Methods and systems for secure data sharing between the first and second zones

By encrypting plaintext data and generating keys and evidence files during the data sharing process, and then transmitting it to a secure platform using network gateway technology, the problem of insufficient control by the data owner is solved, achieving a balance between data sharing and security.

CN114091058BActive Publication Date: 2026-03-31ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-08
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

During the data sharing process, the data owner has insufficient control over the shared data, and the data user may use the data for unauthorized purposes or resell it, leading to data security issues.

Method used

Using physical isolation and gateway technology, plaintext data is encrypted in the first area to generate encrypted data files, and key files and evidence files are generated according to the access permissions of the target users. These are then transmitted to a secure usage platform in the second area through the gateway. The platform controls data usage according to the security management policy of the evidence files.

Benefits of technology

This enhances the data owner's control over shared data, balancing data sharing and data security, and ensuring that data is available but not visible in the second area.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114091058B_ABST
    Figure CN114091058B_ABST
Patent Text Reader

Abstract

This specification provides a method and system for secure data sharing between a first region and a second region, wherein the second region is equipped with a secure access platform. In the first region, plaintext data to be shared with multiple users on the secure access platform is encrypted to generate an encrypted data file. A key file is generated based on the target user's access permissions to the encrypted data file. The encrypted data file needs to be accessed through the secure access platform using the key file. An evidence file is generated based on a security control policy configured for the encrypted data file, including the access permissions for each user. The encrypted data file and key file are transmitted to the target user via a network gateway. The evidence file is transmitted to the secure access platform via the network gateway, and the secure access platform controls the target user's access to the data in the encrypted data file according to the security control policy in the evidence file. This approach balances data sharing and data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to one or more embodiments in the field of computers, and more particularly to methods and systems for secure data sharing between a first region and a second region. Background Technology

[0002] While the country is vigorously promoting data openness and sharing, a core difficulty has always existed in data sharing: data security.

[0003] In the current data sharing scenario, once data is transferred from the data owner to the data user, the actual control of the data belongs to the data user. The data user can retain the data, use it in unauthorized scenarios, or even resell it. The data owner has no control over all uses of the data.

[0004] Therefore, we hope to find an improved solution that can enhance the data owner's control over shared data, thereby balancing data sharing and data security. Summary of the Invention

[0005] This specification describes one or more embodiments of a method and system for secure data sharing between a first region and a second region, which can balance data sharing and data security.

[0006] In a first aspect, a method for secure data sharing between a first region and a second region is provided, wherein the first region and the second region are physically isolated and equipped with a network gateway; the second region is equipped with a secure access platform; the method is executed in the first region, including:

[0007] The plaintext data to be shared with multiple users of the secure platform is encrypted to generate an encrypted data file;

[0008] Based on the target user's target access permissions to the encrypted data file among the multiple users, a corresponding key file is generated; wherein, the encrypted data file needs to be accessed through the secure usage platform using the key file;

[0009] A certificate of authenticity is generated based on the security control policy configured for the encrypted data file; wherein the security control policy includes the respective access permissions of the multiple users.

[0010] The encrypted data file and the key file are transmitted to the target user through the network gateway;

[0011] The evidence file is transmitted to the secure usage platform through the network gateway, so that the secure usage platform can control the target user's use of the data in the encrypted data file according to the security control policy in the evidence file.

[0012] In one possible implementation, the security level of the first area is higher than that of the second area.

[0013] In one possible implementation, the encrypted data file is encrypted using an initial key; the key file contains a derived key obtained using the initial key.

[0014] In one possible implementation, the target access permission is an access permission for a target field of the encrypted data file, and the key file is used to decrypt the data usage results of the target field.

[0015] In one possible implementation, encrypting the plaintext data to be shared with multiple users of the secure platform to generate an encrypted data file includes:

[0016] For plaintext data shared with multiple users of the secure platform, plaintext data files are generated according to predefined file generation formats and rules;

[0017] The plaintext data file is encrypted to generate the encrypted data file.

