Power unstructured file use control method and device, equipment, medium and program product

By acquiring information and usage requirements from unstructured power data files and using file filtering to intercept operation requests, the control problem of unstructured files in the trusted power data space is solved, achieving a balance between data security and data flow.

CN120930174APending Publication Date: 2025-11-11CHINA SOUTHERN POWER GRID BIG DATA SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510755223.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Traditional technologies struggle to achieve fine-grained control over unstructured power data, leading to security risks of data leakage and unauthorized use within the trusted power data space.

Method used

By acquiring file information and usage requirements from unstructured power files, file filtering is used to intercept operation requests. Based on user permissions and control schemes, it is determined whether to allow operations, including opening, editing, sharing, and deleting.

Benefits of technology

It enables accurate control of unstructured power data files, ensuring data security without affecting the normal circulation of files, thus improving the security and controllability of power data in the circulation and use process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930174A_ABST
    Figure CN120930174A_ABST
Patent Text Reader

Abstract

The invention relates to a power unstructured file use control method and device, computer equipment, a computer readable storage medium and a computer program product. The method is applied to an electric power trusted data space, and comprises the following steps: determining an electric power unstructured file, file information and a user main body, and obtaining file use requirement information; based on the file information and the file use requirement information, determining a use control scheme for the power unstructured file; intercepting a use operation for the power unstructured file according to the file filter driver; determining a user permission corresponding to the use operation and a permission requirement corresponding to the use operation in the use control scheme; under the condition that the user permission meets the permission requirement, the use operation is allowed; and prohibiting the use operation under the condition that the user permission does not meet the permission requirement. By adopting the method, the power unstructured file circulation based on the power trusted data space can be realized on the basis of ensuring the data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power technology, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for controlling the use of unstructured power documents. Background Technology

[0002] The digital transformation of the power industry has generated a large number of unstructured power-related documents. For the trusted power data space, the transmission, storage, and use of these documents pose security risks such as malicious copying and unauthorized access. Traditional technologies struggle to achieve fine-grained control over unstructured documents, making it easy for power data to be leaked or misused during circulation and usage. Therefore, how to control the use of unstructured power documents, thereby ensuring data security while enabling the circulation of unstructured power documents within the trusted power data space, is a technical problem that needs to be solved. Summary of the Invention

[0003] Therefore, it is necessary to provide a method, device, computer equipment, computer-readable storage medium, and computer program product for controlling the use of unstructured power documents, in order to realize the circulation of unstructured power documents based on a trusted power data space while ensuring data security.

[0004] Firstly, this application provides a method for controlling the use of unstructured power files, applied to a trusted power data space, the method comprising:

[0005] Power data is obtained from the database accessed by the trusted power data space, and a data information table corresponding to the power data is generated;

[0006] Based on the data information table, unstructured power files are identified from the power data; and the file information of the unstructured power files is determined, including the file name, file storage path, file size, and file format.

[0007] Identify the user entity corresponding to the unstructured power file and obtain the user entity's file usage requirements for the unstructured power file;

[0008] Based on the document information and document usage requirements, a usage control scheme for unstructured power documents is determined.

[0009] Upon receiving a request to use an unstructured power file, the system intercepts the use operation on the unstructured power file according to a preset file filtering driver; wherein the use operation is determined based on the use request; the use request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file;

[0010] Determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme;

[0011] If the user's permissions meet the requirements, the operation is permitted;

[0012] If the user's permissions do not meet the requirements, the operation is prohibited.

[0013] In one embodiment, based on a preset file filtering driver, operations on unstructured power files are blocked, including:

[0014] Determine the file type to which the unstructured power file belongs;

[0015] Based on the file type, determine the system operation type for unstructured power files, and obtain the system operation type;

[0016] Based on the system operation type, the target file filter driver is determined from multiple preset file filter drivers;

[0017] Based on the target file filtering driver, intercept usage operations targeting unstructured power files.

[0018] In one embodiment, the file type includes bitmap files, office files, and other file types; the system operation type includes at least one of write operations, creation operations, and rename operations.

[0019] Based on the file type, determine the system operation type for unstructured power files, resulting in the following system operation types:

[0020] When the unstructured power file is a bitmap file, the system operation type is determined to include write operations and creation operations;

[0021] When unstructured power documents fall under the category of office documents, the system operation types are determined to include write operations, creation operations, and renaming operations.

[0022] When an unstructured power file belongs to another file type, the system operation type is determined to include write operations.

[0023] In one embodiment, the file filtering driver includes a first file filtering driver, a second file filtering driver, and a third file filtering driver; the first file filtering driver is used to monitor write operations and creation operations; the second file filtering driver is used to monitor write operations, creation operations, and renaming operations; and the third file filtering driver is used to monitor write operations.

