Data storage method and device, electronic equipment and storage medium

By developing data evidence storage tools, the processes of data display, reading, encrypted calculation, and storage are automated. Combined with security rules and browser verification, the problems of human error and security in the data evidence storage process are solved, and the success rate and efficiency of evidence storage are improved.

CN120995473APending Publication Date: 2025-11-21QIAN PANGU (SHANGHAI) INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510912836.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-11-21

Smart Images

  • Figure CN120995473A_ABST
    Figure CN120995473A_ABST
Patent Text Reader

Abstract

The invention provides a data storage method and device, electronic equipment and a storage medium, the data storage method is applied to a data storage tool, and the data storage method comprises the following steps: obtaining a data display instruction; displaying data in the target database based on the data display instruction; after a first preset time interval of data display, target data indicated by a data selection instruction is read from the displayed data, and the data selection instruction is generated after selection based on the displayed data; and after a second preset time interval of data reading, performing encryption calculation on the target data, and storing the target data after encryption calculation. By developing a data storage tool, integrated processing such as display, reading, encryption calculation and storage of data in a target database can be automatically realized under the condition that scripts such as data display, reading and encryption do not need to be subjected to code transformation, so that errors caused by calling tools or scripts by storage personnel are avoided, and the success rate of data storage is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a data evidence storage method and device, electronic equipment and a storage medium. BACKGROUND

[0002] The so-called data evidence storage refers to storing data in a database as evidence.

[0003] In order to ensure that data evidence storage is accurately and efficiently performed, a third-party database management tool and a self-defined script are currently used to achieve this. Specifically, an evidence storage personnel uses a third-party database management tool (for example, DBeaver) to make the data in the database visually displayed, and then selects the data in the database that needs to be stored as evidence. Next, the evidence storage personnel runs a pre-edited SQL script to read the selected data, and then runs a pre-edited python script to calculate the read data, and then runs a pre-edited python script to store the calculated data.

[0004] However, different objects need to be called in different processing steps. For example, the third-party database management tool needs to be called when the data is displayed, and the SQL script needs to be called when the data is read. When the objects are called, the calling is manually performed, and object calling errors may exist in a high probability, which may cause errors in data evidence storage and thus reduce the success rate of data evidence storage. SUMMARY

[0005] The embodiments of the present application aim to provide a data evidence storage method, device, electronic equipment and storage medium to improve the success rate of data evidence storage.

[0006] To solve the above technical problems, the embodiments of the present application provide the following technical solutions.

[0007] The first aspect of the present application provides a data evidence storage method, which is applied to a data evidence storage tool, the data evidence storage tool is connected with a target database, the target database stores data to be stored as evidence, and the method comprises the following steps: obtaining a data display instruction; displaying the data in the target database based on the data display instruction; after a first preset time interval of data display, reading target data indicated by a data selection instruction from the displayed data, the data selection instruction being generated after the displayed data is selected; after a second preset time interval of data reading, performing encryption calculation on the target data, and storing the target data after the encryption calculation.

[0008] Compared with the prior art, the data storage method provided by the first aspect of the application can automatically realize the display, reading, encryption calculation and storage of the data in the target database without code modification of the scripts for data display, reading and encryption, and without the need for the storage personnel to call each processing function tool or script, thereby avoiding errors in calling the tools or scripts by the storage personnel, improving the success rate of data storage.

[0009] In some modified embodiments of the first aspect of the application, the data storage tool and the target database are located in the same storage space, and the storage space is configured with a data security output rule. Before displaying the data in the target database based on the data display instruction, the method further comprises: determining whether the data display instruction conforms to the data security output rule; if yes, performing the step of displaying the data in the target database based on the data display instruction; and if no, outputting prompt information that the data display instruction does not conform to the data security output rule.

[0010] The data storage tool and the target database are bundled, and the data display instruction received by the data storage tool is subjected to security detection through the data security output rule of the storage space of the target database, thereby avoiding the theft of the data in the target database by malicious third parties through the data display instruction and improving the security in the data storage process.

[0011] In some modified embodiments of the first aspect of the application, the data storage tool is generated based on an application development framework and a built-in browser thereof, the data display instruction is input through the browser, the data display instruction includes the name of the target database and the username and password for logging into the target database, and the determination of whether the data display instruction conforms to the data security output rule comprises: determining whether the name, the username and the password in the data display instruction input from the browser are the same as the name of the target database and the username and password for logging into the target database pre-stored in the data security output rule; if yes, determining that the data display instruction conforms to the data security output rule; and if no, determining that the data display instruction does not conform to the data security output rule.

[0012] The data storage tool is developed through an application development framework and a built-in browser, so that the data display instruction sent to the data storage tool can be input through the browser, and the storage personnel can carry the name of the target database, the login username and password in the data display instruction through the browser, so that the data storage tool can confirm whether the data display instruction is safe through the database name, the login username and password input by the storage personnel, and the efficiency of the data display instruction safety confirmation is improved.

[0013] In some modified embodiments of the first aspect of the application, reading the target data indicated by the data selection instruction from the displayed data comprises: reading less than or equal to a preset number of to-be-processed data from the target data, performing encryption calculation on the to-be-processed data, and storing the encrypted data; determining whether the target data has been read completely; if yes, determining that the target data storage is completed; if no, after the to-be-processed data is encrypted and stored, reading data equal to or less than the preset number from the target data except the to-be-processed data until the target data is completely read.

[0014] When the selected data is read, the amount of data read each time cannot be greater than the preset number, and after the encryption calculation and storage of the batch of data are completed, the next batch of data is read, ensuring that the data encryption calculation and storage process is smooth, reducing the data storage tool from appearing lagging and crashing due to large data processing amount, and improving the operation performance of the data storage tool. Moreover, the selected data is directly read according to the preset number, which can avoid the evaluation of the overall data amount of the selected data, and improve the data storage efficiency.

