Android mobile phone data security protection system and method

By combining the mobile security management center and the Android sandbox, precise permission management and transparent encryption/decryption of Android phone data are achieved, solving the problems of permission misguidance, insufficient user awareness, and easy cracking of encryption in Android phone data security protection, and ensuring data security and privacy.

CN121351069APending Publication Date: 2026-01-16BEIJING NORMAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511288847.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-10
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing Android phone data security protections suffer from issues such as misleading app permissions, insufficient user security awareness, easy cracking of encrypted files, and high risk of data leakage. In particular, in mobile office scenarios, enterprise and government data are easily stolen.

Method used

It employs a mobile security management center, an Android sandbox, and a security protection app to achieve identity management, permission management, security model management, and app behavior analysis. Through precise access control and transparent encryption/decryption technology, it prevents unauthorized access and illegal theft of data.

Benefits of technology

It enables precise permission management and encrypted storage of Android phone data, preventing malicious apps and viruses from stealing data and ensuring the security and privacy of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121351069A_ABST
    Figure CN121351069A_ABST
Patent Text Reader

Abstract

The invention discloses an Android mobile phone data security protection system, which comprises a mobile phone security management center, an Android sandbox and a security protection APP, and is characterized in that the mobile phone security management center is used for providing unified security management service for mobile phone security, and the security protection APP is deployed in the Android sandbox. The system is used for realizing login of a mobile phone user to a mobile phone security control center, issuing of a security protection strategy and security protection of mobile phone data. Through identity management and authority management of the mobile phone user, authority management of the mobile phone user on the APP is realized, through the system, safe operation protection of the mobile phone APP is realized, and through accurate access control of the APP accessing the Android system API, the situation that the APP realizes unauthorized access of mobile phone user data through unauthorized access of the API is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of Android mobile phone data security protection, and particularly relates to a system and method for Android mobile phone data security protection. BACKGROUND

[0002] With the popularity of smart phones, the functions loaded on the smart phones also increase, and the main way of loading functions is to deploy and install mobile phone APPs on the mobile phones. The data interaction between the mobile phone APPs and the APP servers is also more and more frequent, so there is a risk of illegally stealing data through APPs, and there are two scenarios: 1) the mobile phone APP is an illegal or imitated APP, and leaves a backdoor for stealing mobile phone information, with the purpose of illegally stealing the mobile phone data and other APP data of the user using the APP, and stealing the mobile phone data, 2) the mobile phone APP is maliciously attacked and implanted with a virus, and the virus file maliciously obtains the data on the mobile phone or the data of other APPs from the mobile phone.

[0003] Currently, mobile office is becoming more and more popular, so there are some key data related to enterprises and government affairs on the mobile phones, so if these data are stolen, it may bring great loss to enterprises and government departments.

[0004] The current permission control on the mobile phone is mainly to set the permissions of the APP applications on the mobile phone, strictly control the APP permissions, only grant the necessary permissions to the APP, and encrypt the files on the mobile phone to ensure that the file information is not stolen. The current APP access permission control mainly has the following problems: Some APPs mislead the mobile phone users to open the permissions that may lead to data leakage from the business needs, in order to steal data; The mobile phone users have weak security protection consciousness, and there is randomness in opening the permissions, which leads to data being stolen; The APPs lack awareness of the acquisition of the mobile phone user data, and there is malicious operation of the mobile phone and illegal stealing of the mobile phone user's own data or other office APP related data without the knowledge of the mobile phone user, which brings great loss to the mobile phone user or the enterprise or unit where the user is located.

[0005] The current file encryption mainly has the following problems: The encrypted files have the risk of being cracked; Due to the lack of data security awareness, it is difficult to ensure that all sensitive files are encrypted, and there is a high possibility of sensitive file information leakage. SUMMARY

[0006] The application aims to provide a system and method for Android mobile phone data security protection to solve the technical problems proposed in the background.

