Data intranet and extranet transmission method and device

Through field-level sensitivity classification and dynamic encryption, the problem of insufficient or excessive encryption in intranet and extranet data transmission in existing technologies is solved, and efficient and secure data transmission is achieved, which is suitable for data transmission scenarios involving sensitive information.

CN120602239AActive Publication Date: 2025-09-05INSPUR GENERSOFT CO LTD
View PDF 13 Cites 0 Cited by

Patent Information

Application Number
CN202511100761.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-09-05
Estimated Expiration
2045-08-07

AI Technical Summary

Technical Problem

In the existing technology, the transmission of intranet and extranet data cannot be differentiated and encrypted for different sensitive fields within the data, resulting in insufficient encryption of highly sensitive data and excessive encryption of low-sensitivity data, and insufficient security control of information transmitted externally by enterprises.

Method used

It adopts field-level sensitivity grading and dynamic encryption methods, realizes decoupling and scalable update of field names and contents through field mapping dictionaries, generates structured data and carries metadata in the message header, ensuring that the receiving end can accurately decrypt and restore the data structure without pre-configuration.

Benefits of technology

It achieves strong security for highly sensitive data and low processing overhead for low-sensitivity data, taking into account security, flexibility and system compatibility, significantly reducing the surface of data leakage and improving transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602239A_ABST
    Figure CN120602239A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network data transmission, and discloses a data intranet and extranet transmission method and equipment. The method comprises the following steps: in response to a transmission request of to-be-transmitted data, dividing the to-be-transmitted data according to fields; determining an encryption level according to the sensitivity level of the to-be-transmitted data; generating a plurality of key-value pairs by taking each field name as a key and the field content as a value to obtain structured data; mapping each field name into a field code according to the field mapping dictionary, and encrypting the field content according to the corresponding encryption level; generating a message header comprising a field mapping dictionary identifier, an encryption level identifier and a data type identifier of the to-be-transmitted data; and packaging and transmitting the message header and the structured data. According to the invention, secure transmission of data between the internal and external networks is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data transmission, and in particular relates to a method and device for transmitting data between an intranet and an extranet. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] Currently, the encrypted transmission of data within and outside networks often uses a unified encryption standard. However, different types of data have different sensitivities and encryption requirements. Based on this, existing technologies have proposed tiered encryption schemes based on the sensitivity of the data. However, these encryption technologies still rely on overall encryption and are unable to differentiate between different sensitive fields within the data, leading to problems such as insufficient encryption of highly sensitive data and excessive encryption of less sensitive data. Furthermore, for data files such as internal corporate financial data and contract data, in addition to the aforementioned issues, the control of external transmission is also a factor that affects information security. Currently, the focus is mainly on the encryption of the data itself, which affects corporate information security management. Summary of the Invention

[0004] In view of this, the present invention provides a method and device for transmitting data between an intranet and an extranet, so as to achieve secure file transmission.

[0005] One aspect of the present invention provides a method for transmitting data between an intranet and an extranet, which is applied to a sender and includes the following steps: In response to a transmission request for data to be transmitted, dividing the data to be transmitted by fields; Determining an encryption level according to the sensitivity level of the data to be transmitted; Use each field name as the key and the field content as the value to generate multiple key-value pairs to obtain structured data; Mapping each field name to a field code according to a field mapping dictionary, encrypting the field content according to the corresponding encryption level; and generating a message header, which includes a field mapping dictionary identifier, an encryption level identifier, and a data type identifier of the data to be transmitted; The message header and structured data are packaged and transmitted.

[0006] In some embodiments, the data type of the data to be transmitted includes tabular data and text data; when the data to be transmitted is text data, dividing the data to be transmitted by fields includes: analyzing the text structure, dividing the text data according to chapters, recording the chapter name as a field, and recording the content of each chapter as the field content.

[0007] In some embodiments, after the data to be transmitted is divided into fields, the sensitivity level of each field is evaluated to determine the encryption level of each field; the message header includes a mapping relationship between the field code and the encryption level identifier.

