An access control system and method for unstructured data in a multi-tenant environment
By introducing digest libraries and dynamic cryptography technology in a multi-tenant environment, the problems of unstructured data access control and isolation are solved, and efficient data query and high-performance data access are achieved.
Patent Information
- Application Number
- CN202111141189.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-28
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-09-28
AI Technical Summary
In a multi-tenant environment, it is difficult for the prior art to effectively realize access control and data isolation of unstructured data, especially in terms of high concurrent access and large data capacity access performance.
By introducing a digest library to manage user data and using dynamic cryptography technology to encrypt and decrypt user data, the isolation and efficient query of user data is achieved. At the same time, K-V databases are used to replace relational databases to improve data access performance.
It improves the efficiency of user data query and search, realizes user data isolation and high-performance data access, and adapts to high-concurrency scenarios in multi-tenant environments.
Smart Images

Figure CN113901407B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an access control system and method for unstructured data in a multi-tenant environment, belonging to the technical field of data security. Background Art
[0002] Saas software inevitably faces a multi-tenant environment. With the expansion of user needs, Saas software needs to process more unstructured data (text, images, videos, etc.). Currently, most Saas software uses a relational data combined with data isolation method to achieve secure data access in a multi-tenant environment. The three common data isolation methods are as follows: First, each tenant has an independent database system, but the implementation cost is too high and it is not applicable to the business scenarios of a large number of tenants; Second, multiple tenants share a database with their own independent tablespaces, but due to the concurrent access capabilities of the database itself, it is difficult to achieve identity authentication and data desensitization when multiple tenants access concurrently; Third, fields are distinguished according to tenants, but it is almost impossible to achieve data isolation and it is difficult to perform data access control for different tenants.
[0003] For unstructured data, in the case where data content needs to be encrypted, relational data can neither reflect the convenience of its SQL language nor improve the access performance of large data volumes. Such traditional data storage methods cannot provide a satisfactory solution for users in application scenarios with multi-tenants and high data security requirements. Summary of the Invention
[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide an access control system and method for unstructured data in a multi-tenant environment, which improves the efficiency of user data query and search and realizes the isolation of user data through the management of the abstract library.
[0005] To achieve the above object, the present invention is implemented by the following technical solutions:
[0006] In a first aspect, the present invention provides an access control method for unstructured data in a multi-tenant environment, including:
[0007] Receiving a user data processing request;
[0008] Performing user identity authentication based on the user data processing request;
[0009] When the user identity authentication is passed, user data processing is performed, including user data storage and user data extraction. The user data processing request includes a user data storage request and a user data extraction request, where:
[0010] The user data storage includes:
[0011] Extract parameter information based on the user data storage request, generate data digest information, and store it in the digest library;
[0012] Generate a dynamic password based on the data digest information;
[0013] After encrypting the user data object in the user data storage request based on the dynamic password, store it in the database;
[0014] The user data extraction includes:
[0015] Based on the user data extraction request, obtain data digest information and user encrypted data;
[0016] Generate a dynamic password based on the data digest information;
[0017] After decrypting the user encrypted data based on the dynamic password, extract the user data.
[0018] Furthermore, user identity authentication based on the user data processing request includes:
[0019] Retrieve the user public key on the server side through the account name registered by the user;
[0020] Decrypt the encrypted value field of the user account password based on the user public key to obtain the original encrypted value of the user account password;
[0021] Encrypt the original encrypted value of the user account password using the server private key to obtain an encrypted ciphertext;
[0022] Obtain the password ciphertext saved by the user in the user account database and compare it with the encrypted ciphertext;
[0023] If the comparison is consistent, the user identity authentication is passed, otherwise it fails.
[0024] Furthermore, the user data storage request includes the account name registered by the user, the encrypted value of the user account password, the timestamp of the user-submitted data, the title of the user data, the user unique identifier, and the user data object; the user data extraction request includes the account name registered by the user, the encrypted value of the user account password, the timestamp of the user-submitted data, the title of the user data, and the user unique identifier.
[0025] Furthermore, the user unique identifier value is the hash value of the user CA certificate or the user private key.
[0026] Furthermore, the data digest information includes the timestamp of the user-submitted data, the account name registered by the user, the hash value of the user data object, and the title of the user data.