[0018] In one possible implementation, the access rights include at least one of the following:

[0019] Data usage patterns used to indicate the types of operations allowed, data usage frequency, and data usage controls used to indicate whether the data usage results are displayed in plain text or de-identified.

[0020] In one possible implementation, generating the evidence storage file according to the security control policy configured for the encrypted data file includes:

[0021] The security control strategy is encrypted to generate the evidence storage file.

[0022] In one possible implementation, the second area further includes a blockchain network; the evidence document is stored on the blockchain network by the secure usage platform.

[0023] In one possible implementation, the method further includes:

[0024] Based on the updated security control policy, generate updated evidence storage files;

[0025] The updated evidence storage file is transmitted to the secure usage platform through the network gateway, so that the platform can perform security management according to the security management policy in the updated evidence storage file.

[0026] Secondly, a method for secure data sharing between a first region and a second region is provided, wherein the first region and the second region are physically isolated and equipped with a network gateway; the second region is equipped with a secure access platform; the method is executed in the second region, including:

[0027] A target user among multiple users of the secure access platform obtains an encrypted data file and a key file through a network gateway; wherein, the encrypted data file is plaintext data from the first region that has been encrypted; the key file corresponds to the target user's target access permission to the encrypted data file; the encrypted data file needs to be accessed through the secure access platform using the key file;

[0028] The secure access platform obtains the evidence file from the first area through the network gateway; the evidence file is generated according to the security control policy configured for the encrypted data file, wherein the security control policy includes the respective access permissions of the multiple users;

[0029] The target user issues a data access request, requesting access to the encrypted data file using the key file;

[0030] In response to the data usage request, the secure usage platform controls the target user's use of data in the encrypted data file according to the security control policy in the evidence file.

[0031] In one possible implementation, the method further includes:

[0032] The secure platform authenticates the target user's identity, and if the authentication is successful, controls the target user's use of data in the encrypted data file.

[0033] In one possible implementation, the secure usage platform is equipped with a decryption toolkit;

[0034] The target user issues a data usage request, including:

[0035] The target user requests to invoke the decryption toolkit;

[0036] The control of the target user's use of data in the encrypted data file includes:

[0037] By running the decryption toolkit, the use of data in the encrypted data file is controlled according to the security management policy and using the key file.

[0038] In one possible implementation, controlling the target user's use of data in the encrypted data file includes:

[0039] Obtain the target access permissions corresponding to the target user in the security control policy;

[0040] Based on the target access permissions, the encrypted data file is used to obtain ciphertext results;

[0041] Based on the target access permissions, the encrypted result is processed using the key file to obtain the data processing result fed back to the target user.

[0042] Furthermore, the data utilizes methods including querying or dense computation.

[0043] Furthermore, the target access permissions include data usage patterns, which indicate the types of operations that the target user is allowed to perform;

[0044] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0045] Perform the cryptographic calculation of the operation type on the encrypted data file to obtain the ciphertext result.

[0046] Furthermore, the target access permissions include the frequency of data usage allowed by the target user;

[0047] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0048] Data is used on the encrypted data file if the current usage frequency is not higher than the allowed data usage frequency.

[0049] Furthermore, the target access permissions include data usage control, which indicates permission to display data usage results in plaintext;

[0050] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes:

[0051] The ciphertext result is decrypted using the key file to obtain the plaintext result, which is used as the data processing result.

[0052] Furthermore, the target access permissions include data usage control, which displays the results of data usage in an anonymized manner;

[0053] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes:

[0054] The ciphertext result is decrypted using the key file to obtain the plaintext result;

[0055] The plaintext result is anonymized to obtain the anonymized result, which is used as the data processing result.

[0056] In one possible implementation, the target access permission is access permission to a target field of the encrypted data file, and the use of the data is data use for the target field.

[0057] In one possible implementation, the second area further includes a blockchain network; the method further includes:

[0058] The secure usage platform stores the evidence files on the blockchain network;

[0059] The secure usage platform responds to the data usage request by reading the evidence file from the blockchain network.

