Insurance policy information transfer system and method, electronic equipment and storage medium
By using the unified authentication routing orchestration and visual configuration rule management of the policy information middleware system, the problem of scattered policy information within insurance institutions has been solved, achieving unified data processing and security management, and improving query efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SUNSHINE LIFE INSURANCE CO LTD
- Filing Date
- 2025-12-12
- Publication Date
- 2026-04-28
AI Technical Summary
Insurance institutions have numerous business lines, channels, and systems, resulting in fragmented policy information, inconsistent query criteria, non-standard fields, low efficiency of cross-system queries, difficulty in supporting rapid front-end integration and consistent user experience, insufficient configuration capabilities, weak security and compliance, and difficulty in meeting regulatory requirements.
This paper provides a policy information platform system that obtains policy data from multiple data sources and performs field filtering mapping, data anonymization and result sorting through unified authentication routing orchestration, visual configuration rule management, and combined with transmission message encryption/decryption signature verification and centralized log auditing to achieve unified data processing and security management.
It improves query response speed and user experience consistency, enhances system reusability and configuration flexibility, strengthens security compliance capabilities, and meets the requirements of Information Security Protection Standard 2.0/3.0 and national cryptographic algorithms.
Smart Images

Figure CN121935281A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computer software and insurance information technology, and in particular to a policy information platform system, method, electronic device and storage medium. Background Technology
[0002] With the rapid development of the insurance business, insurance institutions have numerous business lines, channels, and systems, resulting in policy information being scattered across multiple systems. This leads to inconsistent query criteria, non-standardized fields, and low efficiency in cross-system queries, making it difficult to support rapid front-end integration and consistent user experience. Traditional approaches rely primarily on customized development within systems, which suffers from poor reusability and long change cycles. Existing technologies mainly have the following shortcomings: First, the lack of a unified query platform results in inconsistent interface specifications and fragmented query logic across systems, making unified governance and reuse difficult. Second, insufficient configurability requires code modification when integrating new channels or scenarios, leading to slow response times and poor flexibility. Third, weak security and compliance are manifested in inconsistent authentication mechanisms, incomplete audit records, inconsistent data anonymization, and insufficient compatibility with the National Cybersecurity Classified Protection System 2.0 / 3.0 and national cryptographic algorithms, making it difficult to meet regulatory requirements and posing data security risks.
[0003] Therefore, there is an urgent need to provide a technical solution to address the above problems. Summary of the Invention
[0004] To address the aforementioned technical problems, this invention provides a policy information platform system, method, electronic device, and storage medium.
[0005] Firstly, the present invention provides a policy information platform system, the technical solution of which is as follows: The policy information query module is used to perform unified authentication and routing orchestration on policy query requests and generate target requests. According to the configuration rules, the module obtains corresponding policy data from multiple dispersed data sources through the target requests and performs field filtering, field mapping, data anonymization and result sorting on the policy data in sequence to generate a standardized query response. The configuration management module is used to perform visual configuration, storage and distribution management of the configuration rules, which include field visibility rules, field mapping relationships, data anonymization rules and result sorting rules. The security management module is used to encrypt, decrypt, and verify the signatures of the transmission messages corresponding to the policy query request and the standardized query response, and to manage the encryption keys and algorithm suites. The log auditing module is used to record the operation logs generated by the policy information query module, the configuration management module, and the security management module, and to centrally store and retrieve the operation logs.
[0006] The beneficial effects of the policy information middleware system of the present invention are as follows: The system of this invention obtains policy data from multiple data sources and performs field filtering mapping, data anonymization, and result sorting through unified authentication routing orchestration and visual configuration rule management. Combined with transmission message encryption / decryption signature verification and centralized log auditing, it solves the problems of inconsistent query criteria, slow cross-system queries, insufficient configuration, and weak security compliance. It improves query response speed and user experience consistency, enhances system reusability and configuration flexibility, and strengthens security compliance capabilities.
[0007] Based on the above solution, the policy information platform system of the present invention can be further improved as follows.
[0008] In one alternative approach, the policy information query module is specifically used for: Receive the policy query request from external channels and perform unified authentication and verification on the policy query request; After the policy query request passes authentication, the policy query request is routed and orchestrated according to a predefined routing strategy to generate the target request containing the routing orchestration result and authentication context information.
[0009] The advantages of adopting the above optional methods are: to further realize unified entry management and authentication of external requests, to ensure that only authorized requests can access the system, and to accurately distribute requests to the corresponding data sources through routing orchestration, thereby improving system security and request processing accuracy.
