Service execution

By injecting bytecode programs into the service link to acquire and process business data, the problem of inefficiency in the prior art is solved, and efficient data security processing is achieved.

WO2025108032A1PCT designated stage expired Publication Date: 2025-05-30ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Patent Information

Application Number
PCT/CN2024/128493
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-21
Filing Date
2024-10-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When the existing technology adds data security processing strategies to the business link, it is less efficient and requires code transformation and re-launch.

Method used

By determining the process identification and target injection point of the target process, the preset bytecode program is injected into the target process, the original business data is obtained and processed through the data security component, and the original data is replaced to continue the execution of the business.

Benefits of technology

It improves the efficiency of adding data security processing strategies to the business links, and avoids the steps of code transformation and re-launch.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128493_30052025_PF_FP_ABST
    Figure CN2024128493_30052025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present description are a service execution method and apparatus, a storage medium and an electronic device, used for privacy protection. The method comprises determining a process number of a target process and determining a target injection point in the target process; on the basis of the process number and the target injection point, injecting a preset byte code program into the target injection point of the target process; and by means of the byte code program, acquiring original service data at the target injection point in the target process and calling a data security component to process the original service data to obtain processed service data, so as to continue to execute the remaining service corresponding to the process on the basis of the processed service data. According to the method, the data security component can be called by means of the byte code program to process the original service data at the target injection point in a service link, and then the process can continue to execute the service on the basis of the processed service data, such that compared with the prior art, the efficiency of adding a security processing policy in the service link is improved to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Business Execution Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a method, device, storage medium, and electronic device for executing a service. Background Art

[0002] With the continuous development of information technology, various online platforms are enriching people's lives, and with them comes a large demand for ensuring information security. That is, online platforms have the obligation and need to ensure the security of the privacy data of the platform and its users.

[0003] Therefore, within online platforms, data security must be implemented for certain business processes. For example, when displaying database data on a front-end page, the data must be desensitized before display. Another example is when storing private data, homomorphic encryption can be performed before storage.

[0004] In the existing technology, when it is necessary to add a data security processing policy to a business link, code modification is required and then the system is put back online, which is often inefficient.

[0005] Therefore, how to improve the efficiency of incorporating data security processing strategies into business links is an urgent problem to be solved.

[0006] Summary of the Invention

[0007] This specification provides a method, device, storage medium, and electronic device for executing a service to improve the efficiency of adding data security processing functions to a service link.

[0008] This manual adopts the following technical solutions.

[0009] This specification provides a method for business execution, including: determining the process identifier of a target process used to execute a target business, and determining a target injection point in the target process; injecting a preset bytecode program into the target injection point of the target process according to the process identifier and the target injection point; obtaining, through the bytecode program, the original business data required for the target process to use at the target injection point when executing the target business; calling, through the bytecode program, a pre-deployed data security component to process the original business data through the data security component to obtain processed business data; and continuing to execute the target business through the target process based on the processed business data.

[0010] Optionally, determining the process ID of the target process used to execute the target business includes: querying the process IDs of each running process; selecting the target process used to execute the target business from the processes, and determining the process ID of the target process.

[0011] Optionally, the bytecode program is used to obtain the original business data required for the target injection point when the target process executes the target business, specifically including: obtaining the original business data in the local variable table corresponding to the target injection point when the target process executes the target business, and pushing the original business data into the operand stack; calling a pre-deployed data security component through the bytecode program to process the original business data through the data security component to obtain processed business data, specifically including: calling the data security component through the bytecode program to process the original business data in the operand stack to obtain processed business data, and returning the processed business data to the operand stack; based on the processed business data, continuing to execute the target business through the target process, specifically including: replacing the original business data in the local variable table with the processed business data in the operand stack through the bytecode program, so as to continue to execute the target business through the target process based on the processed business data in the local variable table.

[0012] Optionally, the target injection point is identified by a fully qualified class name and a fully qualified method name.

[0013] This specification provides a device for business execution, including: a determination module, used to determine the process identifier of a target process used to execute a target business, and to determine a target injection point in the target process; an injection module, used to inject a preset bytecode program into the target injection point of the target process according to the process identifier and the target injection point; an acquisition module, used to obtain, through the bytecode program, the original business data required for the target process to use at the target injection point when executing the target business; a calling module, used to call a pre-deployed data security component through the bytecode program, so as to process the original business data through the data security component to obtain processed business data; and an execution module, used to continue to execute the target business through the target process based on the processed business data.