[0015] In some modified embodiments of the first aspect of the application, before the encryption calculation of the target data, the method further comprises: obtaining an encryption instruction, the encryption instruction being used to indicate the number of encryptions and the encryption mode each time; and performing the encryption calculation on the target data comprises: performing the encryption calculation on the target data according to the number of encryptions and the encryption mode each time indicated by the encryption instruction.

[0016] According to the number of encryptions and the encryption mode indicated in the encryption instruction of the storage personnel, the data is encrypted multiple times, which can meet different encryption needs of the storage personnel, and can encrypt the data into multiple forms to meet the use needs of the evidence personnel in different scenarios, and improve the flexibility of encryption.

[0017] In some modified embodiments of the first aspect of this application, storing the encrypted target data includes: storing the encrypted target data in a local database so that the encrypted target data can be directly retrieved from the local database after receiving a data selection instruction again; obtaining a storage instruction, which indicates the storage location; creating a target file at the storage location indicated by the storage instruction; and writing the encrypted target data into the target file.

[0018] Data is backed up in a local database. If the data stored in the file is lost, the data storage tool can directly retrieve the corresponding data from the local database when it receives the same data selection instruction again. The data storage tool processes the data once and can retrieve and use it multiple times through the local database, which improves the efficiency of data storage.

[0019] In some modified embodiments of the first aspect of this application, the target file includes multiple sub-files, which split and store the encrypted target data. After writing the encrypted target data into the target file, the method further includes: compressing the files in the multiple sub-files that belong to the same data table in the target database to generate a corresponding compressed file and its corresponding evidence preservation report.

[0020] By managing the evidence storage data in multiple sub-files, when certain data needs to be processed, only one or a few sub-files need to be processed. The amount of data in each sub-file is relatively small, which makes it easy to search and process, and can improve the flexibility and efficiency of evidence storage data management.

[0021] A second aspect of this application provides a data storage device. The device is applied to a data storage tool, which is connected to a target database. The target database stores data to be stored. The device includes: an acquisition module for acquiring a data display instruction; a display module for displaying data from the target database based on the data display instruction; a reading module for reading target data indicated by a data selection instruction from the displayed data after a first preset time interval, wherein the data selection instruction is generated based on the displayed data after selection; and a calculation and storage module for performing encrypted calculations on the target data after a second preset time interval of data reading, and storing the encrypted target data.

[0022] A third aspect of this application provides an electronic device, which includes a processor, a memory, and a bus; wherein the processor and the memory communicate with each other via the bus; the processor is used to call program instructions in the memory to execute the method in the first aspect.

[0023] The fourth aspect of the present application provides a computer readable storage medium, the storage medium comprising: a stored program; wherein the program controls the device where the storage medium is located to execute the method in the first aspect when the program is running.

[0024] The data storage device provided by the second aspect of the present application, the electronic device provided by the third aspect of the present application, and the computer readable storage medium provided by the fourth aspect of the present application have the same or similar beneficial effects as the data storage method provided by the first aspect of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0025] The above and other objects, features and advantages of the present application will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings in which a number of embodiments of the present application are shown by way of example, and wherein like reference numerals refer to like elements throughout. The embodiments of the present application, however, can be embodied in various forms, not just the ones set forth in the drawings, and the present disclosure should not be construed as being limited to the embodiments set forth in the drawings. Rather, the intent is to cover all changes, equivalents, and substitutes for one or more embodiments of the present application covering scope and equivalents of the claims. In the drawings:

[0026] Figure 1 The overall architecture of data storage in the embodiments of the present application is shown in the figure;

[0027] Figure 2 The flow of the data storage method in the embodiments of the present application is shown in the figure Figure 1 ;

[0028] Figure 3 The flow of the data storage method in the embodiments of the present application is shown in the figure Figure 2 ;

[0029] Figure 4 The flow of the data storage method in the embodiments of the present application is shown in the figure Figure 3 ;

[0030] Figure 1 The structure of the data storage device in the embodiments of the present application is shown in the figure Figure 1 ;

[0031] Figure 2 The structure of the data storage device in the embodiments of the present application is shown in the figure Figure 2 ;

[0032] Figure 1 The structure of the electronic device in the embodiments of the present application is shown in the figure. DETAILED DESCRIPTION

[0033] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it is understood that the present application can be embodied in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be accurately conveyed to those skilled in the art.

[0034] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in the present application shall have the usual meanings understood by those skilled in the art to which the present application belongs.

[0035] Currently, in the process of archiving data in the database, the archiving personnel needs to call third-party database management tools, read scripts, encryption calculation scripts and storage scripts in turn. The tools or scripts generally exist in the form of programs, and the forensic personnel may make calling errors manually for numerous programs. Once the archiving personnel makes a calling error for the tools or scripts, an error may occur in a certain link in the data archiving, and finally the data archiving fails, thereby reducing the success rate of data archiving.

[0036] Therefore, the embodiments of the present application provide a data archiving method and device, an electronic device and a storage medium, which develop a data archiving tool. In the tool, the display, reading, encryption calculation and storage of data can be realized in turn. The archiving personnel inputs a data display instruction once, and inputs a data selection instruction again after the display of the data in the corresponding database. The data archiving tool can realize the display, reading, encryption calculation and storage of the data in the database. The archiving personnel only needs to input two instructions, and the data archiving tool can realize a series of links in the data archiving process, avoids the archiving personnel from manually calling different programs multiple times, ensures that the data archiving process is performed according to the correct process, and improves the success rate of data archiving.