[0060] Furthermore, the method also includes:

[0061] The secure access platform obtains the updated evidence storage file from the first area through the network gateway and stores the updated evidence storage file in the blockchain network;

[0062] The step of reading the evidence file from the blockchain network includes: reading the latest recorded evidence file in the blockchain network as the evidence file.

[0063] Thirdly, a system for secure data sharing between a first area and a second area is provided, wherein the first area and the second area are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform; the system is located in the first area and includes:

[0064] The encryption unit is used to encrypt plaintext data to be shared with multiple users of the secure platform, and generate an encrypted data file;

[0065] A key generation unit is used to generate a corresponding key file based on the target user's target access permissions to the encrypted data file generated by the encryption unit among the plurality of users; wherein the encrypted data file needs to be accessed through the secure usage platform using the key file;

[0066] The evidence generation unit is used to generate an evidence file according to the security control policy configured for the encrypted data file generated by the encryption unit; wherein, the security control policy includes the respective access permissions of the multiple users;

[0067] The transmission unit is used to transmit the encrypted data file and the key file to the target user through the network gateway; and to transmit the evidence file to the secure use platform through the network gateway, so that the secure use platform can control the target user's use of the data in the encrypted data file according to the security control policy in the evidence file.

[0068] Fourthly, a system for secure data sharing between a first area and a second area is provided, wherein the first area and the second area are physically isolated and equipped with a network gateway; a secure access platform is provided in the second area; the system is located in the second area and includes:

[0069] The target user among the multiple users of the secure usage platform is used to obtain encrypted data files and key files through a network gateway; wherein, the encrypted data file is obtained by encrypting plaintext data in the first area; the key file corresponds to the target user's target access permissions to the encrypted data file; the encrypted data file needs to be accessed through the secure usage platform using the key file;

[0070] The secure access platform is used to obtain evidence files from the first area through the network gateway; the evidence files are generated according to the security control policy configured for the encrypted data files, wherein the security control policy includes the respective access permissions of the multiple users;

[0071] The target user is also used to issue a data usage request, requesting access to the encrypted data file using the key file;

[0072] The secure usage platform is also used to respond to the data usage request and control the target user's use of data in the encrypted data file according to the security control policy in the evidence file.

[0073] Fifthly, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of the first or second aspect.

[0074] In a sixth aspect, a computing device is provided, including a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, it implements the method of the first aspect or the second aspect.

[0075] The method and system provided in the embodiments of this specification employ physical isolation between the first and second areas and are equipped with a network gateway. The second area is equipped with a secure access platform. In the first area, plaintext data to be shared with multiple users on the secure access platform is first encrypted to generate an encrypted data file. Then, based on the target user's target access permissions to the encrypted data file among the multiple users, a corresponding key file is generated. The encrypted data file needs to be accessed through the secure access platform using the key file. Next, an evidence storage file is generated according to the security control policy configured for the encrypted data file. The security control policy includes the respective access permissions of each of the multiple users. Finally, the encrypted data file and the key file are transmitted to the target user through the network gateway. The evidence storage file is also transmitted to the secure access platform through the network gateway, so that the secure access platform controls the target user's use of the data in the encrypted data file according to the security control policy in the evidence storage file. As can be seen from the above, in this embodiment of the specification, the first area does not directly transmit plaintext data to the second area. Instead, it encrypts the plaintext data to generate an encrypted data file and a key file corresponding to the target user's target access permissions. Based on the security control policy, it generates an evidence storage file. Subsequently, the encrypted data file, the key file, and the evidence storage file are transmitted to the second area through the network gateway. This allows the secure usage platform to control the target user's use of the data in the encrypted data file, achieving data usability without visibility. This enhances the data owner's control over shared data, thus balancing data sharing and data security. Attached Figure Description

[0076] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0077] Figure 1 This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification;

[0078] Figure 2 A schematic diagram illustrating a method for secure data sharing between a first region and a second region according to one embodiment is shown.

[0079] Figure 3 A schematic flowchart illustrating a method for secure data sharing between regions in a power grid according to one embodiment is shown.