[0014] Optionally, the determination module is specifically configured to query the process identifiers of the running processes; select a target process used to execute the target business from the processes, and determine the process identifier of the target process.

[0015] Optionally, the acquisition module is specifically used to obtain, through the bytecode program, the original business data in the local variable table corresponding to the target injection point when the target process executes the target business, and push the original business data into the operand stack; the calling module is specifically used to call the data security component through the bytecode program to process the original business data in the operand stack, obtain processed business data, and return the processed business data to the operand stack; the execution module is specifically used to replace the original business data in the local variable table with the processed business data in the operand stack through the bytecode program, so as to continue to execute the target business through the target process based on the processed business data in the local variable table.

[0016] Optionally, the target injection point is identified by a fully qualified class name and a fully qualified method name.

[0017] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method for executing the above-mentioned service is implemented.

[0018] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned service execution method when executing the program.

[0019] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects.

[0020] In the service execution method provided in this specification, the process identifier of the target process used to execute the target service is determined, as well as the target injection point in the target process. Then, based on the process identifier and the target injection point, a preset bytecode program can be injected into the target injection point of the target process. Furthermore, the bytecode program can be used to obtain the original service data required by the target process at the target injection point when executing the target service. The bytecode program calls a pre-deployed data security component to process the original service data through the data security component to obtain processed service data. Based on the processed service data, the target service is continued to be executed through the target process.

[0021] From the above content, it can be seen that the business execution method provided in this specification can obtain the business data that needs to be securely processed in the business chain through a pre-written bytecode program, and call the data security component through the bytecode program to process the original business data at the target injection point in the business chain of the process. The process can then continue to execute the business based on the processed business data, thereby improving the efficiency of adding security processing strategies to the business chain to a certain extent compared to the existing technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings described herein are used to provide further understanding of this specification and constitute a part of this specification. The illustrative embodiments of this specification and their descriptions are used to explain this specification and do not constitute improper limitations on this specification.

[0023] FIG1 is a flow chart of a method for executing a service in this specification.

[0024] FIG2 is a schematic diagram of a bytecode injection provided in this specification.

[0025] FIG3 is a schematic diagram of a device for executing a service provided in this specification.

[0026] FIG4 is a schematic diagram of an electronic device provided in this specification corresponding to FIG1 . DETAILED DESCRIPTION

[0027] To make the objectives, technical solutions, and advantages of this specification more clear, the following will clearly and completely describe the technical solutions of this specification in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this specification.

[0028] The technical solutions provided by the embodiments of this specification are described in detail below with reference to the accompanying drawings.

[0029] FIG1 is a flow chart of a method for executing a service in this specification, which specifically includes the following steps.

[0030] S100: Determine a process identifier of a target process used to execute a target business, and determine a target injection point in the target process.

[0031] S102: Injecting a preset bytecode program into the target injection point of the target process according to the process identifier and the target injection point.

[0032] When a server runs a software system, the software system can be used to execute one or more businesses. In order to execute the business, there may be many processes inside the server. Different processes exist under different businesses, and the functions executed by each process may be different.

[0033] As the need to ensure data security becomes increasingly important for online platforms, online platforms need to add data security processing strategies to the continuous business links in the software systems running on internal servers and other devices. This requires adding data security processing logic to the process.

[0034] Based on this, the server can determine the process ID of the target process used to execute the target business, and determine the target injection point in the target process. Then, according to the process ID and the target injection point, the preset bytecode program can be injected into the target injection point of the target process.

[0035] The server may query the process identifiers of the running processes (the process identifiers may be process ids), and may select a target process used to execute the target business from the processes, and determine the process identifier of the target process.

[0036] Specifically, there can be multiple target processes. For example, when a process needs to obtain data from a database through network transmission and display it on a front-end page (such as a web page or a user's app), this process can be a target process. For another example, when a process needs to store the obtained data in a system log, this process can be a target process.

[0037] It should be noted that the target process can be selected manually, so that after querying the process IDs of each process, the process ID of the target process can be obtained.

[0038] Because the process ID of a process may change each time the server is started, the application name and process ID corresponding to each process can be queried. Each process's application name and process ID correspond one-to-one. By determining the application name corresponding to the target process requiring data security processing among the processes used to execute the target business, the process ID of the target process can be located using the application name. The jps command can be used to query the application name and process ID of each process running on the server.

[0039] The target business mentioned above can also be defined according to actual needs. For example, the server maintains payment business, transaction business, etc., and the business that needs to add data security processing can be selected as the target business.

