Method and system for online automatic update of secret data required by a software system

By using an online automatic update method and leveraging the collaborative work of local and remote covert management systems, the problem of system downtime required for updating covert data in software systems has been solved. This achieves secure isolation management and automatic updates of covert data, reduces labor costs and the risk of covert data leakage, and improves data consistency and security between systems.

CN122113154APending Publication Date: 2026-05-29齐鲁银行股份有限公司

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
齐鲁银行股份有限公司
Filing Date
2026-01-06
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, updating the hidden data of software systems requires downtime, which leads to frequent service failures between systems. Furthermore, manual management poses a risk of hidden data leakage, making it difficult to achieve consistent management of hidden data across large-scale systems.

Method used

By employing an online automatic update method, and through the collaborative work of local and remote covert management systems, secure isolation management and automatic updates of covert data are achieved, avoiding downtime operations. New covert information is pushed out using automatic update rules and plans, and loosely coupled integration between systems is supported.

Benefits of technology

It enables the updating of confidential data without system downtime, reduces labor costs, minimizes the risk of confidential data leakage, ensures the consistency and security of confidential data between systems, and improves the reliability of system operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122113154A_ABST
    Figure CN122113154A_ABST
Patent Text Reader

Abstract

The application belongs to the field of data security, and provides an online automatic updating method and system for secret data required by a software system. When the software system initiates a secret information request, a local secret management system of the software system acquires the secret information request and determines whether there is valid secret information. If yes, the secret information is returned to the software system. Otherwise, the local secret management system continues to send a secret information request to a remote secret management system. The remote secret management system feeds back secret information to the local secret management system according to the secret information request. The local secret management system saves the secret information after encryption and returns it to the software system. The software system acquires the encrypted secret information for use. Based on the old secret information of the software system, the remote secret management system automatically updates according to corresponding automatic updating rules, plans and updating contents, and actively pushes the new secret information to the local secret management system of the software system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security technology, specifically relating to an online automatic update method and system for confidential data required by a software system. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] Due to the needs of industry security management and supervision, users of application systems, such as operating system users, database users, resource users, service authentication users, etc., need to change their passwords regularly to ensure the security and availability of their system operation.

[0004] In the course of a company's production and operation, changing the password of a system user generally requires stopping the application system service. Otherwise, the inconsistency of the password may cause the application system service to malfunction, which may lead to serious adverse consequences for the company's operations.

[0005] As enterprises continue to develop informatization and digitalization, the scale of application systems is getting larger and larger, and the number of users of various systems is also increasing. The manual verification of password information updates has become a huge burden on enterprises' safe and efficient production and operation.

[0006] Enterprise systems frequently need to interact with each other, requiring the user accounts and passwords of the called systems to be stored persistently in multiple different systems. This can lead to serious risks of password leaks. Furthermore, this situation significantly increases the risk of password inconsistency during changes, potentially causing service malfunctions between application systems due to accidental or missed password changes in different systems.

[0007] Therefore, existing methods for updating important encrypted information (secret information) in software systems generally require the application system to be shut down. Moreover, existing update methods, which require persistent storage across multiple different systems, are prone to losing user passwords during the update process, leading to service failures between application systems. Summary of the Invention

[0008] To address the aforementioned issues, this invention proposes an online automatic update method and system for confidential data required by a software system. This invention can manage and exchange confidential information and achieve loosely coupled integration between systems. It can also achieve secure isolation management of confidential data (such as system passwords and ciphertext) of system users. Without disabling application system services, it can retrieve or switch confidential data (usernames, passwords, etc. of users used by the system), thus solving the problem of exposure of confidential data (usernames and passwords) between multiple systems in an enterprise.

[0009] According to some embodiments, the first solution of the present invention provides an online automatic update method for confidential data required by a software system, which adopts the following technical solution: A method for automatically updating confidential data required by a software system online, comprising: When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

[0010] Furthermore, the software system acquires and uses encrypted and confidential information, including: The software system creates and uses user resources based on encrypted and confidential information, and asynchronously pushes creation log records to the local confidentiality management system. The local confidentiality management system then asynchronously pushes creation log records to the remote confidentiality management system and saves them. After the software system is finished using the software, it releases the user resources and asynchronously pushes a release request to the local covert management system. The local covert management system generates a release log record based on the release request and asynchronously pushes the release log record to the remote covert management system for storage.