[0027] Further, the dynamic password is 128 bits in total. The first 32 bits are the timestamp of the data submitted by the user, the second 32 bits are the unique identifier of the user, the third 32 bits are the hash value of the user data object, and the last 32 bits are the hash value of the account name registered by the user.
[0028] Further, encrypt the user data object in the user data storage request based on the dynamic password, including: using the hash value of the user data object as the key, and encrypting the user data object with the dynamic password.
[0029] Further, obtain the data summary information based on the user data extraction request, including: obtaining the complete summary information from the summary library according to the account name registered by the user and the timestamp value of the data submitted by the user.
[0030] Further, decrypt the user encrypted data based on the dynamic password, including: extracting the user data through the hash value of the user data object in the dynamic password for decryption.
[0031] In a second aspect, an access control system for unstructured data in a multi-tenant environment includes:
[0032] A user request acquisition module, configured to receive a user data processing request;
[0033] An identity authentication module, configured to perform user identity authentication based on the user data processing request;
[0034] A user data processing module, configured to perform user data processing in response to passing the user identity authentication;
[0035] The data processing module includes a user data storage module and a user data extraction module, and the user data processing request includes a user data storage request and a user data extraction request;
[0036] The user data storage request includes,
[0037] A data summary generation module, configured to extract parameter information based on the user data storage request, generate data summary information and store it in the summary library;
[0038] A dynamic password generation module, configured to generate a dynamic password based on the data summary information;
[0039] A data encryption module, configured to encrypt the user data object in the user data storage request based on the dynamic password and then store it in the database;
[0040] The user data extraction request includes:
[0041] A data acquisition module, configured to obtain data summary information and user encrypted data based on the user data extraction request;
[0042] A dynamic password generation module for generating dynamic passwords based on data digest information;
[0043] A data decryption module for decrypting user-encrypted data based on the dynamic password and then extracting user data.
[0044] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:
[0045] The present invention introduces a digest library to digest user unstructured data, greatly improving the query and search efficiency of user data. At the same time, user data isolation is achieved through the management of the digest library. In addition, through dynamic password technology, the encryption of user data without landing is realized, ensuring that user data is in the hands of users themselves. Moreover, a K-V type database is used to replace the relational database to ensure the high speed and high concurrency performance of user data access. Description of the Drawings
[0046] Figure 1 It is a flowchart of user stored data provided by Embodiment 1 of the present invention;
[0047] Figure 2 It is a flowchart of user read data provided by Embodiment 1 of the present invention. Detailed Embodiments
[0048] The present invention will be further described below with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and cannot be used to limit the protection scope of the present invention.
[0049] Embodiment 1:
[0050] A method for accessing control of unstructured data in a multi-tenant environment. On the premise that it is assumed that the user already has a CA certificate or has exchanged public keys with the server and has completed user registration, the user stores data according to the following steps:
[0051] 1. When the user initiates an unstructured data storage request, the user needs to submit data according to the API interface function setdata(username, password, timestamp, title, data, sign) set by the present invention, where username is the account name registered by the user, password is the encrypted value of the user account password (encrypted using the user's private key), timestamp represents the timestamp of the user submitting data, title represents the title of the user data, data is the user data object, that is, the original text of the data submitted by the user, and sign is the user's unique identifier. The sign value is the Hash value of the user's CA certificate or the user's private key.
[0052] 2. After the server receives the user request, it performs user identity authentication. It retrieves the user's public key on the server side through the username, decrypts the password field, and then encrypts the original password using the server's private key. It compares the encrypted password with the ciphertext of the user's password stored in the user account database to perform user identity authentication. If the authentication fails, an error is returned.
[0053] 3. If the identity authentication is successful, the server receives the user data storage request, extracts the parameter information through the API interface function, and generates the data digest information and stores it in the digest library, including: the hash value of timestamp, username, data, and title (using timestamp and username as the first secret key, and title and the hash value of data as the first ciphertext).
[0054] 4. Generate the dynamic password. The dynamic password is 128 bits in total. The first 32 bits are the timestamp, the second 32 bits are the sign, the third 32 bits are the hash value of the date, and the last 32 bits are the hash value of the username.
[0055] 5. Use the dynamic password to encrypt the data with the hash value of the data as the second secret key. The ciphertext is the second ciphertext, which is stored in the user database to complete the entire data storage process.
