Data processing method and device in cloud platform interaction and processor
By encrypting and de-identifying data across different cloud platforms, and utilizing whitelisting policies and identity authentication, the interoperability issues of data transmission between different cloud platforms were resolved, ensuring data security and compliance, reducing the risk of unauthorized access, and improving business efficiency.
Patent Information
- Application Number
- CN202511781075.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-02-24
AI Technical Summary
In the field of cloud computing, data interaction and function calls in heterogeneous cloud architectures face interoperability challenges, resulting in problems such as high development costs, insufficient data security, low business efficiency, limited overseas expansion, and complex operation and maintenance management.
By encrypting and de-identifying the data to be transmitted on the initial cloud platform, transmitting it to the target cloud platform via the target interface, and managing permissions through whitelisting policies and identity authentication, the confidentiality and integrity of data transmission are ensured.
It enables secure and compliant data transmission between different cloud platforms, reduces the risk of unauthorized access, and improves data transmission security and business efficiency.
Smart Images

Figure CN121567425A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and more specifically, to a method, apparatus, and processor for processing data in cloud platform interactions. Background Technology
[0002] Currently, in the cloud computing field, especially when handling data interaction and function calls across different cloud architectures, related technologies face significant interoperability challenges. Because the current cloud service environment consists of multiple different cloud service providers, each with its unique service model, service set, and application programming interfaces (APIs), this diversity and heterogeneity leads to problems such as high development costs, insufficient data security, low business efficiency, limited overseas expansion, and complex operation and maintenance management. Therefore, technical problems remain regarding the effective processing of data during interactions between different cloud platforms.
[0003] There is currently no effective solution to the aforementioned technical problems. Summary of the Invention
[0004] This invention provides a method, apparatus, and processor for processing data in cloud platform interactions, to at least solve the technical problem of the inability to effectively process data in interactions between different cloud platforms.
[0005] According to one aspect of the present invention, a method for processing data in cloud platform interaction is provided. The method may include: acquiring initial data to be transmitted from an initial cloud platform, wherein the initial cloud platform is used to provide data source cloud services, and the initial data to be transmitted includes port data and / or address data; encrypting the initial data to be transmitted to obtain first target data to be transmitted; de-identifying the first target data to be transmitted using a de-identification strategy to obtain second target data to be transmitted, wherein the de-identification strategy is used to represent the rules for de-identifying the encrypted initial data to be transmitted; transmitting the second target data to be transmitted to a target cloud platform using a target interface of the initial cloud platform, wherein the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted, and the target cloud platform is used to receive data source cloud services.
[0006] Further, the initial data to be transmitted is encrypted to obtain the first target data to be transmitted, including: obtaining the document information of the initial data to be transmitted; configuring the configuration parameters in the target interface according to the document information; in response to the completion of the configuration parameter configuration, testing the target interface and obtaining the test result, wherein the test result is used to indicate whether the configuration parameters are configured correctly and whether the target interface responds normally; in response to the test result indicating that the configuration parameters are configured correctly and the target interface responds normally, the initial data to be transmitted is encrypted to obtain the first target data to be transmitted.
[0007] Furthermore, using a de-identification strategy, the first target data to be transmitted is de-identified to obtain the second target data to be transmitted, including: using a de-identification strategy to de-identify the first target data to be transmitted to obtain the de-identified first target data to be transmitted; performing identity authentication on the de-identified first target data to be transmitted, and performing authorization processing on the de-identified first target data to be transmitted that has passed identity authentication; and in response to the completion of the authorization processing, determining the first target data to be transmitted after the authorization processing is completed as the second target data to be transmitted.
[0008] Furthermore, using the target interface of the initial cloud platform, the second target data to be transmitted is transmitted to the target cloud platform, including: using a whitelist strategy to filter the port data and address data in the second target data to be transmitted, obtaining the filtered port data and address data in the second target data to be transmitted, wherein the filtered port data and address data in the second target data to be transmitted are accessible to the target cloud platform; and using the target interface, the second target data to be transmitted is transmitted to the target cloud platform.
[0009] Furthermore, the method also includes recording the second target data during the process of transmitting the second target data to the target cloud platform.
[0010] Furthermore, the method also includes: performing multiple verifications on the second target data to be transmitted to obtain verification results; and triggering an alarm prompt in response to the verification result indicating that the security of the second target data to be transmitted is less than a security threshold.
[0011] According to another aspect of the present invention, a data processing apparatus for interaction between different cloud platforms is also provided. The apparatus includes: an acquisition unit for acquiring initial data to be transmitted from an initial cloud platform, wherein the initial cloud platform provides data source cloud services, and the initial data to be transmitted includes port data and / or address data; an encryption unit for encrypting the initial data to be transmitted to obtain first target data to be transmitted; a desensitization unit for desensitizing the first target data to be transmitted using a desensitization strategy to obtain second target data to be transmitted, wherein the desensitization strategy represents the rules for desensitizing the encrypted initial data to be transmitted; and a transmission unit for transmitting the second target data to be transmitted to a target cloud platform using a target interface of the initial cloud platform, wherein the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted, and the target cloud platform receives data source cloud services.
[0012] According to another aspect of the present invention, a processor is also provided. The processor is used to run a program, wherein the program, when run by the processor, performs the methods described in the embodiments of the present invention.
[0013] According to another aspect of the present invention, an electronic device is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods of various embodiments of the present invention during runtime.
[0014] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is executed, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of the present invention.
[0015] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of the present invention.
[0016] According to another aspect of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods of various embodiments of the present invention.
[0017] According to another aspect of the present invention, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of the present invention.
[0018] According to another aspect of the present invention, a vehicle is also provided that implements the methods of various embodiments of the present invention when executed.
