Data processing method and device, electronic equipment and storage medium
By converting the server of the bank branch into a regional distributed core node, using the Htpa protocol and distributed message database technology, a local area network is formed and financial business requests are independently processed, and the problems of paralysis and service interruption of traditional banking systems during disasters are solved, and the continuity and security of financial services are achieved.
Patent Information
- Application Number
- CN202510639422.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-08-12
AI Technical Summary
When traditional banking systems face major natural disasters or cyber attacks, multi-data center architectures are prone to paralysis, and cannot quickly isolate faulty areas and ensure the continuity of financial services.
When a central data center connection is detected, the bank branch server is converted into a regional distributed core node, using the Htpa protocol and distributed message database technology, a local area network is formed, financial service requests are independently processed, and data security and consistency are ensured through encrypted communication and time-sharing synchronization mechanisms.
It realizes rapid isolation and autonomous operation of the banking system in extreme cases, ensures the continuity and security of financial services, solves the problems of paralysis and service interruption of traditional architectures during disasters, and improves disaster recovery capabilities.
Smart Images

Figure CN120474896A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a data processing method, device, electronic device and storage medium. Background Art
[0002] Data centers are the core infrastructure of banks and other financial institutions, responsible for maintaining and managing computer hardware, software and critical business data to ensure the stability and continuity of financial services.
[0003] In related technologies, banking systems usually adopt a multi-data center architecture (such as three centers in two locations) and implement data backup and fault switching through Active-Active (AA) or Active-Standby (AS) mode to cope with common risks such as hardware failure and network interruption. When the banking system is in normal operation, it relies on the main data center to process transaction requests and synchronizes data to the backup data center to ensure high availability. For example, when a user initiates a transaction through mobile banking or a Point of Sale (POS) terminal, the data is first written to the main data center and then asynchronously or synchronously copied to the backup data center. In a disaster scenario (such as the main data center going down), the banking system uses a preset switching strategy, such as active-standby switching of the data center, to direct traffic to the backup data center to maintain service continuity.
[0004] However, the inventors have discovered that in the event of a major natural disaster or coordinated network attack, multiple data centers may be paralyzed at the same time. The above-mentioned data processing method cannot guarantee the safe operation of financial services, resulting in the interruption of financial services. Summary of the Invention
[0005] The embodiments of the present application provide a data processing method, device, electronic device and storage medium to improve the disaster recovery performance of the banking system and the security of financial service operations.
[0006] In a first aspect, an embodiment of the present application provides a data processing method, which is applied to a bank branch server, and the method includes:
[0007] Convert bank branch servers to regional distributed core nodes when a connection interruption with the central data center is detected;
[0008] Receiving service requests from user terminals and transaction terminals, including query requests and / or transaction requests. A transaction terminal is a terminal that conducts transactions with a user terminal;
[0009] When the business request is a query request, the latest data in the distributed message database is returned. The distributed message is used to record the account data and transaction information of users within the jurisdiction of the bank branch in real time;
[0010] When the business request is a transaction request, the user identity certificate and digital signature in the transaction request are verified, and after the verification is passed, the distributed message database is updated according to the transaction information in the transaction request.
[0011] In a second aspect, an embodiment of the present application provides a data processing device, including:
[0012] A detection module, which is used to convert the bank branch server into a regional distributed core node when it detects a connection interruption with the central data center;
[0013] A receiving module, configured to receive service requests sent by user terminals and transaction terminals, wherein the service requests include query requests and / or transaction requests, and the transaction terminal is a terminal that conducts transactions with the user terminal;
[0014] The processing module is used to return the latest data in the distributed message database when the business request is a query request. The distributed message is used to record the account data and transaction information of users within the jurisdiction of the bank branch in real time;
[0015] The processing module is also used to verify the user identity credentials and digital signature in the transaction request when the business request is a transaction request, and after the verification is passed, update the distributed message database according to the transaction information in the transaction request.