[0011] Furthermore, based on the old confidential information of the software system, the remote confidentiality management system automatically updates the information according to the corresponding automatic update rules, plans, and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system, including: The remote covert management system determines the identification type of the old covert information based on the old covert information stored in the software system; Determine the corresponding automatic update rules, plans, and update content based on the identification type of the old hidden information; Calculate the time period of the new secret information based on the identification type of the old secret information; Based on the corresponding automatic update rules, plans, time cycles and update content, the old secret information is automatically updated to obtain the new secret information; The remote covert management system proactively pushes new covert information to the local covert management system of the software system.

[0012] Furthermore, the identifier types include single information identifiers, replaceable information identifiers, and non-replaceable information identifiers; The update of the single information identifier itself and its corresponding hidden information does not affect the operation of the software system, and only one single information identifier is needed to meet the operation requirements. The update of the replaceable information identifier itself and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally and requires the establishment of more than one different replaceable information identifier to replace each other and use them equally. The update of the irreplaceable information identifier itself and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally and can only use the irreplaceable information identifier itself.

[0013] Furthermore, the calculation of the time period for new hidden information based on the identifier type of old hidden information specifically involves: When the identifier type of the old hidden information is a replaceable information identifier, the contents of at least two replaceable information identifiers are grouped together to generate a unique identifier record. The start date of the preparation period for the new covert information = the effective end date of the old covert information - the number of days in the preparation period for the new covert information; The effective start date of the new secret message = the effective end date of the old secret message; The effective end date of the new confidential information = effective start date + update cycle - number of days in the silent period; The effective start date of the old hidden information = the system working date on which the update process was first executed; The effective end date of old hidden information = effective start date + update cycle - number of days in the silent period; The start date of the silent period for old hidden information = the effective end date of the old hidden information.

[0014] Furthermore, when the identifier type of the old hidden information is a non-replaceable identifier, if the software system is put into a pre-agreed strong control period during the update cycle, then: The effective start date of the new espionage information equals the end date of the period of strict control. The effective end date of the new escrow information = effective start date + update cycle - period of strict control; When the identifier type of the old hidden information is a single information identifier, and the specified update cycle arrives, it will be updated according to the automatic update information. The effective start date of the new hidden information = the working date of the software system that performed the update process; The effective end date of the new hidden information = effective start date + update cycle.

[0015] According to some embodiments, the second aspect of the present invention provides an online update system for confidential data required by a software application system, employing the following technical solution: An online update system for confidential data required by a software application system includes at least one remote confidential management system, multiple software systems, and a local confidential management system deployed locally. When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

[0016] According to some embodiments, a third aspect of the present invention provides a computer-readable storage medium.

[0017] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the online automatic update method for confidential data required by a software system as described in the first embodiment above.

[0018] According to some embodiments, a fourth aspect of the present invention provides a computer device.

[0019] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps in the online automatic update method for confidential data required by a software system as described in the first embodiment above.

[0020] According to some embodiments, a fifth aspect of the present invention provides a computer program product or computer program.

[0021] A computer program product or computer program includes computer instructions stored in a computer-readable storage medium, wherein a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps in the online automatic update method for confidential data required by a software system as described in the first embodiment above.

[0022] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention provides a method and mechanism to achieve secure isolation management of all confidential information within a system, greatly facilitating the classification and management of confidential information such as user categories. It enables the automatic updating and use of confidential information within the system without disabling application system services, saving labor costs. It also enables autonomous updating and use of confidential information among multiple users across large-scale systems, changing the manual updating and use methods between multiple systems, and solving and avoiding the risk of confidential data exposure due to manual maintenance. Attached Figure Description

[0023] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0024] Figure 1 This is a flowchart of obtaining hidden information in an embodiment of the present invention; Figure 2 This is a flowchart illustrating the process of pushing confidential information in an embodiment of the present invention; Figure 3 This is an architecture diagram of an online update system for confidential data required by a software application system, as described in an embodiment of the present invention. Detailed Implementation

[0025] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0026] It should be noted that the following detailed description is illustrative and intended to provide further explanation of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0027] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0028] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0029] Terminology Explanation: Secret Information: The secret information mentioned in this invention refers to important encrypted information used by the software system itself and requiring periodic adjustments. Examples include the user ID and password information of the software system's backend database; the user ID and password information of the operating system on the server hosting the software system; and the user ID and password information that need to be verified during communication or interaction between software systems.