[0019] In this embodiment of the invention, if data transmission is required, initial data to be transmitted from an initial cloud platform can be obtained. The initial cloud platform provides data source cloud services, and the initial data to be transmitted includes port data and / or address data. The initial data to be transmitted can be encrypted to obtain first target data to be transmitted. A desensitization strategy can be used to desensitize the first target data to be transmitted to obtain second target data to be transmitted. The desensitization strategy represents the rules for desensitizing the encrypted initial data to be transmitted. The second target data to be transmitted can be transmitted to a target cloud platform using the target interface of the initial cloud platform. The port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive data source cloud services. In other words, this invention ensures the confidentiality and integrity of the initial data to be transmitted during the interaction between different cloud platforms (initial cloud platform and target cloud platform) through encryption and desensitization processing. This effectively prevents the initial data to be transmitted from being tampered with or leaked during transmission, thus improving the overall security of the initial data to be transmitted. By accessing the target interface, only specific port data and address data are allowed to communicate, which can precisely manage the channel for transmitting the initial data to be transmitted, reduce the risk of unauthorized access, and achieve more granular permission management. This solves the technical problem of not being able to effectively process data during the interaction between different cloud platforms, and achieves the technical effect of effectively processing data during the interaction between different cloud platforms. Attached Figure Description
[0020] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0021] Figure 1 This is a flowchart of a data processing method in cloud platform interaction according to an embodiment of the present invention;
[0022] Figure 2 This is a schematic diagram of a heterogeneous cloud architecture interaction scheme connecting domestic and regional foreign regions according to an embodiment of the present invention;
[0023] Figure 3 This is a schematic diagram of a data processing device in cloud platform interaction according to an embodiment of the present invention. Detailed Implementation
[0024] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0026] According to an embodiment of the present invention, an embodiment of a data processing method in cloud platform interaction is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0027] Figure 1 This is a flowchart of a data processing method in cloud platform interaction according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0028] Step S102: Obtain the initial data to be transmitted from the initial cloud platform.
[0029] In the technical solution provided by step S102 in this embodiment of the invention, the initial cloud platform can be used to provide data source cloud services, and the initial data to be transmitted may include port data and / or address data.
[0030] In this embodiment, the data to be transmitted, i.e., the initial data to be transmitted, can be extracted from the initial cloud platform. The initial cloud platform can refer to the cloud service platform where the enterprise first stored or processed the initial data to be transmitted. It can be any of the mainstream cloud service providers such as Amazon Web Services (AWS), Microsoft (Azure), and Alibaba Cloud. It can be determined according to business needs and the location of the initial data to be transmitted. This is only an example and no specific restrictions are placed on the initial cloud platform here.
[0031] Optionally, port data can refer to the port number used to identify the destination of the initial data transmission during the network transmission process. The port number can be part of the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol stack, used to determine which application on the target computer the initial data should be sent to. In cross-cloud platform interactions, correctly configuring port data is crucial to ensuring that the initial data to be transmitted can be received correctly.
[0032] Optionally, the address data can refer to an Internet Protocol (IP) address, used to locate the data source and the target location of the initial data to be transmitted within the network. In cross-cloud initial data transmission, accurate address data ensures that the initial data is sent to the correct cloud platform and server.
[0033] Optionally, to obtain the initial data to be transmitted from the initial cloud platform, it's necessary to identify which initial cloud platform to obtain the data from, thus determining the appropriate cloud service provider. When obtaining the initial data to be transmitted from the initial cloud platform, the security and compliance requirements of the data should be considered. For example, the principle of least privilege should be applied: ensuring that only users or services that need to access the initial data to be transmitted have the appropriate permissions, reducing the risk of data leakage. Encrypted transmission: even before the initial data is transmitted, encryption can be chosen to prevent unauthorized access during transmission. Data logging and auditing: the process of obtaining the initial data to be transmitted should be recorded, including the time of acquisition, the acquirer, and the type of initial data acquired, to facilitate subsequent auditing and compliance verification.
[0034] In this embodiment of the invention, obtaining the initial data to be transmitted from the initial cloud platform is the first step in the entire data security processing flow, laying the foundation for subsequent initial data transmission.
[0035] Step S104: Encrypt the initial data to be transmitted to obtain the first target data to be transmitted.
[0036] In the technical solution provided by step S104 in the embodiment of the present invention, after obtaining the initial data to be transmitted from the initial cloud platform, the initial data to be transmitted can be encrypted to obtain the first target data to be transmitted.
[0037] In this embodiment, encryption is a crucial means of protecting the security of initial data to be transmitted during cross-cloud platform interactions. By converting the initial data to be transmitted (e.g., raw data) into ciphertext, even if the initial data is intercepted during transmission, attackers cannot decipher its true content, thereby preventing leakage or malicious use of the initial data.
[0038] Optionally, in the context of building overseas cloud platforms and interacting with other clouds, encryption not only enhances the security of the initial data to be transmitted, but is also a necessary measure to comply with data protection regulations such as the General Data Protection Regulation (GDPR).
[0039] Optionally, based on security requirements and computational performance considerations, a suitable encryption algorithm can be selected. Examples include Advanced Encryption Standards (AES), asymmetric encryption algorithms, and Secure Sockets Layer / Transport Layer Security (SSL / TLS) protocols. Block encryption can also be considered to improve efficiency. The key is central to both encryption and decryption processes. The generation, storage, distribution, and destruction of keys all require strict security policies. In cross-cloud interaction scenarios, a Key Management Service (KMS) provided by the cloud service provider can be used to securely manage and use keys.
[0040] Optionally, encrypting the initial data to be transmitted using a selected encryption algorithm and key can transform the initial data into ciphertext, yielding the first target data to be transmitted. Encryption should ensure that sensitive data fields in the initial data are covered, while also considering the compatibility and transmission efficiency of the encrypted initial data.
[0041] In this embodiment of the invention, encryption not only enhances the security of the initial data to be transmitted, but also lays a solid foundation for the subsequent desensitization processing and cross-cloud transmission of the first target data to be transmitted.
[0042] Step S106: Using a desensitization strategy, the first target data to be transmitted is desensitized to obtain the second target data to be transmitted.
[0043] In the technical solution provided by step S106 in the embodiment of the present invention, the desensitization strategy can be used to represent the rules for desensitizing the encrypted initial data to be transmitted.
[0044] In this embodiment, after encrypting the initial data to be transmitted to obtain the first target data to be transmitted, a desensitization strategy can be used to desensitize the first target data to be transmitted to obtain the second target data to be transmitted.