[0008] In some embodiments, the overall sensitivity level of the file is determined based on the sensitivity level of the data to be transmitted; the approval path is matched based on the overall sensitivity level; and it is determined whether the data to be transmitted has passed all approval procedures on the approval path. If so, field-level sensitivity identification is further performed; if not, the approval process is reinitiated.

[0009] In some embodiments, the enterprise organizational structure is obtained to construct reporting links between positions from the bottom up; the number of approval levels is matched based on the sensitivity level, and the approval path is adaptively created based on the position of the file transfer personnel and the number of approval levels.

[0010] In some embodiments, multiple key-value pairs are generated with each field as the key and the field content as the value. After obtaining the structured data, the size and hash value of the structured data are calculated and the data size and hash value are written into the message header.

[0011] In some embodiments, at least one of the field mapping dictionary, the encryption level identifier, and the data type identifier is updated periodically.

[0012] A second aspect of the present invention provides a method for transmitting data over an intranet or extranet, which is applied to a receiving party, the receiving party being in communication with the sending party, and the method comprising the following steps: Receive encrypted data and parse the message header to obtain the encryption level, field mapping dictionary, and data type; Obtain the field name based on the field mapping dictionary, and decrypt the field content based on the decryption algorithm corresponding to the encryption level; Reconstruct the field name and field content according to the data type to obtain the data to be transmitted.

[0013] In some embodiments, the data size and hash value are obtained based on the message header parsing; after obtaining the field name and field content, the data size and hash value are recalculated to perform data consistency judgment.

[0014] A third aspect of the present invention provides an electronic device, comprising a processor and a memory, wherein the memory stores computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method described.

[0015] One or more of the above technical solutions, through field-level sensitivity classification and dynamic encryption, ensure strong security for highly sensitive data while reducing the processing overhead of less sensitive data; use field mapping dictionaries to achieve decoupling and scalable updates of field names and content; the message header centrally carries metadata such as dictionary version, encryption level, and data type, allowing the receiving end to accurately decrypt and restore the data structure without relying on preset configurations, thus taking into account security, flexibility, and system compatibility.

[0016] In addition, by decoupling the two-level sensitivity judgment and approval at the "overall-field level", we can avoid excessive approval of low-sensitivity files and ensure that high-sensitivity fields are targeted and encrypted after approval, significantly reducing the surface of data leakage and improving transmission efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0018] Figure 1 A flowchart of a method for transmitting data between an intranet and an intranet and provided by an exemplary embodiment of the present application is shown; Figure 2 A flowchart of a method for transmitting data between an intranet and an extranet applied to a data receiver is shown in accordance with an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0019] The following describes embodiments of the present application in more detail with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are for illustrative purposes only and are not intended to limit the scope of protection of the present application.

[0020] In the description of the embodiments of the present application, the term “including” and similar terms should be understood as open inclusion, that is, “including but not limited to.” The term “based on” should be understood as “at least partially based on.”

[0021] As described in the background, existing methods for hierarchical encryption based on data sensitivity still rely on overall encryption, failing to differentiate between sensitive fields within the data. This leads to issues such as insufficient encryption of highly sensitive data and excessive encryption of less sensitive data, and fails to fully consider enterprise encryption needs. One or more embodiments of the present invention provide a transmission method that implements hierarchical encryption at the field level while ensuring compliance for external transmission.

[0022] Figure 1 A flowchart of a method for transmitting data between an intranet and an extranet, provided by an exemplary embodiment of the present application, is shown, including the following steps: S101: In response to a request to send data to be transmitted, dividing the data to be transmitted by fields; S102: Determine an encryption level according to the sensitivity level of the data to be transmitted; S103: Generate multiple key-value pairs using each field name as a key and the field content as a value to obtain structured data; S104: Map each field name to a field code according to the field mapping dictionary, encrypt the field content according to the corresponding encryption level; and generate a message header, which includes the version of the field mapping dictionary, the encryption level identifier, and the data type identifier of the data to be transmitted; S105: Pack the message header and structured data for transmission.

[0023] This method uses field-level sensitivity classification and dynamic encryption to ensure strong security for highly sensitive data while reducing the processing overhead of less sensitive data. It uses a field mapping dictionary to achieve decoupling and scalable updates of field names and content. The message header carries metadata such as dictionary version, encryption level, and data type, allowing the receiver to accurately decrypt and restore the data structure without relying on preset configurations, thus taking into account security, flexibility, and system compatibility.

