A method and apparatus for controlling data privacy
By dynamically matching signaling and verification information during the data review control process, loose coupling between the enterprise and multiple review vendors is achieved, solving the problem of low efficiency of data review, improving the flexibility and security of the system, and reducing development and maintenance costs.
Patent Information
- Application Number
- CN202511015504.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-07-22
AI Technical Summary
The demand for encryption technology varies across different industries and application scenarios, resulting in huge challenges for companies in building a unified and efficient data encryption system. Traditional methods increase development costs and maintenance difficulties, limit the flexibility and scalability of the system, and result in low data encryption efficiency.
By dynamically matching and controlling the signaling and verification information during the data review control process, a docking mechanism is provided between the client and the target review manufacturer, achieving loose coupling between the enterprise and multiple review service providers, generating target verification information and call parameters, ensuring signaling matching and data security, and providing a unified call address and parameter format.
It enables enterprises to correspond to multiple data review service providers, improves the efficiency of data review, reduces development and maintenance costs, ensures the security of data transmission and storage, and improves the accuracy and efficiency of data processing.
Smart Images

Figure CN120528704B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of information security technology, and in particular to a control method and device for data confidentiality review. Background Art
[0002] With the rapid development of information technology, data security and privacy protection have become a focal point of social concern. Data encryption and security assessment ("encryption assessment") are crucial means of ensuring data security in various fields, including finance, government affairs, and e-commerce. However, the requirements for encryption technology vary across industries and application scenarios. While there are numerous encryption assessment service providers in the market, they employ varying technical standards and interface protocols. This poses a significant challenge for enterprises in building a unified and efficient encryption assessment system.
[0003] Traditionally, companies have needed to develop custom interface adapters for their chosen review vendors. This not only increases development costs and maintenance difficulties, but also limits system flexibility and scalability. Companies are typically restricted to specific review providers, resulting in low data review efficiency. Therefore, developing a data review management method to address this inefficiency is of great practical significance. Summary of the Invention
[0004] The embodiments of the present application provide a method and device for controlling data confidentiality review, which can improve the efficiency of data confidentiality review.
[0005] To achieve the above objectives, the technical solution of the embodiment of the present application is implemented as follows:
[0006] In a first aspect, embodiments of the present application provide a method for controlling data review, which is applied to a review platform; the method comprises:
[0007] In response to receiving authentication request information sent by a user through a client, generating target verification information of the user; the target verification information includes authentication signaling and the authentication request information;
[0008] Based on the target secret review manufacturer identifier included in the authentication request information, generating a target call parameter corresponding to the target secret review manufacturer identifier; the target call parameter includes the authentication signaling, the platform call address and the request input parameter corresponding to the platform call address;
[0009] Sending the target call parameters to the client, so that the client generates a secret review call request according to the target call parameters and the target call function; the secret review call request includes the call request input parameters, the authentication signaling, the target call function and the data to be processed;
[0010] In response to receiving the secret evaluation call request sent by the client, if the result of checking the signaling contained in the secret evaluation call request according to the target verification information is passed, secret evaluation instruction information is generated according to the target secret evaluation parameter included in the authentication request information, the to-be-processed data and the target call function, and the secret evaluation instruction information is sent to the target secret evaluation manufacturer, so that the target secret evaluation manufacturer performs a data secret evaluation operation corresponding to the target call function on the to-be-processed data.
[0011] The data secret evaluation control method provided by the embodiments of the present application, in the process of controlling data secret evaluation, the secret evaluation platform generates target verification information of a user in response to receiving authentication request information sent by the user through a client; the target verification information includes authentication signaling and the authentication request information; target call parameters corresponding to a target secret evaluation manufacturer identifier are generated based on the target secret evaluation manufacturer identifier included in the authentication request information; the target call parameters include the authentication signaling, a platform call address and request input parameters corresponding to the platform call address; the target call parameters are sent to the client, so that the client generates a secret evaluation call request according to the target call parameters and a target call function; the secret evaluation call request includes call request input parameters, the authentication signaling, the target call function and to-be-processed data; in response to receiving the secret evaluation call request sent by the client, if the result of checking the signaling contained in the secret evaluation call request according to the target verification information is passed, secret evaluation instruction information is generated according to the target secret evaluation parameter included in the authentication request information, the to-be-processed data and the target call function, and the secret evaluation instruction information is sent to the target secret evaluation manufacturer, so that the target secret evaluation manufacturer performs a data secret evaluation operation corresponding to the target call function on the to-be-processed data. This method dynamically controls the matching of signaling and verification information in the process of controlling data secret evaluation, provides a docking mechanism for the client and the target secret evaluation manufacturer, realizes the loose coupling of enterprises and secret evaluation manufacturers, and enables enterprises to correspond to multiple secret evaluation service providers, thereby effectively improving the efficiency of data secret evaluation.
[0012] In an optional embodiment, the target secret evaluation parameter includes an encryption feature parameter; the encryption feature parameter is a special parameter required by the target encryption manufacturer for data secret evaluation operation;
[0013] The secret evaluation instruction information is generated according to the target secret evaluation parameter included in the authentication request information, the to-be-processed data and the target call function, and includes:
[0014] A target encryption feature parameter corresponding to the target encryption manufacturer and the target call function is determined based on a first mapping relationship between a preset call function and a secret evaluation manufacturer and an encryption feature parameter;
[0015] According to the target encryption feature parameter, the to-be-processed data, and the target calling function, obtain secret evaluation indication information; the secret evaluation indication information includes the target encryption feature parameter, the to-be-processed data, and the target calling function.
[0016] The method of the embodiment can, when controlling data secret evaluation, determine a target encryption feature parameter according to a target encryption manufacturer and a target calling function, and then perform a data secret evaluation operation corresponding to the target calling function on the to-be-processed data according to the target encryption feature parameter, thereby accurately identifying the target encryption feature parameter, further reducing the time for implementing the data secret evaluation operation corresponding to the target calling function by the target encryption manufacturer, and effectively improving the efficiency of data secret evaluation.
[0017] In an optional embodiment, in response to receiving the authentication request information sent by the user through the client, the target verification information of the user is generated, including:
[0018] In response to receiving the authentication request information sent by the user through the client, authentication signaling is generated.
[0019] The authentication signaling and the authentication request information are stored in association to obtain the target verification information of the user.
[0020] The method dynamically generates authentication signaling for authentication request information, dynamically performs signaling and verification information matching control in the process of controlling data secret evaluation, provides a docking mechanism of the client and the target secret evaluation manufacturer, realizes loose coupling of the enterprise and the secret evaluation manufacturer, can realize that the enterprise can correspond to multiple secret evaluation service providers, and can effectively improve the efficiency of data secret evaluation.
[0021] In an optional embodiment, the target secret evaluation parameter includes a target encryption key; and the storing, in association, of the authentication signaling and the authentication request information to obtain the target verification information of the user includes:
[0022] The authentication signaling and the authentication request information are associated to obtain basic verification information.
[0023] The basic verification information is encrypted according to the target encryption key to obtain the target verification information of the user.
[0024] The method of the embodiment introduces key encryption in the generation process of the target verification information, ensures the security of data in the transmission and storage process, only decrypts for use when the system is running, avoids the risk of data leakage, can enhance the security of the secret evaluation platform in the control process of data secret evaluation, prevents illegal data secret evaluation requests, and further improves the efficiency of data secret evaluation.