[0024] Based on the system operation type, the target file filter driver is determined from a set of preset file filter drivers, including:

[0025] When the system operation type includes write operations and creation operations, the first file filter driver is determined as the target file filter driver;

[0026] When the system operation type includes write operation, creation operation and rename operation, the second file filter driver is determined as the target file filter driver;

[0027] When the system operation type includes write operations, the third file filter driver is determined as the target file filter driver.

[0028] In one embodiment, the file usage requirement information includes at least one of file usage requirement audio information, file usage requirement text information, file usage image information, and file usage video information;

[0029] Based on document information and document usage requirements, a usage control scheme for unstructured power documents is determined, including:

[0030] The file usage requirement information is input into the pre-trained first model to perform semantic analysis on the file usage requirement information and input the file usage requirements;

[0031] Based on the document information and document usage requirements, a usage control scheme for unstructured power documents is determined.

[0032] In one embodiment, the aforementioned method further includes:

[0033] Based on a preset time interval, second power data is obtained from the database accessed by the trusted power data space;

[0034] The second power unstructured file and the second file information of the second power unstructured file are determined from the second power data.

[0035] Determine the similarity between the second document information and the document information;

[0036] If the similarity is lower than the preset similarity, the power unstructured file is updated according to the second power unstructured file; and the file information is updated according to the second file information.

[0037] Secondly, this application also provides a power unstructured document usage control device, applied to a power trusted data space, the device comprising:

[0038] The acquisition module is used to acquire power data from the database accessed by the trusted power data space and generate a data information table corresponding to the power data; based on the data information table, it identifies unstructured power files from the power data; and determines the file information of the unstructured power files; the file information includes the file name, file storage path, file size, and file format;

[0039] The control scheme determination module is used to determine the user subject corresponding to the power unstructured file and obtain the file usage requirement information of the user subject for the power unstructured file; based on the file information and the file usage requirement information, a usage control scheme for the power unstructured file is determined.

[0040] The control module is configured to, upon receiving a usage request for the unstructured power file, intercept usage operations for the unstructured power file according to a preset file filtering driver; wherein the usage operation is determined based on the usage request; the usage request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file; determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme; allow the usage operation if the user permissions meet the permission requirements; and prohibit the usage operation if the user permissions do not meet the permission requirements.

[0041] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method in the first aspect.

[0042] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method in the first aspect.

[0043] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method in the first aspect.

[0044] The aforementioned methods, devices, computer equipment, computer-readable storage media, and computer program products for controlling unstructured power files within power data determine a usage control scheme for these files based on their corresponding file information and usage requirements. Upon receiving a usage request for an unstructured power file, a file filtering driver intercepts the corresponding usage operation. By comparing the user permissions corresponding to the usage operation with the permission requirements in the usage control scheme, it determines whether the usage operation is permitted. This achieves accurate control over the usage of unstructured power files, ensures data security, and does not affect the circulation of unstructured power files within the trusted power data space. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is a diagram illustrating the application environment of a power unstructured file usage control method in one embodiment.

[0047] Figure 2 This is a flowchart illustrating the control method for using unstructured power files in one embodiment;

[0048] Figure 3 This is another flowchart illustrating the control of the use of unstructured power files in one embodiment;

[0049] Figure 4 This is another flowchart illustrating the control method for using unstructured power files in another embodiment;

[0050] Figure 5 This is a block diagram of a control device for using unstructured power files in one embodiment.

[0051] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0052] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0053] The terms "comprising" and "having," and any variations thereof, as used in this application, are intended to cover non-exclusive inclusion. The term "multiple" as used in this application refers to two or more. The term "and / or" as used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0054] The Power Trusted Data Space is a distributed critical data infrastructure built on existing information networks for data sharing, circulation, and application. Through a systematic technical arrangement, it ensures the confirmation, implementation, and maintenance of data circulation protocols, solves security and trust issues among data providers, users, and service providers, and is applied to the power energy industry to achieve goals such as building a collaborative innovation ecosystem for power data elements and driving enterprise digital transformation through cross-domain data interconnection.

[0055] The efficient flow of electricity data is fundamental to unlocking its potential value and a catalyst for improving market transaction efficiency. Creating a trusted data space and utilizing privacy computing and blockchain technology can significantly improve the security and convenience of multi-party data sharing, opening new avenues for the commercial application of electricity data. This not only promotes the compliant flow of data but also injects strong momentum into the digital transformation of the energy industry, gradually building a secure yet open data ecosystem that creates more value and opportunities for various industries, leading a new round of growth in the digital economy. The flow of data is no longer limited by traditional barriers but has become a core force driving socio-economic development, demonstrating the infinite possibilities of digital transformation.

[0056] Power data can include unstructured power documents. Unstructured power documents refer to collections of data in the power industry that lack a predefined data model or structure. Unlike tables in relational databases, they do not have explicitly defined fields and values. These documents may include free text, images, videos, and other formats, and often contain information crucial for system operation, maintenance, and fault diagnosis. For example, unstructured power documents may include equipment manuals, such as operation manuals for transformers and circuit breakers, as well as power fault analysis reports, electrical wiring diagrams, and so on.