[0024] In step S101, the data types of the data to be transmitted include table data and text data. For example, the table data is financial data such as vouchers, account books, and reports, and the text data is contract text.

[0025] When the data to be transmitted is text data, dividing the data into fields includes analyzing the text structure, dividing the text data into chapters, recording the chapter names as fields, and recording the contents of each chapter as field content. For example, for a contract, chapter names such as "Contract Body," "Contract Terms," ​​and "Liability for Breach of Contract" can be used as fields, with the specific contents of the corresponding chapters as field content. This approach ensures that the text data maintains its structural integrity and logical coherence during transmission.

[0026] In step S102, an encryption level is determined based on the sensitivity of the data to be transmitted. Encryption levels can be categorized into multiple levels, such as low, medium, and high, corresponding to different encryption algorithm strengths and key lengths. This hierarchical encryption approach improves transmission efficiency while ensuring data security. Different encryption algorithms can be used for different fields based on their sensitivity, ensuring the security of highly sensitive data while avoiding unnecessary system overhead caused by over-encryption of less sensitive data.

[0027] For example, when the encryption level is low, the basic AES-128 algorithm is used; when the encryption level is medium, the AES-256 algorithm is used; when the encryption level is high, a combined encryption algorithm such as AES+RSA is used. This process ensures data security and integrity, preventing errors or information loss during the decryption process.

[0028] In step S103, multiple key-value pairs are generated using each field name as a key and the field content as a value to obtain structured data. For example, for the "Contract Subject" field in the contract text, a key-value pair such as {"Contract Subject":"Party A XXX Company, Party B YYY Company"} can be generated.

[0029] In addition, after executing step S103 to generate structured data, the size and hash value of the structured data are calculated and written into the message header for the recipient to verify the integrity of the data. In this way, the data can be ensured not to be tampered with during transmission.

[0030] In step S104, a mapping table of field mapping dictionary identifiers and field mapping dictionary versions, a mapping table of encryption level identifiers and encryption algorithms, and a mapping table of data type identifiers and data type mappings are preconfigured. Each of these mapping tables can have multiple versions and can be stored in the same or different paths. The message body also provides the corresponding access addresses for the field mapping dictionary identifiers, encryption level identifiers, and data type identifiers. The versions and / or addresses of the field mapping dictionary mapping table, encryption level mapping table, and data type mapping table are regularly updated. Since the addresses may change, the mapping table versions may also change, effectively increasing the difficulty of cracking, adapting to ever-changing security requirements, and improving data security.

[0031] The field mapping dictionary is a predefined mapping table that converts plaintext field names into encoded form to enhance transmission security. For example, "Contract Subject" might be mapped to "A001," and "Contract Clause" might be mapped to "A002." The field mapping dictionary is regularly updated to enhance security. This mapping effectively prevents data from being intercepted and misinterpreted during transmission.

[0032] Generate a message header, which includes a field mapping dictionary identifier, an encryption level identifier, and the data type identifier for the data to be transmitted. The mapping relationship between the field mapping dictionary and the encryption level identifier in the message header ensures that the recipient can determine the correct decryption method based on the field encoding. The data type identifier ensures that the recipient can restore the data content in a table or text format.

[0033] In step S105, the message header and structured data are packaged and transmitted. The packaging process combines the message header and structured data into a complete data packet, which is sent to the target recipient according to a predetermined transmission protocol. In this way, it is possible to ensure that the data is not lost or damaged during the transmission process.

[0034] In response to a data transfer request, the approval path for the data to be transferred is also obtained. Based on the encryption level of the data to be transferred, the approval path is verified to determine compliance with the approval process. Data transfer is only carried out after compliance with the approval process is determined. This ensures that the transfer of sensitive data complies with the organization's internal control requirements. This strict approval process effectively prevents unauthorized data transmission.

[0035] Finally, the message header and structured data are packaged and transmitted. This process combines the message header and structured data into a complete data packet, which is then sent to the intended recipient according to the predefined transmission protocol. This ensures that data is not lost or damaged during transmission.