[0007] To achieve the above object, the specific technical solutions of the present application are as follows: a system for data security protection of an Android mobile phone, comprising a mobile phone security management center, an Android sandbox and a security protection APP, the mobile phone security management center being used for providing unified security management service for mobile phone security, the security protection APP being disposed in the Android sandbox and being used for realizing login of a mobile phone user to a mobile phone security control center, issuing of a security protection strategy and realizing security protection of mobile phone data; wherein the mobile phone security management center comprises: an identity management module, used for identity management of the mobile phone user, supporting registration of the mobile phone user and user authentication; a permission management module, used for providing access API and access data permission for a mobile phone APP; a security model management module, used for setting a mobile phone data security protection model; an APP behavior analysis module, used for receiving APP access Android system API log of the mobile phone, performing behavior analysis, discovering malicious APP and giving an alarm to the mobile phone user in time.

[0008] Preferably, the permission management module comprises a control center administrator assisting the mobile phone user in performing mobile phone APP permission management and the mobile phone user designing mobile phone APP permission by himself.

[0009] Preferably, the security model management module comprises: an alarm model, used for alarming APP access Android system API interface and data and notifying the mobile phone user; an access permission confirmation model, used for confirming authorization of APP access Android system API interface and data by the mobile phone user; a mobile phone user self access permission model, used for allowing the mobile phone user who has successfully logged in the control center to access APP service; an audit model, used for formulating audit of APP access Android system API and access data file.

[0010] Preferably, the security protection APP comprises: a mobile phone user security login module, used for realizing login of the mobile phone user to the control center through the security protection APP; a permission strategy acquisition module, used for acquiring, through the security protection APP, access Android system API permission of the APP disposed on the mobile phone from the control center and performing permission control of the APP through an API permission list of each APP; an access control module for providing Android API, used for intercepting access of the APP on the mobile phone to Android API through the security protection APP by providing API access control.

[0011] This invention also relates to a method for protecting data security on Android mobile phones, comprising the following steps: S1. Mobile phone users register in the mobile security control center and set access permissions for the APP; S2. In the mobile security control center, set up a security protection model based on the security protection capabilities supported by the mobile security APP; S3. Mobile users install a mobile protection app, log in to the control center through the app, download permission policies and security models, and perform access control.

[0012] Preferably, the API access permissions for each APP in step S1 include: Mobile phone users register in the mobile security control center and set the apps they can access; Specify the list of Android APIs accessed by the app; Mobile users can select the security model they need for their applications.

[0013] Preferably, the security protection model in step S2 includes: The authorization confirmation sub-model is used to confirm the API of the Android system; The file encryption strategy model is used to set encryption key strategies for files; An unauthorized API access detection model is used to confirm that an app accesses an API it does not have permission to access. AI behavior analysis models are used to analyze an app's API access behavior and data access behavior to discover behavioral patterns. The audit model is used to clearly define how the APP audits API and data access, and sends the audit logs to the control center.

[0014] Preferably, step S3 specifically includes the following steps: Mobile users can install a mobile security app, launch the app, and enter their account and password to securely log in to the control center. After the control center successfully authenticates the user, it issues an identity token to the user. Mobile phone users can set their own security policies or follow the default security policies set by the control center administrator; The mobile security app downloads permission policies and security protection models from the control center and automatically activates the permission policies and security protection models. The security protection app starts security protection on the phone. f. The control center performs statistical analysis on the logs, creates user and APP behavior profiles, issues alerts for any abnormal user or APP behavior, and intelligently distributes policies to directly control the normal operation of the APP.