[0045] Optionally, data anonymization involves replacing, hashing, encrypting, or masking sensitive data fields or portions of the first target data to be transmitted, so that the first target data cannot reveal true information when used in a non-sensitive environment (such as a testing, development, or analysis environment). The anonymization strategy defines how to anonymize specific types of the first target data to be transmitted, including anonymization rules, algorithms, and exceptions.
[0046] Optionally, based on business needs and data security policies, it can be determined which fields contain the primary target data to be transmitted and require anonymization. This includes sensitive data such as personal identification information (e.g., name, ID number, phone number), financial information, and health information. Based on the identified anonymized fields, specific anonymization strategies can be defined. These include replacing real data with fake data, partial masking (e.g., replacing the first few digits of an ID number with an "X"), hashing to ensure the irreversibility of the primary target data, and dynamic anonymization adjusting the degree of anonymization based on the visitor's role and permissions.
[0047] Optionally, the desensitization strategy can be applied to the first target data to be transmitted, and the determined fields can be desensitized to generate the second target data to be transmitted.
[0048] Optionally, for security and compliance reasons, it is necessary to ensure that the data masking strategy complies with data protection regulations such as GDPR. When necessary, a mechanism can be in place to reverse the data masking process for data analysis or to restore the original data. Detailed information about the masking operation can be recorded, including the time of masking, the operator, and the masking strategy, to comply with audit and regulatory requirements.
[0049] In this embodiment of the invention, the above-mentioned desensitization process not only enhances the security of the first target data to be transmitted, but also ensures the compliance of the data processing flow in the construction of overseas cloud platforms and cross-cloud interactions, especially meeting the GDPR requirement for minimizing the processing of the first target data to be transmitted.
[0050] Step S108: Using the target interface of the initial cloud platform, the second target data to be transmitted is transmitted to the target cloud platform.
[0051] In the technical solution provided by step S108 in this embodiment of the invention, the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted; the target cloud platform can be used to receive data source cloud services.
[0052] In this embodiment, after desensitizing the first target data to be transmitted using a desensitization strategy to obtain the second target data to be transmitted, the second target data to be transmitted can be transmitted to the target cloud platform using the target interface of the initial cloud platform.
[0053] Optionally, to ensure the security of the second target data during transmission, secure transmission protocols can be used, such as HyperText Transfer Protocol Secure (HTTPS), which uses Transport Layer Security / Secure Sockets Layer (TLS / SSL) encryption, gRPC Remote Procedure Call (gRPC), which uses TLS encryption; or Secure File Transfer Protocol (SFTP), which uses Secure Shell (SSH) encryption. These protocols not only provide encryption for the transmission of the second target data but also ensure its integrity and authentication, preventing man-in-the-middle attacks and tampering with the second target data.
[0054] Optionally, the target interface can be configured on the source cloud platform (initial cloud platform) according to the target cloud platform's Application Programming Interface (API) documentation, including port data, address data, authentication methods, etc. Afterwards, the configured target interface can be used to send the second target data to be transmitted to the target cloud platform. The port data and address data in the second target data to be transmitted must be consistent with the initial data to be transmitted before encryption and de-identification to ensure that the second target data to be transmitted can be correctly received and processed by the target cloud platform.
[0055] Optionally, during transmission, even if the second target data has been encrypted, encryption protocols such as TLS 1.3 can be used for transmission to add extra security.
[0056] Optionally, access control and logging can also be implemented. During the transmission of the second target data, the Identity and Access Management (IAM) service of the target cloud platform can be used to control the access permissions of the second target data and record detailed logs of the transmission of the second target data, including timestamps, source addresses, destination addresses, and the amount of data transmitted, for subsequent auditing and monitoring.
[0057] Optionally, when the second target data needs to be transferred across national borders, the data protection regulations of the relevant countries or regions, such as GDPR, should be strictly complied with. Ensure that necessary consent or permission is obtained before the second target data is transferred, that sensitive data is adequately protected, that compliant encryption and transmission methods are used, and that logs are maintained so that the compliance of the second target data processing can be demonstrated during future audits.
[0058] For example, suppose you need to transfer data from an initial cloud platform (e.g., AWS) to a target cloud platform (e.g., Azure). First, you can configure the interface. Configure the target interface on AWS, using Azure's API documentation to ensure the port and address data are consistent with the data before encryption, and enable IAM for cross-cloud authorization. Then, using the configured interface, transmit the second target data to Azure via HTTPS (TLS 1.3) encryption, ensuring the security and integrity of the second target data. During the transmission, AWS can grant Azure only the necessary data access permissions according to the GDPR principle of least privilege and record detailed transmission logs for subsequent auditing.
[0059] In this embodiment of the invention, the above steps achieve secure and compliant transmission of the second target data to be transmitted between different cloud platforms, ensuring the dual objectives of data security and business efficiency.
[0060] In steps S102 to S108 of this embodiment of the invention, if data transmission is required, initial data to be transmitted from the initial cloud platform can be obtained. The initial cloud platform provides data source cloud services, and the initial data to be transmitted includes port data and / or address data. The initial data to be transmitted can be encrypted to obtain first target data to be transmitted. A desensitization strategy can be used to desensitize the first target data to be transmitted to obtain second target data to be transmitted. The desensitization strategy represents the rules for desensitizing the encrypted initial data to be transmitted. The second target data to be transmitted can be transmitted to the target cloud platform using the target interface of the initial cloud platform. The port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive data source cloud services. In other words, this invention ensures the confidentiality and integrity of the initial data to be transmitted during the interaction between different cloud platforms (initial cloud platform and target cloud platform) through encryption and desensitization processing. This effectively prevents the initial data to be transmitted from being tampered with or leaked during transmission, thus improving the overall security of the initial data to be transmitted. By accessing the target interface, only specific port data and address data are allowed to communicate, which can precisely manage the channel for transmitting the initial data to be transmitted, reduce the risk of unauthorized access, and achieve more granular permission management. This solves the technical problem of not being able to effectively process data during the interaction between different cloud platforms, and achieves the technical effect of effectively processing data during the interaction between different cloud platforms.
[0061] The method described in this embodiment will be further described below.