[0080] Figure 4A schematic block diagram of a system for secure data sharing between a first region and a second region according to one embodiment is shown.

[0081] Figure 5 A schematic block diagram of a system for secure data sharing between a first region and a second region, according to another embodiment, is shown. Detailed Implementation

[0082] The solution provided in this specification will now be described with reference to the accompanying drawings.

[0083] Figure 1 This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification. This implementation scenario involves secure data sharing between a first region and a second region; that is, it requires balancing data sharing and data security. (Refer to...) Figure 1 The first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform. The network gateway is an information security device that connects two independent host systems using a solid-state switch read / write medium with multiple control functions. Because the two independent host systems are isolated by the network gateway, there is no physical connection, logical connection, or information transmission protocol between the systems. There is no protocol-based information exchange; only protocol-free data transfer occurs in the form of data files. Therefore, the network gateway logically isolates and blocks all network connections that could potentially attack the internal network, preventing external attackers from directly intruding, attacking, or damaging the internal network, thus ensuring the security of the internal hosts.

[0084] In this embodiment, instead of directly transmitting plaintext data to the second area for multiple users to be shared with the secure usage platform, the first area encrypts the plaintext data to generate an encrypted data file. A corresponding key file is generated based on the target user's target access permissions to the encrypted data file. An evidence file is generated based on the security control policy configured for the encrypted data file. The encrypted data file and the key file are then transmitted to the target user via the network gateway. The evidence file is then transmitted to the secure usage platform via the network gateway, allowing the secure usage platform to control the target user's use of the data in the encrypted data file according to the security control policy in the evidence file. This method enables data sharing between the data owner and the data user, and allows the data owner to control the data user's data usage, enhancing the data owner's control over the shared data and thus balancing data sharing and data security.

[0085] It should be noted that, Figure 1Although only the target user is shown, the data in the first area can be shared with multiple users of the secure platform. Since each user may have different access permissions to the aforementioned encrypted data file, it is necessary to generate a key file corresponding to the access permissions for each user. In other words, the key file obtained by each user may be different.

[0086] Figure 2 This diagram illustrates a method for securely sharing data between a first region and a second region according to one embodiment. The method can be based on... Figure 1 In the implementation scenario shown, the first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure usage platform; the method is jointly executed by the first and second areas. It should be noted that the first and second areas mentioned in the embodiments of this specification can be artificially divided functional areas, and physically they can each be composed of one or more independent host systems. Figure 2 As shown, the method for secure data sharing between a first region and a second region in this embodiment includes the following steps: Step 21, the first region encrypts plaintext data to be shared with multiple users of the secure usage platform to generate an encrypted data file; Step 22, the first region generates a corresponding key file based on the target access permissions of the target user among the multiple users for the encrypted data file; wherein, the encrypted data file needs to be accessed through the secure usage platform using the key file; Step 23, the first region generates an evidence file based on the security control policy configured for the encrypted data file; wherein, the security control policy includes the respective access permissions of the multiple users; Step 24, the first region transmits the encrypted data file and the key file to the target user through the network gateway; Step 25, the first region transmits the evidence file to the secure usage platform through the network gateway; Step 26, the target user issues a data usage request, requesting access to the encrypted data file using the key file; Step 27, the secure usage platform responds to the data usage request and controls the target user's use of the data in the encrypted data file according to the security control policy in the evidence file. The specific execution method of each of the above steps is described below.

[0087] First, in step 21, the plaintext data to be shared with multiple users of the secure platform in the first region is encrypted to generate an encrypted data file. It is understood that this encrypted data file can be provided to multiple users of the secure platform.

[0088] In one example, the security level of the first area is higher than that of the second area.

[0089] In this example, because the first area has a higher security level, while sharing data with the second area, it is also necessary to ensure that the second area's use of the data is controllable and to guarantee data security.

[0090] In one example, encrypting plaintext data to be shared with multiple users of the secure platform to generate an encrypted data file includes:

[0091] For plaintext data shared with multiple users of the secure platform, plaintext data files are generated according to predefined file generation formats and rules;

[0092] The plaintext data file is encrypted to generate the encrypted data file.