[0015] Preferably, the step e specifically comprises the following steps: 1) the user clicks the APP deployed in the Android sandbox, the security APP judges whether there is a token, and determines whether the user has the right to access the APP under the premise that there is a token, if there is the right, the access is allowed; 2) the user clicks the business APP to process the business, the API access control component of the security APP obtains the id and API information of the APP, and controls the access right of the APP when the current user uses the APP to access the API, controls through the right control strategy, and starts the security protection model, confirms whether the mobile user authorization is needed through the protection model to access the API, if needed, the authorization page is popped up, if there is the right and needs to be authorized again, the access is allowed after the authorization again; 3) the business APP accesses the file, the API access control component of the security APP obtains the accessed file by intercepting the content of the file access API, then calls the right control strategy to confirm whether the data can be accessed, and confirms that the data can be accessed under the premise, calls the security protection model to confirm whether the mobile user confirmation authorization is needed, if needed, the authorization page is popped up, and the data can be accessed after the authorization; 4) the accessed data is transparently encrypted and decrypted according to the transparent encryption and decryption strategy, and access control is realized; 5) in the whole access, the APP and the API data access are audited according to the sub-model strategy of the security protection model, and the log is sent to the control center.

[0016] The system and method for Android mobile phone data security protection have the following advantages: 1. The application realizes the right management of the mobile user to the APP application through the identity management and right management of the mobile user, realizes the safe operation protection of the mobile APP through the system, and avoids the overright access of the APP to the API to realize the overright access of the mobile user data through the precise access control of the APP to the Android system API.

[0017] 2. The application realizes the right control of the mobile data through the precise control of the data access API interface, prevents the overright access of the data, realizes the trusted storage of the data through the transparent encryption and decryption technology on the basis of the Android sandbox, and prevents the malicious user from obtaining the plaintext data. BRIEF DESCRIPTION OF DRAWINGS

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained from these drawings without creative effort.

[0019] Figure 1 This is a schematic diagram of the overall structure of the present invention; Figure 2 This is a schematic diagram of the access control layer for the APP in this invention. Detailed Implementation

[0020] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the spirit or scope of the embodiments of the invention. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.

[0021] In the description of the embodiments of the present invention, it should be understood that the terms "length", "vertical", "horizontal", "top", "bottom", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only for the convenience of describing the embodiments of the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the embodiments of the present invention.

[0022] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of embodiments of the present invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0023] In this embodiment of the invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection, an electrical connection, or a communication connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this embodiment of the invention according to the specific circumstances.

[0024] The following disclosure provides many different implementations or examples for carrying out different structures of the embodiments of the present invention. To simplify the disclosure of the embodiments of the present invention, specific examples of components and arrangements are described below. Of course, these are merely examples and are not intended to limit the embodiments of the present invention. Furthermore, reference numerals and / or reference letters may be repeated in different examples of the embodiments of the present invention; such repetition is for simplification and clarity and does not in itself indicate a relationship between the various implementations and / or arrangements discussed.

[0025] To better understand the purpose, structure, and function of this invention, the following detailed description of a system and method for data security protection of Android mobile phones, in conjunction with the accompanying drawings, is provided.

[0026] like Figures 1-2 As shown, the present invention provides a system for protecting Android mobile phone data security, including a mobile security management center, an Android sandbox, and a security protection APP. The mobile security management center is used to provide unified security management services for mobile phone security; wherein, the mobile security management center includes: The identity management module is used to manage the identity of mobile phone users. It supports mobile phone user registration and user authentication. After the mobile phone user turns on the phone, the user logs in through the security protection APP. After logging in, the security control center can grant the APP access to the mobile phone system API and security model to protect the mobile phone data. The permission management module is used to provide mobile apps with permissions to access APIs and data. Control center administrators assist mobile users in managing mobile app permissions: This can be configured by the control center security administrator. For example, precise settings can be made regarding which API interface access permissions are required for certain frequently used apps, and access can be blocked for certain apps that may pose a risk of data leakage (mobile users may be allowed to enable or disallow access, to prevent mobile user data leakage); Mobile users can design their own mobile app permissions: Mobile users can manage API permissions and data access for the apps installed on their phones; The security model management module, located in the control center, allows you to set up a mobile data security protection model. The security model mainly includes the following: ²Alarm Model: The app accesses which Android system API interfaces and data, triggers an alarm, and notifies the mobile phone user. ²Access permission confirmation model: Apps need the confirmation and authorization of the mobile phone user before they can access the API interfaces and data of the Android system; ²Mobile User Self-Access Permission Model: This model defines which app services a mobile user is only allowed to access after successfully logging into the control center. When accessing certain API interfaces or data on the Android system, the app must submit an access request to the control center for authorization before access can be granted. This prevents unauthorized access by unauthorized users. Audit Model: The audit model sets out the audit for APP access to Android system APIs and access to data files. When the model is executed, the mobile phone system will send the access audit information to the control center. The APP behavior analysis module is used to analyze the behavior of received mobile phone APP access to Android system API logs, detect malicious APPs, and promptly alert mobile phone users.