[0062] As an optional embodiment, step S104, encrypting the initial data to be transmitted to obtain the first target data to be transmitted, includes: obtaining document information of the initial data to be transmitted; configuring the configuration parameters in the target interface according to the document information; in response to completing the configuration of the configuration parameters, testing the target interface to obtain a test result, wherein the test result is used to indicate whether the configuration parameters are configured correctly and whether the target interface responds normally; in response to the test result indicating that the configuration parameters are configured correctly and the target interface responds normally, encrypting the initial data to be transmitted to obtain the first target data to be transmitted.
[0063] In this embodiment, during the process of encrypting the initial data to be transmitted to obtain the first target data to be transmitted, the document information of the initial data to be transmitted can be obtained; then, the configuration parameters in the target interface can be configured according to the document information; after the configuration parameters are configured, the target interface can be tested to obtain the test results, wherein the test results are used to indicate whether the configuration parameters are configured correctly and whether the target interface responds normally; if the test results indicate that the configuration parameters are configured correctly and the target interface responds normally, the initial data to be transmitted can be encrypted to obtain the first target data to be transmitted.
[0064] Optionally, relevant documentation information for the initial data to be transmitted can be obtained from the initial cloud platform (e.g., the source cloud platform) or data source. This documentation information includes, but is not limited to, data format, field types, sensitive information identifiers, initial cloud platform API documentation, security guidelines, etc. Obtaining this documentation information is crucial for subsequent interface configuration and encryption of the initial data to be transmitted, ensuring that the initial data can be transmitted in the correct format and that the encryption algorithm is compatible with the data type of the initial data to be transmitted.
[0065] Optionally, based on the obtained documentation, the target interface can be configured in detail. This includes setting the correct port number, Uniform Resource Locator (URL) path, request headers, and authentication mechanisms. The interface configuration must comply with the cloud platform's API specifications to ensure that the initial data to be transmitted can be transmitted accurately and without error through the interface.
[0066] Optionally, after configuring the target interface, interface testing can be performed to verify the correctness of the configuration parameters and the normal response of the target interface. Testing may include sending simulated data requests and checking metrics such as response status codes, response times, and data integrity. Through testing, it can be confirmed that the interface configuration is correct and can be safely used for initial data transmission.
[0067] Optionally, once the interface test results show that the configuration parameters are correct and the target interface responds normally, encryption processing can be initiated. Encryption processing can encrypt the initial data to be transmitted according to a preset encryption algorithm to generate the first target data to be transmitted. The selection of the encryption algorithm can take into account factors such as data type, transmission speed, and security requirements to ensure that it provides sufficient security without excessively increasing transmission latency.
[0068] In this embodiment of the invention, the above steps ensure the security and accuracy of the initial data to be transmitted before transmission, and also verify the effectiveness of the target interface, providing a solid foundation for subsequent transmission of the initial data to be transmitted.
[0069] As an optional embodiment, step S106, using a de-identification strategy to de-identify the first target data to be transmitted to obtain the second target data to be transmitted, includes: using a de-identification strategy to de-identify the first target data to be transmitted to obtain the de-identified first target data to be transmitted; performing identity authentication on the de-identified first target data to be transmitted, and performing authorization processing on the de-identified first target data to be transmitted that has passed identity authentication; and in response to the completion of the authorization processing, determining the first target data to be transmitted after the authorization processing is completed as the second target data to be transmitted.
[0070] In this embodiment, during the process of using a de-identification strategy to de-identify the first target data to be transmitted and obtain the second target data to be transmitted, the de-identification strategy can be used to de-identify the first target data to be transmitted, resulting in the de-identified first target data to be transmitted. Then, the de-identified first target data to be transmitted can be authenticated, and the authenticated de-identified first target data to be transmitted can be authorized. After the authorization process is completed, the authorized first target data to be transmitted can be designated as the second target data to be transmitted.
[0071] Optionally, the de-identification strategy can be used to identify and replace sensitive information in the first target data to be transmitted, thereby reducing the risk of leakage of the first target data without compromising data functionality and business requirements. The de-identification strategy may include data replacement, masking, encryption, pseudonymization, etc.
[0072] Optionally, sensitive information identification can identify sensitive fields in the first target data to be transmitted, such as personal identification information, financial information, and health data, through predefined rules or machine learning models.
[0073] Optionally, de-identification processing, i.e., applying de-identification strategies to the identified sensitive information, such as replacing personal information with random strings or using encryption technology to mask financial data. Afterwards, identity authentication can be performed on the first target data to be transmitted after de-identification, confirming the identities of the sender and receiver. This can be done using identity management services provided by the cloud platform (such as AWS IAM or Azure Identity and Access Management Service). After successful authentication, further authorization processing can be performed to restrict data access permissions, ensuring that only authorized entities can access and process the data. After authorization processing is completed, the first target data to be transmitted after de-identification becomes the final second target data to be transmitted, which can be securely transmitted to the target cloud platform through the target interface.
[0074] In this embodiment of the invention, by employing the above steps, de-identification strategies, and identity authentication and authorization mechanisms, the risk of sensitive information leakage during data transmission can be significantly reduced, while ensuring the security and compliance of data transmission, thus enhancing the security of data interaction under a heterogeneous cloud architecture. Describing these de-identification and authorization processes in detail in the patent draft demonstrates the originality and practicality of the technical solution in data privacy protection, and helps to construct a broader and more robust scope of patent protection.
[0075] As an optional embodiment, step S108, using the target interface of the initial cloud platform, transmits the second target data to the target cloud platform, including: using a whitelist strategy to filter the port data and address data in the second target data to be transmitted, obtaining the filtered port data and address data in the second target data to be transmitted, wherein the filtered port data and address data in the second target data to be transmitted are accessible to the target cloud platform; and using the target interface, transmits the second target data to the target cloud platform.
[0076] In this embodiment, during the data security interaction process within the heterogeneous cloud architecture, a whitelist policy is used to filter the second target data before transmitting it to the target cloud platform. This ensures the security and compliance of the data transmission. A whitelist policy is a network security measure that only allows specified IP addresses, port numbers, etc., to access specific services or resources. In cross-cloud data transmission, the whitelist policy can restrict the source of data access and prevent unauthorized access.