[0057] The digital transformation of the power industry has generated a large number of unstructured power-related documents. For the trusted power data space, the transmission, storage, and use of these unstructured documents pose security risks such as data misuse, malicious copying, and unauthorized access. Traditional technologies struggle to achieve precise control over unstructured documents, making it easy for power data to be leaked or misused during circulation and usage.

[0058] Therefore, how to control the use of unstructured power files, so as to achieve the circulation of unstructured power files based on the trusted power data space while ensuring data security, is a technical problem that needs to be solved.

[0059] Based on the above analysis, this application provides a method for controlling the use of unstructured power files, which is illustrated below through embodiments:

[0060] The power unstructured file usage control method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104, or it can be located on the cloud or other network servers. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, etc. Server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0061] In one exemplary embodiment, such as Figure 2 As shown, a method for controlling the use of unstructured power files is provided, which can be applied to... Figure 1 Taking the server in the example, the server can be a server used for the trusted data space of the power industry, including the following steps S201 to S207:

[0062] Step S201: Obtain power data from the database accessed by the trusted power data space and generate a data information table corresponding to the power data.

[0063] Among them, the trusted data space for the power industry refers to the trusted data space for the power industry.

[0064] Among them, power data can be various data and information generated during the operation of the power system.

[0065] In some embodiments, power data classes may include power generation data, power grid operation data, electricity consumption data, electricity market data, etc.

[0066] In some embodiments, power data may include structured and unstructured data.

[0067] In this context, a data information table can refer to a collection of data extracted, transformed, and loaded from one or more databases, organized in a structured manner to facilitate querying, analysis, and reporting. For example, a data information table can be formed by statistical analysis based on the database from which the power data originates and the corresponding data subject.

[0068] In some embodiments, the server can obtain power data from a database accessed by the trusted power data space. The database can be a local database or a cloud database, and generate a data information table corresponding to the power data.

[0069] Step S202: Based on the data information table, identify the unstructured power files from the power data; and determine the file information of the unstructured power files; the file information includes the file name, file storage path, file size, and file format.

[0070] Among them, unstructured power files refer to power data files that do not have a fixed format or pattern.

[0071] In some embodiments, structured power data can be determined from power data based on a data information table, and unstructured power files can be determined from power data other than structured power data.

[0072] Step S203: Determine the user subject corresponding to the unstructured power file and obtain the user subject's file usage requirements information for the unstructured power file.

[0073] In this context, the user entity corresponding to the unstructured electricity data file can be, from a data asset perspective, the rights holder to which the unstructured electricity data file belongs. For example, the user entity can be the entity that uploads the relevant electricity data, or it can be the rights holder corresponding to the unstructured electricity data file determined based on blockchain technology, etc.

[0074] In some embodiments, user entities can declare corresponding file usage requirements for the unstructured power files they own and upload them to the trusted power data space, thereby forming file usage requirement information.

[0075] In some embodiments, while retrieving power data from the database accessed by the trusted power data space, information on the user's file usage requirements for unstructured power files can also be obtained.

[0076] Step S204: Based on the document information and document usage requirements, determine the usage control scheme for unstructured power documents.

[0077] In some embodiments, the importance level of unstructured power files is analyzed based on file information, such as levels 1-3. For example, keywords in the filename are extracted, and semantic analysis is performed on the filename. For instance, for unstructured power files whose filenames contain keywords such as "confidential" or "top secret," the corresponding importance level can be level 3, i.e., the most important. Furthermore, if the storage path of an unstructured power file is the same as or partially the same as the storage path of sensitive data in structured power data, then the unstructured power file can be considered to have a high importance level, such as level 3.

[0078] In some embodiments, a usage control scheme for unstructured power documents can be determined based on the importance level and usage requirements of the documents.

[0079] Step S205: Upon receiving a usage request for an unstructured power file, the usage operation for the unstructured power file is intercepted according to a preset file filtering driver; wherein the usage operation is determined based on the usage request; the usage request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file.

[0080] In some embodiments, the number of use requests can be one or more, and the duration of different use requests can be different.

[0081] In some embodiments, the preset file filtering driver can be one or more.

[0082] In some embodiments, when there are multiple preset file filtering drivers, different file filtering drivers can correspond to different usage requests.

[0083] Step S206: Determine the user permissions corresponding to the use operation, and the permission requirements corresponding to the use operation in the use control scheme.

[0084] In some embodiments, the user entity can be determined based on the usage request corresponding to the usage operation, i.e., the entity requesting the use of the unstructured power files. For example, the user entity can purchase power data assets containing unstructured power files from a user entity. Then, user permissions are determined based on the user entity; that is, user permissions can be specific to the user entity.