[0025] In an optional embodiment, the generating the target invocation parameter corresponding to the target cryptanalysis vendor identifier based on the target cryptanalysis vendor identifier included in the authentication request information comprises:
[0026] determining, based on a preset second mapping relationship between cryptanalysis vendor identifiers and invocation information, basic invocation information corresponding to the target cryptanalysis vendor identifier; the invocation information comprises an invocation address and an input parameter corresponding to the invocation address; the basic invocation information comprises the platform invocation address and the request input parameter corresponding to the platform invocation address; the platform invocation address is the invocation address corresponding to the target cryptanalysis vendor identifier in the second mapping relationship; and the request input parameter is the input parameter corresponding to the target cryptanalysis vendor identifier in the second mapping relationship;
[0027] obtaining, according to the authentication signaling and the basic invocation information, the target invocation parameter corresponding to the target cryptanalysis vendor identifier.
[0028] The method of this embodiment can provide a mechanism for determining target invocation parameters corresponding to different cryptanalysis vendors, improve the accuracy of determining the invocation parameters of cryptanalysis vendors, and further improve the efficiency of data cryptanalysis.
[0029] In an optional embodiment, the request input parameter further comprises a data interface and an invocation example corresponding to the platform invocation address; the data interface is a data format of an interface; and the data interface comprises an interface field name, an interface field type, and an interface field assignment method.
[0030] The method of this embodiment can provide a unified invocation address and parameter format to the outside based on the cryptanalysis platform by setting the data interface and the invocation example, can perform dynamic configuration of parameters based on the data interface and the invocation example, realize seamless connection of the client to the services of different cryptanalysis vendors, is conducive to rapid integration of new cryptanalysis vendors, reduces the development and maintenance costs of the cryptanalysis platform, and can further improve the efficiency of data cryptanalysis.
[0031] In an optional embodiment, the result of the verification of the signaling included in the cryptanalysis invocation request according to the target verification information is obtained by the following process:
[0032] obtaining the signaling included in the cryptanalysis invocation request as first signaling;
[0033] obtaining the authentication signaling corresponding to the user from the target verification information;
[0034] comparing the first signaling with the authentication signaling, and taking the comparison result as the result of the verification of the signaling included in the cryptanalysis invocation request.
[0035] The method of the embodiment provides a mechanism for verifying signaling contained in the secret evaluation calling request according to the target verification information, realizes accurate signaling matching control, guarantees accurate connection of the client and the target secret evaluation manufacturer, and further improves the efficiency of data secret evaluation.
[0036] In an optional embodiment, the method further includes:
[0037] In response to receiving the data secret evaluation result of the to-be-processed data sent by the target secret evaluation manufacturer, the data secret evaluation result is converted into a standard message to obtain a secret evaluation output message;
[0038] The secret evaluation output message is sent to the client, so that the client obtains the data secret evaluation result.
[0039] The method of the embodiment further includes: in response to receiving the data secret evaluation result of the to-be-processed data sent by the target secret evaluation manufacturer, the data secret evaluation result is converted into a standard message to obtain a secret evaluation output message; and the secret evaluation output message is sent to the client, so that the client obtains the data secret evaluation result, thereby providing a mechanism for outputting a data secret evaluation result in a unified message, ensuring accurate mapping of data formats, being capable of performing unified message conversion for each secret evaluation manufacturer, improving the efficiency and accuracy of data processing, and further improving the efficiency of data secret evaluation.
[0040] In a second aspect, the embodiment of the application further provides a data secret evaluation control method applied to a client, and the method includes:
[0041] In response to a user authentication request operation, authentication request information is sent to a secret evaluation platform, so that the secret evaluation platform generates target verification information of the user in response to receiving the authentication request information; the target verification information includes authentication signaling and the authentication request information;
[0042] Target calling parameters corresponding to the target secret evaluation manufacturer identifier are received, which are generated by the secret evaluation platform based on the target secret evaluation manufacturer identifier included in the authentication request information; the target calling parameters include the authentication signaling, a platform calling address, and request input parameters corresponding to the platform calling address;
[0043] A secret evaluation calling request is generated according to the target calling parameters and a target calling function; the secret evaluation calling request includes calling request input parameters, the authentication signaling, the target calling function, and to-be-processed data;
[0044] The secret review call request is sent to the secret review platform; the secret review call request is used by the secret review platform to respond to the receipt of the secret review call request. If the result of verifying the signaling contained in the secret review call request according to the target verification information is passed, then according to the target secret review parameters, the data to be processed and the target call function included in the authentication request information, secret review indication information is generated, and the secret review indication information is sent to the target secret review manufacturer, so that the target secret review manufacturer performs a data secret review operation corresponding to the target call function on the data to be processed.
[0045] The control method of data close review provided by the embodiment of the present application, in the process of controlling data close review, the client responds to the user's authentication request operation and sends authentication request information to the close review platform, so that the close review platform responds to receiving the authentication request information and generates the user's target verification information; the target verification information includes authentication signaling and the authentication request information; the target call parameter corresponding to the target close review manufacturer identifier sent by the close review platform is received; the target call parameter is generated by the close review platform based on the target close review manufacturer identifier included in the authentication request information; the target call parameter includes the authentication signaling, the platform call address and the request input parameter corresponding to the platform call address; according to the target call parameter and The target call function generates a secret review call request; the secret review call request includes a call request input parameter, the authentication signaling, the target call function and the data to be processed; the secret review call request is sent to the secret review platform; the secret review call request is used by the secret review platform to respond to the receipt of the secret review call request. If the result of verifying the signaling contained in the secret review call request according to the target verification information is passed, then according to the target secret review parameters, the data to be processed and the target call function included in the authentication request information, secret review indication information is generated, and the secret review indication information is sent to the target secret review vendor, so that the target secret review vendor performs a data secret review operation corresponding to the target call function on the data to be processed. This method provides a docking mechanism between the client and the target secret review vendor by dynamically matching and controlling the signaling and verification information, thereby achieving loose coupling between the enterprise and the secret review vendor, enabling the enterprise to correspond to multiple secret review service providers, and effectively improving the efficiency of data secret review.
[0046] In a third aspect, an embodiment of the present application further provides a control device for data review, which is applied to a review platform; the device includes:
[0047] A dynamic information construction module is configured to generate target verification information of the user in response to receiving authentication request information sent by the user through the client; the target verification information includes authentication signaling and the authentication request information;
[0048] The calling parameter generation module is configured to generate a target calling parameter corresponding to the target cryptanalysis manufacturer identifier based on the target cryptanalysis manufacturer identifier included in the authentication request information; the target calling parameter includes the authentication signaling, a platform calling address, and a request input parameter corresponding to the platform calling address;
[0049] The calling parameter transmission module is configured to send the target calling parameter to the client, so that the client generates a cryptanalysis calling request according to the target calling parameter and a target calling function; the cryptanalysis calling request includes a calling request input parameter, the authentication signaling, the target calling function, and to-be-processed data.
[0050] The calling request control module is configured to, in response to receiving the cryptanalysis calling request sent by the client, if a result of verifying the signaling included in the cryptanalysis calling request according to the target verification information is passed, generate cryptanalysis instruction information according to the target cryptanalysis parameter included in the authentication request information, the to-be-processed data, and the target calling function, and send the cryptanalysis instruction information to the target cryptanalysis manufacturer, so that the target cryptanalysis manufacturer performs a data cryptanalysis operation corresponding to the target calling function on the to-be-processed data.
