the encrypted signature and N is the modulus in the RSA algorithm.

[0118] The generated digital signature S is attached to the client's pre-set convention to form an encryption key with the signature. The transaction encryption key and asset data can then be converted into a function value, which is then bound to the connection node to obtain an encrypted data chain.

[0119] At the same time, in order to protect the information and data of each customer and distinguish the information and data of each customer, the encrypted data chain can be stored in a preset distributed storage area, and the preset distributed storage area can be regionally encrypted.

[0120] The pre-set distributed storage area is the area allocated after a customer creates an account. When encrypting the pre-set distributed storage area, the signature can also be used for encryption. Each time data is retrieved, it must be verified using the previously generated encryption signature. Only after verification is successful can the encrypted data chain be extracted and used as the next encrypted transaction data chain for the next processing.

[0121] By encrypting data and storage areas, information security can be greatly ensured and the risk of information theft can be reduced.

[0122] In one embodiment, the data service type includes an asset update type, which may be a type in which a customer updates an asset configuration. The encryption method for the asset update type is an update encryption method. For example, encrypting the asset data based on the encryption method and the feature data may include the following sub-steps:

[0123] S51. If the encryption mode is an update encryption mode, search for historical data corresponding to the customer from a preset database.

[0124] S52: Determine the difference between the historical data and the asset data based on the data items of the historical data.

[0125] S53: After constructing an updated encryption key using the numerical value of the feature data and the difference value, encrypt the asset data using the updated encryption key.

[0126] In one operation mode, if the encryption mode is an update encryption mode, the historical data corresponding to the customer is searched from a preset database. The historical data may be the asset data previously stored by the customer.

[0127] Next, the difference between the historical data and the asset data can be determined based on the data items in the historical data. The data items can be items of different assets. For example, a customer's assets include AA financial management, BB insurance, and CC fixed deposits.

[0128] If a client needs to reconfigure and update their three assets, they can obtain the values ​​of wealth management, insurance, and fixed deposits from historical data, and then obtain the values ​​of wealth management, insurance, and fixed deposits from asset data. They can then calculate the difference value of wealth management, insurance, and fixed deposits respectively.

[0129] Then, the numerical value of the characteristic data and the numerical value of the difference value are used to construct a key to obtain an updated encryption key.

[0130] In one operation mode, the construction mode can concatenate the numerical values ​​of the characteristic data to obtain a concatenated value, and then add the numerical values ​​of several difference values ​​to the concatenated value according to a preset character interval to obtain an updated encryption key.

[0131] In another operation mode, based on the quantum encryption algorithm, the numerical values ​​of several characteristic data can be used to generate a binary key value and the numerical value of the difference value can be converted into a binary value. The binary key value and the binary value can be concatenated into a string, and then the string can be photon polarized according to a preset polarization direction to generate an encryption key.

[0132] The asset data is then encrypted using an updated encryption key. The encryption method can be to compress the asset data using the encryption key as the file encryption password. The specific encryption method can be adjusted according to actual needs.

[0133] In this embodiment, the embodiment of the present application provides an encryption method for asset data, which has the following beneficial effects: the present application obtains the customer's asset data to be processed and the data service type corresponding to the asset data; performs data verification processing on the asset data based on the data service type; when the processing result of the data verification processing is passed, the feature data is extracted from the asset data; after determining the encryption method corresponding to the data service type, the asset data is encrypted according to the encryption method and the feature data. The present application performs data verification processing on the asset data according to the data service type, which can ensure that the information is accurate before encryption, improve the security of the information, avoid using incorrect data for encryption, and thus avoid causing data redundancy and wasting management resources; at the same time, the encryption process is encrypted according to the specific business type, which can further improve security and reduce the probability of tampering.

[0134] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0135] Reference Figure 2 , shows a structural block diagram of an asset data encryption device provided by an embodiment of the present application;

[0136] Specifically include:

[0137] Acquisition module 201, used to acquire the client's asset data to be processed and the data service type corresponding to the asset data;

[0138] Verification module 202, configured to perform data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer authority;

[0139] The extraction module 203 is configured to extract feature data from the asset data when the result of the data verification process is passed, wherein the feature data includes data corresponding to asset location features, business features, and time features;

[0140] The encryption module 204 is configured to determine an encryption method corresponding to the data service type and then encrypt the asset data according to the encryption method and the characteristic data.

[0141] Optionally, the data service type includes: asset transaction type, and the encryption method includes: transaction encryption method;

[0142] The encrypting the asset data according to the encryption method and the characteristic data includes:

[0143] If the encryption method is a transaction encryption method, searching the transaction data chain corresponding to the customer from a preset database and searching the connection node corresponding to the transaction encryption method in the transaction data chain;

[0144] Constructing an encrypted signature using the characteristic data, and constructing a transaction encryption key using the encrypted signature and a convention preset by the customer;

[0145] After converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain;

[0146] The encrypted data chain is stored in a preset distributed storage area, and the preset distributed storage area is regionally encrypted.