[0036] For example, the message header uses JSON format and includes the following mandatory fields: {dict, encryption, data_info, fields_order}. dict includes the field mapping dictionary identifier and download address, encryption indicates the encryption level, data_info stores metadata such as the data type, size, and hash value of the file to be transferred, and fields_order stores a sequential array of field codes, used to restore the original structure. To prevent special characters from disrupting the transmission protocol, the entire message header is Base64-encoded and encapsulated with the message body via a 4-byte length prefix for transmission.

[0037] Through the above steps, this method achieves secure and efficient transmission of different types of data, and is particularly suitable for data transmission scenarios involving sensitive information. This method can effectively improve the security and reliability of data transmission.

[0038] The aforementioned sensitivity-level-based encryption method is executed based on the overall sensitivity of the file being transmitted. However, in reality, not all fields in a file are highly sensitive. If all fields are encrypted uniformly without distinguishing them, unnecessary system overhead can easily occur. Furthermore, the external transmission of enterprise files requires management and control. Currently, the management of highly sensitive files typically requires approval before they can be sent. However, the current link between the approval process and the file's sensitivity level is manually set. By specifying approval conditions and approval paths, the person sending the file must apply for approval in advance according to regulations. For example, if the transfer amount of financial data exceeds a certain amount, the personnel positions that must review it must be reviewed in sequence. However, there is a lack of monitoring of the sensitivity of the files being uploaded for approval and the compliance of the approval path. As long as the system detects approval, it will allow the file to be sent, which is detrimental to enterprise data security.

[0039] Based on this, in some embodiments, in step S102, the overall sensitivity level of the file is first determined based on the sensitivity level of the data to be transmitted; the approval path is matched based on the overall sensitivity level; and it is determined whether the data to be transmitted has passed all approval procedures on the approval path. If so, field-level sensitivity identification is further performed; if not, the approval process is re-initiated.

[0040] Exemplarily, the data to be transmitted is financial data, and the main risk items and other risk items are distinguished, and scoring rules for the main risk items and other risk items are set respectively, and the sensitivity level is determined according to the total score of the main risk items and other risk items. For example, the maximum sensitivity level is set to 5, the main risk item score ranges from 1 to 5, and the other risk items range from 0 to 2. The overall sensitivity level of financial data is calculated as follows: sensitivity level = min(5, main risk item score + ceil(cumulative value of other risk item scores / 2)), and the ceil function represents upward evidence collection. Based on the above calculation method, as long as the main risk item score itself is already very high, for example, 5 points, even if the other risk items are all 0, the overall score is 5 points. The accumulation of other risk items may lead to an increase in sensitivity, so the impact of other risk items is compressed to a score increment of 0-2. Through the ceil function, it can be guaranteed that as long as there is a little contribution, at least 1 will be added to avoid underestimation of transmission risk.

[0041] Taking vouchers as an example, the primary risk factor is the privacy information strength P, which ranges from 1 to 5. If a voucher contains a bank card or ID card number, it is assigned a value of 5; if it only contains the full customer or supplier name, it is assigned a value of 3; and if none of this information is included, it is assigned a value of 1. Other risk factors include the amount level A (based on the proportion of the single transaction amount to the annual revenue), the number of times it has been transferred externally (including this time), and the document timeliness Δt (the number of days since the creation date). The percentage of the single transaction amount to the annual revenue is assigned different values ​​depending on the numerical range. For example, if the single transaction amount is greater than or equal to 1%, A is assigned a value of 5; within the range [0.5%, 1%), A is assigned a value of 4; within the range [0.1%, 0.5%), A is assigned a value of 3; within the range (0, 0.1%), A is assigned a value of 2; and if the value is 0, A is assigned a value of 1. The number of times it has been transferred externally can be understood as having been approved; the greater the number of times it has been transferred externally, the lower the risk; and the greater the number of days since the creation date, the lower the document timeliness Δt. The voucher sensitivity level = min(5, P + ceil((A + T + Δt) / 2)).