[0030] Information identifier: This refers specifically to any unique reference point within a software system. Examples include database usernames used by the system and service IDs required for inter-system authentication.

[0031] Example 1 like Figure 1 and Figure 2 As shown, this embodiment provides a method for automatically updating confidential data required by a software system online. In this embodiment, the method includes the following steps: When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

[0032] The local covert management system refers to a client of a covert management system deployed on a software system and possessing limited covert management functions; The remote covert management system refers to the server-side of the covert management system, which is deployed on the covert management system and has all the covert management functions.

[0033] The covert management system includes at least one server and multiple clients; the server manages and stores all covert information; the clients manage and store covert information related to the relevant software system (or understood as within their permissions).

[0034] It's understandable that the software system here can be either the target software system or the user software system; the local covert management system stores and manages covert information that can be used within the permissions of the corresponding software system. The remote covert management system represents the server side of the covert management system itself, managing all covert information, while the local covert management system represents the client side, retaining only partial information—specifically, only covert information within the permissions of the corresponding software system. The remote system is the server side of the covert management system, managing all covert information; the local system is the local service of the covert management system, managing only covert information within the permissions of the local software system.

[0035] Local and remote are a combined design; the combination of local and remote is preferred in the design. For system groups with low requirements (low risk management, emergency management, etc.), the local node can be omitted. In this case, the covert management system will not perform local covert information processing. For systems with important security management, the combination of local and remote design can reduce the impact of unexpected terminal failures on the covert management system server and provide at least one covert information adjustment period for risk mitigation.

[0036] Software systems include, but are not limited to, target software systems and user software systems; among which, The target software system refers to the software system to which the confidential information stored and managed by the confidential management system belongs; The software system mentioned refers to a system that uses the hidden information of the target software system.

[0037] The software system acquires and uses encrypted and confidential information, including: The software system creates and uses user resources based on encrypted and confidential information, and asynchronously pushes creation log records to the local confidentiality management system. The local confidentiality management system then asynchronously pushes creation log records to the remote confidentiality management system and saves them. After the software system is finished using the software, it releases the user resources and asynchronously pushes a release request to the local covert management system. The local covert management system generates a release log record based on the release request and asynchronously pushes the release log record to the remote covert management system for storage.

[0038] The software system categorizes its own confidential information and registers it separately in the confidentiality management system. The confidential information includes essential key content for ease of use, mainly including categories (such as categorization into query, modification, and internal administrator permissions), available systems (systems that can be legally used), and other information, which can be found in the attribute information listed in Tables 1, 2, and 3.

[0039] Based on the confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the updated confidential information to the local confidentiality management system of the software system.

[0040] A software system can be either a target software system or a user software system. A key characteristic of a target software system is that it contains its own confidential information that it needs to maintain and is responsible for within the confidential management system. A key characteristic of a user software system is that it contains confidential information that it can legally use, but is not limited to, its own.

[0041] All confidential information belonging to the target software system is registered on the server side of the confidentiality management system; some of this confidential information is for the system's own use, while some is for use by other systems. If a software system has confidential information managed by the confidentiality management system, then that system is the target software system; if that software system also legally uses confidential information belonging to other software systems, then that software system is also a user system.

[0042] Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans, and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system. The automatic update process is as follows: It is understandable that, from the perspective of continuous availability of software systems, the hidden information used by the software system itself and the hidden information used for interaction between software systems are classified. The update method of the hidden information itself, such as the operating system user executing passwd, is not the content of this embodiment. The key content of this invention is that the use of the hidden information is unaffected before and after the update.

[0043] In this embodiment, the hidden information of the software system is divided into three categories: single information identifier, replaceable information identifier, and non-replaceable information identifier. Different rules and methods are used to manage the hidden information of different categories.

[0044] The remote covert management system determines the identification type of the old covert information based on the old covert information stored in the software system; Determine the corresponding automatic update rules, plans, and update content based on the identification type of the old hidden information; Calculate the time period of the new secret information based on the identification type of the old secret information; Based on the corresponding automatic update rules, plans, time cycles and update content, the old secret information is automatically updated to obtain the new secret information; The remote covert management system proactively pushes new covert information to the local covert management system of the software system.