[0037] Firstly, the overall architecture of the data archiving method provided by the embodiments of the present application is described.

[0038] Figure 1 For the overall architecture of the data archiving in the embodiments of the present application, referring to FIG. 1, the architecture can include a database 11, an archiving personnel 12 and a data archiving tool 13. The data archiving tool 13 is connected with the database 11. Figure 2

[0039] The database 11 stores data to be archived.

[0040] The data archiving tool 13 here is a tool developed based on the data archiving method provided by the embodiments of the present application. In the data archiving tool 13, the display, reading, encryption calculation and storage of the data in the database 11 and the respective corresponding codes are sequentially included.

[0041] ​When the evidence storage personnel 12 needs to store the data in the database 11, the evidence storage personnel 12 installs the data evidence storage tool 13 locally. The evidence storage personnel 12 inputs the data display instruction to the data evidence storage tool 13, and the data evidence storage tool 13 displays the data in the database 11. After the evidence storage personnel 12 sees the displayed data, the evidence storage personnel 12 can select the data to be stored, that is, inputs the data selection instruction. The data evidence storage tool 13 then reads, encrypts, calculates and stores the selected data, thereby completing the storage of the data required by the evidence storage personnel 12 in the database 11.

[0042] In actual application, the above database can be a database in the cloud or a database in a device in a case scene. The specific existence scene of the database is not limited here.

[0043] Next, the data evidence storage method provided by the embodiment of the present application is described in detail.

[0044] Figure 1 The flow of the data evidence storage method in the embodiment of the present application is shown in Figure 2 , and the method can include: Figure 2

[0045] S21: Obtain a data display instruction.

[0046] When the evidence storage personnel needs to store the data in the database, the evidence storage personnel first needs to see the data in the database, and then determine which data to be stored. At this time, the evidence storage personnel needs to send the data display instruction to the data evidence storage tool. After the data evidence storage tool receives the data display instruction, all the data in the database is displayed.

[0047] In the data display instruction, the identifier of the database to be displayed (that is, the target database) also needs to be included, so that the data evidence storage tool only displays the database to be stored, and does not display the data in other databases, thereby improving the security of the data in the database. The identifier can be the name, address, etc.

[0048] In the data display instruction, the format requirement of the data to be displayed can also be included, for example: display according to the original format of the database, display the font as bold, display the font size as four, etc. In this way, the flexibility of the data display in the database can be realized, the actual viewing needs of different evidence storage personnel (for example, the font of the displayed data can be enlarged, etc.) can be met, the accuracy of the subsequent data selection can be improved, and the accuracy of the data storage can be improved.

[0049] S22: Display the data in the target database based on the data display instruction.

[0050] ​After the data storage tool receives the data display instruction, if the instruction does not contain the identification of the database, the data storage tool displays the data in all the databases that can be displayed. If the instruction contains the identification of the database, that is, the instruction can know which databases (i.e., target databases) the data needs to be displayed in, the data storage tool displays all the data in the target databases.

[0051] During the display, the data can be displayed in the device currently installed with the data storage tool, or the data can be displayed in other storage locations indicated by the data storage personnel through the data storage tool. The specific location of the data display is not limited here.

[0052] S23: After the first preset time interval of the data display, the target data indicated by the data selection instruction is read from the displayed data, and the data selection instruction is generated based on the selected displayed data.

[0053] After the data is displayed, the data storage personnel can select the data that needs to be stored in the displayed data. The data storage personnel can select the data through the selection box, or can select the data through the specified location, or can select the data through the data characteristics. After the data storage personnel finishes selecting the data, the data selection instruction is generated accordingly. In the data selection instruction, the operation information of the data selected by the data storage personnel is contained. Then, the data selection instruction is sent to the data storage tool.

[0054] After the data storage tool receives the data selection instruction, the data storage tool does not immediately read the data based on the data selection instruction, but after the first preset time interval of the data display, the data storage tool locks the corresponding data (i.e., target data) in the target database based on the content of the data selection instruction, and then copies the target data to realize the reading of the target data. Through the first preset time interval, the data display and the data reading can be automatically connected without modifying the codes of the data display and the data reading.

[0055] The specific value of the first preset time interval can be set to a fixed value according to experience, or can be determined according to the average time length of the data display and the data selection by the user, so as to realize the dynamic adjustment of the first preset time interval, and then improve the data storage efficiency. The specific value of the first preset time interval is not limited here.

[0056] After the target data is read out, the target data in the target database can be deleted or not, which needs to be determined according to the security requirement of the evidence storage personnel for the target data. When the evidence storage personnel has a security requirement for the target data, or has a high-level security requirement, the target data in the target database needs to be deleted after the target data is read out. When the evidence storage personnel has no security requirement for the target data, or has a low-level security requirement, the target data in the target database can not be deleted after the target data is read out.

[0057] S24: After a second preset time interval of data reading, the target data is encrypted and calculated, and the target data after the encryption calculation is stored.

[0058] After the target data is read out, the target data is encrypted and calculated again and stored after a second preset time interval. In this way, continuous automatic execution of data reading and data encryption can be realized without modifying the connection relationship of the corresponding code or script.

[0059] In the encryption calculation, any algorithm can be used to encrypt and calculate the read-out target data, such as symmetric encryption algorithm, asymmetric encryption algorithm, hash algorithm, etc. The encryption calculation of the target data can improve the security of data evidence storage. In the storage process, the target data after the encryption calculation can be stored in a default location or a custom location. In this way, the evidence storage of the target data in the target database is completed.