[0085] In some embodiments, the usage control scheme may include the permissions required to use unstructured power files. Exemplarily, different usage operations may have different or the same permission requirements.

[0086] In some embodiments, the permission requirements in the control scheme can be determined based on hierarchical classification, such as level 1 permission requirements, level 2 permission requirements, level 3 permission requirements, etc.

[0087] Step S207: If the user's permissions meet the permission requirements, allow the operation; if the user's permissions do not meet the permission requirements, prohibit the operation.

[0088] For example, user permissions could be reading permissions, but the permission requirement is editing permissions; therefore, the user permissions do not meet the permission requirement.

[0089] In some embodiments, both user permissions and permission requirements can be based on the same permission level classification standard, such as level one permission, level two permission, etc. For example, the permission level classification standard is from level one to level three, decreasing step by step. The user permission can be level one permission, and the permission requirement is level two permission. Therefore, the user permission meets the permission requirement.

[0090] The aforementioned technical solution targets unstructured power files within power data. It determines a usage control scheme for these files based on their file information and usage requirements. Upon receiving a usage request for an unstructured power file, a file filtering driver intercepts the corresponding usage operation. By comparing the user permissions corresponding to the usage operation with the corresponding permission requirements in the usage control scheme, it determines whether the usage operation is permitted. This achieves accurate control over the usage behavior of unstructured power files, ensures data security, and does not affect the circulation of unstructured power files within the trusted power data space.

[0091] In one embodiment, such as Figure 3 As shown, the aforementioned "intercepting usage operations for unstructured power files based on a preset file filtering driver" may include steps S301 to S303:

[0092] Step S301: Determine the file type to which the unstructured power file belongs.

[0093] In some embodiments, the file type to which the power unstructured file belongs can be determined by the file information corresponding to the power unstructured file, such as the file format and file name.

[0094] Step S302: Determine the system operation type for unstructured power files based on the file type, and obtain the system operation type.

[0095] Among these, system operation types can be viewed from the perspective of a computer system and refer to operations related to unstructured electrical files. For example, system operation types can include write operations, create operations, etc.

[0096] In some embodiments, a file type may correspond to one or more system operation types.

[0097] In some embodiments, the system operation types corresponding to different file types can be completely different or partially different.

[0098] Step S303: Determine the target file filter driver from multiple preset file filter drivers according to the system operation type;

[0099] In some embodiments, different file filtering drivers can intercept different usage operations.

[0100] Step S304: Based on the target file filtering driver, intercept usage operations for unstructured power files.

[0101] In some embodiments, the usage operations for unstructured power files may correspond to one or more system operations, so the file filtering driver can intercept the corresponding system operations to block the usage operations for unstructured power files.

[0102] The above technical solution determines the file type of the unstructured power file and the corresponding system operation type based on the file type. Then, based on the system operation type, it determines the target file filtering driver, thereby intercepting the usage operations of the unstructured power file.

[0103] In one embodiment, the aforementioned file type may include bitmap files, office files, and other file types; the aforementioned system operation type may include at least one of write operation, create operation, and rename operation; the aforementioned "determining the system operation type for the power unstructured file based on the file type, and obtaining the system operation type" may include: if the power unstructured file is a bitmap file, determining that the system operation type includes write operation and create operation; if the power unstructured file is an office file, determining that the system operation type includes write operation, create operation, and rename operation; if the power unstructured file is another type of file, determining that the system operation type includes write operation.

[0104] In some embodiments, bitmap files can be a type of file formatted as a bitmap. A bitmap is a format used to store digital images.

[0105] In some embodiments, office files can be document types created and used in an office environment to complete various work tasks. These file formats support multiple functions such as text editing, data processing, and presentations. For example, office files may include files in formats such as .doc, .xls, and .ppt.

[0106] In some embodiments, other file types can be unstructured power files other than bitmap files and office files. For example, other file types may include CAD engineering drawings, audio and video recordings, power grid simulation model files, etc.

[0107] The above technical solution determines different system operation types for different file types of unstructured power files, thus obtaining the system operation types. This clarifies the required system operation types for different file types and provides a decision-making basis for subsequent file filtering, thereby serving the accurate interception of usage operations for unstructured power files.

[0108] In one embodiment, the aforementioned file filtering driver includes a first file filtering driver, a second file filtering driver, and a third file filtering driver; the first file filtering driver is used to monitor write operations and creation operations; the second file filtering driver is used to monitor write operations, creation operations, and renaming operations; and the third file filtering driver is used to monitor write operations. The aforementioned "determining the target file filtering driver from a set of preset file filtering drivers based on the system operation type" may include: determining the first file filtering driver as the target file filtering driver when the system operation type includes write operations and creation operations; determining the second file filtering driver as the target file filtering driver when the system operation type includes write operations, creation operations, and renaming operations; and determining the third file filtering driver as the target file filtering driver when the system operation type includes write operations.