[0045] The identification types include single information identification, replaceable information identification, and non-replaceable information identification; The update of the single information identifier itself and its corresponding hidden information does not affect the operation of the software system, and only one single information identifier is needed to meet the operation requirements. The update of the replaceable information identifier and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally, and more than one different replaceable information identifier needs to be established to replace each other and be used equally. At the same time, the identifier itself can establish more than one different identifier, which can replace each other and be used equally. After the replacement, the relevant programs, services or application functions of the system can be used normally.

[0046] The update of the irreplaceable information identifier itself and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally and can only use the irreplaceable information identifier itself.

[0047] When the identifier type of the old hidden information is a single information identifier, and the specified update cycle arrives, it will be updated according to the automatic update information. The effective start date of the new hidden information = the working date of the software system that performed the update process; The effective end date of the new hidden information = effective start date + update cycle.

[0048] The hidden information of the Single Message Identifier does not affect system operation; therefore, when the specified period arrives, the configured update method is executed. Changes to the related information of the Single Message Identifier do not affect system operation; therefore, the execution strategy is to set the next valid start date to equal the current working date and directly execute the update. After the update is completed, the valid start date and valid end date are calculated.

[0049] For example, the hidden information identifier SSID01 of software system SID01 is: username U1, password / key is P1; then the establishment information is shown in Table 1.

[0050] Table 1. Identification Records for Single Information Identifiers

[0051] Global stealth identifier: Each combination of stealth information is assigned a globally unique identifier.

[0052] Global group identifier: A unique identifier for the global group that needs to be established for replaceable information identifiers.

[0053] Global system identifier: A unique identifier assigned in the hidden system for software systems that are included in the management.

[0054] Update cycle: The standard update cycle for confidential information. Preparation period: The time allotted before the official effective date of the confidential information for adjusting its validity. After this period, the confidential information itself will be in a usable state.

[0055] Quiet Period: The secure, unused period before the confidential information expires and is no longer used. During this time, the confidential information itself remains available but is not actually offered for external use. After this period ends, the confidential information is placed in a temporary state. The default unit is days.

[0056] Strict control period: For non-replaceable identifiers and confidential information, no external services will be provided during this period until the update is successful.

[0057] Effective start date: The date on which the confidential information is effectively enabled.

[0058] Effective end date: The date on which the confidential information is officially discontinued. Allowed Status: Whether the conditions for updating are met. Divided into Always Allowed and Conditionally Allowed.

[0059] When the identifier type of the old hidden information is a replaceable information identifier, the contents of at least two replaceable information identifiers are grouped together to generate a unique identifier record. The start date of the preparation period for the new covert information = the effective end date of the old covert information - the number of days in the preparation period for the new covert information; The effective start date of the new secret message = the effective end date of the old secret message; The effective end date of the new confidential information = effective start date + update cycle - number of days in the silent period; The effective start date of the old hidden information = the system working date on which the update process was first executed; The effective end date of old hidden information = effective start date + update cycle - number of days in the silent period; The start date of the silent period for old hidden information = the effective end date of the old hidden information.

[0060] A method and mechanism for periodically replacing replaceable identifier-related hidden information. Based on the replaceable characteristic, a periodic rotation replacement method is used to achieve graceful replacement of old and new information, providing the latest and most effective hidden information.

[0061] The replacement process can be described as follows: a. The new secret information undergoes a preparatory availability process (how to update the content of the secret information itself and its availability status is not the focus of this invention). After completion, the new secret information is in a usable state.

[0062] The preparation date for the new secret message = the start date of the silent period for the old secret message.

[0063] b. Old, hidden information enters a period of silence.

[0064] c. When the target software system or the software system using the target software system obtains this type of secret information, the secret system provides feedback on the relevant content of the new secret information; the secret information system actively pushes the new secret information to the local secret system of the target software system / the software system using the target software system.

[0065] d. After the quiet period of the old hidden information ends, the old hidden information is suspended from use, and the suspension status is successfully completed.

[0066] In a covert system, related information with at least two replaceable identifiers is grouped together and uniquely identified. For example: The hidden information identifier RSID02 of software system SID01: username U2, password / key is P2; The hidden information identifier RSID03 of software system SID01: username U3, password / key is P3; RSID02 and RSID02 are a pair of interchangeable identifiers, and the relevant information is shown in Table 2.