[0077] Optionally, after obtaining the second target data to be transmitted, and after the second target data has been encrypted and de-identified, the port data and address data used for transmission can be extracted from the second target data. Then, a whitelist policy can be configured in the firewall or security group of the source cloud platform, according to the needs of the target cloud platform, allowing specific port data and address data to access the target interface. This means that only the ports and IP addresses specified in the list can transmit the second target data.
[0078] Optionally, a whitelist strategy can be used to filter port and address data in the second target data to be transmitted, retaining only information that is allowed to be accessed by the target cloud platform. Then, the filtered data is transmitted to the target cloud platform via the target interface using secure transmission protocols (such as HTTPS / TLS, gRPC, SFTP), ensuring data security and integrity during transmission.
[0079] Optionally, detailed information about the second target data transmission can also be recorded, including the source address, destination address, port number, amount of data transmitted, and timestamp, to meet compliance and auditing requirements.
[0080] Optionally, suppose you are transferring a second target data from Alibaba Cloud to Google Cloud Platform, and this second target data contains multiple fields, such as the target IP address, source IP address, port number, and encrypted data packets. You can extract the port and address data to determine the target port (e.g., port number) and target IP address used for data transmission; for example, port number 8080 and target IP address 192.168.xy. Then, you can set up a whitelist in Alibaba Cloud's security group, allowing only access from 192.168.xy and opening port 8080 for data transmission. The whitelist policy ensures that the transmitted data only contains port and address data allowed by the whitelist policy; other irrelevant or non-whitelisted data is not transmitted. Afterwards, using HTTPS / TLS or gRPC protocols, the second target data is transferred from Alibaba Cloud to GCP through the configured target interface.
[0081] In this embodiment of the invention, by using the above steps to filter data using a whitelist strategy and then transmitting it to the target cloud platform via encryption, the security of the second target data transmission is ensured, while also complying with the requirements of data protection regulations such as GDPR, thus avoiding unnecessary compliance risks.
[0082] As an optional embodiment, the method further includes: recording the second target data to be transmitted during the process of transmitting the second target data to the target cloud platform.
[0083] In this embodiment, the second target data can be recorded during the process of transmitting the second target data to the target cloud platform. For example, the timestamp, data source and target, data volume, data content summary, operator information, transmission protocol and encryption method can be recorded to form a log.
[0084] Optionally, the timestamp can record the precise time of the second target data transmission, including the start time, end time, and timestamps of the entire transmission process. The data source and target can record information about the source cloud platform (or service) and target cloud platform of the second target data, including but not limited to IP address, port number, and cloud service provider name. The data volume can record the size of the transmitted second target data, which can be file size, number of data packets, or total number of bytes. For the transmitted second target data, a summary or hash value can be recorded to facilitate data comparison or verification of its integrity when necessary. Operator information can record the identity information of the user or system performing the data transmission operation, including username, operation time, and operation permissions. The transmission protocol and encryption method can record the transmission protocol (such as HTTPS, gRPC, SFTP) and encryption method used to demonstrate the security of the second target data transmission.
[0085] Optionally, after obtaining the logs, they can be stored to ensure that the logs of the second target data transmission are persistently stored on the cloud platform. The storage method must comply with data protection regulations, such as GDPR, and the log retention period can be required to be at least one year for auditing and monitoring.
[0086] Optionally, the data transmission logs of the second target data to be transmitted can be standardized to facilitate subsequent querying and analysis. The logs can contain sufficient information to trace the details of each transmission of the second target data. Access to the second target data transmission logs can also be strictly controlled to ensure that only authorized maintenance or auditing personnel can access them, preventing unauthorized viewing or tampering. Furthermore, the second target data transmission logs can be analyzed periodically to monitor transmission trends, abnormal activities, etc., and to promptly identify and address problems in the transmission of the second target data.
[0087] In this embodiment of the invention, by recording the data transmission process of the second target data in detail, enterprises can not only ensure the security and compliance of the data transmission of the second target data, but also gain a deeper understanding of the data interaction pattern of the second target data through log analysis, optimize data management strategies, and improve operational efficiency and business security.
[0088] As an optional embodiment, the method further includes: performing multiple verifications on the second target data to be transmitted to obtain a verification result; and triggering an alarm prompt in response to the verification result indicating that the security of the second target data to be transmitted is less than a security threshold.
[0089] In this embodiment, during the secure transmission of the second target data, multiple verifications can be performed on the second target data to ensure that it is in a secure state before transmission, thus preventing the risk of leakage or tampering.
[0090] Optionally, multi-factor authentication refers to assessing the security level of the second target data before transmission through a variety of different security authentication mechanisms, which may include, but are not limited to, data integrity verification, encryption strength verification, and data access permission review.
[0091] Optionally, data integrity verification involves calculating the hash value of the data and comparing it with a pre-stored hash value to ensure that the second target data to be transmitted has not been tampered with. Encryption strength verification can check whether the encryption algorithm complies with industry security standards; for example, verifying whether a sufficiently strong encryption algorithm is used, and whether the management and updating of encryption keys are secure. Data access permission review can be used to confirm whether the access permissions for the second target data to be transmitted are correctly set; for example, checking whether the whitelist policy covers legitimate access requests and excluding sources that should not access the data.
[0092] Optionally, the above verification results are comprehensively evaluated to determine whether the overall security level of the second target data to be transmitted has reached the set security threshold. If the comprehensive security evaluation shows that the security of the second target data to be transmitted is less than the security threshold, an alarm is triggered to notify the relevant security team or operations and maintenance personnel to take remedial measures in a timely manner, such as strengthening encryption, reconfiguring permission rules, or suspending data transmission.
[0093] Optionally, through multiple verification and alarm mechanisms, the security status of the second target data to be transmitted before transmission can be effectively monitored and guaranteed, reducing the occurrence of security incidents and improving the stability and reliability of the data transmission of the second target data.