[0060] As to the specific value of the second preset time interval, since data encryption no longer needs user operation, the second preset time interval can be less than the first preset time interval, and only the time for calling the data encryption instruction is reserved, that is, the starting time for the data encryption script. By reducing the total time interval, the data evidence storage efficiency is improved. The specific value of the second preset time interval is not limited here.

[0061] From the above, the data evidence storage method provided by the embodiments of the present application can automatically realize the integrated processing of the display, reading, encryption calculation and storage of the data in the target database without code modification for the scripts of data display, reading and encryption, without the need for the evidence storage personnel to call each processing function tool or script, avoid the error of the evidence storage personnel in calling the tools or scripts, and improve the success rate of data evidence storage.

[0062] Further, as to the data evidence storage method provided by the embodiments of the present application, Figure 3Refinements and extensions of the method shown, the embodiments of the present application also provide a data archiving method.

[0063] Figure 2 For the flow of the data archiving method in the embodiments of the present application Figure 3 , see Figure 4 shown, the method can include:

[0064] S31: install data archiving tool.

[0065] When the database is located in the cloud, the archiving personnel needs to operate in the cloud through a device in order to archive the data in the database. The data archiving tool can be used as a desktop application installed in the desktop of the device accessing the cloud.

[0066] The desktop application can be developed through a framework. For example, the desktop application is written using the Electron+React framework. Of course, the developer can also use the framework corresponding to the development language familiar to the developer to write the desktop application. The specific framework used to develop the desktop application is not limited here.

[0067] The desktop application can be developed from two aspects. The first aspect is to develop a database visualization function. The second aspect is to develop a programmed data processing flow of data display, reading, encryption calculation, storage, etc.

[0068] In the development of the visualization function of the desktop application, the application development framework and its built-in browser can be used to achieve this. In this way, the user can conveniently input instructions, select data, confirm archiving, etc. through the browser to achieve the user's convenient operation of database visualization. For example, the Electron built-in Google browser. Of course, other types of browsers can also be selected according to actual conditions, and then the appropriate framework can be selected.

[0069] In the development of the integrated processing flow of the desktop application, a series of operations on data can be achieved using the programming interface provided by the application development framework. For example, in the Node environment of Electron, the application programming interface (API) provided by Node is used to achieve connection to the database, sharded reading, hash calculation, and file saving.

[0070] When the database is located at the case site, the evidence storage personnel can store the data evidence tool as a software program in the mobile storage device. When the evidence storage personnel needs to store the data in the database, the evidence storage personnel can connect the mobile storage device with the device where the database is located, and after the connection is successful, start the software program in the device where the database is located, and operate in the software program, so as to realize the data storage in the database.

[0071] In the installation of the data evidence tool, in order to avoid the data evidence tool causing data security problems to the target database in the use process, the data evidence tool can be installed in the storage space where the target database is located, so that the data security output rule configured by the storage space for protecting the safety of the target database can be used, and the data evidence tool is limited at the same time, so as to avoid the data evidence tool being compromised and affecting the data security in the target database, and improve the security when the data evidence tool is used to view the target database. The data security output rule here can be to output only encrypted data, or not to output display data, or to output only data of a specified format instruction. The specific content of the data security output rule is not limited here.

[0072] S32: Obtain a data display instruction.

[0073] The step S32 here has the same specific implementation mode as the foregoing step S21, and the related description in the foregoing step S21 can be referred to, and details are not repeated here.

[0074] S33: Determine whether the data display instruction meets the data security output rule. If yes, execute S34, if not, execute S35.

[0075] The data display instruction is used to instruct the data in the target database to be displayed. The display of the data will necessarily obtain the data in the target database, or show the data in the target database to the outside. The data security output rule is used to limit the output of the data in the database to the outside. The data evidence tool is compromised, and a malicious third party may make the data in the target database output to the outside through the data display instruction. The data security output rule for ensuring the safety of the data in the target database can avoid the malicious leakage of the data in the target database by the compromised data display instruction, and further improve the security of the data display in the database while realizing the visualization of the database.

[0076] In the data display instruction, the archiving personnel can input the name of the target database to be displayed and the username and password for logging into the target database in addition to the specific display command. In the data security output rule, the name of the target database and the username and password for logging into the target database can also be pre-configured. In this way, the archiving personnel only needs to input the content once, and the logging into the target database and the verification of the instruction can be realized, thereby ensuring the security of data display and improving the efficiency of data display.

[0077] Specifically, the step S33 can include:

[0078] Step A1: Determine whether the name, username and password in the data display instruction input from the browser are the same as the name of the target database and the username and password for logging into the target database pre-configured in the data security output rule. If yes, execute step A2. If no, execute step A3.

[0079] Step A2: Determine that the data display instruction conforms to the data security output rule.

[0080] Step A3: Determine that the data display instruction does not conform to the data security output rule.

[0081] If the archiving personnel is impersonated or the data archiving tool is compromised, the data display instruction input by the archiving personnel can be tampered with. In this case, the content in the data display instruction received by the data archiving tool from the browser will deviate from the corresponding content in the data security output rule. For example, the data security output rule specifies a general database, but a malicious third party wants to access some important databases through the data archiving tool, and then specifies the display of the important databases in the data display instruction. In this case, the name of the database in the data display instruction will be different from that in the data security output rule, and it will be found that the data display instruction has a security problem. For another example, a malicious third party wants to impersonate the archiving personnel to use the data archiving tool to spy on the target database, but the malicious third party does not have the username and password for logging into the target database, or the username and password is forged. In this case, the matching determination will not match the username and password of the target database in the data security output rule, and it will be found that the data display instruction has a security problem. In this case, the relevant personnel will be reminded to strengthen the security protection of the target database.