[0051] In an optional embodiment, the target cryptanalysis parameter includes an encryption feature parameter; the encryption feature parameter is a special parameter required by a target encryption manufacturer for a data cryptanalysis operation;
[0052] The calling request control module is specifically configured to:
[0053] determine a target encryption feature parameter corresponding to the target encryption manufacturer and the target calling function based on a first mapping relationship between a preset calling function and a cryptanalysis manufacturer and an encryption feature parameter;
[0054] obtain cryptanalysis instruction information according to the target encryption feature parameter, the to-be-processed data, and the target calling function; the cryptanalysis instruction information includes the target encryption feature parameter, the to-be-processed data, and the target calling function.
[0055] In an optional embodiment, the dynamic information construction module is specifically configured to:
[0056] generate authentication signaling in response to receiving the authentication request information sent by the user through the client;
[0057] store the authentication signaling and the authentication request information in association to obtain target verification information of the user.
[0058] In an optional embodiment, the target cryptanalysis parameter includes a target encryption key; and the dynamic information construction module is specifically configured to:
[0059] associate the authentication signaling with the authentication request information to obtain basic verification information;
[0060] encrypt the basic verification information according to the target encryption key to obtain target verification information of the user.
[0061] In an optional embodiment, the calling parameter generation module is specifically configured to:
[0062] determine, based on a preset second mapping relationship between a cryptanalysis vendor identifier and calling information, basic calling information corresponding to the target cryptanalysis vendor identifier; the calling information includes a calling address and an input parameter corresponding to the calling address; the basic calling information includes the platform calling address and the request input parameter corresponding to the platform calling address; the platform calling address is the calling address corresponding to the target cryptanalysis vendor identifier in the second mapping relationship; and the request input parameter is the input parameter corresponding to the target cryptanalysis vendor identifier in the second mapping relationship;
[0063] obtain target calling parameters corresponding to the target cryptanalysis vendor identifier according to the authentication signaling and the basic calling information.
[0064] In an optional embodiment, the request input parameter further includes a data interface corresponding to the platform calling address and a calling example; the data interface is a data format of an interface; and the data interface includes an interface field name, an interface field type, and an interface field assignment method.
[0065] In an optional embodiment, the calling request control module is specifically configured to:
[0066] obtain signaling contained in the cryptanalysis calling request as first signaling;
[0067] obtain the authentication signaling corresponding to the user from the target verification information;
[0068] compare the first signaling with the authentication signaling, and take a result of the comparison as a result of verification on the signaling contained in the cryptanalysis calling request.
[0069] In an optional embodiment, the apparatus further includes a cryptanalysis response output module; the cryptanalysis response output module is configured to:
[0070] in response to receiving the data cryptanalysis result of the to-be-processed data sent by the target cryptanalysis vendor, perform standard message conversion on the data cryptanalysis result to obtain a cryptanalysis output message;
[0071] send the cryptanalysis output message to the client, so that the client obtains the data cryptanalysis result.
[0072] In a fourth aspect, the embodiments of the present application further provide a data privacy evaluation control device, applied to a client, comprising:
[0073] a signaling control initiation module, configured to, in response to a user's authentication request operation, send authentication request information to a privacy evaluation platform, so that the privacy evaluation platform generates target verification information of the user in response to receiving the authentication request information; the target verification information comprises authentication signaling and the authentication request information;
[0074] a calling parameter receiving module, configured to receive target calling parameters corresponding to the target privacy evaluation manufacturer identifier sent by the privacy evaluation platform; the target calling parameters are generated by the privacy evaluation platform based on the target privacy evaluation manufacturer identifier included in the authentication request information; the target calling parameters comprise the authentication signaling, a platform calling address, and request input parameters corresponding to the platform calling address;
[0075] a calling request generating module, configured to generate a privacy evaluation calling request according to the target calling parameters and a target calling function; the privacy evaluation calling request comprises calling request input parameters, the authentication signaling, the target calling function, and to-be-processed data;
[0076] a calling request triggering module, configured to send the privacy evaluation calling request to the privacy evaluation platform; the privacy evaluation calling request is used for the privacy evaluation platform to, in response to receiving the privacy evaluation calling request, generate privacy evaluation instruction information according to the target privacy evaluation parameters included in the authentication request information, the to-be-processed data, and the target calling function, and send the privacy evaluation instruction information to the target privacy evaluation manufacturer, so that the target privacy evaluation manufacturer performs a data privacy evaluation operation corresponding to the target calling function on the to-be-processed data.
[0077] In a fifth aspect, the embodiments of the present application further provide a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and when the computer program is executed by a processor, the data privacy evaluation control method of the first aspect or the second aspect is implemented.
[0078] In a sixth aspect, the embodiments of the present application further provide an electronic device, comprising a memory and a processor, wherein the memory stores a computer program capable of running on the processor, and when the computer program is executed by the processor, the processor implements the data privacy evaluation control method of the first aspect or the second aspect.
[0079] The technical effects brought by any one of the implementation manners of the third aspect to the sixth aspect can be referred to the technical effects brought by the corresponding implementation manners of the first aspect or the second aspect, which will not be described herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0081] Figure 1 A flowchart of a data review control method provided in an embodiment of the present application;
[0082] Figure 2 A flowchart of a data security control method according to an embodiment of the present application for generating target verification information in response to receiving authentication request information;
[0083] Figure 3 A flowchart of a data security control method provided in an embodiment of the present application for associating and storing authentication signaling with authentication request information to obtain target verification information;
[0084] Figure 4 A flowchart of a method for controlling data review provided in an embodiment of the present application for generating target call parameters corresponding to a target review manufacturer identifier;
[0085] Figure 5 A flowchart of a method for controlling data confidentiality provided in an embodiment of the present application for obtaining a result of verifying the signaling included in a confidentiality review call request according to target verification information;
[0086] Figure 6 A flowchart of a method for controlling data confidentiality reviews according to an embodiment of the present application for generating confidentiality review indication information;
[0087] Figure 7 A flowchart of a method for controlling data confidentiality review provided in an embodiment of the present application, which enables a client to obtain data confidentiality review results;
[0088] Figure 8 A flowchart of another data review control method provided in an embodiment of the present application;
[0089] Figure 9 This is one of the structural diagrams of a control device for data confidentiality provided in an embodiment of the present application;
[0090] Figure 10 This is a second structural diagram of a control device for data confidentiality review provided in an embodiment of the present application;
[0091] Figure 11Another structural schematic diagram of a data security evaluation control device provided by an embodiment of the present application is provided.
[0092] Figure 12 A structural schematic diagram of an electronic device provided by an embodiment of the present application is provided. DETAILED DESCRIPTION
[0093] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0094] It should be noted that the terms “include” and “have” and their variants involved in the documents of the present application are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device containing a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0095] Some words appearing in the text will be explained below:
[0096] (1) Nacos (Dynamic Naming and Configuration Service): Nacos is an open source and powerful dynamic service discovery, service configuration and service management platform. As a cloud-based solution, Nacos aims to help developers better build, manage and discover various services in microservice architecture.
[0097] (2) MapStruct: MapStruct is a Java-based annotation processor that simplifies the conversion process between JavaBeans, and improves development efficiency and system performance by generating type-safe mapping code.