[0010] In one alternative approach, the policy information query module is specifically used for: Based on the routing orchestration results in the configuration rules, the target request is distributed to multiple corresponding distributed data sources; Receive policy data corresponding to the target request returned from the multiple distributed data sources; Based on the field visibility rules in the configuration rules, field filtering is performed on the policy data; Based on the field mapping relationship in the configuration rules, field mapping is performed on the policy data that has been filtered by field. Based on the data anonymization rules in the configuration rules, data anonymization is performed on the policy data that has undergone field mapping; Based on the result sorting rules in the configuration rules, the policy data that has been anonymized is sorted to generate the standardized query response containing the sorted policy data.
[0011] The benefits of adopting the above optional methods are as follows: further realizing the acquisition and unified processing of data from multiple data sources, ensuring data format consistency through field filtering and mapping, protecting information security through data anonymization, improving the query experience through result sorting, and ultimately forming a standardized response, thereby enhancing the system's reusability.
[0012] In an alternative approach, the configuration management module is specifically used for: The system receives configuration operations for the field visibility rules, field mapping relationships, data anonymization rules, and result sorting rules through a visual configuration interface. Store the configuration rules defined by the configuration operation into the rule database; The configuration rules stored in the rule database are distributed to the policy information query module.
[0013] The advantages of adopting the above optional methods are: providing a more visual configuration interface to reduce the technical threshold of rule configuration, storing configurations in the database for unified management, real-time distribution to ensure that rules take effect in a timely manner, improving system flexibility and configuration efficiency, and adapting to new scenarios without code modification.
[0014] In one alternative approach, the security management module is specifically used for: Receive the first transmission message corresponding to the policy query request, and decrypt and verify the first transmission message based on the encryption key and the algorithm suite; Receive the second transmission message corresponding to the standardized query response, and encrypt and sign the second transmission message based on the encryption key and the algorithm suite; The encryption key and the algorithm suite are stored, updated, and access controlled.
[0015] The advantages of adopting the above optional methods are: further ensuring the confidentiality and integrity of data transmission, preventing information leakage and tampering, unifying the management of keys and algorithm suites to ensure the consistency of encryption mechanisms, meeting the requirements of the Information Security Protection Standard 2.0 / 3.0 and national cryptographic algorithms, and strengthening the system's security protection capabilities.
[0016] In one alternative approach, the log auditing module is specifically used for: Collect the first operation log generated by the policy information query module when performing data query and processing; Collect the second operation log generated by the configuration management module when configuring and modifying rules; Collect the third operation logs generated by the security management module when performing encryption, decryption, and signature verification; The first operation log, the second operation log, and the third operation log are transmitted to a centralized log storage system for storage. In response to a log retrieval request, the corresponding operation log is retrieved from the centralized log storage system and returned.
[0017] The benefits of adopting the above-mentioned optional methods are as follows: further realizing comprehensive recording and centralized management of operational behavior, facilitating post-event traceability and problem investigation, supporting rapid retrieval to improve operation and maintenance efficiency, providing a data foundation for security auditing, meeting compliance requirements, and enhancing system auditability.
[0018] In an alternative approach, the log auditing module is further configured to: Perform integrity verification on the operation log and generate a security audit report based on predefined audit rules.
[0019] The advantages of adopting the above optional methods are: further ensuring that the logs have not been tampered with through integrity verification, guaranteeing the credibility of audit data, automatically generating audit reports to reduce manual intervention, improving audit efficiency and accuracy, timely detecting security anomalies, and providing strong support for compliance inspections.
[0020] Secondly, this invention provides a method for a policy information platform, employing a policy information platform system as described in this invention. The technical solution of this method is as follows: Unified authentication and routing orchestration are performed on policy query requests to generate target requests; according to configuration rules, corresponding policy data are obtained from multiple dispersed data sources through the target requests, and field filtering, field mapping, data anonymization and result sorting are performed on the policy data in sequence to generate standardized query responses; The configuration rules are configured, stored, and distributed in a visual manner. The configuration rules include field visibility rules, field mapping relationships, data anonymization rules, and result sorting rules. The system encrypts, decrypts, and verifies the signatures of the transmission messages corresponding to the policy query request and the standardized query response, and manages the encryption keys and algorithm suites. Record the generated operation logs and centrally store and retrieve the operation logs.
[0021] The beneficial effects of the policy information middleware method of the present invention are as follows: The method of this invention obtains policy data from multiple data sources and performs field filtering mapping, data anonymization and result sorting through unified authentication routing orchestration and visual configuration rule management. Combined with transmission message encryption / decryption signature verification and centralized log auditing, it solves the problems of inconsistent query criteria, slow cross-system query, insufficient configuration and weak security compliance, improves query response speed and user experience consistency, enhances system reusability and configuration flexibility, and strengthens security compliance capabilities.