[0082] Of course, the data security output rule can also include the format characteristics of the instruction, the characteristics of the display instruction and the characteristics of the output instruction. In this way, if the format of the data display instruction is incorrect, or it is not used for data display, or it is used for data output, it will be found in time, and the corresponding operation will not be performed based on the instruction, thereby fully ensuring the security of the data in the target database.

[0083] S34: Display the data in the target database based on the data display instruction.

[0084] The step S34 herein has the same implementation manner as the aforementioned step S22, and reference can be made to the related description in the step S22, which will not be repeated here.

[0085] S35: Output the prompt information that the data display instruction does not conform to the data security output rule.

[0086] After seeing the prompt information, the evidence storage personnel can confirm whether the data display instruction issued by him or her is correct. If it is found that there is an error in the instruction, the instruction can be modified and then re-sent to ensure the normal progress of the data evidence storage. If it is determined that there is no error in the instruction, it is highly probable that the data evidence storage tool is compromised, the data display instruction issued by the evidence storage personnel is maliciously tampered with, and at this time, the data evidence storage tool needs to be killed to restore the data evidence storage tool to normal, so as to ensure the safe continuation of the data evidence storage work.

[0087] After the data in the target database is displayed, the evidence storage personnel can batch-select the target data that he or she needs to store from the displayed data. After the evidence storage personnel selects the target data, a data selection instruction will be generated accordingly, and the data selection instruction will be sent to the data evidence storage tool so that the data evidence storage tool can read the target data from the target database.

[0088] In the process of reading the target data from the target database, the target data can be read directly and all at once, or the target data can be read in batches, and then encrypted and stored in batches.

[0089] S36: Read less than or equal to a preset number of to-be-processed data from the target data to perform encryption calculation on the to-be-processed data, and store the data after the encryption calculation.

[0090] For the target data in the target database, a preset number of data can be read directly. If the number of target data is greater than or equal to the preset number, the preset number of data can be read from the target data. If the number of target data is less than the preset number, the preset number of data cannot be read from the target data, and then less than the preset number of data, i.e., the target data, is read from the target data.

[0091] Before reading less than or equal to the preset number of to-be-processed data from the target data, it can also be judged whether the difference between the number of target data and the preset number is greater than the preset difference. If yes, it means that the number of target data is huge, and it is necessary to read in batches according to the preset number, so as to speed up the data reading process. If not, it means that the number of target data does not exceed the preset number, or the number of excess is not much, and it can be read in batches according to less than the preset number. In this way, without increasing the data reading time, the burden of the data storage tool can be further reduced, and the data storage performance can be optimized.

[0092] It should be noted that the above-mentioned number can refer to the data size or the data number, for example, 10000. Reading the target data in batches according to the preset data number can avoid the breakage of the same part of data, and ensure the integrity of the data in the storage process.

[0093] After reading a batch of to-be-processed data from the target data of the target database, the to-be-processed data is stored in an encrypted manner, and it is also necessary to judge whether the target data in the target database has been read completely. The two processes of encryption storage and judgment do not affect each other, and the two processes are carried out at the same time, which can ensure the smooth progress of data storage and improve the efficiency of data storage.

[0094] S37: It is judged whether the target data is read completely. If yes, S38 is executed, and if not, S39 is executed.

[0095] After the target data in the target database is read, the data can be deleted from the target database, or the data can be marked in the target data. In this way, whether the target data still exists in the target database or whether the target data is completely marked can determine whether the target data is completely read. If there is no target data in the target database or the target data is completely marked, it is determined that the target data is completely read. If there is still target data in the target database or the target data is not completely marked, it is determined that the target data is not completely read.

[0096] S38: It is determined that the target data storage is completed.

[0097] After the last batch of data is read, the last batch of data is stored in an encrypted manner, and it is also judged whether there is data in the target data that has not been read. If it is judged that there is no data, it means that the target data has been stored in an encrypted manner, and at this time it can be determined that the target data storage is completed.

[0098] S39: After the to-be-processed data is encrypted and stored, the data equal to or less than the preset number of data other than the to-be-processed data is read from the target data until the target data is completely read.

[0099] Read a batch of data from the target data of the target database, and store the batch of data after encryption. If there is still unread data in the target data, continue to read a batch of data from the unread data and store the batch of data after encryption. Repeat the above process until there is no unread data in the target data. That is, the target data needs to be read, encrypted and stored in batches.

[0100] For each batch of read data to be processed, the next step is to perform encryption calculation. Before encryption calculation, the encryption method needs to be determined. In addition to encryption according to the default encryption method, encryption can also be performed according to the requirements of the evidence storage personnel, that is, based on encryption instructions.

[0101] S310: Obtain an encryption instruction, which is used to indicate the number of encryptions and the encryption method of each encryption.

[0102] For the encryption instruction, the evidence storage personnel can input it in the data evidence storage tool before data evidence storage. Each encryption can be performed according to the requirements in the encryption instruction. Alternatively, the encryption instruction can be obtained from the evidence storage personnel before each encryption. This can enable different data to be encrypted in different ways, achieve encryption diversification, and further improve the security of data evidence storage.

[0103] In the encryption instruction, the number of encryptions can refer to how many times the same data is encrypted, or how many times the same data is sequentially encrypted. Each encryption corresponds to an encryption method, and the encryption method corresponding to each encryption can be completely the same, partially the same, or completely different. For example, in the encryption instruction, it is indicated that the encryption is performed twice, and the encryption methods are hash256 and hash512, respectively. Then, for data a, hash256 can be used to process data a to obtain data b, and hash512 can be used to process data a to obtain data c. Alternatively, hash256 can be used to process data a to obtain data b first, and then hash512 can be used to process data b to obtain data e. Alternatively, both of the above can be performed.