[0042] Taking account books as an example, the primary risk factor is account importance S. Accounts related to paid-in capital, principal operating income, cash, and bank deposits are assigned a value of 5. Accounts related to current accounts and expenses receive decreasing scores. Other risk factors include customer / supplier importance C, balance-to-net-asset ratio B, and document timeliness Δt. The higher the customer / supplier importance, the larger the value assigned to C, the higher the balance-to-net-asset ratio, the larger the value assigned to B, and the longer the account has been created, the lower the document timeliness Δt. The account book sensitivity level is calculated as min(5, S + ceil((C + B + Δt) / 2)).

[0043] Taking a report as an example, the primary risk item is the forecast attribute F. If it includes revenue / profit forecasts, the value is assigned 5. If it includes cost / expense forecasts or asset / liability forecasts, the score decreases. Other risk items include forecast impact I and document timeliness Δt. Forecast impact I represents the change in the forecast value relative to the current value. The report sensitivity level = min(5,F+ceil((Δt+I) / 2)).

[0044] For example, the data to be transmitted is contract data. Primary risk items and other risk items are distinguished, and scoring rules are set for each. The sensitivity level is determined based on the total score of the primary and other risk items. For example, the maximum sensitivity level is set to 5, the primary risk item score ranges from 1 to 5, and the other risk items range from 0 to 2. Primary risk item C is determined based on the contract type and sensitive clause type. Contract types include strategic / framework contracts, procurement / sales contracts, and labor contracts. Sensitive clauses include confidentiality, price, technology, intellectual property, exclusivity, and wagering clauses. Pre-set scores are assigned to different contract types for the inclusion of different types of sensitive clauses. Other risk items include contract value level A, partner importance B, number of external transfers T, and document timeliness Δt. A higher contract value indicates a higher value for A, a more important partner, a higher value for B, a higher number of external transfers, a lower value for T, and a longer timeframe from the creation date, resulting in a lower document timeliness Δt. Contract sensitivity level = min(5,C+ceil((A+B+T+Δt) / 3)).

[0045] The approval path includes one-level approval and multi-level approval. The higher the sensitivity, the more approval levels there are. Optionally, the company's organizational structure and job settings can be obtained to build a reporting link between positions from the bottom up; the number of approval levels is matched based on the sensitivity level, and the approval path is adaptively created based on the position and number of approval levels of the file transfer personnel. Examples of financial data reporting links include: Finance Department Fund Specialist, Fund Supervisor, Finance Manager, Legal Affairs Director, Legal Affairs Manager; and Contract Data Reporting Links include: Purchasing Supervisor, Finance Manager, Legal Manager, CFO / CEO. Based on this, if the organizational structure within the company changes or there are job changes, the reporting link can be adaptively updated, and the approval path determined based on the sensitivity of the data to be transferred can also be updated accordingly.

[0046] After determining that the data to be transmitted has passed all approval procedures on the prescribed approval path, the sensitivity level of each field is evaluated to determine the encryption level of each field, thereby achieving field-level hierarchical encryption. For financial data, the evaluation process will comprehensively consider the commercial value, privacy level and legal compliance requirements of the data. For example, bank account information is usually rated as highly sensitive and requires the highest level of encryption; while public financial report data may be rated as low sensitivity and use a lower level of encryption. For contract texts, the evaluation process will consider the importance of the terms, confidentiality requirements and legal risks. For example, price terms and confidentiality terms are usually rated as highly sensitive, while general descriptions may be rated as low sensitivity. Through this evaluation, it can be ensured that data is properly protected during transmission. For example, the sensitivity level of each field can be determined by setting a mapping relationship between fields and sensitivity levels. It should be noted that the maximum sensitivity level of a field does not exceed the overall sensitivity level of the data to be transmitted.

[0047] By decoupling sensitivity assessment and approval at both the overall and field levels, we prevent over-approval of low-sensitivity documents while ensuring targeted encryption of high-sensitivity fields after approval, significantly reducing the risk of data leakage and improving transmission efficiency. The approval process is synchronized with the enterprise organizational structure in real time, eliminating the need for manual maintenance of process templates when positions change or rules are adjusted.

[0048] Figure 2 A flowchart of a method for transmitting data between an intranet and an extranet applied to a data receiver provided by an exemplary embodiment of the present application is shown, including the following steps: S201: Receive encrypted data and obtain the encryption level, field mapping dictionary, and data type based on the message header analysis; S202: Obtain a field name based on a field mapping dictionary, and decrypt the field content based on a decryption algorithm corresponding to the encryption level; S203: Reconstruct the field name and field content according to the data type to obtain the data to be transmitted.