[0093] Then, in step 22, the first region generates a corresponding key file based on the target user's target access permissions to the encrypted data file among the plurality of users; wherein, the encrypted data file needs to be accessed through the secure usage platform using the key file. It is understood that the target user's use of the encrypted data file depends not only on the key file but also on the secure usage platform.

[0094] In one example, the encrypted data file is encrypted using an initial key; the key file contains a derived key obtained using the initial key.

[0095] In this example, after the target user obtains the encrypted data file and the key file, they are unable to use the key file to recover the encrypted data file into plaintext data, thus ensuring that the data shared by the users in the second area is available but not visible to the users in the first area.

[0096] In one example, the target access permission is the access permission to a target field of the encrypted data file, and the key file is used to decrypt the data usage results of the target field.

[0097] In this example, the encrypted data file includes multiple fields, and the target user may only have access to some of them.

[0098] Next, in step 23, the first region generates an evidence file based on the security control policy configured for the encrypted data file; wherein, the security control policy includes the respective access permissions of the multiple users. It is understood that the security control policy specifies how each user should specifically use the encrypted data file.

[0099] In one example, the access permissions include at least one of the following:

[0100] Data usage patterns used to indicate the types of operations allowed, data usage frequency, and data usage controls used to indicate whether the data usage results are displayed in plain text or de-identified.

[0101] For example, the data usage pattern indicates that only addition calculations are allowed, the data usage frequency indicates that the number of times it is used per year shall not exceed 10,000, and the data usage control indicates that the data usage results are displayed in anonymized form.

[0102] In one example, generating the evidence storage file according to the security control policy configured for the encrypted data file includes:

[0103] The security control strategy is encrypted to generate the evidence storage file.

[0104] In this example, the secure platform is able to decrypt the evidence file and prevent other parties from tampering with the security control policy through encryption.

[0105] In step 24, the first region transmits the encrypted data file and the key file to the target user through the network gateway. It is understood that when the encrypted data file needs to be shared with multiple users in the second region, the encrypted data file and the key file corresponding to each user need to be transmitted to each user separately through the network gateway; that is, different users may have different key files.

[0106] In the embodiments described in this specification, for the same encrypted data file, multiple key files can be generated according to the respective access permissions of different users, with each key file corresponding to the access permissions of the corresponding user.

[0107] For example, in step 22, key file A is generated based on user A's access permissions to the encrypted data file; key file B is generated based on user B's access permissions to the encrypted data file; and key file C is generated based on user C's access permissions to the encrypted data file. In step 24, the first region transmits the encrypted data file and key file A to user A through the network gateway; the first region transmits the encrypted data file and key file B to user B through the network gateway; and the first region transmits the encrypted data file and key file C to user C through the network gateway.

[0108] In step 25, the first region transmits the evidence file to the secure access platform via the network gateway. It is understood that the secure access platform is the medium through which users access encrypted data files, and the control over user access to encrypted data files is achieved through the secure access platform.

[0109] In one example, the method further includes:

[0110] The first area generates updated evidence storage files based on the updated security control policy;

[0111] The updated evidence storage file is transmitted to the secure usage platform through the network gateway, so that the platform can perform security management according to the security management policy in the updated evidence storage file.

[0112] In step 26, the target user issues a data access request, requesting access to the encrypted data file using the key file. It is understood that the user can be a device or a cluster of devices, etc.

[0113] In the embodiments described in this specification, a data usage request can be triggered by a manual instruction issued by the target user.

[0114] Finally, in step 27, the secure platform responds to the data usage request and, according to the security control policy in the evidence file, controls the target user's use of the data in the encrypted data file. It is understood that the above control may include, but is not limited to, restrictions on data usage patterns, data usage frequency, etc.

[0115] In one example, the second area also includes a blockchain network; the evidence document is stored on the blockchain network by the secure usage platform.