[0098] With the rapid development of information technology, data security and privacy protection have become the focus of social attention. In the fields of finance, government affairs, e-commerce and other fields, data encryption and security evaluation (referred to as “security evaluation”) are important means to protect data security. However, the demand for encryption technology varies in different industries and different application scenarios. Although there are many security evaluation service providers in the market, the technical standards and interface protocols adopted by each of them are not the same, which brings great challenges to enterprises to build a unified and efficient security evaluation system.
[0099] Conventionally, an enterprise needs to customize and develop an interface adaptation layer for a selected privacy evaluation vendor, which not only increases development cost and maintenance difficulty, but also limits flexibility and scalability of the system, and the enterprise can usually correspond to only a specific privacy evaluation service provider, and the efficiency of data privacy evaluation is not high. Therefore, how to provide a data privacy evaluation management method to solve the problem of low efficiency of data privacy evaluation has important practical significance.
[0100] To solve the existing technical problems, the embodiments of the present application provide a data privacy evaluation control method and device. In the process of controlling data privacy evaluation, the privacy evaluation platform generates target verification information of a user in response to receiving authentication request information sent by the user through a client; the target verification information includes authentication signaling and authentication request information; target call parameters corresponding to a target privacy evaluation vendor identifier included in the authentication request information are generated; the target call parameters include authentication signaling, a platform call address, and request input parameters corresponding to the platform call address; the target call parameters are sent to the client, so that the client generates a privacy evaluation call request according to the target call parameters and a target call function; the privacy evaluation call request includes call request input parameters, authentication signaling, a target call function, and to-be-processed data; in response to receiving the privacy evaluation call request sent by the client, if the result of verifying the signaling included in the privacy evaluation call request according to the target verification information is passed, the privacy evaluation indication information is generated according to the target privacy evaluation parameters included in the authentication request information, the to-be-processed data, and the target call function, and the privacy evaluation indication information is sent to the target privacy evaluation vendor, so that the target privacy evaluation vendor performs a data privacy evaluation operation corresponding to the target call function on the to-be-processed data. The method dynamically controls the matching of signaling and verification information in the process of controlling data privacy evaluation, provides a docking mechanism of the client and the target privacy evaluation vendor, realizes loose coupling between the enterprise and the privacy evaluation vendor, and can realize that one enterprise can correspond to multiple privacy evaluation service providers, and can effectively improve the efficiency of data privacy evaluation.
[0101] In order to make the application purposes, technical solutions and advantages of the embodiments of the present application clearer, the present application will be described in further detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the scope of protection of the present application.
[0102] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the drawings.
[0103] The embodiment of the application provides a data privacy evaluation control method, which is applied to a privacy evaluation platform. The privacy evaluation platform can be a server or a terminal device. The following embodiments of the application take the privacy evaluation platform as a server for example.
[0104] The embodiment of the application provides a data privacy evaluation control method, which is applied to a privacy evaluation platform. The privacy evaluation platform can be a server or a terminal device. The following embodiments of the application take the privacy evaluation platform as a server for example. Figure 1 As shown in the figure, the method comprises the following steps:
[0105] Step S101, in response to receiving the authentication request information sent by the user through the client, target verification information of the user is generated.
[0106] The target verification information comprises authentication signaling and authentication request information.
[0107] In some embodiments of the application, in step S101, in response to receiving the authentication request information sent by the user through the client, the process of generating the target verification information of the user can be implemented through the following steps as shown in the figure: Figure 2
[0108] Step S201, in response to receiving the authentication request information sent by the user through the client, authentication signaling is generated.
[0109] The authentication request information comprises a target privacy evaluation manufacturer identifier and a target privacy evaluation parameter.
[0110] In specific implementation, the server generates authentication signaling in response to receiving the authentication request information sent by the user through the client. The authentication request information comprises a target privacy evaluation manufacturer identifier and a target privacy evaluation parameter.
[0111] Step S202, the authentication signaling and the authentication request information are stored in association to obtain the target verification information of the user.
[0112] In specific implementation, the server stores the authentication signaling and the authentication request information in association to obtain the target verification information of the user.
[0113] In some optional embodiments, the target privacy evaluation parameter comprises a target encryption key.
[0114] In some optional embodiments, a Nacos console is constructed to obtain a Nacos configuration center. The Nacos configuration center is used for managing the configuration of services and applications. The target verification information is stored in the Nacos configuration center.
[0115] In some embodiments of the application, the target encryption key can be used for encrypting the information stored in the Nacos configuration center, so as to improve the security of data in the transmission and storage process.
[0116] The method of this embodiment dynamically generates authentication signaling for authentication request information, dynamically performs signaling and verification information matching control during the control of data critical review, and provides a docking mechanism between the client and the target critical review manufacturer, thereby achieving loose coupling between the enterprise and the critical review manufacturer, enabling the enterprise to correspond to multiple critical review service providers, and effectively improving the efficiency of data critical review.
[0117] In the above step S202, the authentication signaling is associated with the authentication request information and stored to obtain the user's target verification information, such as Figure 3 As shown, this can be achieved by following the steps below:
[0118] Step S301: associate the authentication signaling with the authentication request information to obtain basic verification information.
[0119] During specific implementation, the server associates the authentication signaling with the authentication request information to obtain basic verification information.
[0120] Step S302: encrypt the basic verification information according to the target encryption key to obtain the user's target verification information.
[0121] During specific implementation, the server encrypts the basic verification information according to the target encryption key to obtain the user's target verification information.
[0122] The method of this embodiment introduces key encryption during the generation of target verification information to ensure the security of data during transmission and storage. The data is decrypted and used only when the system is running to avoid the risk of data leakage. This can enhance the security of the control process of data secret review by the secret review platform, prevent illegal data secret review requests, and further improve the efficiency of data secret review.
[0123] Step S102: Based on the target secret review manufacturer identifier included in the authentication request information, generate target call parameters corresponding to the target secret review manufacturer identifier; the target call parameters include authentication signaling, platform call address and request input parameters corresponding to the platform call address.
[0124] During specific implementation, the server generates target call parameters corresponding to the target secret review manufacturer identifier based on the target secret review manufacturer identifier; the target call parameters include authentication signaling, platform call address, and request input parameters corresponding to the platform call address.
[0125] In some embodiments of the present application, the request input includes an optional calling function.
[0126] In one embodiment, in step S102, based on the target secret review manufacturer identifier included in the authentication request information, a target call parameter corresponding to the target secret review manufacturer identifier is generated, such as Figure 4 As shown, this can be achieved by following the steps below:
[0127] In step S401, the server determines the basic call information corresponding to the target cryptanalysis vendor identifier based on the preset second mapping relationship between the cryptanalysis vendor identifier and the call information.
[0128] The call information includes a call address and an input parameter corresponding to the call address, and the basic call information includes a platform call address and a request input parameter corresponding to the platform call address. The platform call address is the call address corresponding to the target cryptanalysis vendor identifier in the second mapping relationship, and the request input parameter is the input parameter corresponding to the target cryptanalysis vendor identifier in the second mapping relationship.
[0129] In specific implementation, the server determines the basic call information corresponding to the target cryptanalysis vendor identifier based on the preset second mapping relationship between the cryptanalysis vendor identifier and the call information. The call information includes a call address and an input parameter corresponding to the call address, and the basic call information includes a platform call address and a request input parameter corresponding to the platform call address. The platform call address is the call address corresponding to the target cryptanalysis vendor identifier in the second mapping relationship, and the request input parameter is the input parameter corresponding to the target cryptanalysis vendor identifier in the second mapping relationship.