[0109] The above technical solution determines the target file filtering driver based on the system operation type, thereby enabling the target file filtering driver to be applicable to the interception of usage operations of the power unstructured files, ensuring accurate interception.

[0110] In one embodiment, the aforementioned file usage requirement information includes at least one of file usage requirement audio information, file usage requirement text information, file usage image information, and file usage video information; the aforementioned "determining a usage control scheme for unstructured power files based on file information and file usage requirement information" may include: inputting file usage requirement information into a pre-trained first model to perform semantic analysis on the file usage requirement information and inputting the file usage requirements; and determining a usage control scheme for unstructured power files based on the file information and file usage requirements.

[0111] The first model can be a pre-trained artificial intelligence model.

[0112] By using the first model to analyze the document usage requirements information, the document usage requirements can be extracted, and then the usage control scheme for unstructured power documents can be accurately determined based on the document information and document usage requirements.

[0113] In one embodiment, such as Figure 4 As shown, the aforementioned method may further include steps S401 to S404:

[0114] Step S401: Based on a preset time interval, obtain second power data from the database accessed by the trusted power data space.

[0115] The time interval can be dynamic or fixed, such as one minute, one hour, one day, one week, etc.

[0116] Step S402: Determine the second unstructured power file and the second file information of the second unstructured power file from the second power data.

[0117] Step S403: Determine the similarity between the second file information and the file information.

[0118] In some embodiments, the similarity between the second file information and the file information can be determined based on a preset power data model. The power data model can be a pre-trained artificial intelligence model, which can be used to identify and output the similarity between the second file information and the file information.

[0119] Step S404: If the similarity is lower than the preset similarity, update the power unstructured file according to the second power unstructured file; and update the file information according to the second file information.

[0120] The above technical solution acquires second power data periodically to obtain a second unstructured power file and second file information, and determines the similarity between the second file information and the file information. If the similarity is lower than a preset similarity, it indicates that there is a difference between the two, and the unstructured power file can be updated based on the second unstructured power file; and the file information can be updated based on the second file information to ensure the real-time performance of the unstructured power file and the file information. If the similarity is greater than the preset similarity, it indicates that the difference between the two is small, and no update is required, thus avoiding excessively frequent updates and resource waste.

[0121] In an exemplary embodiment, corresponding to the aforementioned method for controlling the use of unstructured power files, a control system for controlling the use of unstructured power files is provided. This system can be used to implement the aforementioned method for controlling the use of unstructured power files. The system may include the following:

[0122] This system includes a data usage control module. This module manages data usage after delivery, ensuring it is used according to contractual requirements and preventing data misuse, malicious copying, and other leaks. Control and record information is achieved through model information such as control strategy model data, control strategy model tables, control strategy tables, and control strategy history. Specific functions include data usage scope control, anti-copy-paste, usage time control, anti-screenshot / screen recording, application access whitelist configuration, file save-as-a-file protection, data destruction, watermark protection, data storage protection, and print protection.

[0123] Data control refers to the control over factors such as the time, place, subject, behavior, and object of data asset use through machine-readable digital contracts during the transmission, storage, use, and destruction of data.

[0124] Data control technology enables data providers to control the entire lifecycle of data, such as data revocation, usage limits (number of uses and time limits), and data destruction after use. Data control technologies mainly include control techniques, access control, and data sandboxes. Data control technology primarily addresses security and trust issues in parts of data transmission, storage, use, and destruction. It focuses on achieving controllability and auditability of data and participating parties.

[0125] Regarding "controllability": This addresses the previous problem of uncontrolled copying and dissemination of data assets due to the low cost and intangible nature of data. Data control technology uses technical means to compel data users to fulfill the terms of digital contracts, restricting unintentional or intentional actions by data users to forward data assets to unauthorized third parties, and ensuring that data assets sent by data providers and all their copies are completely destroyed after use.

[0126] Regarding "auditability": This solves the previous problem of difficulty in monitoring the data flow process. When the control strategies in digital contracts are monitored and executed, they record information such as user operations and data status as byproducts, thus forming auditable logs.

[0127] The following are the usage control guidelines for (electrical) unstructured documents:

[0128] Unstructured file information, unstructured file control information, data classification and evaluation information, data source information, dynamic and static data structure information, sensitive data identification information, data classification and evaluation information, and task management information are managed in a unified manner. Through real-time comprehensive evaluation of multiple factors, file usage control is implemented. When unstructured files are opened locally, editing permissions are controlled using file filtering technology. File filtering can control write operations on all files in the system, thereby prohibiting unauthorized operations. The main text of workflow applications is edited using Office controls, and its editing permissions are controlled similarly to those of standalone files.

[0129] 1. Unstructured File Information: Manages basic information about unstructured files, such as filename, file path, and file size. Provides basic information support for file usage control.