[0104] S311: According to the number of encryptions and the encryption method of each encryption indicated by the encryption instruction, perform encryption calculation on the target data respectively.

[0105] After reading a batch of data to be processed, the batch of data to be processed is encrypted.

[0106] When encrypting specifically, the target data is encrypted by the corresponding encryption method according to the number of times of encryption. At the same time, the target data can also be repeatedly encrypted according to the corresponding encryption method, and then a prompt information of whether the repeatedly encrypted data needs to be output. If the storage personnel feedback needs, it can be stored immediately, which can improve the diversity of the storage data without affecting the normal data storage, and is suitable for different business scenarios with different security requirements. If the storage personnel feedback does not need, it can be discarded immediately, which will not affect the normal data storage.

[0107] S312: Store the target data after encryption calculation in the local database, so that when the data selection instruction is received again, the target data after encryption calculation can be directly called from the local database.

[0108] The target data after encryption calculation is stored in the local database, which is data backup.

[0109] When the normally stored data is lost, the storage personnel will reissue the data selection instruction to the data storage tool. At this time, the data storage tool can no longer read, encrypt, etc. the target data or the target data, but first searches the local data to see if the corresponding data exists. If it exists, the data corresponding to the data selection instruction can be directly found from the local database, so as to feed back to the storage personnel, improve the data storage efficiency, and if it does not exist, perform data reading, encryption, etc.

[0110] Alternatively, the storage personnel can carry a re-storage mark in the data selection instruction when reissuing the data selection instruction to the data storage tool. After the data storage tool finds the mark in the data selection instruction, it can no longer read, encrypt, etc. the target data or the target data, but can directly find the data corresponding to the data selection instruction from the local database, so as to feed back to the storage personnel, improve the data storage efficiency, and if the data storage tool does not find the re-storage mark in the data selection instruction, perform data reading, encryption, etc.

[0111] S313: Obtain a storage instruction, the storage instruction being used to indicate a storage location.

[0112] S314: Create a target file in the storage location indicated by the storage instruction.

[0113] S315: Write the target data after encryption calculation into the target file.

[0114] After a batch of data to be processed is encrypted, the encrypted data is written into a file.

[0115] In particular, when writing, the evidence storage personnel can configure the storage instruction in the data evidence storage tool before the current evidence storage. In this way, the data evidence storage tool can directly store data according to the storage location configured in the instruction each time data storage is performed, which can improve the data storage efficiency. The data evidence storage tool can also ask the evidence storage personnel for a storage location inquiry before each data storage, and the evidence storage personnel can input a storage instruction indicating the storage location based on the inquiry. In this way, the data evidence storage tool can change the storage location flexibly according to the actual needs of the evidence storage personnel each time data storage is performed, which improves the flexibility of data storage. Alternatively, the above two methods can be combined. When the storage locations indicated in the two instructions are the same, data storage is performed again, which can avoid malicious third parties providing incorrect locations in the inquiry to cause data leakage, and further improves the security of data evidence.

[0116] After obtaining the storage instruction, the storage location of the data can be determined through the storage instruction, so as to create a file in the storage location, and then write the target data after encryption calculation into the file. Here, the file is created and the target data after encryption calculation is written into the file, which utilizes the feature of the file that is easy to view and search, and realizes convenient searching of the evidence data.

[0117] Since the target data is read and encrypted in batches, the same batch of encrypted data can be stored in the same file. Alternatively, if there is too much encrypted data stored in the same file, the encrypted data can be further split into multiple files for storage. Alternatively, all encrypted data can be uniformly split into multiple files for storage. The specific way of storing encrypted data in multiple files is not limited here. That is, the target file includes multiple sub-files, and the multiple sub-files split and store the target data after encryption calculation. The size of the sub-file can be limited to within 15M to ensure that fast searching can be realized in the sub-file and the efficiency of evidence data management is improved.

[0118] S316: Compress the files belonging to the same data table in the target database in the multiple sub-files to generate corresponding compressed files and their corresponding evidence reports.

[0119] In the database, different functions or types of data are generally stored in different data tables for easy data management in the database. That is, the target database contains multiple data tables. The evidence storage personnel will select data from one or more data tables in the target database according to actual evidence storage needs. That is, the target data can be data in multiple tables in the target database. The target data is processed in batches during reading, encryption and other processes, so the data stored in multiple sub-files belongs to the same data table or does not belong to the same data table. Compressing the sub-files corresponding to the same data table can integrate the data belonging to the same data table, i.e., the same type of data in the target data, thereby reducing the storage space occupied by the evidence data and improving the convenience of evidence data management.

[0120] When determining the files belonging to the same data table from multiple sub-files, since the data characteristics of different data tables are different, the characteristics of the data in each sub-file can be determined, and then the sub-files with the same characteristics are regarded as the sub-files belonging to the same data table. Alternatively, each sub-file is directly subjected to clustering processing, and the sub-files under each cluster after the clustering processing are the sub-files belonging to the same data table.

[0121] The files belonging to the same data table are compressed, and an evidence report of the corresponding compressed file is also generated. In the evidence report, the summary of the data content in the compressed file, the message digest algorithm (MD5) value and the like can be included, so that the evidence storage personnel can quickly find the corresponding evidence data through the evidence report. The original data in the file before compression or the unencrypted data directly read from the database can also be included. In actual application, the evidence report adopts the pdf format, which facilitates the evidence storage personnel to quickly and accurately view the evidence data. Of course, the evidence report can also adopt other formats, for example, the doc, docx and the like, which are not limited here.

[0122] Finally, the data evidence storage method provided in the embodiment of the present application is described again.