[0022] Thirdly, the technical solution of an electronic device according to the present invention is as follows: It includes a memory, a processor, and a program stored in the memory and running on the processor, wherein the processor executes the program to implement the steps of the policy information middleware method of the present invention.
[0023] Fourthly, the technical solution of a computer-readable storage medium provided by the present invention is as follows: The computer-readable storage medium stores instructions that, when read, cause the computer-readable storage medium to perform the steps of the policy information platform method of the present invention.
[0024] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0025] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This is a schematic diagram of the structure of an embodiment of the policy information middleware system of the present invention; Figure 2 A schematic diagram of the overall architecture of the policy information middleware system; Figure 3 This is a flowchart illustrating an embodiment of a policy information middleware method according to the present invention. Figure 4 This is a schematic diagram of an embodiment of an electronic device according to the present invention. Detailed Implementation
[0026] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein.
[0027] Figure 1 This diagram illustrates the structure of an embodiment of a policy information middleware system 100 provided by the present invention. Figure 1 As shown, the policy information platform system 100 includes: The policy information query module 101 is used to perform unified authentication and routing orchestration on policy query requests and generate target requests. According to the configuration rules, the module obtains corresponding policy data from multiple dispersed data sources through the target requests and performs field filtering, field mapping, data anonymization and result sorting on the policy data in sequence to generate a standardized query response.
[0028] Among them, a policy query request refers to a service call initiated by an external application or terminal to the policy information platform system to query information related to a specific life insurance policy; for example, after policyholder "User A" enters their ID number and policy number through the insurance company's official application, the application sends a network request containing the query conditions to the policy information platform. Unified authentication refers to the centralized and standardized process by which the policy information platform verifies the identity legitimacy and operation permissions of all incoming policy query requests; for example, after receiving a query request, the policy information platform verifies the validity of the requester's digital certificate and whether the user has the permission to query the target policy, allowing only requests that pass the verification to proceed to the next process. Routing orchestration refers to the logical decision-making process of decomposing a single policy query request and directing it to multiple different backend data sources for collaborative processing according to a preset strategy; for example, based on the policy type, a request to query a certain whole life insurance policy needs to be simultaneously directed to the "core business system" to obtain the main insurance information, to the "customer center system" to obtain the policyholder information, and to the "supplementary insurance system" to obtain health disclosure information. The target request refers to an internal processing object generated after the policy query request has completed authentication and routing orchestration. This object contains a defined data source access path and verified identity information. For example, the system generates an internal instruction object that specifies the three data source addresses that the request needs to access, the corresponding query parameters, and the identity identifier of the authorized agent who initiated the request.
[0029] Configuration rules refer to a set of configurable strategies defined and maintained through the configuration management module to uniformly control data query, processing, and output behavior. For example, a rule can be configured to stipulate that query results from "online self-service channels" must include the "cash value" field, and the "mobile phone number" field must be anonymized. The final list should be sorted in descending order by "insurance date." Data sources refer to backend systems or databases that independently store policy, customer, and product-related business data. For example, an insurance company's "core business system," "customer information database," and "health management platform" are all sources from which the policy information platform needs to aggregate data. Policy data refers to the set of original business information related to the queried policy, obtained from various data sources. For example, the obtained information set includes original fields and values such as policy number, product name, sum insured, policyholder's name, ID number, and health questionnaire results.
[0030] Field filtering refers to the process of removing fields from the original policy data that the requesting party is not authorized to view, based on field visibility rules. For example, hiding the "Annual Income" and "Detailed Home Address" fields in "Partner Bank Channel" and filtering out data from these fields during processing. Field mapping refers to the process of converting heterogeneous field names from different data sources into unified standard field names based on field mapping relationships. For example, mapping the source system field name "CONT_NO" to the standard field name "policyNumber", and mapping "PREMIUM_AMT" to "premium". Data anonymization refers to the process of converting or masking sensitive information in policy data to protect personal privacy, based on data anonymization rules. Result sorting refers to the process of rearranging the processed policy data set according to result sorting rules. A standardized query response refers to the final result message output by the policy information query module after filtering, mapping, desensitizing, and sorting the data, with the format and content conforming to predetermined standards. For example, it outputs a JSON message with a fixed structure, where all field names are consistent, sensitive information is desensitized, and the policy list is sorted according to specified rules.
[0031] The configuration management module 102 is used to perform visual configuration, storage and distribution management of the configuration rules, which include field visibility rules, field mapping relationships, data anonymization rules and result sorting rules.