[0130] 2. Unstructured file control information: Defines file access permissions and control information, such as editing permissions, access permissions, user permissions, etc., used to control file editing permissions and access restrictions.

[0131] 3. Real-time monitoring routines: Real-time monitoring of files is achieved by intercepting and transmitting IRPs such as file opening, creation, and deletion, ensuring that file operations comply with predefined control policies.

[0132] Requests from user-mode programs are intercepted by the filter driver before reaching the file system driver. The filter driver compares the user permissions of the current system session with the access control permissions of the file to be operated on to determine the subsequent action of the IRP request.

[0133] Real-time file monitoring is achieved by intercepting and transmitting Instructions for File Opening, Creation, and Deletion (IRPs). Relevant filter driver routines include IRP_MJ_CREATE and IRP_MJ_SETINFORMATION. In these routines, after evaluation, IRPs that are not of interest are directly passed to the lower-level driver for processing, while IRPs of interest are either modified or returned directly to the upper layer, thus achieving real-time file monitoring from the driver layer.

[0134] Windows operating systems handle write operations differently for different file types. Simply filtering IRP_MJ_WRITE is insufficient to fully control editing permissions; association techniques are needed to identify write operations. The methods are as follows:

[0135] For BMP files (bitmap files), write operations do not operate on the original file. Instead, a new file with the same name as the original is created, overwriting the original file, and then the write operation is performed on the new file. Therefore, when controlling write operations on BMP files, an association technique is required, which involves monitoring not only write operations but also creation operations.

[0136] For Office-related files, write operations are not performed on the original file. Instead, a temporary file is first created, the write operation is performed in the temporary file, the original file is deleted after writing, and finally the temporary file is renamed back to the original file. Therefore, when using association technology to control write operations on Office-related files, in addition to monitoring write operations, it is also necessary to monitor creation and renaming operations.

[0137] For write protection of other files (other types of files), it is only necessary to control the write operation of IRP packets.

[0138] The aforementioned technical solution, in the data transmission, storage, and usage stages, utilizes multi-factor real-time comprehensive evaluation, file filtering-driven technology, real-time monitoring and auditing, and data usage control processing to uniformly manage unstructured file information, unstructured file control information, data hierarchical classification and evaluation information, data source information, dynamic and static data structure information, sensitive data identification information, data hierarchical classification information, and task management information. Through multi-factor real-time comprehensive evaluation, file usage control is implemented; when unstructured files are opened locally, editing permissions are controlled via file filtering-driven technology; file filtering-driven technology can control write operations on all files in the system, thereby prohibiting unauthorized operations. Thus, through multi-factor real-time evaluation, file filtering-driven technology, and real-time monitoring and auditing, refined usage control of unstructured power files is achieved, improving the security, controllability, and auditability of power data in the circulation and usage stages.

[0139] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0140] Based on the same inventive concept, this application also provides an electrical unstructured document usage control device for implementing the aforementioned electrical unstructured document usage control method. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations of one or more electrical unstructured document usage control device embodiments provided below can be found in the limitations of the electrical unstructured document usage control method described above, and will not be repeated here.

[0141] In one exemplary embodiment, such as Figure 5 As shown, a power unstructured document usage control device 500 is provided, applied to a power trusted data space. The device includes:

[0142] The acquisition module 501 is used to acquire power data from the database accessed by the trusted power data space and generate a data information table corresponding to the power data; based on the data information table, identify unstructured power files from the power data; and determine the file information of the unstructured power files; the file information includes file name, file storage path, file size, and file format;

[0143] The control scheme determination module 502 is used to determine the user subject corresponding to the power unstructured file and obtain the file usage requirement information of the user subject for the power unstructured file; based on the file information and the file usage requirement information, a usage control scheme for the power unstructured file is determined.

[0144] The control module 503 is configured to, upon receiving a usage request for the unstructured power file, intercept usage operations for the unstructured power file according to a preset file filtering driver; wherein the usage operation is determined based on the usage request; the usage request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file; determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme; allow the usage operation if the user permissions meet the permission requirements; and prohibit the usage operation if the user permissions do not meet the permission requirements.

[0145] In one embodiment, the control module 503 is further configured to intercept usage operations for unstructured power files based on a preset file filtering driver, including: determining the file type to which the unstructured power file belongs; determining the system operation type for the unstructured power file based on the file type, thereby obtaining the system operation type; determining a target file filtering driver from a plurality of preset file filtering drivers based on the system operation type; and intercepting usage operations for the unstructured power file based on the target file filtering driver.