[0016] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor;
[0017] Memory stores computer-executable instructions;
[0018] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0020] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0021] The data processing method, device, electronic device and storage medium provided by this application overcome the limitations of the traditional multi-data center architecture by utilizing regional distributed core nodes. When the connection to the central data center is interrupted, the designated bank branch server can be quickly transformed into a regional distributed core node, using security protocols and distributed message database technology to achieve autonomous financial services within the jurisdiction while ensuring data security. In an emergency, the regional distributed core nodes can independently process various financial business requests. This solution effectively solves key problems such as the traditional architecture being prone to paralysis during major disasters, the inability to quickly isolate the fault area, and post-disaster service interruptions, thereby improving the disaster recovery capabilities and business continuity of the banking system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0023] Figure 1 A flowchart of a data processing method provided in this application;
[0024] Figure 2 A flowchart of another data processing method provided in this application;
[0025] Figure 3 A local area network diagram provided for this application;
[0026] Figure 4 A schematic diagram of the structure of a data processing device provided in this application;
[0027] Figure 5 This is a schematic diagram of the structure of an electronic device provided in this application.
[0028] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0029] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0030] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] First, let’s explain the terms involved in this application:
[0032] A data center is a department or organization responsible for maintaining and managing the computer hardware and software environment. It typically includes infrastructure such as servers, storage devices, and network equipment, as well as application software such as operating systems, database management systems, and middleware. The role of a data center is to provide a stable and reliable computing environment to meet the business needs of an organization.
[0033] HTPA protocol: A dedicated encryption communication protocol based on a modified version of the 802.11ax protocol. Its core mechanisms include: (1) the client pre-stores a list of encryption algorithms dedicated to the branch area; (2) identity authentication and key negotiation are achieved through CA certificate distribution and public key infrastructure, including the process of dynamically generating random password strings and session keys between the client and the server; (3) a 2-bit branch authentication code is embedded in the 802.11ax control frame to distinguish bank devices from ordinary terminals and limit the communication range to devices in the pre-stored jurisdiction user list; (4) the complete communication process covers algorithm list exchange, certificate verification, DH key negotiation and modified 802.11ax message authentication code (MAC) verification, which is specifically used for secure data transmission and identity authentication between user terminals, POS machines and bank branch servers in the bank branch disaster emergency mode.
[0034] Transport Layer Security (TLS): TLS and its predecessor, Secure Sockets Layer (SSL), are standardized protocols that provide security and data integrity for internet communications and have become the industry standard for secure communications. The TLS / SSL protocol consists of a record layer and a transport layer. The record layer defines the encapsulation format of transport layer data, ensuring the reliability and security of encrypted data transmission.
[0035] Currently, the banking industry generally adopts a disaster recovery architecture consisting of two or three data centers, using active-active (AA) or active-standby (AS) modes for data backup and failover to address common hardware failures or network outages. However, this traditional architecture still has significant shortcomings in extreme scenarios such as major natural disasters, hostile cyberattacks, and ransomware threats.
[0036] Specifically, in the relevant technologies, the banking system mainly relies on the deployment model of data centers in multiple locations and adopts a centralized management architecture. All transaction requests are uniformly processed by the main data center and synchronized to the backup data center in real time. When the main data center fails, the business traffic can be automatically switched to the backup data center.
[0037] Although this architecture can cope with common failure scenarios, it has three key design flaws: first, the centralized deployment of data centers makes them prone to simultaneous paralysis during large-scale disasters; second, there is a lack of a mechanism to quickly isolate the affected area in the event of a cyber attack, which may cause the attack to spread rapidly; third, the isolated area cannot independently establish an emergency network, resulting in the interruption of financial services, which directly affects residents' lives and the normal operation of industry and commerce.
[0038] These defects indicate that traditional data center architectures can no longer meet the business continuity requirements in extreme situations. There is an urgent need to develop new disaster recovery solutions that have rapid regional isolation capabilities, support distributed networking, and can guarantee minimized financial services.