[0094] In embodiments of the present invention, if data transmission is required, initial data to be transmitted from an initial cloud platform can be obtained. The initial cloud platform provides data source cloud services, and the initial data to be transmitted includes port data and / or address data. The initial data to be transmitted can be encrypted to obtain first target data to be transmitted. A desensitization strategy can be used to desensitize the first target data to be transmitted to obtain second target data to be transmitted. The desensitization strategy represents the rules for desensitizing the encrypted initial data to be transmitted. The second target data to be transmitted can be transmitted to a target cloud platform using the target interface of the initial cloud platform. The port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive data source cloud services. In other words, this invention ensures the confidentiality and integrity of the initial data to be transmitted during the interaction between different cloud platforms (initial cloud platform and target cloud platform) through encryption and desensitization processing. This effectively prevents the initial data to be transmitted from being tampered with or leaked during transmission, thus improving the overall security of the initial data to be transmitted. By accessing the target interface, only specific port data and address data are allowed to communicate, which can precisely manage the channel for transmitting the initial data to be transmitted, reduce the risk of unauthorized access, and achieve more granular permission management. This solves the technical problem of not being able to effectively process data during the interaction between different cloud platforms, and achieves the technical effect of effectively processing data during the interaction between different cloud platforms.
[0095] The technical solutions of the embodiments of the present invention will be illustrated below with reference to preferred embodiments.
[0096] Currently, the cloud computing field includes numerous cloud service providers, each with its own service model, service set, and application programming interface. This presents an interoperability challenge for two mature cloud architectures in terms of data interaction and function calls.
[0097] In related technologies, methods to solve the aforementioned problems (interoperability between users and the cloud, or between clouds) often employ abstraction, specifically falling into two categories: one is to provide a set of universal APIs, which need to be mapped to the proprietary APIs of each cloud service provider; the other is to introduce a "proxy" to adapt and adjust the user's perspective from the cloud service's perspective. However, in actual connected vehicle business development, especially in the construction of overseas cloud platforms and cross-cloud interactions, the challenges are often caused by unclear business requirements, data security requirements, the workload of subsequent migration, and compliance requirements such as cross-border regulations. Therefore, technical problems remain regarding the effective processing of data during cross-cloud platform interactions.
[0098] Therefore, to solve the above problems, a heterogeneous cloud architecture that requires minimal development effort, is decoupled, and ensures data security is essential, and can be deployed independently, is needed. This architecture allows for the development of different logical solutions based on business needs, continuous optimization and elimination of redundancy, aiming to address interoperability issues at their root.
[0099] Therefore, this invention provides a method for connecting domestic and regional overseas cloud architectures for interaction. Based on the core principles of "minimizing development workload, maximizing data security, and adapting to overseas markets," it prioritizes the reuse of native cloud vendor components and standardized protocols. Considering the potential differences between cloud vendors in different clouds, customized interfaces are developed to achieve information exchange based on business needs. Strict whitelisting and minimal control are implemented, ensuring only necessary ports are opened and the other party's cloud resource IP is added to the security group, denying access to the entire network. When cross-border access is necessary, authentication and encryption schemes are used, and transmission logs are retained. Sensitive data is transmitted only after de-identification. For regions with network blockades, transit through neutral zones or compliant satellite lines are used, and core business deployments are avoided in sanctioned regions. The interface layer uses RESTful API + HTTPS (TLS 1.3) as the standard protocol, reusing cloud vendor API gateways. High-frequency, small-data use gRPC, and large-data synchronization uses SFTP / S3 protocols. No underlying communication logic development is required; only API configuration parameters are needed to complete the connection. Identity authentication and access control rely on cloud vendor IAM services to achieve cross-cloud role authorization and single sign-on. Native signature mechanism is enabled to prevent tampering and forgery. In overseas scenarios, the GDPR principle of least privilege is strictly followed. Idle permissions are periodically revoked and administrator accounts are forced to enable multi-factor authentication (MFA).
[0100] In addition, during the network configuration phase, the setup and whitelist configuration of the dedicated line / Virtual Private Network (VPN) are completed, and overseas cross-border compliance is confirmed and necessary network licenses are applied for simultaneously. For interface integration, gateway configuration, cross-cloud authorization, and joint debugging are completed, adapting to overseas TLS 1.3 encryption and API access rate limiting. Data security configuration includes enabling transmission and static encryption, configuring de-identification rules, selecting compliant encryption services, and retaining logs. Auditing and monitoring enable cloud vendor operation logs; abnormal alarms are configured to ensure log retention meets local requirements for more than one year and supports audit access. At the operations and maintenance level, audit logs enable full traceability of operations and data transmission, and predefined fault recovery scripts ensure the emergency response speed promised by the Service Level Agreement (SLA). The overall solution, through four layers of protection—network isolation, identity authentication, data encryption, and audit traceability—maximizes the reduction of development costs while fully meeting the special requirements of overseas compliance, network, and operations and maintenance, and can be quickly adapted to mainstream overseas markets.
[0101] Figure 2 This is a schematic diagram of a heterogeneous cloud architecture interaction scheme connecting domestic and regional / international areas according to an embodiment of the present invention, such as... Figure 2 As shown, it includes: domestic region 201 and overseas region 202.
[0102] Domestic Region 201 refers to cloud service resources or data centers located within China, possessing localized computing, storage, networking, and security services.
[0103] Overseas Region 202 refers to cloud service resources or data centers located outside of China, belonging to different cloud service providers, and serving specific geographical areas.
[0104] In this embodiment, in terms of development cost, 90% of the operations reuse cloud vendor native components and standardized protocols, with a total development workload of less than 5 person-days. This significantly reduces the manpower and time investment of enterprises in technology development, reduces the additional costs brought by customized development, and enables enterprises to focus more resources on core business innovation.
[0105] Optionally, in terms of data security, data transmission and functions are achieved between domestic region 201 and overseas region 202 through a secure network connection. The call is protected by a four-layer protection system of network isolation (dedicated line / VPN), identity authentication (IAM), data encryption (KMS), and audit traceability (log). This system ensures data security throughout the entire process from network entry, interface access, data transmission and storage to operation auditing, effectively preventing risks such as unauthorized access, data leakage, and tampering. It meets international security standards and overseas compliance requirements such as GDPR and SCHREMS II, improves the company's data security governance level, and enhances customers' and partners' trust in data security.
[0106] Optionally, in terms of business efficiency, the solution deployment cycle is only 7-15 days, enabling rapid interconnection between different clouds. This allows enterprises to quickly respond to changes in business needs, such as cross-cloud business expansion and elastic resource scheduling. Simultaneously, leveraging cloud vendors' native capabilities such as global acceleration and load balancing, it improves international network access speed and stability, ensures high availability of cross-cloud applications, optimizes user experience, and facilitates efficient business operations.