[0147] Optionally, the data service type includes: asset update type, and the encryption mode includes: update encryption mode;

[0148] The encrypting the asset data according to the encryption method and the characteristic data includes:

[0149] If the encryption method is an update encryption method, the historical data corresponding to the customer is searched from a preset database;

[0150] determining, based on data items of the historical data, a difference value between the historical data and the asset data;

[0151] After constructing an updated encryption key using the numerical value of the feature data and the difference value, the asset data is encrypted using the updated encryption key.

[0152] Optionally, the performing data verification processing on the asset data based on the data service type includes:

[0153] Searching for a plurality of business services in a preset permission list based on the data service type, wherein the preset permission list is a list constructed using a plurality of services corresponding to the customer's permissions;

[0154] Obtaining the text content corresponding to each of the business services to obtain multiple service texts and obtaining the description text of each item of the asset data;

[0155] After manually proofreading each of the description texts, a text matching degree is calculated based on the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, the processing result of the data verification process is determined to be passed.

[0156] Optionally, the device further comprises:

[0157] A rating module, configured to calculate a customer's service rating value using the asset data after the data verification process passes the processing result;

[0158] a push module, configured to search for a number of push services according to the service level value if the service level value is different from the customer's historical level value;

[0159] The graph module is used to construct a business graph using the service information of the several push services and to display the business graph to customers.

[0160] Optionally, the device further comprises:

[0161] a times module, configured to, after the step of performing data verification processing on the asset data based on the data service type, determine the number of business anomalies of the customer within a preset time period when the processing result of the data verification processing is failure, wherein the number of business anomalies is the number of times the processing result of the data verification processing is failure;

[0162] The alarm module is used to perform dynamic alarm processing according to the number of business anomalies.

[0163] As for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0164] Reference Figure 3 , shows a structural block diagram of an asset data encryption system provided by an embodiment of the present application;

[0165] Specifically comprising: an online management platform and multiple business terminals, wherein the online management platform is respectively connected to the multiple business terminals in communication;

[0166] The online management platform is applicable to the asset data encryption method as described in the above embodiment.

[0167] Reference Figure 4 , showing a computer device of an asset data encryption method of the present application, which may specifically include the following:

[0168] The computer device 12 is a general-purpose computing device. The components of the computer device 12 may include, but are not limited to, one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0169] The bus 18 represents one or more of several types of bus 18 structures, including a memory bus 18 or memory controller, a peripheral bus 18, an accelerated graphics port, a processor, or a local bus 18 that utilizes any of a variety of bus 18 architectures. Examples of such architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus 18, a Micro Channel Architecture (MAC) bus 18, an Enhanced ISA bus 18, an Audio Video Electronics Standards Association (VESA) local bus 18, and a Peripheral Component Interconnect (PCI) bus 18.

[0170] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.

[0171] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be configured to read and write to non-removable, non-volatile magnetic media (commonly referred to as a "hard drive"). Although Figure 4 Although not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), as well as an optical drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) can be provided. In these cases, each drive can be connected to bus 18 via one or more data media interfaces. The memory may include at least one program product having a set (e.g., at least one) of program modules 42 configured to perform the functions of various embodiments of the present application.

[0172] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in a memory. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules 42, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 generally perform the functions and / or methods of the embodiments described herein.

[0173] The computer device 12 may also communicate with one or more external devices 14 (e.g., a keyboard, a pointing device, a display 24, a camera, etc.), one or more devices that enable a user to interact with the computer device 12, and / or any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the computer device 12 may also communicate with one or more networks (e.g., a local area network (LAN)), a wide area network (WAN), and / or a public network (e.g., the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with the other modules of the computer device 12 via the bus 18. It should be understood that although Figure 4 Not shown, other hardware and / or software modules may be used in conjunction with the computer device 12, including but not limited to microcode, device drivers, redundant processing units 16, external disk drive arrays, RAID systems, tape drives, and data backup storage systems 34.

[0174] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the asset data encryption method provided in the embodiment of the present application.

[0175] That is, when the processing unit 16 executes the above program, the following is achieved:

[0176] Obtain the client's asset data to be processed and the data service type corresponding to the asset data;

[0177] Performing data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer's authority;

[0178] When the result of the data verification process is passed, feature data is extracted from the asset data, the feature data including: data corresponding to asset location features, business features, and time features;

[0179] After determining the encryption method corresponding to the data service type, the asset data is encrypted according to the encryption method and the characteristic data.

[0180] In an embodiment of the present application, the present application further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the encryption method of asset data provided in all embodiments of the present application is implemented.

[0181] That is, when the program is executed by the processor:

[0182] Obtain the client's asset data to be processed and the data service type corresponding to the asset data;

[0183] Performing data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer's authority;

[0184] When the result of the data verification process is passed, feature data is extracted from the asset data, the feature data including: data corresponding to asset location features, business features, and time features;

[0185] After determining the encryption method corresponding to the data service type, the asset data is encrypted according to the encryption method and the characteristic data.