[0039] Based on the above analysis, the present application provides a data processing method, device, electronic device and storage medium. In this method, when the connection with the central data center is detected to be interrupted, the bank branch server is immediately converted into a regional distributed core node to take over the financial services within the jurisdiction. The bank branch server uses the HTPA protocol to achieve secure communication and transaction verification based on a local area network that includes branch servers, automated teller machines (ATMs), POS machines and other equipment, and maintains a distributed message database to record user account data in the jurisdiction. In the event of a disaster, the bank branch server can independently process query and transaction requests to ensure that basic financial services are not interrupted. This method achieves rapid isolation and autonomous operation of the affected area, solving the problem that traditional architectures are unable to cope with extreme disasters, the spread of attacks and post-disaster service interruptions.
[0040] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0041] Figure 1A flow chart of a data processing method provided in this application is as follows: Figure 1 As shown, with the bank branch server as the execution subject, the method includes the following steps:
[0042] S101. When a connection interruption with the central data center is detected, the bank branch server is converted into a regional distributed core node.
[0043] It is understandable that when the banking system is operating normally, the central data center handles business requests. When a disaster occurs in a certain area, the central data center can proactively disconnect from the affected area and will not accept business requests from users in that area after the disconnection.
[0044] When a branch server detects a disconnect from the central data center (e.g., due to a natural disaster or cyberattack), it automatically switches to a regional distributed core node, taking over financial services within its jurisdiction. This switchover is accomplished by activating pre-installed distributed core system application servers, ensuring that branch servers can quickly take over business processing responsibilities when the central data center is unavailable.
[0045] S102: Receive service requests sent by the user terminal and the transaction terminal.
[0046] The service request includes an inquiry request and / or a transaction request, and the transaction terminal is a terminal that conducts transactions with the user terminal.
[0047] While operating as a regional distributed core node, the bank branch server receives service requests from user terminals and transaction terminals such as POS machines. User terminals initiate requests through a modified banking application program (APP), which has integrated support for the HTTPS protocol and can establish a secure connection with the bank branch server. The transaction terminal connects directly to the bank branch server via the local area network.
[0048] It should be noted that all connected terminal devices need to pass authentication including the network identification code.
[0049] S103: When the service request is a query request, the latest data in the distributed message database is returned.
[0050] In this embodiment, distributed messages are used to record account data and transaction information of users within the jurisdiction of a bank branch in real time. Optionally, the distributed message database utilizes a chained storage structure, comprising multiple data blocks, including a message header, a user information area, a balance information message area, and a transaction flow area. Database types include, but are not limited to, TDSQL. User balances are stored as key-value pairs of "username:balance," and transaction flows are recorded in chronological order to ensure data integrity and traceability.
[0051] The distributed message database also includes a user information area, which records the information of all users within the jurisdiction of the bank branch. If the user is not in the user information area, the user cannot conduct financial transactions and must be authenticated by the bank branch and manually added to the user information area.
[0052] For query requests received, the bank branch server can directly extract the latest data from the locally maintained time-sharing message database and return it to the user terminal.
[0053] S104: When the business request is a transaction request, verify the user identity certificate and digital signature in the transaction request, and after the verification is passed, update the distributed message database according to the transaction information in the transaction request.
[0054] When processing a transaction request, the bank branch server first verifies the user's identity credentials contained in the request, including the branch identification code and digital signature stored in the bank card chip. This verification process is accomplished using the HTTPS protocol, which employs asymmetric encryption and certificate authentication to ensure secure communications. Once verified, the bank branch server updates the user's balance and transaction flow information in its time-sharing message database in real time and propagates these changes to relevant terminals within its jurisdiction through a time-sharing synchronization mechanism to maintain data consistency.
[0055] In the data processing method provided in this embodiment, if a region loses connection with the central data center due to a disaster or attack, the bank branch server in that area automatically switches to local service mode. At this point, the bank branch server maintains minimal service operations through encrypted communications over an independent network with certified ATMs, POS terminals, and other terminal devices within its jurisdiction, continuing to provide basic financial services. Transaction data is synchronized and backed up in real time between the bank branch server and terminal devices, forming a distributed ledger mechanism. This embodiment method ensures service continuity in extreme situations and guarantees the secure operation of financial services.