[0067] Table 2. Identification Records of Replaceable Information Identifiers

[0068] When the identifier type of the old hidden information is a non-replaceable identifier, and the software system is put into a pre-agreed strong control period during the update cycle, then: The effective start date of the new espionage information equals the end date of the period of strict control. The effective end date of the new escrow information = effective start date + update cycle - period of strict control; The confidential information of the irreplaceable identifier must be subject to a "strictly controlled date", such as choosing a weekend or a date when the target software system is not in operation.

[0069] The change process can be described as follows: a. Enter the agreed mandatory control period. The number of days in the mandatory control period must be greater than the maximum overdue period; the mandatory control period should be within the update cycle.

[0070] The covert information system proactively pushes strong control status information of covert information to the target software system / the local covert system of the software system using it.

[0071] b. After the maximum timeout period is exceeded, perform a secret information update. After the update is complete, calculate the valid start and end dates.

[0072] c. After the expiration of the control period, when the target software system or the software system using the target software system obtains such confidential information, the confidential system will provide feedback on the updated confidential information; the confidential information system will proactively push the updated confidential information to the local confidential system of the target software system / the software system using the target software system.

[0073] For example, the hidden information identifier SNID04 of software system SID01 is: username U4, password / key is P4, as shown in Table 3.

[0074] Table 3 Identification Records of Non-Replaceable Information Identifiers

[0075] like Figure 2 As shown, the remote covert management system actively pushes new covert information to the local covert management system of the software system. The process is as follows: The remote covert management system proactively pushes new covert information to the local covert management system of the software system; The local covert management system replaces the old local covert information with the new covert information, thus completing the local covert information update of the software system; The local covert management system sends new covert information to the software system. The software system updates the pooled resources based on the new covert information and returns an update confirmation message to the local covert management system. The local covert management system will send an update confirmation message back to the remote covert management system.

[0076] After the remote covert management system updates the covert information, it will proactively push an update request to the local covert management system of the software system, and the local covert management system will then call the software system service to perform the internal update.

[0077] This embodiment provides an automatic renewal mechanism for confidential information used in the interaction between software systems, ensuring that the security of the interaction verification between software systems remains effective.

[0078] The covert management system itself uses this invention to manage and communicate covert information of internal nodes. With the support of encryption and security, it automatically updates covert information according to policies and rules, achieving high-strength data security without human intervention.

[0079] This embodiment provides a secure management method for confidential data exchanged between systems, which solves the problem of exposure of confidential data (usernames, passwords) between multiple systems in an enterprise. It can complete the creation, modification and maintenance of confidential information related to confidential information identification with confidential systems.

[0080] Example 2 This embodiment provides an online update system for confidential data required by a software application system, including at least one remote confidential management system, multiple software systems, and a local confidential management system deployed locally. When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

[0081] like Figure 3 As shown, the overall system architecture described in this embodiment consists of three systems: system server A1, system server A2, and remote covert management system C. Here, A1 system server and A2 system server refer to servers of different software systems; The A1 system server includes the application components of the A1 system, the main application service of the A1 system, the local privacy management system, and the privacy management service of the A1 system. The A2 system server includes the application components of the A2 system, the main application service of the A2 system, the local privacy management system, and the privacy management service of the A2 system.

[0082] The remote covert management system is divided into the remote covert management system and the application services of the covert management system.

[0083] The descriptions of each embodiment in the above embodiments have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0084] The proposed system can be implemented in other ways. For example, the system embodiments described above are merely illustrative, and the division of modules described above is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed.

[0085] Example 3 This embodiment provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in the online automatic update method for confidential data required by a software system as described in Embodiment 1 above.

[0086] Example 4 This embodiment provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps in the online automatic update method for confidential data required by a software system as described in Embodiment 1 above.

[0087] Example 5 This embodiment provides a computer program product or computer program, including computer instructions stored in a computer-readable storage medium. The processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps in the online automatic update method for confidential data required by a software system as described in Embodiment 1 above.