[0186] Any combination of one or more computer-readable media may be employed. A computer-readable medium may be a computer signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program for use by or in connection with an instruction execution system, apparatus, or device.

[0187] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0188] The computer program code for performing the operations of the present application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, through the Internet using an Internet service provider). The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referenced.

[0189] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0190] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0191] The above is a detailed introduction to the encryption method, device, system, equipment and medium for asset data provided by this application. Specific examples are used in this article to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for general technical personnel in this field, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A method for encrypting asset data, characterized in that: The method comprises: Obtain the client's asset data to be processed and the data service type corresponding to the asset data; Performing data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer's authority; When the result of the data verification process is passed, feature data is extracted from the asset data, the feature data including: data corresponding to asset location features, business features, and time features; After determining the encryption method corresponding to the data service type, encrypting the asset data according to the encryption method and the characteristic data; The data service type includes: asset transaction type, and the encryption method includes: transaction encryption method; The encrypting the asset data according to the encryption method and the characteristic data includes: If the encryption method is a transaction encryption method, searching the transaction data chain corresponding to the customer from a preset database and searching the connection node corresponding to the transaction encryption method in the transaction data chain; Constructing an encrypted signature using the characteristic data, and constructing a transaction encryption key using the encrypted signature and a convention preset by the customer; After converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain; The encrypted data chain is stored in a preset distributed storage area, and the preset distributed storage area is regionally encrypted.

2. The asset data encryption method according to claim 1, characterized in that: The data service type includes: asset update type, and the encryption method includes: update encryption method; The encrypting the asset data according to the encryption method and the characteristic data includes: If the encryption method is an update encryption method, the historical data corresponding to the customer is searched from a preset database; determining, based on data items of the historical data, a difference value between the historical data and the asset data; After constructing an updated encryption key using the numerical value of the feature data and the difference value, the asset data is encrypted using the updated encryption key.

3. The asset data encryption method according to claim 1, characterized in that: The performing data verification processing on the asset data based on the data service type includes: Searching for a plurality of business services in a preset permission list based on the data service type, wherein the preset permission list is a list constructed using a plurality of services corresponding to the customer's permissions; Obtaining the text content corresponding to each of the business services to obtain multiple service texts and obtaining the description text of each item of the asset data; After manually proofreading each of the description texts, a text matching degree is calculated based on the description text and the multiple service texts, and when the text matching degree is greater than a preset threshold, the processing result of the data verification process is determined to be passed.

4. The asset data encryption method according to any one of claims 1 to 3, characterized in that: After the data verification process is completed, the method further includes: Calculating a customer's service level value using the asset data; If the service level value is different from the customer's historical level value, searching for several push services according to the service level value; A business map is constructed using the service information of the several push services, and the business map is displayed to customers.

5. The asset data encryption method according to any one of claims 1 to 3, characterized in that: After the step of performing data verification processing on the asset data based on the data service type, the method further includes: When the result of the data verification process is failure, the number of business anomalies of the customer within a preset time period is determined, and the number of business anomalies is the number of times the result of the data verification process is failure; Dynamic alarm processing is performed based on the number of business anomalies.

6. An asset data encryption device, characterized in that: The device comprises: An acquisition module is used to obtain the client's asset data to be processed and the data service type corresponding to the asset data; A verification module, configured to perform data verification processing on the asset data based on the data service type, wherein the data verification processing is a process of matching and proofreading the asset data with the business service of the customer authority; an extraction module, configured to extract feature data from the asset data when the result of the data verification process is passed, the feature data including data corresponding to asset location features, business features, and time features; an encryption module, configured to determine an encryption method corresponding to the data service type and then encrypt the asset data according to the encryption method and the characteristic data; The data service type includes: asset transaction type, and the encryption method includes: transaction encryption method; The encrypting the asset data according to the encryption method and the characteristic data includes: If the encryption method is a transaction encryption method, searching the transaction data chain corresponding to the customer from a preset database and searching the connection node corresponding to the transaction encryption method in the transaction data chain; Constructing an encrypted signature using the characteristic data, and constructing a transaction encryption key using the encrypted signature and a convention preset by the customer; After converting the transaction encryption key and the asset data into a function value, the function value is bound to the connection node to obtain an encrypted data chain; The encrypted data chain is stored in a preset distributed storage area, and the preset distributed storage area is regionally encrypted.

7. An encryption system for asset data, characterized in that: The system includes: an online management platform and multiple business terminals, wherein the online management platform is respectively connected to the multiple business terminals for communication; The online management platform is applicable to the asset data encryption method as described in any one of claims 1-5.

8. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the asset data encryption method according to any one of claims 1 to 5 when executing the computer program.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer-executable program, and the computer-executable program is used to enable a computer to execute the asset data encryption method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Server-based financial service digital processing method and system

    CN118797690A