[0123] Before formally performing data evidence storage, a desktop application is first written using the Electron+React framework to implement a series of processes for data evidence storage in the database. Specifically, the Google browser is built in Electron to realize visual data, thereby performing related operations such as input, selection, confirmation and the like. In the Node environment of Electron, the API provided by Node is used to implement related operations such as connection to the database, sharded reading, hash calculation, file saving and the like.

[0124] Figure 3 Flowchart of the data evidence storage method in the embodiment of the present applicationFigure 5 As shown in Figure 1 When it is necessary to store evidence of data in a database, the evidence storage personnel inputs the database name, username and password through a browser. The program uses the mysql2 library to determine whether the user input is correct, and if so, connects to the database. After the database is successfully connected, the program reads the table and field information and displays the read information to the evidence storage personnel. The evidence storage personnel selects the table and field to be calculated, and batch selection is supported.

[0125] After the evidence storage personnel selects the table and field, the program uses the mysql statement to loop through the selected data table, and then reads the data in the table in batches, 10,000 data at a time. The crypto library is used to calculate the hash of the read data, and two hashes, hash256 and hash512, are calculated respectively.

[0126] Next, the program uses the sqlite3 library to create a local database and stores the calculated hash data in the local database. At the same time, the exceljs library is used to create an excel file and write the calculated hash data into the excel file. The excel file is processed in batches, and the file size is limited to within 15M.

[0127] Finally, the archiver library is used to zip the generated excel file, and then the pdfkit library is used to generate a pdf report and feed back to the evidence storage personnel. Each table in the database corresponds to a zip package and a pdf report.

[0128] At this point, the data evidence storage method provided by the embodiments of the present application has been fully described.

[0129] Based on the same inventive concept, as an implementation of the above method, the embodiments of the present application also provide a data evidence storage device.

[0130] The data evidence storage device is applied to a data evidence storage tool, and the data evidence storage tool is connected to a target database, and the target database stores data to be stored.

[0131] Figure 5 The structure of the data evidence storage device in the embodiments of the present application is shown in Figure 5 , as shown in Figure 6 The device can include an acquisition module 51, a display module 52, a reading module 53 and a calculation and storage module 54. The acquisition module 51, the display module 52, the reading module 53 and the calculation and storage module 54 are connected in sequence.

[0132] The acquisition module 51 is configured to acquire a data display instruction.

[0133] The display module 52 is configured to display the data in the target database based on the data display instruction.

[0134] The reading module 53 is configured to read the target data indicated by the data selection instruction from the displayed data after a first preset time interval of the data display, the data selection instruction being generated based on the displayed data after selection.

[0135] The calculation and storage module 54 is configured to perform encryption calculation on the target data after a second preset time interval of the data reading, and store the target data after the encryption calculation.

[0136] Further, as a refinement and expansion of the device shown in Figure 2 The present application also provides a data storage device.

[0137] Figure 6 The data storage device in the present application is shown in the structure diagram Figure 7 , referring to Figure 7 , the device can include: an acquisition module 61, a judgment module 62, a display module 63, a prompt module 64, a reading module 65, an instruction module 66, an encryption module 67 and a storage module 68. Wherein, the acquisition module 61, the judgment module 62, the display module 63, the reading module 65, the instruction module 66, the encryption module 67 and the storage module 68 are connected in sequence. The prompt module 64 is connected to the judgment module 62.

[0138] The acquisition module 61 is configured to acquire the data display instruction.

[0139] When the data storage tool and the target database are located in the same storage space, and the storage space is configured with a data security output rule, the judgment module 62 is configured to judge whether the data display instruction conforms to the data security output rule. If yes, the display module 63 is entered, and if no, the prompt module 64 is entered.

[0140] When the data storage tool is generated based on an application development framework and a built-in browser thereof, the data display instruction is input through the browser, and the data display instruction includes the name of the target database and the username and password for logging into the target database, the judgment module 62 includes: an instruction judgment unit 621, a first determination unit 622 and a second determination unit 623. Wherein, the instruction judgment unit 621 is connected with the first determination unit 622 and the second determination unit 623 respectively.

[0141] The instruction judgment unit 621 is configured to judge whether the name, the username and the password in the data display instruction input from the browser are the same as the name of the target database and the username and password for logging into the target database pre-stored in the data security output rule. If yes, the first determination unit 622 is entered, and if no, the second determination unit 623 is entered.

[0142] The first determination unit 622 is configured to determine that the data display instruction meets the data security output rule.

[0143] The second determination unit 623 is configured to determine that the data display instruction does not meet the data security output rule.

[0144] The display module 63 is configured to display data in the target database based on the data display instruction.

[0145] The prompt module 64 is configured to output prompt information that the data display instruction does not meet the data security output rule.

[0146] The reading module 65 includes a reading unit 651, a data judgment unit 652, a completion determination unit 653, and a loop unit 654. The reading unit 651, the data judgment unit 652, and the completion determination unit 653 are connected in sequence, and the loop unit 654 is connected to the data judgment unit 652.

[0147] The reading unit 651 is configured to read data less than or equal to a preset number from the target data, to perform encryption calculation on the data, and to store the data after the encryption calculation.

[0148] The data judgment unit 652 is configured to determine whether the target data is all read. If yes, the data judgment unit 652 enters the completion determination unit 653. If no, the data judgment unit 652 enters the loop unit 654.

[0149] The completion determination unit 653 is configured to determine that the storage of the target data is completed.

[0150] The loop unit 654 is configured to read data equal to or less than the preset number from the target data except the data to be processed after the encryption calculation and the storage of the data to be processed, until the target data is all read.

[0151] The instruction module 66 is configured to obtain an encryption instruction. The encryption instruction is used to indicate the number of times of encryption and the encryption mode each time.