[0130] In step S402, the server obtains the target call parameter corresponding to the target cryptanalysis vendor identifier according to the authentication signaling and the basic call information.
[0131] In specific implementation, the server obtains the target call parameter corresponding to the target cryptanalysis vendor identifier according to the authentication signaling and the basic call information.
[0132] In the method of this embodiment, a mechanism for determining the target call parameter corresponding to different cryptanalysis vendors is provided, the accuracy of determining the call parameter of the cryptanalysis vendor is improved, and the efficiency of data cryptanalysis is further improved.
[0133] In one embodiment, the request input parameter further includes a data interface corresponding to the platform call address and a call example. The data interface is the data format of the interface, and the data interface includes an interface field name, an interface field type, and an interface field assignment method.
[0134] In the method of this embodiment, the request input parameter further includes a data interface corresponding to the platform call address and a call example. The data interface is the data format of the interface, and the data interface includes an interface field name, an interface field type, and an interface field assignment method. Thus, a standardized interface encapsulation is provided, the cryptanalysis platform can provide a unified call address and parameter format to the outside, the parameter can be dynamically configured based on the data interface and the call example, the client can seamlessly connect the services of different cryptanalysis vendors, it is beneficial to quickly integrate new cryptanalysis vendors, the development and maintenance costs of the cryptanalysis platform are reduced, and the efficiency of data cryptanalysis can be further improved.
[0135] Step S103, sending the target calling parameter to the client, so that the client generates a confidential evaluation calling request according to the target calling parameter and the target calling function.
[0136] The confidential evaluation calling request includes a calling request input parameter, authentication signaling, a target calling function and to-be-processed data.
[0137] In some embodiments of the present application, the calling request input parameter can be a request input parameter corresponding to a target platform calling address; and the target platform calling address can be a platform calling address corresponding to the target calling function.
[0138] In some embodiments of the present application, the target calling function can be a calling function selected by a user.
[0139] In some embodiments of the present application, the confidential evaluation calling request is used to call a target calling function of a target confidential evaluation vendor.
[0140] Step S104, in response to receiving the confidential evaluation calling request sent by the client, if the result of verifying the signaling contained in the confidential evaluation calling request according to the target verification information is passed, generating confidential evaluation indication information according to the target confidential evaluation parameter, the to-be-processed data and the target calling function included in the authentication request information, and sending the confidential evaluation indication information to the target confidential evaluation vendor, so that the target confidential evaluation vendor performs a data confidential evaluation operation corresponding to the target calling function on the to-be-processed data.
[0141] In some optional embodiments, the result of verifying the signaling contained in the confidential evaluation calling request according to the target verification information in the above step S104 can be obtained through the following steps, as shown in the following table. Figure 5
[0142] Step S501, obtaining the signaling contained in the confidential evaluation calling request as first signaling.
[0143] In specific implementation, the server obtains the signaling contained in the confidential evaluation calling request as first signaling.
[0144] Step S502, obtaining the authentication signaling corresponding to the user from the target verification information.
[0145] In specific implementation, the server obtains the authentication signaling corresponding to the user from the target verification information.
[0146] Step S503, comparing the first signaling with the authentication signaling, and taking the comparison result as the result of verifying the signaling contained in the confidential evaluation calling request.
[0147] In specific implementation, the server compares the first signaling with the authentication signaling, and takes the comparison result as the result of verifying the signaling contained in the confidential evaluation calling request.
[0148] The method of the embodiment provides a mechanism for verifying signaling contained in a cryptographic evaluation call request according to target verification information, realizes accurate signaling matching control, guarantees accurate connection of a client and a target cryptographic evaluation manufacturer, and further effectively improves the efficiency of data cryptographic evaluation.
[0149] In an embodiment, the target cryptographic evaluation parameter includes an encryption feature parameter; the encryption feature parameter is a special parameter required by the target encryption manufacturer for a data cryptographic evaluation operation; in step S104, the process of generating the cryptographic evaluation instruction information according to the target cryptographic evaluation parameter, the to-be-processed data and the target call function included in the authentication request information is as shown in Figure 6 The process can be implemented through the following steps:
[0150] In step S601, the target encryption feature parameter corresponding to the target encryption manufacturer and the target call function is determined based on a preset first mapping relationship between the call function and the cryptographic evaluation manufacturer and the encryption feature parameter.
[0151] In specific implementation, the server determines the target encryption feature parameter corresponding to the target encryption manufacturer and the target call function based on the preset first mapping relationship between the call function and the cryptographic evaluation manufacturer and the encryption feature parameter.
[0152] In some embodiments of the application, a parameter mapping is established in advance, wherein the parameter mapping allows a user to configure corresponding specific parameters for different cryptographic evaluation manufacturers according to actual needs; the cryptographic evaluation platform completes parameter conversion through the parameter mapping, ensuring call accuracy.
[0153] In step S602, the cryptographic evaluation instruction information is obtained according to the target encryption feature parameter, the to-be-processed data and the target call function; the cryptographic evaluation instruction information includes the target encryption feature parameter, the to-be-processed data and the target call function.
[0154] In specific implementation, the server obtains the cryptographic evaluation instruction information according to the target encryption feature parameter, the to-be-processed data and the target call function included in the cryptographic evaluation call request; the cryptographic evaluation instruction information includes the target encryption feature parameter, the to-be-processed data and the target call function.
[0155] The method of the embodiment can, when controlling data cryptographic evaluation, determine the target encryption feature parameter according to the target encryption manufacturer and the target call function, and then perform a data cryptographic evaluation operation corresponding to the target call function on the to-be-processed data according to the target encryption feature parameter, realize accurate identification of the target encryption feature parameter, further reduce the time for implementing the data cryptographic evaluation operation corresponding to the target call function by the target encryption manufacturer, and effectively improve the efficiency of data cryptographic evaluation.
[0156] In some optional embodiments, after the cryptographic evaluation instruction information is sent to the target cryptographic evaluation manufacturer to make the target cryptographic evaluation manufacturer perform a data cryptographic evaluation operation corresponding to the target call function on the to-be-processed data,Figure 7 As shown, the method further includes the following steps:
[0157] In step S701, in response to receiving the data privacy evaluation result of the target privacy evaluation vendor, the data privacy evaluation result is converted into a standard message to obtain a privacy evaluation output message.
[0158] In particular implementation, the server, in response to receiving the data privacy evaluation result of the target privacy evaluation vendor, converts the data privacy evaluation result into a standard message to obtain a privacy evaluation output message.
[0159] In some optional embodiments, the standard message conversion is performed by using MapStruct.
[0160] In some optional embodiments, the process of standard message conversion includes: obtaining a one-to-one corresponding Mapping file set for each privacy evaluation vendor; and performing message conversion through the Mapping file corresponding to the target privacy evaluation vendor to obtain a privacy evaluation output message conforming to a preset transmission standard.
[0161] In the embodiments of the present application, the preset transmission standard can be a pre-designated unified standard for internal message transmission, which reduces errors caused by format differences and provides clear guidance for the access of new privacy evaluation vendors.
[0162] In step S702, the privacy evaluation output message is sent to the client to enable the client to obtain the data privacy evaluation result.
[0163] In particular implementation, the server sends the privacy evaluation output message to the client to enable the client to obtain the data privacy evaluation result.