[0027] The security app is deployed in an Android sandbox to enable mobile users to log in to the mobile security control center, distribute security policies, and protect mobile data. Its main functions are as follows: Secure login for mobile users: Mobile users can log in to the control center through a security-protected app; Permission policy acquisition: The security protection app obtains the access permissions of the apps deployed on the phone to the Android system API from the control center; the app's permissions are controlled through the API permission list of each app. Provide access control for Android APIs: In security apps, API access control is provided to intercept access to Android APIs from apps on the phone, and to perform API access control. The main functions include: Based on the APP permission control list, control the APP's access to Android APIs, and only API permissions allowed by the policy can be accessed. It can grant permission confirmation to mobile apps when they access Android system APIs. Only after the mobile user has granted permission can the app access the Android API. App access control: It can control the access permissions of apps deployed in the sandbox, ensuring that only mobile users who have successfully logged in to the control center can use certain apps; Log auditing is performed on the APP's API access behavior, and the log audit information is sent to the control center. The audit center analyzes the logs, assesses the trustworthiness of the APP, and promptly notifies mobile phone users of APPs suspected of being malicious. Data generated by the app and user data are encrypted and access controlled according to encryption policies: It can transparently encrypt and decrypt app files. An encryption / decryption driver layer is added to ensure that stored app files and user data files are encrypted. For file reading, access control is implemented through the data access API according to policy permissions, thereby controlling read and write permissions for data files.

[0028] This invention also relates to a method for protecting data security on Android mobile phones, comprising the following steps: S1. Mobile phone users register in the mobile security control center and set access permissions for apps. The permissions for each app to access the API include: Mobile phone users register in the mobile security control center and set the apps they can access; Specify the list of Android APIs that your app can access. In the security control center, there is a default list of Android system APIs that can be controlled. Select the list of APIs that each app can access. Mobile users select the security model they need for the application; S2. In the mobile security control center, based on the security protection capabilities supported by the mobile security APP, set up a security protection model, which includes: Authorization confirmation sub-model: Confirms that Android system APIs require confirmation from the mobile phone user before they can be used; File encryption strategy model: Which files need to be encrypted, and the encryption key setting strategy; Unauthorized API Access Detection Model: If an app accesses an API it does not have permission to, it is identified as a high-risk, unauthorized access, and an alert is generated in a timely manner. AI behavior analysis model: Analyzes the API access behavior and data access behavior of the APP, discovers behavioral patterns, and promptly alerts the APP for behaviors that deviate from the patterns; Audit model: Clearly define the audit of the APP's API and data access, and send the audit logs to the control center; S3. Mobile users install a mobile protection app, log in to the control center through the app, download permission policies and security models, and perform access control. This includes the following steps: Mobile users can install a mobile security app, launch the app, and enter their account and password to securely log in to the control center. After the control center successfully authenticates the user, it issues an identity token to the user. Mobile phone users can set their own security policies or follow the default security policies set by the control center administrator; The mobile security app downloads permission policies and security protection models from the control center and automatically activates the permission policies and security protection models. The security protection app initiates security protection on the phone, which includes the following steps: 1) When a user clicks on an app deployed in the Android sandbox, the protected app checks if there is a token. If so, it checks if the user has permission to access the app. If the user has permission, it allows access. 2) When a user clicks on the business APP to process business, the API access control component of the security protection APP obtains the APP's ID and API information, and controls the APP's access to the API when the current user is using the APP. This is done through permission control policies. At the same time, the security protection model is activated to confirm whether the mobile phone user needs to authorize access to the API. If so, an authorization page pops up. If the user has permission but needs to authorize again, then authorization is granted before access is allowed. 3) When a business app accesses a file, the API access control component of the security protection app intercepts the content of the file access API, obtains the file to be accessed, and then calls the permission control policy to confirm whether the data can be accessed. If access is confirmed, the security protection model is called to confirm whether the mobile user needs to confirm authorization. If so, an authorization page pops up, and access can only be granted after authorization. 4) For accessed data, transparent encryption and decryption are performed according to a transparent encryption and decryption strategy to achieve access control; 5) Throughout the entire access process, log auditing is performed on the access to APP and API data according to the sub-model policies of the security protection model, and the logs are sent to the control center; f. The control center performs statistical analysis on the logs, creates user and APP behavior profiles, issues alerts for any abnormal user or APP behavior, and intelligently distributes policies to directly control the normal operation of the APP.