[0032] Among them, field visibility rules refer to sub-rules in the configuration rules used to define the range of data fields that can be displayed in different scenarios; for example, defining a rule: when the request channel is "external cooperation platform", only the three fields "policy number", "product name", and "annual premium" are allowed to be returned. Field mapping relationship refers to sub-rules in the configuration rules used to define the correspondence between source data field names and middle platform standard field names; for example, defining a mapping relationship: the source field "CLIENT_NAME" corresponds to the standard field "clientName", and the source field "EFF_DATE" corresponds to the standard field "effectiveDate". Data anonymization rules refer to sub-rules in the configuration rules used to define the fields that need to be anonymized and the specific anonymization algorithm; for example, defining a rule: for the standard field "idCard", use the algorithm of "keeping the first six and the last four, and replacing the middle with asterisks", and for the "mobile" field, use the algorithm of "keeping the first three and the last four, and replacing the middle with asterisks". The result sorting rule refers to the sub-rule in the configuration rule used to define the order of the output results; for example, the sorting rule is defined as follows: first sort in descending order according to "policy status" (valid first), and then sort in descending order according to "cumulative premium" if the status is the same.
[0033] The security management module 103 is used to encrypt, decrypt, and sign the transmission messages corresponding to the policy query request and the standardized query response, and to manage the encryption keys and algorithm suites.
[0034] Transmission messages refer to communication data packets carrying business requests or responses transmitted over a network; for example, HTTPS request data packets sent by external channels and HTTPS response data packets returned by the policy information platform are both transmission messages. Encryption / decryption and signature verification refer to the security processing performed by the security management module on transmission messages entering and leaving the policy information platform, including decryption, signature verification, encryption, and signature generation; for example, decrypting and verifying the signature of received request messages to ensure their integrity and trustworthiness; encrypting and attaching digital signatures to sent response messages to ensure transmission security. Encryption keys refer to the secret parameters or strings necessary for performing encryption / decryption and signature verification operations; for example, a specific length of cryptographic string agreed upon and used by the policy information platform and external channels as the key for a symmetric encryption algorithm. Algorithm suites refer to a combination of specific cryptographic algorithms used to implement security functions such as encryption / decryption and signature verification; for example, using SM2, SM3, and SM4 algorithms recognized by the national cryptography management department for asymmetric encryption, digest calculation, and symmetric encryption respectively, constitutes a compliant algorithm suite.
[0035] The log auditing module 104 is used to record the operation logs generated by the policy information query module 101, the configuration management module 102 and the security management module 103, and to centrally store and retrieve the operation logs.
[0036] The operation log refers to the timestamped information entries generated by the policy information platform during its operation to record key operation events. For example, the generated log information is: "2025-08-10 11:05:22, Agent [Employee ID 1001] queried policy [POL20250810001] through the [Counter System]". The technical solution in this embodiment obtains policy data from multiple data sources and performs field filtering mapping, data anonymization, and result sorting through unified authentication routing orchestration and visual configuration rule management. Combined with transmission message encryption / decryption signature verification and centralized log auditing, it solves the problems of inconsistent query criteria, slow cross-system queries, insufficient configuration, and weak security compliance. It improves query response speed and user experience consistency, enhances system reusability and configuration flexibility, and strengthens security compliance capabilities.
[0037] In one alternative approach, the policy information query module 101 is specifically used for: Receive the policy query request from external channels and perform unified authentication and verification on the policy query request.
[0038] External channels refer to various front-end business platforms or third-party applications that access and use the policy information platform query service; for example, insurance companies' mobile applications, official websites, telephone customer service centers, and cooperating bank agency systems.
[0039] After the policy query request passes authentication, the policy query request is routed and orchestrated according to a predefined routing strategy to generate the target request containing the routing orchestration result and authentication context information.
[0040] The predefined routing strategy refers to a rule base pre-set in the policy information platform to guide the selection of data sources based on the request content. For example, a strategy might be set such that if the policy type being queried includes "critical illness coverage," the request must be routed to the "core business system" and the "health insurance data center." The routing orchestration result refers to a clear list of all target data sources and their parameters that the request needs to access, derived after analyzing the specific request according to the predefined routing strategy. For example, for a given query, the result might be that access to the "core business system" (parameter: policy number) and the "health insurance data center" (parameter: insured ID) is required. The authentication context information refers to an information object generated after successful unified authentication, containing details of the verified identity and permissions, used for access control in subsequent stages. For example, the generated information object might include: user identifier: "U10001", role: "VIP customer", access channel: "APP", and data permission level: "A".