[0164] The method of the embodiments provides a mechanism for outputting data privacy evaluation results in a unified message, ensures accurate mapping of data formats, can perform unified message conversion for each privacy evaluation vendor, improves the efficiency and accuracy of data processing, and further improves the efficiency of data privacy evaluation.
[0165] The data privacy evaluation control method provided by the embodiments of the present application can dynamically control the matching of the signaling and the verification information, provide a docking mechanism of the client and the target privacy evaluation manufacturer, realize the loose coupling of the enterprise and the privacy evaluation manufacturer, enable the enterprise to correspond to multiple privacy evaluation service providers, and effectively improve the data privacy evaluation efficiency.
[0166] The embodiments of the present application provide a data privacy evaluation control method, which is applied to a client; wherein the privacy evaluation platform can be a terminal device. The following embodiments of the present application take the client to which the data privacy evaluation control method is applied as an example to illustrate.
[0167] The embodiments of the present application also provide a data privacy evaluation control method, which is applied to a client; as shown in the following embodiments of the present application. Figure 8 The embodiments of the present application also provide a data privacy evaluation control method, which is applied to a client; as shown in the following embodiments of the present application.
[0168] In step S801, in response to the authentication request operation of the user, authentication request information is sent to the privacy evaluation platform, so that the privacy evaluation platform generates target verification information of the user in response to receiving the authentication request information; the target verification information includes authentication signaling and authentication request information.
[0169] Step S802, receiving the target calling parameter corresponding to the target privacy evaluation vendor identifier sent by the privacy evaluation platform; the target calling parameter is generated by the privacy evaluation platform based on the target privacy evaluation vendor identifier included in the authentication request information; the target calling parameter includes authentication signaling, platform calling address and request input parameter corresponding to the platform calling address.
[0170] Step S803, generating a privacy evaluation calling request according to the target calling parameter and the target calling function; the privacy evaluation calling request includes calling request input parameter, authentication signaling, target calling function and data to be processed.
[0171] Step S804, sending the privacy evaluation calling request to the privacy evaluation platform; the privacy evaluation calling request is used for the privacy evaluation platform to respond to the received privacy evaluation calling request, and if the result of verifying the signaling included in the privacy evaluation calling request according to the target verification information is passed, the privacy evaluation platform generates privacy evaluation instruction information according to the target privacy evaluation parameter, the data to be processed and the target calling function included in the authentication request information, and sends the privacy evaluation instruction information to the target privacy evaluation vendor, so that the target privacy evaluation vendor performs data privacy evaluation operation corresponding to the target calling function on the data to be processed.
[0172] The control method for data privacy evaluation provided in the embodiments of the present application can provide a docking mechanism of the client and the target privacy evaluation vendor by dynamically performing signaling matching control in the process of controlling data privacy evaluation, realize loose coupling of the enterprise and the privacy evaluation vendor, and enable the enterprise to correspond to multiple privacy evaluation service providers, thereby effectively improving the efficiency of data privacy evaluation.
[0173] Based on the same inventive concept, the embodiments of the present application also provide a control device for data privacy evaluation. Since the device is a device corresponding to the control method for data privacy evaluation provided in the embodiments of the present application, and the principle of solving problems of the device is similar to that of the method, the implementation of the device can be referred to the implementation of the above method, and the repeated parts will not be described herein.
[0174] Figure 9 A structure schematic diagram of a control device for data privacy evaluation provided in the embodiments of the present application is shown, and the control device for data privacy evaluation is applied to a privacy evaluation platform; as shown in Figure 9 the control device for data privacy evaluation includes a dynamic information construction module 901, a calling parameter generation module 902, a calling parameter transmission module 903 and a calling request management and control module 904.
[0175] The dynamic information construction module 901 is configured to generate target verification information of a user in response to receiving authentication request information sent by the user through a client; the target verification information includes authentication signaling and authentication request information.
[0176] The calling parameter generation module 902 is configured to generate a target calling parameter corresponding to the target encryption evaluation manufacturer identifier based on the target encryption evaluation manufacturer identifier included in the authentication request information; the target calling parameter includes authentication signaling, a platform calling address, and request input parameters corresponding to the platform calling address;
[0177] The calling parameter transmission module 903 is configured to send the target calling parameter to the client, so that the client generates an encryption evaluation calling request according to the target calling parameter and the target calling function; the encryption evaluation calling request includes calling request input parameters, authentication signaling, the target calling function, and to-be-processed data.
[0178] The calling request management module 904 is configured to, in response to receiving the encryption evaluation calling request sent by the client, if a result of verifying the signaling included in the encryption evaluation calling request according to the target verification information is passed, generate encryption evaluation instruction information according to the target encryption evaluation parameter, the to-be-processed data, and the target calling function included in the authentication request information, and send the encryption evaluation instruction information to the target encryption evaluation manufacturer, so that the target encryption evaluation manufacturer performs a data encryption evaluation operation corresponding to the target calling function on the to-be-processed data.
[0179] In an optional embodiment, the target encryption evaluation parameter includes an encryption feature parameter; the encryption feature parameter is a special parameter required by the target encryption manufacturer for the data encryption evaluation operation.
[0180] The calling request management module 904 is specifically configured to:
[0181] determine a target encryption feature parameter corresponding to the target encryption manufacturer and the target calling function based on a preset first mapping relationship between the calling function and the encryption evaluation manufacturer and the encryption feature parameter;
[0182] obtain the encryption evaluation instruction information according to the target encryption feature parameter, the to-be-processed data, and the target calling function; the encryption evaluation instruction information includes the target encryption feature parameter, the to-be-processed data, and the target calling function.
[0183] In an optional embodiment, the dynamic information construction module 901 is specifically configured to:
[0184] generate the authentication signaling in response to receiving the authentication request information sent by the user through the client;
[0185] store the authentication signaling and the authentication request information in association to obtain target verification information of the user.
[0186] In an optional embodiment, the target encryption evaluation parameter includes a target encryption key; and the dynamic information construction module 901 is specifically configured to:
[0187] associate the authentication signaling and the authentication request information to obtain basic verification information;
[0188] The base check information is encrypted according to the target encryption key, to obtain target check information of the user.
[0189] In an optional embodiment, the calling parameter generation module 902 is specifically configured to:
[0190] Based on a preset second mapping relationship between the target encryption evaluation vendor identifier and the calling information, the base calling information corresponding to the target encryption evaluation vendor identifier is determined; the calling information includes a calling address and an input parameter corresponding to the calling address; the base calling information includes a platform calling address and a request input parameter corresponding to the platform calling address; the platform calling address is the calling address corresponding to the target encryption evaluation vendor identifier in the second mapping relationship; and the request input parameter is the input parameter corresponding to the target encryption evaluation vendor identifier in the second mapping relationship.
[0191] According to the authentication signaling and the base calling information, the target calling parameter corresponding to the target encryption evaluation vendor identifier is obtained.
[0192] In an optional embodiment, the request input parameter further includes a data interface corresponding to the platform calling address and a calling example; the data interface is a data format of an interface; and the data interface includes an interface field name, an interface field type, and an interface field assignment method.
[0193] In an optional embodiment, the calling request control module 904 is specifically configured to:
[0194] Obtain the signaling contained in the encryption evaluation calling request as the first signaling;
[0195] Obtain the authentication signaling corresponding to the user from the target check information;
[0196] Compare the first signaling with the authentication signaling, and take the comparison result as a result of checking the signaling contained in the encryption evaluation calling request.