[0029] Here, "APP" refers to third-party applications for smartphones. Some well-known app stores include... Apple's App Store, Google's Google Play Store, Anzhi Marketplace, BlackBerry App World for BlackBerry users, Microsoft's Marketplace, and so on.

[0030] Android sandbox: A computer science term, in the security field, it's a security mechanism that provides an isolated environment for programs running on the Android system. Through the Android sandbox, developers can control access to Android system APIs by enabling mobile apps to run on the device. The Android sandbox is a built-in feature of the Android system that protects apps and mobile data by isolating the application's runtime environment and preventing direct interaction between different applications or malicious attacks. Its core functions are reflected in the following aspects: Each application runs under a unique user ID (UID) and process. The system achieves resource separation through process isolation and user permission mechanisms in the Linux kernel. By default, applications cannot directly access the resources of other applications, such as data or system functions, which effectively prevents malware from spreading across applications.

[0031] Android sandboxes restrict application permissions by default, such as prohibiting unauthorized phone calls and data reading. When an application attempts to perform malicious behavior (such as cross-process data theft), the system will directly block it. This mechanism is based on SELinux's mandatory access control, combined with dynamic permission management (such as Android 15's dynamic permission wall), which can adjust permissions in real time to deal with abnormal behavior.

[0032] The Android sandbox allows software developers to add a driver layer for accessing Android APIs, enabling access control for apps' access to Android. Figure 2 The levels shown: The API access control layer can control an app's access to Android API interfaces, preventing malicious APIs from making unauthorized access to Android system APIs.

[0033] It is understood that the present invention has been described through some embodiments, and those skilled in the art will recognize that various changes or equivalent substitutions can be made to these features and embodiments without departing from the spirit and scope of the invention. Furthermore, under the teachings of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the invention. Therefore, the present invention is not limited to the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application are within the protection scope of the present invention.

Claims

1. A system for protecting data security on Android mobile phones, characterized in that: The mobile phone security management center, an Android sandbox and a security protection APP are included, the mobile phone security management center is used for providing unified security management service for mobile phone security, the security protection APP is arranged in the Android sandbox and is used for realizing login of a mobile phone user to a mobile phone security control center, issuing of a security protection strategy and realizing security protection of mobile phone data; wherein the mobile phone security management center includes: An identity management module is used for identity management of the mobile phone user, supports mobile phone user registration and user authentication; A permission management module is used for providing access API and data access permission for the mobile phone APP; A security model management module is used for setting a mobile phone data security protection model; An APP behavior analysis module is used for receiving APP access Android system API log of the mobile phone, performing behavior analysis, finding malicious APP and timely alarming the mobile phone user.

2. The system for securing data of an Android phone according to claim 1, wherein: The permission management module includes control center administrator assisting the mobile phone user in mobile phone APP permission management and the mobile phone user designing mobile phone APP permission by himself.