[0088] Those skilled in the art will understand that embodiments of the present invention can provide methods, systems, or computer program products. Therefore, the present invention can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0089] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0090] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0091] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0092] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0093] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

Claims

1. A method for automatically updating confidential data required by a software system online, characterized in that, include: When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

2. The online automatic update method for confidential data required by a software system as described in claim 1, characterized in that, The software system acquires and uses encrypted and confidential information, including: The software system creates and uses user resources based on encrypted and confidential information, and asynchronously pushes creation log records to the local confidentiality management system. The local confidentiality management system then asynchronously pushes creation log records to the remote confidentiality management system and saves them. After the software system is finished using the software, it releases the user resources and asynchronously pushes a release request to the local covert management system. The local covert management system generates a release log record based on the release request and asynchronously pushes the release log record to the remote covert management system for storage.

3. The online automatic update method for confidential data required by a software system as described in claim 1, characterized in that, The remote covert management system automatically updates the old covert information based on the software system according to the corresponding automatic update rules, plans, and update content, and actively pushes the new covert information to the local covert management system of the software system, including: The remote covert management system determines the identification type of the old covert information based on the old covert information stored in the software system; Determine the corresponding automatic update rules, plans, and update content based on the identification type of the old hidden information; Calculate the time period of the new hidden information based on the identification type of the old hidden information; Based on the corresponding automatic update rules, plans, time cycles, and update content, old secret information is automatically updated to obtain new secret information; The remote covert management system proactively pushes new covert information to the local covert management system of the software system.

4. The online automatic update method for confidential data required by a software system as described in claim 3, characterized in that, The identification types include single information identification, replaceable information identification, and non-replaceable information identification; The update of the single information identifier itself and its corresponding hidden information does not affect the operation of the software system, and only one single information identifier is needed to meet the operation requirements. The update of the replaceable information identifier itself and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally and requires the establishment of more than one different replaceable information identifier to replace each other and use them equally. The update of the irreplaceable information identifier itself and its corresponding hidden information affects the operation of the software system. After the update, the software system operates normally and can only use the irreplaceable information identifier itself.

5. The online automatic update method for confidential data required by a software system as described in claim 3, characterized in that, The calculation of the time period for new hidden information based on the identifier type of old hidden information is specifically as follows: When the identifier type of the old hidden information is a replaceable information identifier, the contents of at least two replaceable information identifiers are grouped together to generate a unique identifier record. The start date of the preparation period for the new covert information = the effective end date of the old covert information - the number of days in the preparation period for the new covert information; The effective start date of the new secret message = the effective end date of the old secret message; The effective end date of the new confidential information = effective start date + update cycle - number of days in the silent period; The effective start date of the old hidden information = the system working date on which the update process was first executed; The effective end date of old hidden information = effective start date + update cycle - number of days in the silent period; The start date of the silent period for old hidden information = the effective end date of the old hidden information.

6. The online automatic update method for confidential data required by a software system as described in claim 5, characterized in that, When the identifier type of the old hidden information is a non-replaceable identifier, and the software system is put into a pre-agreed strong control period during the update cycle, then: The effective start date of the new espionage information equals the end date of the period of strict control. The effective end date of the new escrow information = effective start date + update cycle - period of strict control; When the identifier type of the old hidden information is a single information identifier, and the specified update cycle arrives, it will be updated according to the automatic update information. The effective start date of the new hidden information = the working date of the software system that performed the update process; The effective end date of the new hidden information = effective start date + update cycle.

7. An online update system for confidential data required by a software application system, characterized in that, If it includes at least one remote covert management system, multiple software systems, and a local covert management system deployed locally, then: When the software system initiates a request for confidential information, the local confidentiality management system of the software system obtains the request and determines whether there is valid confidential information. If there is, the confidential information is returned to the software system; otherwise, the local confidentiality management system continues to send confidential information requests to the remote confidentiality management system. The remote covert management system sends covert information back to the local covert management system based on the covert information request. The local covert management system encrypts and saves the covert information and then returns it to the software system. The software system then retrieves the encrypted covert information for use. Based on the old confidential information of the software system, the remote confidentiality management system automatically updates according to the corresponding automatic update rules, plans and update content, and actively pushes the new confidential information to the local confidentiality management system of the software system.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the steps in the online automatic update method for the hidden data required by a software system as described in any one of claims 1-6.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps in the online automatic update method for the hidden data required by a software system as described in any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps in the online automatic update method for confidential data required by a software system as described in any one of claims 1-6.