[0146] In one embodiment, the file type includes bitmap files, office files, and other file types; the system operation type includes at least one of write operation, create operation, and rename operation; the control module 503 is further configured to determine the system operation type for the power unstructured file based on the file type, and obtain the system operation type, including: if the power unstructured file is a bitmap file, determining that the system operation type includes write operation and create operation; if the power unstructured file is an office file, determining that the system operation type includes write operation, create operation, and rename operation; if the power unstructured file is another type of file, determining that the system operation type includes write operation;

[0147] In one embodiment, the file filtering driver includes a first file filtering driver, a second file filtering driver, and a third file filtering driver; the first file filtering driver is used to monitor write operations and creation operations; the second file filtering driver is used to monitor write operations, creation operations, and renaming operations; the third file filtering driver is used to monitor write operations; the control module 503 is further used to determine a target file filtering driver from a plurality of preset file filtering drivers according to the system operation type, including: determining the first file filtering driver as the target file filtering driver when the system operation type includes write operations and creation operations; determining the second file filtering driver as the target file filtering driver when the system operation type includes write operations, creation operations, and renaming operations; and determining the third file filtering driver as the target file filtering driver when the system operation type includes write operations.

[0148] In one embodiment, the file usage requirement information includes at least one of file usage requirement audio information, file usage requirement text information, file usage image information, and file usage video information; the usage control scheme determination module 502 is further configured to determine a usage control scheme for the unstructured power file based on the file information and the file usage requirement information, including: inputting the file usage requirement information into a pre-trained first model to perform semantic analysis on the file usage requirement information and inputting the file usage requirements; and determining a usage control scheme for the unstructured power file based on the file information and the file usage requirements.

[0149] In one embodiment, the acquisition module 501 is further configured to acquire second power data from the database accessed by the trusted power data space based on a preset time interval; determine a second unstructured power file and second file information of the second unstructured power file from the second power data; determine the similarity between the second file information and the file information; update the unstructured power file according to the second unstructured power file if the similarity is lower than a preset similarity; and update the file information according to the second file information.

[0150] The aforementioned unstructured power documents utilize various modules within the control device, which can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware within or independently of the processor in a computer device, or stored in software within the computer device's memory, facilitating processor execution of the corresponding operations.

[0151] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data required for implementing a power unstructured document usage control method, such as power unstructured documents. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a power unstructured document usage control method.

[0152] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0153] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0154] Power data is obtained from the database accessed by the trusted power data space, and a data information table corresponding to the power data is generated;

[0155] Based on the data information table, unstructured power files are identified from the power data; and the file information of the unstructured power files is determined, including the file name, file storage path, file size, and file format.

[0156] Identify the user entity corresponding to the unstructured power file and obtain the user entity's file usage requirements for the unstructured power file;

[0157] Based on the document information and document usage requirements, a usage control scheme for unstructured power documents is determined.

[0158] Upon receiving a request to use an unstructured power file, the system intercepts the use operation on the unstructured power file according to a preset file filtering driver; wherein the use operation is determined based on the use request; the use request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file;

[0159] Determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme;

[0160] If the user's permissions meet the requirements, the operation is allowed; if the user's permissions do not meet the requirements, the operation is prohibited.

[0161] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0162] Based on the preset file filtering driver, operations targeting unstructured power files are blocked, including:

[0163] Determine the file type to which the unstructured power file belongs;

[0164] Based on the file type, determine the system operation type for unstructured power files, and obtain the system operation type.

[0165] Based on the system operation type, the target file filter driver is determined from multiple preset file filter drivers;

[0166] Based on the target file filtering driver, intercept usage operations targeting unstructured power files.

[0167] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0168] File types include bitmap files, office files, and other file types; system operation types include at least one of write operations, create operations, and rename operations.

[0169] Based on the file type, the system operation type for unstructured power files is determined, including: if the unstructured power file is a bitmap file, the system operation type includes write and create operations; if the unstructured power file is an office file, the system operation type includes write, create, and rename operations; if the unstructured power file is another type of file, the system operation type includes write operations.

[0170] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0171] The file filtering driver includes a first file filtering driver, a second file filtering driver, and a third file filtering driver; the first file filtering driver is used to monitor write operations and creation operations; the second file filtering driver is used to monitor write operations, creation operations, and renaming operations; and the third file filtering driver is used to monitor write operations.

[0172] Based on the system operation type, the target file filter driver is determined from multiple preset file filter drivers, including: when the system operation type includes write operation and creation operation, the first file filter driver is determined as the target file filter driver; when the system operation type includes write operation, creation operation and rename operation, the second file filter driver is determined as the target file filter driver; when the system operation type includes write operation, the third file filter driver is determined as the target file filter driver.

[0173] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0174] The file usage requirement information includes at least one of the following: file usage requirement audio information, file usage requirement text information, file usage requirement image information, and file usage requirement video information;

[0175] Based on document information and document usage requirements, a usage control scheme for unstructured power documents is determined, including: inputting document usage requirements into a pre-trained first model to perform semantic analysis on the document usage requirements and inputting the document usage requirements; and determining a usage control scheme for unstructured power documents based on the document information and document usage requirements.