[0107] Optionally, in terms of overseas expansion, it fully adapts to the special requirements of overseas cross-border compliance, multi-regional deployment, and international network environment, enabling enterprises to smoothly enter mainstream overseas markets, avoid the risk of business obstruction due to compliance, network and other issues, accelerate the process of globalization, and enhance competitiveness in overseas markets.
[0108] Optionally, in terms of operation and maintenance management, based on cloud vendors' native monitoring, logging, and alarm tools, traceability of cross-cloud operations and rapid fault response are achieved, simplifying operation and maintenance processes, reducing operation and maintenance complexity, enabling enterprises to conduct daily management and fault diagnosis in cross-cloud environments more efficiently, and ensuring the continuous and stable operation of business.
[0109] Optionally, leased lines / VPNs can be used to achieve low-latency, high-bandwidth, and secure data transmission channels, avoiding the instability and security risks associated with the public internet. Regional relay is used in certain situations, such as in regions with network restrictions, to relay data through cloud resources in neutral third-party regions to ensure compliance and unimpeded data flow. Compliant satellite leased line access is used, particularly in overseas regions with inadequate regional network infrastructure or sanctioned areas, to establish compliant data transmission channels via satellite communication.
[0110] Optionally, API gateway and interface adaptation: An API gateway can be established between the two clouds to standardize and adapt different API sets, enabling seamless cross-cloud service calls. Furthermore, by defining detailed interface layer specifications, such as RESTful API + HTTPS (TLS 1.3), gRPC, SFTP / S3, etc., efficient and secure data transmission can be ensured.
[0111] Optionally, identity authentication and access control can leverage cloud vendors' IAM services to implement cross-cloud role authorization and single sign-on, ensuring authorized and secure API access. Simultaneously, enabling a native signature mechanism prevents token tampering and forgery, ensuring data transmission integrity. In the authentication process, the token represents the authorization credentials a user obtains after successful login.
[0112] Optionally, data security configuration may include static and dynamic encryption of data, configuration of de-identification rules, and selection of compliant encryption services to meet data security and privacy protection requirements.
[0113] Optionally, auditing and monitoring can be performed by logging operations, configuring anomaly alerts and log retention policies to ensure that operations are traceable and comply with local laws and regulations, such as GDPR and SCHREMS II.
[0114] Optionally, at the operations and maintenance level, cloud vendors' monitoring, logging, and alerting tools can be relied upon to automate operations and maintenance across cloud environments, including fault detection, recovery, and daily management, in order to reduce operational complexity and improve business continuity.
[0115] In embodiments of the present invention, if data transmission is required, initial data to be transmitted from an initial cloud platform can be obtained. The initial cloud platform provides data source cloud services, and the initial data to be transmitted includes port data and / or address data. The initial data to be transmitted can be encrypted to obtain first target data to be transmitted. A desensitization strategy can be used to desensitize the first target data to be transmitted to obtain second target data to be transmitted. The desensitization strategy represents the rules for desensitizing the encrypted initial data to be transmitted. The second target data to be transmitted can be transmitted to a target cloud platform using the target interface of the initial cloud platform. The port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive data source cloud services. In other words, this invention ensures the confidentiality and integrity of the initial data to be transmitted during the interaction between different cloud platforms (initial cloud platform and target cloud platform) through encryption and desensitization processing. This effectively prevents the initial data to be transmitted from being tampered with or leaked during transmission, thus improving the overall security of the initial data to be transmitted. By accessing the target interface, only specific port data and address data are allowed to communicate, which can precisely manage the channel for transmitting the initial data to be transmitted, reduce the risk of unauthorized access, and achieve more granular permission management. This solves the technical problem of not being able to effectively process data during the interaction between different cloud platforms, and achieves the technical effect of effectively processing data during the interaction between different cloud platforms.
[0116] According to embodiments of the present invention, a data processing apparatus for cloud platform interactions is also provided. It should be noted that this data processing apparatus for cloud platform interactions can be used to execute the data processing method for cloud platform interactions described in the embodiments.
[0117] Embodiments of the present invention also provide a data processing apparatus for cloud platform interaction. Figure 3 This is a schematic diagram of a data processing device in cloud platform interaction according to an embodiment of the present invention, such as... Figure 3 As shown, the data processing device 300 in cloud platform interaction includes: an acquisition unit 302, an encryption unit 304, a desensitization unit 306, and a transmission unit 308.
[0118] The acquisition unit 302 is used to acquire the initial data to be transmitted from the initial cloud platform, wherein the initial cloud platform is used to provide data source cloud services, and the initial data to be transmitted includes port data and / or address data.
[0119] The encryption unit 304 is used to encrypt the initial data to be transmitted to obtain the first target data to be transmitted.
[0120] The desensitization unit 306 is used to perform desensitization processing on the first target data to be transmitted using a desensitization strategy to obtain the second target data to be transmitted. The desensitization strategy is used to represent the rules for desensitizing the encrypted initial data to be transmitted.
[0121] The transmission unit 308 is used to transmit the second target data to the target cloud platform using the target interface of the initial cloud platform. The port data in the second target data is consistent with the port data in the initial data to be transmitted, and the address data in the second target data is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive the data source cloud service.
[0122] Optionally, the encryption unit 304 includes: an acquisition subunit, used to acquire document information of the initial data to be transmitted; configure the configuration parameters in the target interface according to the document information; a test subunit, used to test the target interface in response to the completion of the configuration parameters and obtain a test result, wherein the test result is used to indicate whether the configuration parameters are configured correctly and whether the target interface responds normally; and an encryption subunit, used to encrypt the initial data to be transmitted in response to the test result indicating that the configuration parameters are configured correctly and the target interface responds normally, to obtain the first target data to be transmitted.
[0123] Optionally, the desensitization unit 306 includes: a desensitization subunit, used to perform desensitization processing on the first target data to be transmitted using a desensitization strategy to obtain the desensitized first target data to be transmitted; an authentication subunit, used to perform identity authentication on the desensitized first target data to be transmitted, and to perform authorization processing on the desensitized first target data to be transmitted that has passed identity authentication; and a determination subunit, used to determine the first target data to be transmitted after the authorization processing is completed as the second target data to be transmitted in response to the completion of the authorization processing.