[0041] Among the above optional methods, unified entry management and authentication of external requests are further implemented to ensure that only authorized requests can access the system. Requests are accurately distributed to the corresponding data sources through routing orchestration, thereby improving system security and the accuracy of request processing.
[0042] In one alternative approach, the policy information query module 101 is specifically used for: Based on the routing orchestration results in the configuration rules, the target request is distributed to multiple corresponding distributed data sources.
[0043] Receive policy data corresponding to the target request returned from the multiple distributed data sources.
[0044] Based on the field visibility rules in the configuration rules, field filtering is performed on the policy data.
[0045] Based on the field mapping relationship in the configuration rules, field mapping is performed on the policy data that has been filtered by field.
[0046] Among them, the policy data after field filtering refers to the intermediate dataset formed after removing invisible fields from the original policy data according to the field visibility rules; for example, if the original data has 20 fields, only the data of the 8 fields that are allowed to be displayed will remain after filtering.
[0047] Based on the data anonymization rules in the configuration rules, data anonymization is performed on the policy data that has undergone field mapping.
[0048] Among them, the policy data after field mapping refers to the intermediate data after field filtering, and the dataset after the field names are uniformly converted to standard names; for example, the filtered field "INSURED_NAME" is mapped to "insuredName", and "POL_START" is mapped to "policyStartDate".
[0049] Based on the result sorting rules in the configuration rules, the policy data that has been anonymized is sorted to generate the standardized query response containing the sorted policy data.
[0050] Specifically, the data-desensitized policy data refers to a dataset that has undergone field mapping, where the values of specified sensitive fields have been transformed according to rules; for example, the value of the standard field "idCard" is displayed as "100000********0001", and the value of the "mobile" field is displayed as "130****5678". The sorted policy data refers to the final output dataset after the data-desensitized dataset has been reorganized according to predetermined sorting rules; for example, multiple policy records are arranged from highest to lowest based on "premium due".
[0051] Among the above optional methods, it is further possible to obtain data from multiple data sources and process them uniformly, ensure data format consistency through field filtering and mapping, protect information security through data anonymization, improve the query experience through result sorting, and finally form a standardized response to enhance the system's reusability.
[0052] In an alternative embodiment, the configuration management module 102 is specifically used for: The system receives configuration operations for the field visibility rules, field mapping relationships, data anonymization rules, and result sorting rules through a visual configuration interface.
[0053] The visual configuration interface refers to the operation page provided by the configuration management module, which allows operations personnel to manage rules through a graphical interaction. For example, in a web management backend, administrators can set rules such as field visibility and anonymization methods by clicking, dragging, and filling out forms. Configuration operations refer to the specific actions taken by operations personnel to manage configuration rules on the visual configuration interface. For example, an administrator clicks the "Add" button on the interface, selects the fields to be displayed for "Telemarketing Channels," sets the anonymization method, and finally clicks "Save and Apply."
[0054] The configuration rules defined by the configuration operation are stored in the rule database.
[0055] The rules database refers to a database specifically used to persistently store all configuration rules data; for example, a database table named "config_center" records all the rule details corresponding to each channel.
[0056] The configuration rules stored in the rule database are distributed to the policy information query module 101.
[0057] Among the above optional methods, a visual configuration interface is further provided to reduce the technical threshold of rule configuration, the configuration is stored in the database for unified management, and real-time distribution ensures that the rules take effect in a timely manner, thereby improving the system's flexibility and configuration efficiency and adapting to new scenarios without code modification.
[0058] In an alternative embodiment, the security management module 103 is specifically used for: Receive the first transmission message corresponding to the policy query request, and decrypt and verify the first transmission message based on the encryption key and the algorithm suite.
[0059] The first transmission message refers to a network data packet sent from an external channel to the policy information platform, carrying a policy query request; for example, an HTTPS request packet carrying encryption and signature information, the content of which is to query the policy number "POL20250810001".
[0060] Receive the second transmission message corresponding to the standardized query response, and encrypt and sign the second transmission message based on the encryption key and the algorithm suite.
[0061] The second transmission message refers to a network data packet sent from the policy information platform to external channels, carrying a standardized query response; for example, an encrypted and signed HTTPS response packet containing formatted and de-identified JSON data of the policy details.
[0062] The encryption key and the algorithm suite are stored, updated, and access controlled.
[0063] Among the above-mentioned optional methods, the confidentiality and integrity of data transmission are further guaranteed, information leakage and tampering are prevented, the unified management of keys and algorithm suites ensures the consistency of encryption mechanisms, meets the requirements of the Information Security Protection Standard 2.0 / 3.0 and the national cryptographic algorithm, and strengthens the system's security protection capabilities.