[0197] In an optional embodiment, as shown in Figure 10 The apparatus further includes an encryption evaluation response output module 1001; the encryption evaluation response output module 1001 is configured to:
[0198] In response to receiving the data encryption evaluation result of the to-be-processed data sent by the target encryption evaluation vendor, the data encryption evaluation result is converted into a standard message to obtain an encryption evaluation output message;
[0199] The encryption evaluation output message is sent to the client, so that the client obtains the data encryption evaluation result.
[0200] Figure 11 Fig. 6 shows a structural schematic diagram of another data encryption evaluation control apparatus provided by an embodiment of the present application, which is applied to a client; as Figure 11As shown, the method comprises: a signaling control initiation module 1101, a call parameter receiving module 1102, a call request generating module 1103, and a call request triggering module 1104.
[0201] The signaling control initiation module 1101 is configured to, in response to a user's authentication request operation, send authentication request information to the secret evaluation platform, so that the secret evaluation platform generates target verification information of the user in response to receiving the authentication request information; the target verification information comprises authentication signaling and the authentication request information.
[0202] The call parameter receiving module 1102 is configured to receive target call parameters corresponding to a target secret evaluation vendor identifier sent by the secret evaluation platform; the target call parameters are generated by the secret evaluation platform based on the target secret evaluation vendor identifier included in the authentication request information; the target call parameters comprise authentication signaling, a platform call address, and request input parameters corresponding to the platform call address.
[0203] The call request generating module 1103 is configured to generate a secret evaluation call request according to the target call parameters and a target call function; the secret evaluation call request comprises call request input parameters, authentication signaling, the target call function, and to-be-processed data.
[0204] The call request triggering module 1104 is configured to send the secret evaluation call request to the secret evaluation platform; the secret evaluation call request is used for the secret evaluation platform to, in response to receiving the secret evaluation call request, if a result of verifying signaling included in the secret evaluation call request according to the target verification information is passed, generate secret evaluation instruction information according to the target secret evaluation parameters, the to-be-processed data, and the target call function included in the authentication request information, and send the secret evaluation instruction information to the target secret evaluation vendor, so that the target secret evaluation vendor performs a data secret evaluation operation corresponding to the target call function on the to-be-processed data.
[0205] Based on the same inventive concept as the method embodiments, the embodiments of the present application also provide an electronic device. The electronic device can be used for the control of data secret evaluation. In the embodiments of the present application, the electronic device can be a server or a terminal device. In an embodiment, the electronic device can be a server. In this embodiment, the structure of the electronic device can be as shown in the figure. Figure 12 As shown, the electronic device comprises a memory 1201, a communication module 1203, and one or more processors 1202.
[0206] The memory 1201 is configured to store computer programs executed by the processor 1202. The memory 1201 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and programs required for running instant messaging functions, etc.; the data storage area can store various instant messaging information and operation instruction sets, etc.
[0207] The memory 1201 can be a volatile memory, such as a random-access memory (RAM), or a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory 1201 can be a combination of the above memories.
[0208] The processor 1202 can include one or more central processing units (CPUs) or digital processing units, etc. The processor 1202 is configured to implement the control method of the data encryption described above when invoking the computer program stored in the memory 1201.
[0209] The communication module 1203 is configured to communicate with a server and other terminal devices.
[0210] The specific connection medium between the memory 1201, the communication module 1203 and the processor 1202 is not limited in the embodiments of the present application. In the embodiments of the present application, the memory 1201 and the processor 1202 are connected through the bus 1204, and the bus 1204 is represented by a thick line in the embodiments of the present application. The connection mode between other components is only schematically illustrated and is not limited. The bus 1204 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, only one thick line is used to represent the bus 1204 in the embodiments of the present application, but it does not mean that there is only one bus or only one type of bus. Figure 12 Figure 12 The connection mode between other components is only schematically illustrated and is not limited. The bus 1204 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, only one thick line is used to represent the bus 1204 in the embodiments of the present application, but it does not mean that there is only one bus or only one type of bus. Figure 12
[0211] According to an aspect of the present application, a computer program product or computer program is provided, which comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device performs the control method of data security in the above-mentioned embodiments. The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0212] The above description is merely a specific implementation of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, and all such changes or replacements shall be encompassed within the scope of protection of the present application.
Claims
1. A data confidentiality control method, characterized in that: Applied to a critical review platform; the method includes: In response to receiving authentication request information sent by a user through a client, generating target verification information of the user; the target verification information includes authentication signaling and the authentication request information; Based on the target secret review manufacturer identifier included in the authentication request information, generating a target call parameter corresponding to the target secret review manufacturer identifier; the target call parameter includes the authentication signaling, the platform call address and the request input parameter corresponding to the platform call address; Sending the target call parameters to the client, so that the client generates a secret review call request according to the target call parameters and the target call function; the secret review call request includes the call request input parameters, the authentication signaling, the target call function and the data to be processed; In response to receiving the secret review call request sent by the client, if the result of verifying the signaling included in the secret review call request according to the target verification information is passed, then generating secret review indication information according to the target secret review parameters included in the authentication request information, the data to be processed and the target call function, and sending the secret review indication information to the target secret review vendor, so that the target secret review vendor performs a data secret review operation corresponding to the target call function on the data to be processed; The target secret review parameters include encryption feature parameters; the encryption feature parameters are special parameters required by the target encryption manufacturer to perform data secret review operations; The generating of the secret review indication information according to the target secret review parameters, the data to be processed, and the target call function included in the authentication request information includes: Determining target encryption characteristic parameters corresponding to the target encryption manufacturer and the target calling function based on a first mapping relationship between a preset calling function, a cryptographic evaluation manufacturer, and an encryption characteristic parameter; Obtaining secret review indication information according to the target encryption characteristic parameters, the data to be processed, and the target call function; the secret review indication information includes the target encryption characteristic parameters, the data to be processed, and the target call function; The generating of a target call parameter corresponding to the target secret review manufacturer identifier based on the target secret review manufacturer identifier included in the authentication request information includes: Based on a preset second mapping relationship between the secret review manufacturer identifier and the call information, the basic call information corresponding to the target secret review manufacturer identifier is determined; the call information includes a call address and an input parameter corresponding to the call address; the basic call information includes the platform call address and the request input parameter corresponding to the platform call address; the platform call address is the call address corresponding to the target secret review manufacturer identifier in the second mapping relationship; the request input parameter is the input parameter corresponding to the target secret review manufacturer identifier in the second mapping relationship; According to the authentication signaling and the basic call information, a target call parameter corresponding to the target secret review manufacturer identifier is obtained.
2. The method according to claim 1, characterized in that The response receives the authentication request information sent by the user through the client, and generates the target verification information of the user, including: In response to receiving the authentication request information sent by the user through the client, generating authentication signaling; The authentication signaling is associated with the authentication request information and stored to obtain the target verification information of the user.
3. The method according to claim 2, characterized in that The target evaluation parameter includes a target encryption key; the associating and storing the authentication signaling with the authentication request information to obtain the target verification information of the user includes: Associating the authentication signaling with the authentication request information to obtain basic verification information; The basic verification information is encrypted according to the target encryption key to obtain the target verification information of the user.