[0056] Figure 2 A flow chart of another data processing method provided in this application, such as Figure 2 As shown, this embodiment Figure 1 Based on the embodiment, the data processing method is described in detail. With the bank branch server as the execution subject, the method of this embodiment includes the following steps:
[0057] S201. When a connection interruption with the central data center is detected, the bank branch server is converted into a regional distributed core node.
[0058] In this embodiment, when a bank branch server detects a connection loss with the central data center, it immediately activates an emergency mechanism and switches itself to a regional distributed core node. This process is triggered automatically, requiring no human intervention, ensuring that the bank branch server can quickly take over business processing responsibilities when the central data center is unavailable. After transitioning to a regional distributed core node, the bank branch will independently handle financial business within its jurisdiction, maintaining the normal operation of basic financial services.
[0059] S202: Establish a local area network with authenticated user terminals and transaction terminals within the jurisdiction of the bank branch through the pre-deployed bridge switch.
[0060] Specifically, the bank branch server quickly builds a local area network that includes all authentication devices within the jurisdiction through pre-deployed bridge switch equipment. Figure 3 As shown in the figure, this network includes not only the bank's own ATMs, POS machines, branch cash intelligent processing terminals, branch management personal computers (PCs), and branch database servers, but also certified honest shops, certified merchant cash register systems, express lockers and other equipment. When a LAN is required, a bridge switch starts working. Currently, a bridge switch can achieve a 1cm 3 The bridge switch uses the modified 802.11ax protocol. By adding two branch authentication code bits in the control frame, representing the bank branch and the private key code bit, it is used to authenticate the access device through the HTPA protocol, thus ensuring that only authorized devices can access the local area network.
[0061] When establishing a local area network, bank branches use minimized business servers, and the distributed core application servers can be deployed on an ordinary server or even a home laptop after reducing some functions.
[0062] In daily mode, when balance changes occur, the bank branch server updates the balance information in real time via HTTPS protocol signaling within the local area network. Specifically, when a user pays with their mobile phone or card, in addition to submitting transaction data to the central data center, the balance change information is also synchronously recorded in the timed message databases of the user's phone, the local ATM, and the merchant's POS terminal. It's important to note that in this mode, the final balance remains based on the central data center's records.
[0063] In disaster response mode, when the central data center is unavailable, the bank branch server takes over. At this point, user phones and transaction terminals (ATMs, POS machines) within the jurisdiction will proactively synchronize data with the bank branch server. After computational verification, the balance of users within the jurisdiction is updated. All transactions will interact directly with the bank branch server.
[0064] When the connection with the central data center is restored, the bank branch server will compare the data with the central data center, and after confirming that it is correct, it will write the data back to the central database to complete the unification of the system status.
[0065] S203: Receive a connection request sent by the user terminal, where the connection request includes the branch identification code in the bank card chip, a list of encryption algorithms supported by the user terminal, and a first random number.
[0066] In this embodiment, when a user terminal initiates a connection request through the bank app, it automatically carries the branch identification code stored in the bank card chip, a list of encryption algorithms supported by the user terminal, and a randomly generated value. This information is the basis for establishing secure communication. The branch identification code is used to verify whether the user belongs to the current jurisdiction, the encryption algorithm list allows the server to select the appropriate encryption method, and the random number is used for subsequent key generation.
[0067] S204: When it is determined based on the branch identification code that the user belongs to a user within the jurisdiction of the bank branch, a target encryption algorithm is selected from a list of encryption algorithms supported by the user terminal.
[0068] In this embodiment, upon receiving a connection request, the bank branch server first verifies whether the branch identification code exists in a pre-stored list of users in its jurisdiction. Upon successful verification, the bank branch server notifies the user via the bank app whether the connection was successful or if re-registration is required. Furthermore, the bank branch server selects the most appropriate algorithm from the list of encryption algorithms provided by the user terminal as the communication encryption scheme. This selection process comprehensively considers security and performance factors to ensure adequate security without unduly impacting transaction processing speed.