[0064] In an alternative embodiment, the log auditing module 104 is specifically used for: The first operation log generated by the policy information query module 101 when performing data query and processing is collected.
[0065] The first operation log refers to the records generated by the policy information query module during the execution of data query, processing and output; for example, the log reads: "2025-08-10 11:05:23, [policy information query module] successfully retrieved policy details from the core business system, taking 65 milliseconds." Collect the second operation log generated when the configuration management module 102 executes rule configuration and modification.
[0066] The second operation log refers to the record generated by the configuration management module when any change operation is made to the configuration rules; for example, the log: "2025-08-10 09:15:30, [Configuration Management Module] Administrator [Administrator A] modified the field display rules of the channel [Online Banking]". Collect the third operation log generated when the security management module 103 performs encryption, decryption and signature verification.
[0067] The third operation log refers to the record generated by the security management module when performing security operations such as message encryption / decryption and signature verification. For example, the log reads: "2025-08-10 11:05:22, [Security Management Module] completed the decryption and signature verification of request [REQ-20250810-001], status: successful." The first operation log, the second operation log, and the third operation log are transmitted to a centralized log storage system for storage.
[0068] The centralized log storage system refers to a backend system used to uniformly collect, store, and index all operation logs of the policy information platform; for example, a log management platform built on the Elasticsearch, Logstash, and Kibana technology stack.
[0069] In response to a log retrieval request, the corresponding operation log is retrieved from the centralized log storage system and returned.
[0070] A log retrieval request refers to a query command with filtering conditions issued by a user or administrator to the log audit module of the policy information platform in order to locate and view specific historical operation records. For example, on August 15, 2025, security administrator "Administrator B" entered the query conditions "time range: 2025-08-10 to 2025-08-12, operation module: policy information query module" in the management platform for internal auditing needs and initiated a query. This command is a log retrieval request.
[0071] Among the above-mentioned optional methods, it is possible to further realize comprehensive recording and centralized management of operational behavior, facilitate post-event traceability and problem investigation, support rapid retrieval to improve operation and maintenance efficiency, provide a data foundation for security auditing, meet compliance requirements, and enhance system auditability.
[0072] In an alternative embodiment, the log auditing module 104 is further configured to: Perform integrity verification on the operation log and generate a security audit report based on predefined audit rules.
[0073] Integrity verification refers to the verification process performed by the log auditing module to ensure that operation logs have not been tampered with or corrupted after generation, transmission, and storage; for example, comparing the hash values of log entries to confirm whether their content has remained complete and consistent since recording. Predefined audit rules refer to log analysis strategies and conditions set in advance for automatically monitoring and detecting potentially risky operations; for example, setting a rule that if the same user account initiates policy inquiries in more than 3 cities within 1 minute, it is marked as abnormal behavior. Security audit reports refer to comprehensive security status documents periodically generated by the log auditing module based on the analysis of operation logs, especially after screening according to predefined audit rules; for example, a weekly report including the total number of requests, the number of intercepted abnormal requests, a list of triggered alarm events, and handling suggestions.
[0074] Among the above-mentioned optional methods, integrity verification is further used to ensure that logs have not been tampered with, guarantee the credibility of audit data, automatically generate audit reports to reduce manual intervention, improve audit efficiency and accuracy, promptly detect security anomalies, and provide strong support for compliance inspections.
[0075] like Figure 2As shown, the policy information platform system architecture comprises a gateway layer, a data logic processing layer, and a permission rule configuration layer, connected sequentially. The gateway layer serves as a unified entry point to external channels, responsible for receiving policy query requests, managing permissions, verifying channel identities, and encrypting / decrypting transmitted messages. Requests processed by the gateway layer are then delivered to the data logic processing layer. This layer orchestrates and aggregates requests, supports cross-data source joint queries, maps and standardizes heterogeneous data fields, and generates templated output based on configuration. The permission rule configuration layer is a centralized control plane responsible for the visual configuration and management of various business rules and security policies, covering query rule settings, channel access control, backend data interface address allocation, multi-tenant data isolation, and unified management of encryption keys and national cryptographic algorithm suites.
[0076] The policy information platform system 100 is implemented by four main functional modules. The policy information query module 101 corresponds to the core of data logic processing, supporting the combination of various query conditions, retrieving policy data from dispersed data sources according to configured rules, and completing processing and assembly. The configuration management module 102 corresponds to the functional entity of the permission rule configuration layer, providing a visual interface to dynamically configure query rules, field mapping relationships, data anonymization rules, and result display formats. The security management module 103 is integrated into the gateway layer and the permission rule configuration layer, ensuring data transmission and storage security, implementing message encryption and decryption, digital signature verification, and managing the lifecycle of encryption keys. The log auditing module 104 runs through all layers, recording operation logs generated by each module to ensure traceability of behavior.