[0040] S104: Obtaining, through the bytecode program, original business data required for the target process to use at the target injection point when executing the target business.

[0041] S106: calling a pre-deployed data security component through the bytecode program to process the original business data through the data security component to obtain processed business data.

[0042] S108: Based on the processed business data, continue to execute the target business through the target process.

[0043] After determining the process identifier of the target process and the target injection point in the target process, the preset bytecode program can be injected into the target injection point of the target process to obtain the original business data at the target injection point in the target process through the bytecode program, and the pre-deployed data security component can be called through the bytecode program to process the original business data through the data security component to obtain processed business data, so as to continue to execute the above-mentioned target business based on the processed business data.

[0044] The above-mentioned bytecode program can be artificially written in the form of bytecode (Java bytecode), and the above-mentioned data security component can be in the form of a jar package. The function of the bytecode program is: after being injected into the target injection point, it obtains the original business data that needs to be securely processed at the target injection point, calls the data security component to process the original business data, and obtains the processed business data.

[0045] It is necessary to combine Java's attach mechanism and instrumentation mechanism to inject bytecode programs. The process ID can be specified through the attach mechanism to start the injector (agant program), and the bytecode program can be injected into the target process through the injector combined with the instrumentation mechanism.

[0046] Among them, through the above-mentioned bytecode program, the original business data in the local variable table corresponding to the target injection point in the target process can be obtained, and the original business data can be pushed into the operand stack. Then, the bytecode program can be used to call the data security component to process the original business data in the operand stack to obtain the processed business data, and return the processed business data to the operand stack. The bytecode program replaces the original business data in the local variable table with the processed business data in the operand stack to complete the processing of the original business data. Then, the target process can continue to execute the target business based on the processed business data in the local variable table.

[0047] It should be noted that the raw business data mentioned here can be data that requires security processing, such as data involving user privacy. Therefore, the bytecode program can filter out data of the target type from the local variable table as the raw business data, and the target type can be manually set.

[0048] FIG2 is a schematic diagram of a bytecode injection provided in this specification.

[0049] As shown in Figure 2, assuming the target injection point is between logic A and logic B, after the bytecode program is injected and the process executes logic A, the bytecode program will call the data security component to perform security processing on the original business data and return the processed business data to its original location, allowing the process to continue executing logic B. This allows data security processing policies to be added to the business chain without the user's awareness.

[0050] Therefore, the data security component mentioned above may be a program specifically used to process data securely. For example, the data security component may encrypt or desensitize the data. For another example, the data security component may also be used to perform security verification on users.

[0051] For example, original business data related to the user's identity can be obtained, and the user's identity can be authenticated through the data security component based on the original business data. The processed business data can be used to indicate whether the user's identity authentication is successful.

[0052] It should be noted that the above target injection points can be identified by fully qualified class names and fully qualified method names.

[0053] From the above content, it can be seen that the business execution method provided in this specification can obtain the business data that needs to be securely processed in the business chain through a pre-written bytecode program, and call the data security component through the bytecode program to process the original business data at the target injection point in the business chain of the process. The process can then continue to execute the business based on the processed business data, thereby improving the efficiency of adding security processing strategies to the business chain to a certain extent compared to the existing technology.

[0054] It should be noted that, for ease of description, the execution subject of this method is described as a server in the above content. The execution subject of this method can be a computer, a large service platform, etc., which is not limited here.

[0055] The above is a method for executing services provided in one or more embodiments of this specification. Based on the same idea, this specification also provides a device for executing services, as shown in FIG3 .

[0056] Figure 3 is a schematic diagram of a business execution device provided in this specification, which specifically includes: a determination module 301, used to determine the process identifier of the target process used to execute the target business, and to determine the target injection point in the target process; an injection module 302, used to inject a preset bytecode program into the target injection point of the target process according to the process identifier and the target injection point; an acquisition module 303, used to obtain, through the bytecode program, the original business data required for the target process to use at the target injection point when executing the target business; a calling module 304, used to call a pre-deployed data security component through the bytecode program, so as to process the original business data through the data security component to obtain processed business data; an execution module 305, used to continue to execute the target business through the target process based on the processed business data.

[0057] Optionally, the determining module 301 is specifically configured to query the process IDs of the running processes; select a target process used to execute the target business from the processes, and determine the process ID of the target process.