[0069] S205. Send the identification information of the target encryption algorithm, the server certificate of the bank branch server, and the second random number to the user terminal. After the user terminal verifies the server certificate, it generates a random password string and encrypts the random password string using the public key in the server certificate.
[0070] The format of the encrypted random password string matches the target encryption algorithm.
[0071] In this embodiment, after the bank branch server determines the target encryption algorithm, it returns the algorithm identifier, its own digital certificate, and another random number to the user terminal. The server certificate contains the branch's public key and identity information, allowing the user terminal to verify the server's authenticity. This step completes the initial negotiation of encrypted communication and prepares for the subsequent establishment of a secure channel.
[0072] S206: After receiving the encrypted random password string sent by the user terminal, determine the session key synchronously with the user terminal according to the encrypted random password string, the first random number and the second random number, and establish an encrypted communication channel.
[0073] Specifically, the user terminal encrypts a random password string using the server's public key and transmits it back to the bank branch server. Based on this password string and the two previously exchanged random numbers, both parties independently calculate the same session key, including the encryption key and MAC key, through a key exchange algorithm. This process ensures that even if the communication is intercepted, attackers cannot decipher the actual transaction content, providing security for subsequent business interactions.
[0074] S207: Receive a service request sent by the user terminal through the encrypted communication channel.
[0075] In this embodiment, after establishing a secure channel, all service requests sent by the user terminal are encrypted. The bank branch server then categorizes and processes the requests based on their type, ensuring that query requests are quickly responded to and transaction requests are securely executed. This design ensures both service efficiency and transaction security.
[0076] S208: When the business request is a transaction request, verify the user identity certificate and digital signature in the transaction request, and after the verification is passed, update the distributed message database according to the transaction information in the transaction request.
[0077] Optionally, the user identity credential includes the branch identification code of the bank card chip, and the digital signature includes a first digital signature of the user terminal and a second digital signature of the transaction partner of the user terminal.
[0078] The bank branch server can extract the branch identification code from the transaction request and verify whether the user exists in the pre-stored bank branch's jurisdiction user list based on the branch identification code.
[0079] After the verification is passed (i.e., it is confirmed that the user exists in the pre-stored bank branch's jurisdiction user list), the bank branch server uses the user terminal's public key to verify the first digital signature and uses the transaction counterpart's public key to verify the second digital signature.
[0080] Optionally, the distributed message database includes a balance information message area and a transaction flow message area.
[0081] The bank branch server adds a key-value pair to the balance information message area and records the transaction flow in the transaction flow area. The key-value pair includes the user name and balance, and the transaction flow includes the transaction information.
[0082] Specifically, the bank branch server performs two verification steps on transaction requests: first, verifying the legitimacy of the branch identification code on the user's bank card, and then verifying the validity of both the user's and the merchant's digital signatures. Only transactions that pass all verification steps are processed. During this process, the bank branch server updates the balance information and transaction history in its instant messaging database in real time to ensure timely and accurate data.
[0083] S209: Periodically synchronize the incremental data in the distributed message database to the user terminals and transaction terminals in the local area network.
[0084] To maintain data consistency, bank branch servers regularly synchronize the latest transaction changes with other devices on the network. This incremental synchronization mechanism reduces network burden and ensures that all terminals have access to the latest data. The synchronization process also uses encrypted transmission to prevent data tampering during transmission.
[0085] S210: After detecting that the connection with the central data center is restored, randomly extract transaction data of at least two user terminals from the distributed message database and verify the transaction data.
[0086] In this embodiment, when the connection between the bank branch server and the central data center is restored, the entire data is not synchronized immediately. Instead, transaction records from multiple user terminals are randomly sampled for comparison and verification. This sampling verification mechanism quickly identifies and resolves data inconsistencies, ensuring that the data ultimately synchronized to the central data center is completely accurate and reliable. For any discrepancies discovered, the bank branch server initiates a dedicated process for manual review and correction.