4. A data confidentiality control method, characterized in that: Applied to the client; includes: In response to the user's authentication request operation, send authentication request information to the secret review platform, so that the secret review platform generates the user's target verification information in response to receiving the authentication request information; the target verification information includes authentication signaling and the authentication request information; Receive a target call parameter corresponding to the target secret review vendor identifier sent by the secret review platform; the target call parameter is generated by the secret review platform based on the target secret review vendor identifier included in the authentication request information; the target call parameter includes the authentication signaling, the platform call address, and the request input parameter corresponding to the platform call address; Generate a secret review call request according to the target call parameters and the target call function; the secret review call request includes the call request input parameters, the authentication signaling, the target call function and the data to be processed; The secret review call request is sent to the secret review platform; the secret review call request is used by the secret review platform to respond to the secret review call request. If the result of verifying the signaling included in the secret review call request according to the target verification information is passed, secret review indication information is generated according to the target secret review parameters, the data to be processed and the target call function included in the authentication request information, and the secret review indication information is sent to the target secret review manufacturer, so that the target secret review manufacturer performs a data secret review operation corresponding to the target call function on the data to be processed; Wherein, the target secret review parameters include encryption characteristic parameters; the encryption characteristic parameters are special parameters required by the target encryption vendor to perform data secret review operations; the generating of secret review indication information according to the target secret review parameters, the data to be processed, and the target calling function included in the authentication request information includes: determining the target encryption characteristic parameters corresponding to the target encryption vendor and the target calling function based on a preset first mapping relationship between the calling function, the secret review vendor, and the encryption characteristic parameters; obtaining the secret review indication information according to the target encryption characteristic parameters, the data to be processed, and the target calling function; the secret review indication information includes the target encryption characteristic parameters, the data to be processed, and the target calling function; Based on the target secret review manufacturer identifier included in the authentication request information, target call parameters corresponding to the target secret review manufacturer identifier are generated, including: based on a preset second mapping relationship between the secret review manufacturer identifier and the call information, the basic call information corresponding to the target secret review manufacturer identifier is determined; the call information includes a call address and an input parameter corresponding to the call address; the basic call information includes the platform call address and the request input parameter corresponding to the platform call address; the platform call address is the call address corresponding to the target secret review manufacturer identifier in the second mapping relationship; the request input parameter is the input parameter corresponding to the target secret review manufacturer identifier in the second mapping relationship; according to the authentication signaling and the basic call information, the target call parameters corresponding to the target secret review manufacturer identifier are obtained.
5. A data confidentiality control device, characterized in that: Applied to a critical review platform; the device comprises: A dynamic information construction module is configured to generate target verification information of the user in response to receiving authentication request information sent by the user through the client; the target verification information includes authentication signaling and the authentication request information; A calling parameter generation module is used to generate a target calling parameter corresponding to the target secret review manufacturer identifier included in the authentication request information; the target calling parameter includes the authentication signaling, the platform calling address and the request input parameter corresponding to the platform calling address; A call parameter transfer module is used to send the target call parameters to the client, so that the client generates a secret review call request according to the target call parameters and the target call function; the secret review call request includes the call request input parameters, the authentication signaling, the target call function and the data to be processed; A call request control module is configured to respond to the secret review call request sent by the client, and if the result of verifying the signaling included in the secret review call request according to the target verification information is passed, generate secret review indication information based on the target secret review parameters, the data to be processed, and the target call function included in the authentication request information, and send the secret review indication information to the target secret review vendor, so that the target secret review vendor performs a data secret review operation corresponding to the target call function on the data to be processed; The target secret review parameters include encryption feature parameters; the encryption feature parameters are special parameters required by the target encryption manufacturer to perform data secret review operations; The call request control module is specifically used to: Determining target encryption characteristic parameters corresponding to the target encryption manufacturer and the target calling function based on a first mapping relationship between a preset calling function, a cryptographic evaluation manufacturer, and an encryption characteristic parameter; Obtaining secret review indication information according to the target encryption characteristic parameters, the data to be processed, and the target call function; the secret review indication information includes the target encryption characteristic parameters, the data to be processed, and the target call function; The calling parameter generation module is specifically used to: Based on a preset second mapping relationship between the secret review manufacturer identifier and the call information, the basic call information corresponding to the target secret review manufacturer identifier is determined; the call information includes a call address and an input parameter corresponding to the call address; the basic call information includes the platform call address and the request input parameter corresponding to the platform call address; the platform call address is the call address corresponding to the target secret review manufacturer identifier in the second mapping relationship; the request input parameter is the input parameter corresponding to the target secret review manufacturer identifier in the second mapping relationship; According to the authentication signaling and the basic call information, a target call parameter corresponding to the target secret review manufacturer identifier is obtained.
6. A data confidentiality control device, characterized in that: Applied to a client; the device includes: A signaling control initiation module is configured to respond to a user's authentication request operation and send authentication request information to the review platform, so that the review platform generates target verification information of the user in response to receiving the authentication request information; the target verification information includes authentication signaling and the authentication request information; A calling parameter receiving module is used to receive a target calling parameter corresponding to the target secret review vendor identifier sent by the secret review platform; the target calling parameter is generated by the secret review platform based on the target secret review vendor identifier included in the authentication request information; the target calling parameter includes the authentication signaling, the platform calling address, and the request input parameter corresponding to the platform calling address; A call request generation module is used to generate a secret review call request according to the target call parameters and the target call function; the secret review call request includes the call request input parameters, the authentication signaling, the target call function and the data to be processed; A call request triggering module, configured to send the secret review call request to the secret review platform; the secret review call request is used by the secret review platform to respond to receipt of the secret review call request. If the result of verifying the signaling included in the secret review call request according to the target verification information is passed, secret review indication information is generated according to the target secret review parameters, the data to be processed and the target call function included in the authentication request information, and the secret review indication information is sent to the target secret review vendor, so that the target secret review vendor performs a data secret review operation on the data to be processed corresponding to the target call function; Wherein, the target secret review parameters include encryption characteristic parameters; the encryption characteristic parameters are special parameters required by the target encryption vendor to perform data secret review operations; the generating of secret review indication information according to the target secret review parameters, the data to be processed, and the target calling function included in the authentication request information includes: determining the target encryption characteristic parameters corresponding to the target encryption vendor and the target calling function based on a preset first mapping relationship between the calling function, the secret review vendor, and the encryption characteristic parameters; obtaining the secret review indication information according to the target encryption characteristic parameters, the data to be processed, and the target calling function; the secret review indication information includes the target encryption characteristic parameters, the data to be processed, and the target calling function; Based on the target secret review manufacturer identifier included in the authentication request information, target call parameters corresponding to the target secret review manufacturer identifier are generated, including: based on a preset second mapping relationship between the secret review manufacturer identifier and the call information, the basic call information corresponding to the target secret review manufacturer identifier is determined; the call information includes a call address and an input parameter corresponding to the call address; the basic call information includes the platform call address and the request input parameter corresponding to the platform call address; the platform call address is the call address corresponding to the target secret review manufacturer identifier in the second mapping relationship; the request input parameter is the input parameter corresponding to the target secret review manufacturer identifier in the second mapping relationship; according to the authentication signaling and the basic call information, the target call parameters corresponding to the target secret review manufacturer identifier are obtained.
7. A computer-readable storage medium storing a computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 3 or the method according to claim 4 is implemented.
8. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the computer program is executed by the processor, the method according to any one of claims 1 to 3 or the method according to claim 4 is implemented.
Citation Information
Patent Citations
Interface rule verification method, device, computer device and storage medium
CN109344642A
Information processing method and device and storage medium
CN115237614A