[0116] Blockchain technology is not a single information technology; it relies on existing peer-to-peer network communication technologies, consensus algorithms, asymmetric encryption technologies, and data storage technologies, combined with unique innovations to achieve entirely new functions. The essence and core of a blockchain network is a distributed ledger. Transaction data in the network is packaged into blocks, digitally watermarked, and linked to this ledger in chronological order. All nodes in the network hold copies of this ledger and synchronize with each other through a consensus protocol, jointly maintaining the ledger's updates. Furthermore, blockchain uses mathematical or cryptographic methods to ensure that once information is recorded in the ledger, that record can never be modified; data can only be updated by appending blocks. Blockchain solves many pain points in various industries, possessing characteristics such as distributed architecture, trustlessness, immutability, unforgeability, and traceability. It is considered to have the potential to completely transform current business operations and create new business models.

[0117] In one example, the method further includes:

[0118] The secure platform authenticates the target user's identity, and if the authentication is successful, controls the target user's use of data in the encrypted data file.

[0119] In this example, the target user can be authenticated using an account plus password method, but is not limited to that used.

[0120] In one example, the secure platform is deployed with a decryption toolkit;

[0121] The target user issues a data usage request, including:

[0122] The target user requests to invoke the decryption toolkit;

[0123] The control of the target user's use of data in the encrypted data file includes:

[0124] By running the decryption toolkit, the use of data in the encrypted data file is controlled according to the security management policy and using the key file.

[0125] In one example, controlling the target user's use of data in the encrypted data file includes:

[0126] Obtain the target access permissions corresponding to the target user in the security control policy;

[0127] Based on the target access permissions, the encrypted data file is used to obtain ciphertext results;

[0128] Based on the target access permissions, the encrypted result is processed using the key file to obtain the data processing result fed back to the target user.

[0129] Furthermore, the data utilizes methods including querying or dense computation.

[0130] Furthermore, the target access permissions include data usage patterns, which indicate the types of operations that the target user is allowed to perform;

[0131] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0132] Perform the cryptographic calculation of the operation type on the encrypted data file to obtain the ciphertext result.

[0133] Furthermore, the target access permissions include the frequency of data usage allowed by the target user;

[0134] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0135] Data is used on the encrypted data file if the current usage frequency is not higher than the allowed data usage frequency.

[0136] Furthermore, the target access permissions include data usage control, which indicates permission to display data usage results in plaintext;

[0137] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes:

[0138] The ciphertext result is decrypted using the key file to obtain the plaintext result, which is used as the data processing result.

[0139] Furthermore, the target access permissions include data usage control, which displays the results of data usage in an anonymized manner;

[0140] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes:

[0141] The ciphertext result is decrypted using the key file to obtain the plaintext result;

[0142] The plaintext result is anonymized to obtain the anonymized result, which is used as the data processing result.

[0143] Understandably, the ciphertext result is a string of uninterpretable characters, unreadable and unusable. Data usage control may require converting the ciphertext result into a decrypted state, but it is not desirable to display it directly in plaintext, so an additional layer of anonymization control is added. For example, the ciphertext result is "rasmus lerdorf", which, after decryption, will contain the plaintext result "1391000881", and will be displayed as "139****881" in an anonymized form.

[0144] In one example, the target access permission is access permission to a target field of the encrypted data file, and the use of the data is data use for the target field.

[0145] In one example, the second area also includes a blockchain network; the method further includes:

[0146] The secure usage platform stores the evidence files on the blockchain network;

[0147] The secure usage platform responds to the data usage request by reading the evidence file from the blockchain network.

[0148] Furthermore, the method also includes:

[0149] The secure access platform obtains the updated evidence storage file from the first area through the network gateway and stores the updated evidence storage file in the blockchain network;

[0150] The step of reading the evidence file from the blockchain network includes: reading the latest recorded evidence file in the blockchain network as the evidence file.