[0087] The data processing method provided in the embodiment of the present application is designed to switch the bank branch server to a regional distributed core node autonomously. When the connection with the central data center is detected to be interrupted, it can immediately connect to the financial services within the jurisdiction, effectively solving the problem that the traditional multi-data center architecture is prone to complete paralysis in the event of a major disaster or network attack. The local area network composed of pre-deployed bridging switches and modified 802.11ax protocols, combined with the dual authentication mechanism of the HTPA encryption protocol, not only ensures that only authorized terminals can access the network, but also realizes end-to-end encryption protection of transaction data, thereby quickly isolating the affected area and preventing the spread of attacks. The chain storage structure and time-sharing synchronization mechanism of the time-sharing message database enable transaction data to be backed up in real time at multiple points between bank branch servers, user terminals and POS machines in an emergency situation, which not only ensures data consistency in an emergency state, but also avoids the dependence of traditional large databases. The random sampling comparison mechanism used after the connection is restored ensures the accuracy of data synchronization through probability verification. This series of technological innovations jointly achieves the goal of maintaining basic financial services in extreme situations, while ensuring the security and reliability of the banking system, fundamentally overcoming the key defects of existing technologies such as insufficient disaster recovery capabilities, low isolation efficiency, and post-disaster service interruptions.
[0088] In a possible embodiment, step S207 is specifically implemented by the bank branch server receiving the incremental data sent by the user terminal and the transaction terminal in time and segment, and assembling the incremental data.
[0089] Incremental data includes transaction flows.
[0090] Accordingly, the specific implementation of step S209 is that the bank branch server sends the assembled incremental data to the transaction terminal, so that the transaction terminal synchronizes the assembled incremental data to the user terminal.
[0091] In this embodiment, the process by which the bank branch server receives incremental data sent by user terminals and transaction terminals in time-sharing and segmented fashion effectively establishes an efficient and reliable data synchronization mechanism. When a user conducts a transaction in an emergency, the transaction data is intelligently segmented into multiple packets, each containing a specific sequence identifier and timestamp. These packets are then transmitted in batches to the bank branch server via the HTTPS encryption protocol. This time-sharing and segmented transmission method not only adapts to unstable network environments and ensures that critical transaction data is not lost, but also effectively reduces the amount of data transmitted in a single transmission, avoiding network congestion. Upon receiving these packets, the bank branch server intelligently reassembles them based on the segmentation information in the message header to restore the complete transaction record. In particular, for data requiring high continuity, such as transaction flow, the bank branch server prioritizes processing and verification, ensuring that every transaction is accurately recorded in the time-sharing message database.
[0092] After completing the assembly of the incremental data, the bank branch server initiates the data synchronization and distribution process. During this process, the server doesn't simply broadcast the data to all terminals; instead, it employs an intelligent routing strategy. First, the assembled incremental data is sent to the POS terminals directly involved in the transaction. These terminals then forward the data to the relevant user terminals. This hierarchical synchronization mechanism reduces the network load on core nodes while ensuring reliable data transmission through intermediate forwarding by the transaction terminals.
[0093] It is important to note that each synchronization is accompanied by data integrity verification information. Upon receiving the data, the user terminal can verify its authenticity to prevent tampering or errors during transmission. This design ensures that financial data across the entire jurisdiction remains highly consistent during emergencies, providing a reliable data foundation for subsequent restoration of connectivity with the central data center.
[0094] Figure 4 A schematic diagram of the structure of a data processing device provided in this application, such as Figure 4 As shown, the data processing device 10 of this embodiment is used to implement the operations corresponding to the bank branch server in any of the above method embodiments. The data processing device 10 provided in this embodiment includes:
[0095] Detection module 11, used to convert the bank branch server into a regional distributed core node when it detects that the connection with the central data center is interrupted;
[0096] A receiving module 12 is configured to receive service requests sent by user terminals and transaction terminals, where the service requests include query requests and / or transaction requests. The transaction terminal is a terminal that conducts transactions with the user terminal.
[0097] Processing module 13, used to return the latest data in the distributed message database when the business request is a query request. The distributed message is used to record the account data and transaction information of users within the jurisdiction of the bank branch in real time;
[0098] The processing module 13 is further configured to verify the user identity certificate and digital signature in the transaction request when the business request is a transaction request, and update the distributed message database according to the transaction information in the transaction request after the verification is passed.