[0077] The policy information platform system 100 is developed using the Spring Cloud microservice framework. It uses a MySQL relational database for persistent storage of core policy information and configuration rules. A Redis in-memory database is used to cache frequently accessed data to improve performance. A centralized log storage and retrieval system is built using the ELK technology stack.
[0078] The policy information query module 101 automatically calls multi-source policy query interfaces based on configuration rules. These configuration rules clearly define the range of data fields allowed to different channels. The built-in rule engine filters the fields returned by the interfaces, extracts allowed field values, and sorts, anonymizes, and populates the results with standard names based on the configuration. For extended functionality, the policy information platform system 100 provides a third-party feedback interface for face recognition services to record verification results. The face recognition function on the mini-program is modularly encapsulated, providing face recognition initialization and recognition result query interfaces.
[0079] Figure 3The diagram illustrates a flowchart of an embodiment of a policy information middleware method provided by the present invention. This method employs a policy information middleware system as provided by the present invention. Figure 3 As shown, the method includes the following steps: S1. Perform unified authentication and routing orchestration on policy query requests to generate target requests; according to configuration rules, obtain corresponding policy data from multiple dispersed data sources through the target requests, and sequentially perform field filtering, field mapping, data anonymization, and result sorting on the policy data to generate standardized query responses; S2. Perform visual configuration, storage and distribution management of the configuration rules, which include field visibility rules, field mapping relationships, data anonymization rules and result sorting rules; S3. Encrypt, decrypt, and verify the signatures of the transmission messages corresponding to the policy query request and the standardized query response, and manage the encryption keys and algorithm suites; S4. Record the generated operation logs and centrally store and retrieve the operation logs.
[0080] It should be noted that the beneficial effects of the policy information middleware method provided in the above embodiments are the same as those of the policy information middleware system 100 described above, and will not be repeated here. Furthermore, the system provided in the above embodiments is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the system can be divided into different functional modules according to the actual situation to complete all or part of the functions described above. In addition, the system and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, and will not be repeated here.
[0081] The policy information middleware system 100 of the present invention can be a computer program (including program code) running on a computer device. For example, the policy information middleware system 100 of the present invention is an application software that can be used to execute the corresponding steps in the policy information middleware method of the present invention.
[0082] In some embodiments, the policy information platform system 100 of the present invention can be implemented in a combination of hardware and software. As an example, the policy information platform system 100 of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the policy information platform method of the present invention. For example, the processor in the form of a hardware decoding processor can be one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0083] The modules described in the embodiments of this invention can be implemented in software or hardware. The names of the modules are not, in some cases, limiting the scope of the module itself.
[0084] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the above-mentioned policy information platform methods. That is, an electronic device according to an embodiment of the present invention may include, but is not limited to: a processor and a memory; the memory is used to store the computer program; the processor is used to execute the policy information platform method shown in any embodiment of the present invention by calling the computer program.
[0085] In one alternative embodiment, an electronic device is provided, such as Figure 4 As shown, Figure 4 The illustrated electronic device 4000 includes a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, which can be used for data interaction between the electronic device and other electronic devices, such as sending and / or receiving data. It should be noted that in practical applications, the transceiver 4004 is not limited to one type, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of the present invention.
[0086] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this invention. Processor 4001 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0087] Bus 4002 may include a path for transmitting information between the aforementioned components. Bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 4002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus 4002 is represented by only one thick line, but this does not mean that there is only one bus or one type of bus.
[0088] The memory 4003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0089] The memory 4003 stores application code (computer program) for executing the present invention, and its execution is controlled by the processor 4001. The processor 4001 executes the application code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.
[0090] Among them, electronic devices can also be terminal devices. A terminal device can be any terminal device that can install applications and access web pages through applications, including at least one of smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, smart TVs, and smart in-vehicle devices.
[0091] It should be noted that, Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of the present invention.
[0092] An embodiment of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-described policy information platform methods.
[0093] Alternatively, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, a floppy disk, and an optical data storage device, etc.
[0094] In an exemplary embodiment, a computer program product or computer program is also provided, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the aforementioned policy information platform method.
[0095] Computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0096] It should be understood that the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0097] The computer-readable storage medium provided in this invention can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0098] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the methods shown in the above embodiments.
[0099] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.
[0100] It should be noted that the terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and represent a limitation on a specific order or sequence. Where appropriate, the order of use for similar objects can be interchanged so that the embodiments of this application described herein can be implemented in an order other than that shown or described.