[0151] The method provided in this specification embodiment employs physical isolation between the first and second areas and is equipped with a network gateway. The second area is equipped with a secure access platform. In the first area, plaintext data to be shared with multiple users on the secure access platform is first encrypted to generate an encrypted data file. Then, based on the target user's target access permissions to the encrypted data file among the multiple users, a corresponding key file is generated. The encrypted data file needs to be accessed through the secure access platform using the key file. Next, an evidence storage file is generated according to the security control policy configured for the encrypted data file. The security control policy includes the respective access permissions of each of the multiple users. Finally, the encrypted data file and the key file are transmitted to the target user through the network gateway. The evidence storage file is also transmitted to the secure access platform through the network gateway, so that the secure access platform controls the target user's use of the data in the encrypted data file according to the security control policy in the evidence storage file. As can be seen from the above, in this embodiment of the specification, the first area does not directly transmit plaintext data to the second area. Instead, it encrypts the plaintext data to generate an encrypted data file and a key file corresponding to the target user's target access permissions. Based on the security control policy, it generates an evidence storage file. Subsequently, the encrypted data file, the key file, and the evidence storage file are transmitted to the second area through the network gateway. This allows the secure usage platform to control the target user's use of the data in the encrypted data file, achieving data usability without visibility. This enhances the data owner's control over shared data, thus balancing data sharing and data security.

[0152] Figure 3 This diagram illustrates a method flow for secure data sharing between regions in a power grid, according to one embodiment. (Refer to...) Figure 3Physical isolation and network gateways are used between the high-security zone and the low-security zone. The high-security zone is equivalent to the first area mentioned above, and the low-security zone is equivalent to the second area mentioned above. The high-security zone is equipped with a scheduling and operation platform and a high-security zone data source security adaptation platform. The scheduling and operation platform, as a real-time data source, can generate various types of data, such as operation management data, operation data, event information data, compliance-introduced external data, and market operation data. The above data can be shared as plaintext data with users in the low-security zone. The real-time data source access file generation system in the high-security zone generates plaintext data files according to predefined file generation formats and rules. The file generation system then accesses the high-security zone's data source security adaptation platform to encrypt the plaintext data files, generating encrypted data files (encrypted file generation). It also generates key files based on user access permissions for the encrypted data files; different permissions for different users correspond to different key files (data access key generation). Simultaneously, according to the high-security zone's data management requirements, security control policies are configured for the shared encrypted data files, including data user permissions such as data usage patterns, data usage frequency, and data usage control rules. After the security policies are configured, a certificate of authenticity is generated (credible certificate of permissions). The encrypted files, data access keys, and credible certificate of permissions are then transmitted unidirectionally to the low-security zone via a network gateway and distributed to the corresponding systems. The low-security zone includes the Data Security Chain, the low-security zone encrypted data security usage platform (hereinafter referred to as the security usage platform), and multiple users. The Data Security Chain is a blockchain network, and the multiple users include a power grid management platform, a customer service platform, and an operation control platform. The secure usage platform stores the contents of the trusted authorization records on the blockchain to ensure data security and auditability. Users of various business systems use the secure usage platform to determine authorization based on the latest on-chain authorization, access encrypted data files using keys according to their permissions, and perform cryptographic calculations and decryption of the results.

[0153] In the high-security zone, data owners can transmit updated access records at any time via a network gateway, ensuring their control over the data. The secure usage platform can also generate trusted access records based on user behavior with encrypted data files, storing these records on the blockchain to further guarantee data security and auditability.

[0154] This embodiment of the specification enables secure data sharing across network gateways by setting up a data security chain in the low-security zone. It enables the generation of trusted encrypted files and the setting and management of data access permissions in the high-security zone. The encrypted data files and keys are securely transmitted to the low-security zone through the network gateway. The low-security zone accesses and calculates encrypted data based on data authorization, achieving data usability without visibility, thus balancing the requirements of both data sharing and data security.