[0099] In a possible embodiment, the receiving module 12 is further configured to receive a connection request sent by a user terminal, the connection request including the branch identification code in the bank card chip, a list of encryption algorithms supported by the user terminal, and a first random number;
[0100] The processing module 13 is further configured to select a target encryption algorithm from a list of encryption algorithms supported by the user terminal when determining that the user belongs to a user within the jurisdiction of the bank branch based on the branch identification code;
[0101] The data processing device 10 further includes a sending module, which is configured to send identification information of the target encryption algorithm, the server certificate of the bank branch server, and the second random number to the user terminal. After the user terminal verifies the server certificate, the module generates a random password string and encrypts the random password string using the public key in the server certificate. The format of the encrypted random password string matches the target encryption algorithm.
[0102] The processing module 13 is further configured to, after receiving the encrypted random password string sent by the user terminal from the receiving module 12, synchronously determine the session key with the user terminal based on the encrypted random password string, the first random number, and the second random number, and establish an encrypted communication channel;
[0103] Correspondingly, the receiving module 12 is configured to receive a service request sent by a user terminal through an encrypted communication channel.
[0104] In a possible embodiment, the processing module 13 is further configured to establish a local area network with authenticated user terminals and transaction terminals within the jurisdiction of the bank branch through a pre-deployed bridging switch;
[0105] The sending module is also used to periodically synchronize the incremental data in the distributed message database to the user terminals and transaction terminals in the local area network.
[0106] In a possible embodiment, the receiving module 12 is configured to receive incremental data sent by the user terminal and the transaction terminal in different time periods and segments, and assemble the incremental data, wherein the incremental data includes transaction flow;
[0107] Correspondingly, the sending module is specifically configured to send the assembled incremental data to the transaction terminal, so that the transaction terminal synchronizes the assembled incremental data to the user terminal.
[0108] In a possible embodiment, the processing module 13 is further configured to randomly extract transaction data of at least two user terminals from the distributed message database and verify the transaction data after detecting that the connection with the central data center is restored.
[0109] In a possible embodiment, the user identity credential includes the branch identification code of the bank card chip, and the digital signature includes a first digital signature of the user terminal and a second digital signature of the transaction counterpart of the user terminal;
[0110] The processing module 13 is further configured to extract the branch identification code from the transaction request and verify whether the user exists in the pre-stored user list of the bank branch based on the branch identification code;
[0111] After the verification is successful, the first digital signature is verified using the public key of the user terminal;
[0112] The second data signature is verified using the transaction counterpart's public key.
[0113] In a possible embodiment, the distributed message database includes a balance information message area and a transaction flow message area;
[0114] The processing module 13 is used to add a key-value pair in the balance information message area, where the key-value pair includes the user name and the balance; and record the transaction flow in the transaction flow area, where the transaction flow includes transaction information.
[0115] The data processing device 10 provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.
[0116] Figure 5 This is a schematic diagram of the structure of an electronic device provided by this application. Figure 5 As shown, the electronic device 20 provided in this embodiment includes: a memory 21 and at least one processor 22. Optionally, the device 20 also includes a communication component 23. The memory 21, the processor 22 and the communication component 23 are connected via a bus 24.
[0117] During the specific implementation process, at least one processor 22 executes the computer-executable instructions stored in the memory 21, so that the at least one processor 22 performs the above method.
[0118] The specific implementation process of the processor 22 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0119] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules in the processor.
[0120] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.
[0121] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0122] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0123] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0124] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0125] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in a device as discrete components.
[0126] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0127] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0128] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0129] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0130] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0131] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A data processing method, characterized in that: Applied to a bank branch server, the method includes: Upon detecting a disconnection with the central data center, converting the bank branch server into a regional distributed core node; Receiving service requests sent by a user terminal and a transaction terminal, wherein the service requests include query requests and / or transaction requests, and the transaction terminal is a terminal that conducts transactions with the user terminal; When the service request is a query request, the latest data in the distributed message database is returned. The distributed message is used to record the account data and transaction information of users within the jurisdiction of the bank branch in real time; When the business request is a transaction request, the user identity certificate and digital signature in the transaction request are verified, and after the verification is passed, the distributed message database is updated according to the transaction information in the transaction request.