3. The system for securing data of an Android phone according to claim 1, wherein: The security model management module includes: An alarm model is used for alarming APP access Android system API interface and data, notifying the mobile phone user; An access permission confirmation model is used for confirming APP access Android system API interface and data through the mobile phone user authorization; A mobile phone user self access permission model is used for allowing the mobile phone user successfully logging in the control center to access APP service; An audit model is used for formulating audit of APP access Android system API and access data file.

4. The system for securing data of an Android phone according to claim 1, wherein: The security protection APP includes: A mobile phone user security login module is used for realizing login of the mobile phone user to the control center through the security protection APP; A permission strategy acquisition module is used for acquiring access Android system API permission of the APP arranged on the mobile phone from the control center through the security protection APP, performing APP permission control through API permission list of each APP; An Android API access control module is used for intercepting APP access Android API access on the mobile phone through API access control provided in the security protection APP.

5. A method for securing data of an Android mobile phone, characterized in that: The steps include: S1, the mobile phone user registers in the mobile phone security control center and sets access APP permission; S2, in the mobile phone security control center, a security protection model is set according to security protection capability supported by the mobile phone security APP; S3, the mobile phone user installs the mobile phone protection APP, logs in the control center through the mobile phone protection APP, downloads permission strategy and security model and performs access control.

6. The method for securing data of an Android phone according to claim 5, characterized in that: The permission of each APP access API in the step S1 includes: The mobile phone user registers in the mobile phone security control center and sets accessible APP; The Android API list accessed by the APP is determined; The mobile phone user selects a security model to be applied.

7. The method of claim 5, wherein the method further comprises: The security protection model in the step S2 includes: An authorization confirmation submodel is used for confirming Android system API; A file encryption strategy model is used for setting file encryption key strategy; An unauthorized access API detection model is used for confirming APP access API without permission; An AI behavior analysis model is used to analyze API access behavior and data access behavior of the APP and find behavior rules. An audit model is used to audit API and data access of the APP and send audit logs to the control center.

8. The method of claim 5, wherein the method further comprises: The step S3 specifically includes the following steps: A mobile phone user installs a mobile phone protection APP, inputs an account and a password after starting the APP, and performs a secure login to the control center. The control center issues an identity token token to the user after the user authentication is successful. The mobile phone user sets a security policy of his own or follows a security policy set by default by an administrator of the control center. The mobile phone protection APP downloads a permission policy and a security protection model from the control center and automatically starts the permission policy and the security protection model. The security protection APP starts to protect the mobile phone. The control center performs statistical analysis on logs, portraits a user and an APP behavior, alarms abnormal behaviors of the user and the APP, and intelligently issues a policy to directly control normal operation of the APP.

9. The method of claim 8, wherein the method further comprises: The step e specifically includes the following steps: 1) The user clicks the APP deployed in an Android sandbox, the protection APP determines whether there is a token token, determines whether the user has a permission to access the APP on the premise that there is the token token, and allows access if the user has the permission. 2) The user clicks a business APP to perform business processing, an API access control component of the security protection APP acquires an id and API information of the APP, performs access control on a permission of the APP to access an API when the user uses the APP, controls the permission through a permission control policy, starts a security protection model, confirms whether the user needs to authorize the access to the API through the protection model, pops up an authorization page if the user needs to authorize, and allows the access after the user authorizes again if the user has the permission and needs to authorize again. 3) The business APP performs file access, the API access control component of the security protection APP acquires accessed files by intercepting content of a file access API, confirms whether the data can be accessed by calling a permission control policy, confirms whether the data can be accessed on the premise that the data can be accessed, calls the security protection model, confirms whether the user needs to authorize, pops up an authorization page if the user needs to authorize, and allows the access after the user authorizes. 4) The accessed data is transparently encrypted and decrypted according to a transparent encryption and decryption policy to realize access control. 5) During the whole access, logs of access of the APP to API data are audited according to a sub-model policy of the security protection model, and the logs are sent to the control center.