[0101] Those skilled in the art will recognize that this invention can be implemented as a system, method, or computer program product. Therefore, this invention can be specifically implemented in the following forms: it can be entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this invention can also be implemented as a computer program product contained in one or more computer-readable media, which includes computer-readable program code.
[0102] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A policy information platform system, characterized in that, include: The policy information query module is used to perform unified authentication and routing orchestration on policy query requests and generate target requests. According to the configuration rules, the corresponding policy data is obtained from multiple dispersed data sources through the target request, and the policy data is sequentially processed by field filtering, field mapping, data anonymization and result sorting to generate a standardized query response; The configuration management module is used to perform visual configuration, storage and distribution management of the configuration rules, which include field visibility rules, field mapping relationships, data anonymization rules and result sorting rules. The security management module is used to encrypt, decrypt, and verify the signatures of the transmission messages corresponding to the policy query request and the standardized query response, and to manage the encryption keys and algorithm suites. The log auditing module is used to record the operation logs generated by the policy information query module, the configuration management module, and the security management module, and to centrally store and retrieve the operation logs.
2. The policy information platform system according to claim 1, characterized in that, The policy information query module is specifically used for: Receive the policy query request from external channels and perform unified authentication and verification on the policy query request; After the policy query request passes authentication, the policy query request is routed and orchestrated according to a predefined routing strategy to generate the target request containing the routing orchestration result and authentication context information.
3. The policy information platform system according to claim 2, characterized in that, The policy information query module is specifically used for: Based on the routing orchestration results in the configuration rules, the target request is distributed to multiple corresponding distributed data sources; Receive policy data corresponding to the target request returned from the multiple distributed data sources; Based on the field visibility rules in the configuration rules, field filtering is performed on the policy data; Based on the field mapping relationship in the configuration rules, field mapping is performed on the policy data that has been filtered by field. Based on the data anonymization rules in the configuration rules, data anonymization is performed on the policy data that has undergone field mapping; Based on the result sorting rules in the configuration rules, the policy data that has been anonymized is sorted to generate the standardized query response containing the sorted policy data.
4. The policy information platform system according to claim 3, characterized in that, The configuration management module is specifically used for: The system receives configuration operations for the field visibility rules, field mapping relationships, data anonymization rules, and result sorting rules through a visual configuration interface. Store the configuration rules defined by the configuration operation into the rule database; The configuration rules stored in the rule database are distributed to the policy information query module.
5. The policy information platform system according to any one of claims 1 to 4, characterized in that, The security management module is specifically used for: Receive the first transmission message corresponding to the policy query request, and decrypt and verify the first transmission message based on the encryption key and the algorithm suite; Receive the second transmission message corresponding to the standardized query response, and encrypt and sign the second transmission message based on the encryption key and the algorithm suite; The encryption key and the algorithm suite are stored, updated, and access controlled.
6. The policy information platform system according to claim 5, characterized in that, The log auditing module is specifically used for: Collect the first operation log generated by the policy information query module when performing data query and processing; Collect the second operation log generated by the configuration management module when configuring and modifying rules; Collect the third operation logs generated by the security management module when performing encryption, decryption, and signature verification; The first operation log, the second operation log, and the third operation log are transmitted to a centralized log storage system for storage. In response to a log retrieval request, the corresponding operation log is retrieved from the centralized log storage system and returned.
7. The policy information platform system according to claim 6, characterized in that, The log auditing module is also used for: Perform integrity verification on the operation log and generate a security audit report based on predefined audit rules.
8. A method for a policy information middleware platform, employing the policy information middleware platform system as described in any one of claims 1 to 7, characterized in that, include: Unified authentication and routing orchestration are performed on policy query requests to generate target requests; According to the configuration rules, the corresponding policy data is obtained from multiple dispersed data sources through the target request, and the policy data is sequentially processed by field filtering, field mapping, data anonymization and result sorting to generate a standardized query response; The configuration rules are configured, stored, and distributed in a visual manner. The configuration rules include field visibility rules, field mapping relationships, data anonymization rules, and result sorting rules. The system encrypts, decrypts, and verifies the signatures of the transmission messages corresponding to the policy query request and the standardized query response, and manages the encryption keys and algorithm suites. Record the generated operation logs and centrally store and retrieve the operation logs.
9. An electronic device, characterized in that, The electronic device includes a processor coupled to a memory, the memory storing at least one computer program, which is loaded and executed by the processor to enable the electronic device to implement the policy information platform method as described in claim 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which, when executed by a processor, implements the policy information middleware method as described in claim 8.