2. The method according to claim 1, characterized in that Before receiving the service request sent by the user terminal and the transaction terminal, the method further includes: receiving a connection request sent by the user terminal, the connection request including the branch identification code in the bank card chip, a list of encryption algorithms supported by the user terminal, and a first random number; When it is determined based on the branch identification code that the user belongs to a user within the jurisdiction of the bank branch, a target encryption algorithm is selected from a list of encryption algorithms supported by the user terminal; Sending the identification information of the target encryption algorithm, the server certificate of the bank branch server, and the second random number to the user terminal, so that the user terminal verifies the server certificate, generates a random password string, and encrypts the random password string using the public key in the server certificate, where the format of the encrypted random password string matches the target encryption algorithm; After receiving the encrypted random password string sent by the user terminal, synchronously determining a session key with the user terminal based on the encrypted random password string, the first random number, and the second random number, and establishing an encrypted communication channel; Accordingly, the receiving of the service request sent by the user terminal and the transaction terminal includes: Receive a service request sent by the user terminal through the encrypted communication channel.
3. The method according to claim 1, characterized in that Before receiving the service request sent by the user terminal and the transaction terminal, the method further includes: Establishing a local area network with authenticated user terminals and transaction terminals within the jurisdiction of the bank branch through a pre-deployed bridge switch; Accordingly, after updating the distributed message database according to the transaction information in the transaction request, the method further includes: The incremental data in the distributed message database is periodically synchronized to the user terminals and transaction terminals in the local area network.
4. The method according to claim 3, characterized in that The receiving of the service request sent by the user terminal and the transaction terminal includes: receiving incremental data sent by the user terminal and the transaction terminal in time and segment, and assembling the incremental data, wherein the incremental data includes transaction flow; Accordingly, the periodic synchronization of incremental data in the distributed message database to user terminals and transaction terminals in the local area network includes: The assembled incremental data is sent to the transaction terminal, so that the transaction terminal synchronizes the assembled incremental data to the user terminal.
5. The method according to claim 1, wherein The method further comprises: After detecting that the connection with the central data center is restored, transaction data of at least two user terminals in the distributed message database are randomly extracted and the transaction data are verified.
6. The method according to claim 1, characterized in that The user identity credential includes the branch identification code of the bank card chip, and the digital signature includes a first digital signature of the user terminal and a second digital signature of the transaction partner of the user terminal; The verifying the user identity certificate and digital signature in the transaction request includes: Extracting the branch identification code from the transaction request, and verifying whether the user exists in a pre-stored list of users in the jurisdiction of the bank branch based on the branch identification code; After the verification is successful, the first digital signature is verified using the public key of the user terminal; The second data signature is verified using the public key of the transaction object.
7. The method according to any one of claims 1 to 6, characterized in that The distributed message database includes a balance information message area and a transaction flow message area; The updating of the distributed message database according to the transaction information in the transaction request includes: In the balance information message area, add a key-value pair, wherein the key-value pair includes the user name and the balance; The transaction flow is recorded in the transaction flow area, and the transaction flow includes the transaction information.
8. A data processing device, characterized in that: include: a detection module, configured to convert the bank branch server into a regional distributed core node upon detecting a disconnection with the central data center; a receiving module, configured to receive service requests sent by a user terminal and a transaction terminal, wherein the service requests include query requests and / or transaction requests, and the transaction terminal is a terminal that conducts transactions with the user terminal; a processing module configured to return the latest data in a distributed message database when the service request is a query request, wherein the distributed message is used to record account data and transaction information of users within the jurisdiction of the bank branch in real time; The processing module is further configured to verify the user identity credentials and digital signature in the transaction request when the business request is a transaction request, and update the distributed message database according to the transaction information in the transaction request after the verification is passed.
9. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.