[0049] In step S201, the system receives an encrypted data packet from the sender. This packet consists of a message header and an encrypted data body. The system performs preliminary processing on the received data packet, extracting key information from the message header. This information includes the encryption level, field mapping dictionary, and data type. The encryption level can be categorized as low, medium, and high, corresponding to encryption algorithms of varying complexity. The field mapping dictionary provides the mapping between original field names and encrypted field names. The data type specifies the data format, which can include table and text.

[0050] In step S202, based on the parsed field mapping dictionary, the encrypted field name is obtained and mapped back to the original field name. Then, the system selects the corresponding decryption algorithm according to the encryption level in the message header to decrypt the field content.

[0051] In step S203, the obtained field names and field contents are reorganized and reconstructed into the original data format based on the parsed data type. For example, if the data type is a table, the field names and field contents are reorganized into a table; if the data type is text, they are reconstructed into text. This step ensures the readability and usability of the decrypted data, allowing the recipient to correctly understand and use the data.

[0052] Step S202 also performs a data consistency check. Specifically, in addition to the information parsed in step S201, the system extracts two verification pieces of information from the message header: data size and hash value. The data size is measured in bytes, and the hash value is typically generated using algorithms such as SHA-256 or MD5. This information is used for subsequent consistency verification to ensure that the data has not been tampered with during transmission. Based on the reconstructed data in step S202, the data size and hash value are recalculated. The data size is obtained by calculating the byte length of the reconstructed data; the hash value is calculated using the same hash algorithm as the sender. The data size and hash value extracted from the message header are compared with the recalculated data size and hash value. If the two sets of values ​​are identical, the data has not been tampered with during transmission, and the consistency check passes. If there is any inconsistency, it indicates that the data may have been tampered with or an error occurred during transmission. The system will reject the data and request retransmission from the sender. This mechanism effectively ensures data security and reliability, ensuring that the data remains in its original state during transmission.

[0053] In a preferred embodiment, when the system performs data consistency checks, it also records the results and generates a log, including information such as the time the data was received, the source of the data, and the consistency check results, to facilitate subsequent audits and troubleshooting. These records provide strong support for system security and traceability, ensuring that problems can be quickly located and resolved.

[0054] Through this method, the system can securely receive and parse encrypted data, ensuring its integrity and reliability through consistency checks, effectively preventing data tampering or corruption during transmission. This method has significant application value in the field of data transmission, providing users with greater security and a better data transmission experience.

[0055] based on Figure 1 The provided transmission method, an embodiment of the present invention also provides a data intranet and extranet transmission device, applied to the sender, including: a source data receiving module, configured to divide the data to be transmitted by field in response to a transmission request of the data to be transmitted; an encryption level determination module, configured to determine the encryption level according to the sensitivity level of the data to be transmitted; a data encryption module, configured to generate multiple key-value pairs with each field name as a key and the field content as a value to obtain structured data; map each field name to a field code according to the field mapping dictionary, and encrypt the field content according to the corresponding encryption level; and generate a message header, the message header including a field mapping dictionary identifier, an encryption level identifier and a data type identifier of the data to be transmitted; and package the message header and the structured data for transmission.

[0056] based on Figure 2The provided transmission method, an embodiment of the present invention also provides a data intranet and extranet transmission device, applied to the receiving party, including: an encrypted data receiving module, configured to receive encrypted data, and obtain the encryption level, field mapping dictionary and data type based on message header parsing; a data decryption module, configured to obtain the field name based on the field mapping dictionary, and decrypt based on the decryption algorithm corresponding to the encryption level to obtain the field content; a data reconstruction module, configured to reconstruct the field name and field content according to the data type to obtain the data to be transmitted.

[0057] The memory in the embodiment of the present invention is used to store various types of data to support Figure 1 or Figure 2 Execution of the method shown in .