[0056] The user extracts data according to the following steps:
[0057] 1. When the user initiates an unstructured data extraction request, the user needs to perform a data extraction request according to the API interface function getdata(username, password, timestamp, title, sign) set in the present invention, where username is the user's registered account name, password is the encrypted value of the user account password (encrypted using the user's private key), timestamp represents the timestamp when the user submits the data (which can be empty), title represents the title of the user data, and sign is the user's unique identifier. The sign value is the Hash value of the user's CA certificate or the user's private key.
[0058] 2. After the server receives the user request, it performs user identity authentication. It retrieves the user's public key on the server side through the username, decrypts the password field, and then encrypts the original password using the server's private key. It compares the encrypted password with the ciphertext of the user's password stored in the user account database to perform user identity authentication. If the authentication fails, an error is returned.
[0059] 3. Obtain the complete summary information from the summary library according to the username and timestamp values, including: the hash value of the user data data.
[0060] 4. Generate a dynamic password. The dynamic password is 128 bits in total. The first 32 bits are the timestamp, the second 32 bits are the sign, the third 32 bits are the hash value of the date, and the last 32 bits are the hash value of the username.
[0061] 5. Extract the user data through the hash value of the data, decrypt it and return the data to the user to complete the user data extraction process.
[0062] Embodiment 2:
[0063] An access control system for unstructured data in a multi-tenant environment, including:
[0064] A user request acquisition module, configured to receive a user data processing request;
[0065] An identity authentication module, configured to perform user identity authentication based on the user data processing request;
[0066] A user data processing module, configured to perform user data processing in response to passing the user identity authentication;
[0067] The data processing module includes a user data storage module and a user data extraction module, and the user data processing request includes a user data storage request and a user data extraction request;
[0068] The user data storage request includes,
[0069] A data summary generation module, configured to extract parameter information based on the user data storage request, generate data summary information and store it in the summary library;
[0070] A dynamic password generation module, configured to generate a dynamic password based on the data summary information;
[0071] A data encryption module, configured to encrypt the user data object in the user data storage request based on the dynamic password and then store it in the database;
[0072] The user data extraction request includes:
[0073] A data acquisition module, configured to acquire data summary information and user encrypted data based on the user data extraction request;
[0074] A dynamic password generation module, configured to generate a dynamic password based on the data summary information;
[0075] A data decryption module, which is used to decrypt the user's encrypted data based on the dynamic password and then extract the user data.
[0076] Embodiment 3:
[0077] The embodiment of the present invention further provides an access control device for unstructured data in a multi-tenant environment, including a processor and a storage medium;
[0078] The storage medium is used to store instructions;
[0079] The processor is used to operate according to the instructions to execute the steps of the following method:
[0080] Receive a user data processing request;
[0081] Perform user identity authentication based on the user data processing request;
[0082] When the user identity authentication is passed, perform user data processing, including user data storage and user data extraction. The user data processing request includes a user data storage request and a user data extraction request, where:
[0083] The user data storage includes:
[0084] Extract parameter information based on the user data storage request, generate data digest information and store it in the digest library;
[0085] Generate a dynamic password based on the data digest information;
[0086] Encrypt the user data object in the user data storage request based on the dynamic password and then store it in the database;
[0087] The user data extraction includes:
[0088] Obtain data digest information and user encrypted data based on the user data extraction request;
[0089] Generate a dynamic password based on the data digest information;
[0090] Decrypt the user encrypted data based on the dynamic password and then extract the user data.
[0091] Embodiment 4:
[0092] The embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the following method are implemented:
[0093] Receive a user data processing request;
[0094] Perform user identity authentication based on the user data processing request;
[0095] When the user authentication is passed, user data processing is performed, including user data storage and user data extraction. The user data processing request includes a user data storage request and a user data extraction request, where:
[0096] The user data storage includes:
[0097] Extract parameter information based on the user data storage request, generate data digest information and store it in the digest library;
[0098] Generate a dynamic password based on the data digest information;
[0099] After encrypting the user data object in the user data storage request based on the dynamic password, store it in the database;
[0100] The user data extraction includes:
[0101] Based on the user data extraction request, obtain the data digest information and the user encrypted data;
[0102] Generate a dynamic password based on the data digest information;
[0103] After decrypting the user encrypted data based on the dynamic password, extract the user data.