[0058] Optionally, the acquisition module 303 is specifically used to obtain, through the bytecode program, the original business data in the local variable table corresponding to the target injection point when the target process executes the target business, and push the original business data into the operand stack; the calling module 304 is specifically used to call the data security component through the bytecode program to process the original business data in the operand stack, obtain processed business data, and return the processed business data to the operand stack; the execution module 305 is specifically used to replace the original business data in the local variable table with the processed business data in the operand stack through the bytecode program, so as to continue to execute the target business through the target process based on the processed business data in the local variable table.

[0059] Optionally, the target injection point is identified by a fully qualified class name and a fully qualified method name.

[0060] This specification also provides a computer-readable storage medium, which stores a computer program. The computer program can be used to execute the above-mentioned service execution method.

[0061] This specification also provides a schematic structural diagram of the electronic device shown in Figure 4. As shown in Figure 4, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above-mentioned service execution method. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0062] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages ​​and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.

[0063] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules that implement the method and structures within the hardware component.

[0064] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or physical devices, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0065] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0066] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0067] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0068] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0069] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0070] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0071] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0072] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0073] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0074] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0075] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing nodes connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage nodes.

[0076] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

[0077] The foregoing is merely an example of the present invention and is not intended to limit the present invention. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.

Claims

1. A method for executing a business, comprising: Determine the process identifier of the target process used to execute the target business, and determine the target injection point in the target process; Injecting a preset bytecode program into the target injection point of the target process according to the process identifier and the target injection point; Obtaining, through the bytecode program, original business data required to be used at the target injection point when the target process executes the target business; By means of the bytecode program, a pre-deployed data security component is called to process the original business data by means of the data security component to obtain processed business data; Based on the processed business data, continue to execute the target business through the target process.

2. The method according to claim 1, determining the process identifier of the target process used to execute the target service, comprising: Query the process ID of each running process; A target process used to execute the target business is selected from the processes, and a process identifier of the target process is determined.

3. The method according to claim 1, wherein the original business data required for use at the target injection point when the target process executes the target business is obtained through the bytecode program, specifically comprising: Obtaining, through the bytecode program, original business data in the local variable table corresponding to the target injection point when the target process executes the target business, and pushing the original business data into the operand stack; The bytecode program is used to call a pre-deployed data security component to process the original business data through the data security component to obtain processed business data, specifically including: Calling a data security component through the bytecode program to process the original business data in the operand stack to obtain processed business data, and returning the processed business data to the operand stack; Based on the processed business data, continuing to execute the target business through the target process specifically includes: The original business data in the local variable table is replaced by the processed business data in the operand stack through the bytecode program, so as to continue to execute the target business through the target process based on the processed business data in the local variable table.

4. The method as claimed in claim 1, wherein the target injection point is identified by a fully qualified class name and a fully qualified method name.

5. A device for executing a service, comprising: A determination module, used to determine the process identifier of a target process used to execute a target business, and to determine a target injection point in the target process; An injection module, used for injecting a preset bytecode program into a target injection point of the target process according to the process identifier and the target injection point; An acquisition module, used to acquire, through the bytecode program, the original business data required to be used at the target injection point when the target process executes the target business; A calling module, used to call a pre-deployed data security component through the bytecode program, so as to process the original business data through the data security component to obtain processed business data; An execution module is used to continue executing the target business through the target process based on the processed business data.

6. In the device as described in claim 5, the determination module is specifically used to query the process identifier of each running process; select a target process used to execute the target business from the various processes, and determine the process identifier of the target process.

7. The device according to claim 5, wherein the acquisition module is specifically used to acquire, through the bytecode program, the original business data in the local variable table corresponding to the target injection point when the target process executes the target business, and push the original business data into the operand stack; The calling module is specifically used to call the data security component through the bytecode program to process the original business data in the operand stack to obtain processed business data, and return the processed business data to the operand stack; The execution module is specifically used to replace the original business data in the local variable table with the processed business data in the operand stack through the bytecode program, so as to continue to execute the target business through the target process based on the processed business data in the local variable table.

8. In the device as described in claim 5, the target injection point is identified by a fully qualified class name and a fully qualified method name.

9. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 4.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 4 when executing the program.

Citation Information

Patent Citations

  • Data desensitization method and device, readable storage medium and electronic equipment

    CN115185534A

  • Data processing method and device, storage medium and electronic equipment

    CN115357940A

  • Data protection method and device, storage medium and electronic equipment

    CN115495777A

  • Service execution method and device, storage medium and electronic equipment

    CN117592104A

  • Software upgrading using dynamic link library injection

    US20220334828A1

Cited By

  • Trusted data space construction method and equipment based on Eclipse EDC and medium

    CN120805194A