[0058] It is understood that the memory can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. The memory in the embodiment of the present invention can store the following: Figure 1 or Figure 2 The computer programs corresponding to the steps in the method shown in . The operating system includes various system programs, such as a framework layer, a core library layer, and a driver layer, which are used to implement various basic services and handle hardware-based tasks. The application program can include various application programs.

[0059] As an example, a processor can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0060] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer readable medium, the computer program including a computer program for executing Figure 1 or Figure 2 In such an embodiment, the computer program can be downloaded and installed from a network via the communication portion and / or installed from a removable medium. When the computer program is executed by the central processing unit, the various functions defined in the apparatus of the present application are performed.

[0061] in, Figure 1 or Figure 2The computer program instructions corresponding to the method shown can also be stored in a computer readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0062] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A method for transmitting data between an intranet and an extranet, applied to a sender, characterized in that: The following steps are involved: In response to a transmission request for data to be transmitted, dividing the data to be transmitted by fields; Determining an encryption level according to the sensitivity level of the data to be transmitted; Use each field name as the key and the field content as the value to generate multiple key-value pairs to obtain structured data; Map each field name to a field code according to the field mapping dictionary, and encrypt the field content according to the corresponding encryption level; and generating a message header, wherein the message header includes a field mapping dictionary identifier, an encryption level identifier, and a data type identifier of the data to be transmitted; The message header and structured data are packaged and transmitted.

2. The method for transmitting data between an intranet and an extranet according to claim 1, wherein: The data types of the data to be transmitted include tabular data and text data; when the data to be transmitted is text data, dividing the data to be transmitted by fields includes: analyzing the text structure, dividing the text data according to chapters, recording the chapter names as fields, and recording the contents of each chapter as field contents.

3. The method for transmitting data between an intranet and an extranet according to claim 1 or 2, wherein: After the data to be transmitted is divided into fields, the sensitivity level of each field is evaluated to determine the encryption level of each field; the message header includes a mapping relationship between the field code and the encryption level identifier.

4. The method for transmitting data between an intranet and an extranet according to claim 3, wherein: According to the sensitivity level of the data to be transmitted, the overall sensitivity level of the file is determined; according to the overall sensitivity level, the approval path is matched; it is determined whether the data to be transmitted has passed all the approval procedures on the approval path. If so, further field-level sensitivity identification is performed; if not, the approval process is reinitiated.

5. The method for transmitting data between an intranet and an extranet according to claim 4, wherein: Obtain the reporting links between positions in the enterprise organizational structure from the bottom up; match the number of approval levels based on sensitivity levels, and adaptively create approval paths based on the positions and number of approval levels of file transfer personnel.

6. The method for transmitting data between an intranet and an extranet according to claim 1, wherein: Multiple key-value pairs are generated with each field as the key and the field content as the value. After obtaining the structured data, the size and hash value of the structured data are calculated and written into the message header.

7. The method for transmitting data between an intranet and an extranet according to claim 1, wherein: At least one of the field mapping dictionary, the encryption level identifier, and the data type identifier is updated periodically.

8. A method for transmitting data between an intranet and an extranet, applied to a receiving party, the receiving party being in communication connection with the sending party in the method according to any one of claims 1 to 7, characterized in that: The method comprises the following steps: Receive encrypted data and parse the message header to obtain the encryption level, field mapping dictionary, and data type; Obtain the field name based on the field mapping dictionary, and decrypt the field content based on the decryption algorithm corresponding to the encryption level; Reconstruct the field name and field content according to the data type to obtain the data to be transmitted.

9. The method for transmitting data between an intranet and an extranet according to claim 8, wherein: The data size and hash value are also obtained based on the message header analysis; after obtaining the field name and field content, the data size and hash value are recalculated to perform data consistency judgment.

10. An electronic device, characterized in that: The electronic device comprises a processor and a memory, wherein computer instructions are stored in the memory. When the computer instructions are executed by the processor, the electronic device executes the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • QR code data transmission system and method based on internal and external network isolation

    CN111585960A

  • Business information approval method and device, computer equipment and storage medium

    CN112734181A

  • Data transmission method and device, electronic equipment and storage medium

    CN113595982A

  • Data encryption method and device for different sensitive fields

    CN114139185A

  • Message data processing method and related equipment

    CN118869845A