[0104] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0105] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0106] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the processes and / or blocks Figure 1 one or more of the processes and / or blocks Figure 1 specified in one or more of the blocks or blocks.
[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes and / or blocks Figure 1 one or more of the processes and / or blocks Figure 1 specified in one or more of the blocks or blocks.
[0108] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. An access control method for unstructured data in a multi-tenant environment, characterized in that, Including: Receiving a user data processing request; Performing user identity authentication based on the user data processing request; When the user identity authentication is passed, performing user data processing, including user data storage and user data extraction; The user data processing request includes a user data storage request and a user data extraction request, where: The user data storage includes: Extracting parameter information based on the user data storage request, generating data digest information and storing it in the digest library; Generating a dynamic password based on the data digest information; Using the dynamic password to encrypt the user data object with the hash value of the user data object as the key, and then storing it in the database; The user data extraction includes: Based on the user data extraction request, obtaining data digest information and user encrypted data; Generating a dynamic password based on the data digest information; Extracting the user data after decrypting it by extracting the user data object's hash value in the dynamic password, and then extracting the user data; The data digest information includes the timestamp of the user-submitted data, the account name registered by the user, the hash value of the user data object, and the title of the user data; Based on the user data extraction request, obtaining data digest information, including: obtaining the complete digest information from the digest library according to the account name registered by the user and the timestamp value of the user-submitted data.
2. The access control method for unstructured data in a multi-tenant environment according to claim 1, characterized in that Performing user identity authentication based on the user data processing request, including: retrieving the user public key on the server side through the account name registered by the user; decrypting the encrypted value field of the user account password using the user public key to obtain the original encrypted value of the user account password; encrypting the original encrypted value of the user account password using the server private key to obtain the encrypted ciphertext; obtaining the password ciphertext saved by the user in the user account database and comparing it with the encrypted ciphertext; if the comparison is consistent, the user identity authentication is passed, otherwise it fails.
3. The access control method for unstructured data in a multi-tenant environment according to claim 1, characterized in that, The user data storage request includes the account name registered by the user, the encrypted value of the user account password, the timestamp of the user-submitted data, the title of the user data, the user unique identifier, and the user data object; the user data extraction request includes the account name registered by the user, the encrypted value of the user account password, the timestamp of the user-submitted data, the title of the user data, and the user unique identifier.
4. The access control method for unstructured data in a multi-tenant environment according to claim 3, wherein The user unique identifier value is the hash value of the user CA certificate or the user private key.
5. The access control method for unstructured data in a multi-tenant environment according to claim 1, wherein The dynamic password is 128 bits in total. The first 32 bits are the timestamp of the user-submitted data, the second 32 bits are the user unique identifier, the third 32 bits are the hash value of the user data object, and the last 32 bits are the hash value of the account name registered by the user.
6. An access control system for unstructured data in a multi-tenant environment, characterized in that, Including: A user request acquisition module for receiving a user data processing request; An identity authentication module for performing user identity authentication based on the user data processing request; A user data processing module for performing user data processing when the user identity authentication is passed; The data processing module includes a user data storage module and a user data extraction module, and the user data processing request includes a user data storage request and a user data extraction request; The user data storage request includes, A data digest generation module for extracting parameter information based on the user data storage request, generating data digest information and storing it in the digest library; A dynamic password generation module for generating dynamic passwords based on data digest information; A data encryption module for encrypting a user data object with a dynamic password using the hash value of the user data object as a key and storing it in a database; The user data extraction request includes: A data acquisition module for acquiring data digest information and user encrypted data based on a user data extraction request; A dynamic password generation module for generating dynamic passwords based on data digest information; A data decryption module for decrypting and extracting user data by extracting the user data through the hash value of the user data object in the dynamic password; The data digest information includes the timestamp of the user-submitted data, the account name registered by the user, the hash value of the user data object, and the title of the user data; Based on a user data extraction request, acquiring data digest information includes: acquiring complete digest information from a digest library according to the account name registered by the user and the timestamp value of the user-submitted data.
Citation Information
Patent Citations
Data obtaining method based on access key
CN107306246A
Multi-tenant based cloud platform tenant management method and industrial Internet of Things cloud platform for implementing method
CN107896220A