[0152] The encryption module 67 is configured to perform encryption calculation on the target data according to the number of times of encryption and the encryption mode each time indicated by the encryption instruction.

[0153] The storage module 68 includes a backup unit 681, a location unit 682, a file unit 683, a writing unit 684, and a compression generation unit 685. The backup unit 681, the location unit 682, the file unit 683, the writing unit 684, and the compression generation unit 685 are connected in sequence.

[0154] The backup unit 681 is configured to store the target data after encryption calculation in a local database, so that the target data after encryption calculation can be directly called from the local database when the data selection instruction is received again.

[0155] The position unit 682 is configured to acquire a storage instruction, the storage instruction being used to indicate a storage position.

[0156] The file unit 683 is configured to create a target file in the storage position indicated by the storage instruction.

[0157] The write unit 684 is configured to write the target data after encryption calculation into the target file.

[0158] When the target file includes a plurality of subfiles, the plurality of subfiles being used to store the target data after encryption calculation, the compression generation unit 685 is configured to compress the files belonging to the same data table in the target database in the plurality of subfiles, and generate a corresponding compressed file and a corresponding evidence report.

[0159] It should be noted that the above description of the device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0160] Based on the same inventive concept, the embodiments of the present application further provide an electronic device.

[0161] ​ For the structural schematic diagram of the electronic device in the embodiments of the present application, refer to ​ As shown in the figure, the electronic device can include a processor 71, a memory 72 and a bus 73; wherein the processor 71 and the memory 72 can communicate with each other through the bus 73; the processor 71 is used to call the program instruction in the memory 72, so as to execute the method in one or more of the above embodiments.

[0162] It should be noted that the above description of the electronic device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the electronic device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0163] Based on the same inventive concept, the embodiments of the present application further provide a computer readable storage medium, which can include a stored program; wherein when the program runs, the device where the storage medium is located executes the method in one or more of the above embodiments.

[0164] It should be noted that the above description of the storage medium embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0165] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data evidence storage method, characterized in that, The method is applied to a data evidence tool connected with a target database in which data to be evidenced is stored, and comprises: acquiring a data display instruction; displaying data in the target database based on the data display instruction; after a first preset time interval of data display, reading target data indicated by a data selection instruction from the displayed data, the data selection instruction being generated after selection based on the displayed data; after a second preset time interval of data reading, performing encryption calculation on the target data, and storing the target data after encryption calculation.

2. The method of claim 1, wherein, The data evidence tool and the target database are located in the same storage space, which is configured with a data security output rule, and before displaying data in the target database based on the data display instruction, the method further comprises: determining whether the data display instruction conforms to the data security output rule; if yes, performing the step of displaying data in the target database based on the data display instruction; if no, outputting prompt information that the data display instruction does not conform to the data security output rule.

3. The method of claim 2, wherein, The data evidence tool is generated based on an application development framework and a built-in browser thereof, the data display instruction is input through the browser, and the data display instruction includes the name of the target database and the username and password for logging into the target database, and the determination of whether the data display instruction conforms to the data security output rule comprises: determining whether the name, username and password in the data display instruction input from the browser are the same as the name of the target database and the username and password for logging into the target database pre-stored in the data security output rule; if yes, it is determined that the data display instruction conforms to the data security output rule; if no, it is determined that the data display instruction does not conform to the data security output rule.

4. The method according to any one of claims 1 to 3, characterized in that, The reading of target data indicated by a data selection instruction from displayed data comprises: reading less than or equal to a preset number of to-be-processed data from the target data to perform encryption calculation on the to-be-processed data and store the data after encryption calculation; determining whether the target data is all read; if yes, it is determined that the target data evidence is completed; if no, after the to-be-processed data is encrypted and stored, the data equal to or less than the preset number of data other than the to-be-processed data is read from the target data until the target data is all read.

5. The method according to any one of claims 1 to 3, characterized in that, Before the encryption calculation on the target data, the method further comprises: acquiring an encryption instruction, the encryption instruction being used to indicate the number of encryption and the encryption mode each time; the encryption calculation on the target data comprises: performing encryption calculation on the target data according to the number of encryption and the encryption mode each time indicated by the encryption instruction.

6. The method according to any one of claims 1 to 3, characterized in that, the storage of the target data after encryption calculation comprises: The target data after encryption calculation is stored in a local database, so that the target data after encryption calculation can be directly called from the local database when the data selection instruction is received again; An acquisition instruction is obtained, and the acquisition instruction is used to indicate a storage position; A target file is created in the storage position indicated by the acquisition instruction; The target data after encryption calculation is written into the target file.

7. The method of claim 6, wherein, The target file includes a plurality of sub-files, and the target data after encryption calculation is stored in the plurality of sub-files. After the target data after encryption calculation is written into the target file, the method further includes: Files in the plurality of sub-files belonging to the same data table in the target database are compressed to generate corresponding compressed files and corresponding evidence reports.

8. A data notarization apparatus, characterized by, The device is applied to a data evidence tool, the data evidence tool is connected with a target database, and the target database stores data to be stored as evidence. The device includes: An acquisition module is configured to acquire a data display instruction; A display module is configured to display data in the target database based on the data display instruction; A reading module is configured to read target data indicated by a data selection instruction from displayed data after a first preset time interval of data display, the data selection instruction being generated after selection based on the displayed data; A calculation and storage module is configured to perform encryption calculation on the target data after a second preset time interval of data reading, and store the target data after encryption calculation.

9. An electronic device, comprising: The electronic device includes a processor, a memory, and a bus. The processor, the memory, and the bus communicate with each other. The processor is configured to call program instructions in the memory to execute the method in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The storage medium includes a stored program. When the program runs, the device where the storage medium is located executes the method in any one of claims 1 to 7.