[0124] Optionally, the transmission unit 308 includes: a filtering subunit, used to filter the port data and address data in the second target data to be transmitted using a whitelist strategy, to obtain the filtered port data and address data in the second target data to be transmitted, wherein the filtered port data and address data in the second target data to be transmitted are accessible to the target cloud platform; and a transmission subunit, used to transmit the second target data to be transmitted to the target cloud platform using the target interface.
[0125] Optionally, the method further includes: a recording subunit, used to record the second target data to be transmitted during the process of transmitting the second target data to the target cloud platform.
[0126] Optionally, the method further includes: a verification subunit for performing multiple verifications on the second target data to be transmitted to obtain a verification result; and a prompting subunit for triggering an alarm prompt in response to the verification result indicating that the security of the second target data to be transmitted is less than a security threshold.
[0127] In this embodiment, the acquisition unit 302 is used to acquire the initial data to be transmitted from the initial cloud platform, wherein the initial cloud platform is used to provide data source cloud services, and the initial data to be transmitted includes port data and / or address data; the encryption unit 304 is used to encrypt the initial data to be transmitted to obtain the first target data to be transmitted; the desensitization unit 306 is used to desensitize the first target data to be transmitted using a desensitization strategy to obtain the second target data to be transmitted, wherein the desensitization strategy is used to represent the rules for desensitizing the encrypted initial data to be transmitted; the transmission unit 308 is used to transmit the second target data to be transmitted to the target cloud platform using the target interface of the initial cloud platform, wherein the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive the data source cloud services, thereby solving the technical problem of not being able to effectively process data in cross-cloud platform interactions and achieving the technical effect of effectively processing data in cross-cloud platform interactions.
[0128] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0129] According to another aspect of the present invention, a processor is also provided. The processor is used to run a program, wherein the program, when run by the processor, performs the methods described in the embodiments of the present invention.
[0130] According to embodiments of the present invention, an electronic device is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods of various embodiments of the present invention during runtime.
[0131] According to embodiments of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is executed, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of the present invention.
[0132] According to embodiments of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of the present invention.
[0133] According to embodiments of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the methods of various embodiments of the present invention.
[0134] According to embodiments of the present invention, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of the present invention.
[0135] According to embodiments of the present invention, a vehicle is also provided that implements the methods of various embodiments of the present invention when executed.
[0136] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0137] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0138] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0139] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0140] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0141] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for processing data in cloud platform interaction, characterized in that, include: Obtain the initial data to be transmitted from the initial cloud platform, wherein the initial cloud platform is used to provide data source cloud services, and the initial data to be transmitted includes port data and / or address data; The initial data to be transmitted is encrypted to obtain the first target data to be transmitted; Using a desensitization strategy, the first target data to be transmitted is desensitized to obtain the second target data to be transmitted. The desensitization strategy is used to represent the rules for desensitizing the encrypted initial data to be transmitted. Using the target interface of the initial cloud platform, the second target data to be transmitted is transmitted to the target cloud platform, wherein the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted. The target cloud platform is used to receive the data source cloud service.
2. The method according to claim 1, characterized in that, The initial data to be transmitted is encrypted to obtain the first target data to be transmitted, including: Obtain the document information of the initial data to be transmitted; Configure the configuration parameters in the target interface according to the document information; In response to the completion of the configuration parameters, the target interface is tested to obtain test results, wherein the test results are used to indicate whether the configuration parameters are configured correctly and whether the target interface responds normally; In response to the test result indicating that the configuration parameters are configured correctly and the target interface responds normally, the initial data to be transmitted is encrypted to obtain the first target data to be transmitted.
3. The method according to claim 2, characterized in that, Using a de-identification strategy, the first target data to be transmitted is de-identified to obtain the second target data to be transmitted, including: Using the aforementioned desensitization strategy, the first target data to be transmitted is desensitized to obtain the desensitized first target data to be transmitted. The first target data to be transmitted after de-identification is authenticated, and the first target data to be transmitted after de-identification that has passed the authentication is authorized. In response to the completion of the authorization process, the first target data to be transmitted after the authorization process is completed is determined as the second target data to be transmitted.
4. The method according to claim 3, characterized in that, Using the target interface of the initial cloud platform, the second target data to be transmitted is transmitted to the target cloud platform, including: Using a whitelist strategy, the port data and address data in the second target data to be transmitted are filtered to obtain the filtered port data and address data in the second target data to be transmitted. The filtered port data and address data in the second target data to be transmitted are allowed to be accessed by the target cloud platform. Using the target interface, the second target data to be transmitted is transmitted to the target cloud platform.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: During the process of transmitting the second target data to the target cloud platform, the second target data is recorded.
6. The method according to claim 5, characterized in that, The method further includes: Multiple verifications are performed on the second target data to be transmitted to obtain the verification results; In response to the verification result that the security of the second target data to be transmitted is less than the security threshold, an alarm is triggered.
7. A data processing device for interaction on a heterogeneous cloud platform, characterized in that, include: An acquisition unit is used to acquire initial data to be transmitted from an initial cloud platform, wherein the initial cloud platform is used to provide data source cloud services, and the initial data to be transmitted includes port data and / or address data. An encryption unit is used to encrypt the initial data to be transmitted to obtain the first target data to be transmitted; The desensitization unit is used to desensitize the first target data to be transmitted using a desensitization strategy to obtain the second target data to be transmitted. The desensitization strategy is used to represent the rules for desensitizing the encrypted initial data to be transmitted. The transmission unit is used to transmit the second target data to the target cloud platform using the target interface of the initial cloud platform, wherein the port data in the second target data to be transmitted is consistent with the port data in the initial data to be transmitted, and the address data in the second target data to be transmitted is consistent with the address data in the initial data to be transmitted, and the target cloud platform is used to receive the data source cloud service.
8. A processor, characterized in that, The processor is used to run a program, wherein the program executes the method according to any one of claims 1 to 6 when it runs.
9. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 6.
10. A vehicle, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 6.