[0176] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0177] Based on a preset time interval, second power data is obtained from the database accessed by the trusted power data space;

[0178] The second power unstructured file and the second file information of the second power unstructured file are determined from the second power data.

[0179] Determine the similarity between the second document information and the document information;

[0180] If the similarity is lower than the preset similarity, the power unstructured file is updated according to the second power unstructured file; and the file information is updated according to the second file information.

[0181] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.

[0182] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0183] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0184] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0185] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for controlling the use of unstructured power documents, characterized in that, Applied to a trusted power data space, the method includes: Power data is obtained from the database accessed by the trusted power data space, and a data information table corresponding to the power data is generated; Based on the data information table, unstructured power files are identified from the power data; and the file information of the unstructured power files is determined; the file information includes the file name, file storage path, file size, and file format; Identify the user entity corresponding to the unstructured power file and obtain the user entity's file usage requirements for the unstructured power file; Based on the file information and the file usage requirements information, a usage control scheme for the unstructured power file is determined; Upon receiving a usage request for the unstructured power file, the system intercepts the usage operation for the unstructured power file according to a preset file filtering driver; wherein the usage operation is determined based on the usage request; the usage request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file; Determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme; If the user's permissions meet the permission requirements, the usage operation is permitted; If the user's permissions do not meet the permission requirements, the operation is prohibited.

2. The method according to claim 1, characterized in that, The step of intercepting usage operations on the unstructured power files according to a preset file filtering driver includes: Determine the file type to which the unstructured power file belongs; Based on the file type, determine the system operation type for the unstructured power file; Based on the system operation type, a target file filtering driver is determined from a plurality of preset file filtering drivers; Based on the target file filtering driver, intercept usage operations targeting the unstructured power file.

3. The method according to claim 2, characterized in that, The file types include bitmap files, office files, and other file types; the system operation types include at least one of write operations, create operations, and rename operations. The step of determining the system operation type for the unstructured power file based on the file type, and obtaining the system operation type, includes: When the unstructured power file belongs to the bitmap file type, the system operation type is determined to include write operation and create operation; When the unstructured power file belongs to the office file category, the system operation type is determined to include write operation, create operation, and rename operation; If the unstructured power file belongs to the other file type, the system operation type is determined to include a write operation.

4. The method according to claim 3, characterized in that, The file filtering driver includes a first file filtering driver, a second file filtering driver, and a third file filtering driver; the first file filtering driver is used to monitor write operations and creation operations; the second file filtering driver is used to monitor write operations, creation operations, and renaming operations. The third file filtering driver is used to monitor write operations; The step of determining the target file filter driver from a plurality of preset file filter drivers according to the system operation type includes: When the system operation type includes write operation and create operation, the first file filter driver is determined as the target file filter driver; When the system operation type includes write operation, creation operation and rename operation, the second file filter driver is determined as the target file filter driver. If the system operation type includes a write operation, the third file filter driver is determined as the target file filter driver.

5. The method according to claim 1, characterized in that, The file usage requirement information includes at least one of the following: file usage requirement audio information, file usage requirement text information, file usage image information, and file usage video information; The step of determining a usage control scheme for the unstructured power documents based on the document information and the document usage requirements information includes: The file usage requirement information is input into a pre-trained first model to perform semantic analysis on the file usage requirement information and input the file usage requirements; Based on the file information and the file usage requirements, a usage control scheme for the unstructured power files is determined.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Based on a preset time interval, second power data is obtained from the database accessed by the trusted power data space; The second unstructured power file and the second file information of the second unstructured power file are determined from the second power data. Determine the similarity between the second file information and the stated file information; If the similarity is lower than a preset similarity, the power unstructured file is updated according to the second power unstructured file; and the file information is updated according to the second file information.

7. A control device for the use of unstructured electrical documents, characterized in that, The device, applied to a trusted power data space, includes: The acquisition module is used to acquire power data from the database accessed by the trusted power data space and generate a data information table corresponding to the power data; based on the data information table, it identifies unstructured power files from the power data; and determines the file information of the unstructured power files; the file information includes the file name, file storage path, file size, and file format; The control scheme determination module is used to determine the user subject corresponding to the power unstructured file and obtain the file usage requirement information of the user subject for the power unstructured file; based on the file information and the file usage requirement information, a usage control scheme for the power unstructured file is determined. The control module is configured to, upon receiving a usage request for the unstructured power file, intercept usage operations for the unstructured power file according to a preset file filtering driver; wherein the usage operation is determined based on the usage request; the usage request includes at least one of opening a file, editing a file, sharing a file, copying a file, and deleting a file; determine the user permissions corresponding to the usage operation, and the permission requirements corresponding to the usage operation in the usage control scheme; allow the usage operation if the user permissions meet the permission requirements; and prohibit the usage operation if the user permissions do not meet the permission requirements.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.