[0155] According to another embodiment, a system for secure data sharing between a first region and a second region is also provided, wherein the first region and the second region are physically isolated and equipped with a network gateway; the second region is equipped with a secure usage platform; the system is located in the first region and is used to perform the actions performed in the first region in the methods provided in the embodiments of this specification. Figure 4 A schematic block diagram of a system for secure data sharing between a first region and a second region, according to one embodiment, is shown. Figure 4 As shown, the system 400 includes:

[0156] Encryption unit 41 is used to encrypt plaintext data to be shared with multiple users of the secure platform and generate an encrypted data file;

[0157] The key generation unit 42 is used to generate a corresponding key file based on the target user's target access permissions to the encrypted data file generated by the encryption unit 41 among the plurality of users; wherein the encrypted data file needs to be accessed through the secure usage platform using the key file;

[0158] The evidence generation unit 43 is used to generate an evidence file according to the security control policy configured for the encrypted data file generated by the encryption unit 41; wherein, the security control policy includes the respective access permissions of the multiple users;

[0159] The transmission unit 44 is used to transmit the encrypted data file and the key file to the target user through the network gateway; and to transmit the evidence file to the secure use platform through the network gateway, so that the secure use platform can control the target user's use of the data in the encrypted data file according to the security control policy in the evidence file.

[0160] Optionally, as an example, the security level of the first area is higher than that of the second area.

[0161] Optionally, as an embodiment, the encrypted data file is encrypted using an initial key; the key file contains a derived key obtained using the initial key.

[0162] Optionally, as an embodiment, the target access permission is the access permission for a target field of the encrypted data file, and the key file is used to decrypt the data usage results of the target field.

[0163] Optionally, as one embodiment, the encryption unit 41 includes:

[0164] The generation subunit is used to generate plaintext data files according to predefined file generation formats and file generation rules for plaintext data to be shared with multiple users of the secure platform.

[0165] The encryption subunit is used to encrypt the plaintext data file generated by the generation subunit to generate the encrypted data file.

[0166] Optionally, as an example, the access permissions include at least one of the following:

[0167] Data usage patterns used to indicate the types of operations allowed, data usage frequency, and data usage controls used to indicate whether the data usage results are displayed in plain text or de-identified.

[0168] Optionally, as an embodiment, the evidence generation unit 43 is specifically used to encrypt the security control strategy and generate the evidence file.

[0169] Optionally, as an embodiment, the second area further includes a blockchain network; the evidence file is stored on the blockchain network by the secure usage platform.

[0170] Optionally, as an embodiment, the evidence generation unit 43 is further configured to generate updated evidence files according to the updated security control policy;

[0171] The transmission unit 44 is also used to transmit the updated evidence storage file generated by the evidence storage generation unit 43 to the secure use platform through the network gateway, so that the platform can perform security management according to the security management policy in the updated evidence storage file.

[0172] According to another embodiment, a system for secure data sharing between a first region and a second region is also provided, wherein the first region and the second region are physically isolated and equipped with a network gateway; the second region is equipped with a secure usage platform; the system is located in the second region and is used to perform the actions performed in the second region in the methods provided in the embodiments of this specification. Figure 5 A schematic block diagram of a system for secure data sharing between a first region and a second region, according to another embodiment, is shown. Figure 5 As shown, the system 500 includes:

[0173] The target user 51 among the multiple users of the secure use platform is used to obtain an encrypted data file and a key file through a network gateway; wherein, the encrypted data file is obtained by encrypting plaintext data in the first area; the key file corresponds to the target user 51's target access permission to the encrypted data file; the encrypted data file needs to be accessed through the secure use platform 52 using the key file;

[0174] The secure access platform 52 is used to obtain evidence files from the first area through the network gateway; the evidence files are generated according to the security control policy configured for the encrypted data files, wherein the security control policy includes the respective access permissions of the multiple users;

[0175] The target user 51 is also used to issue a data access request, requesting access to the encrypted data file using the key file;

[0176] The secure usage platform 52 is also used to respond to the data usage request and control the target user 51's use of data in the encrypted data file according to the security control policy in the evidence file.

[0177] Optionally, as an embodiment, the secure usage platform 52 is also used to authenticate the target user 51, and if the authentication is successful, to control the target user 51's use of data in the encrypted data file.

[0178] Optionally, as an embodiment, the secure use platform 52 is deployed with a decryption toolkit;

[0179] The target user 51 sends a data usage request, including:

[0180] Target user 51 requests to invoke the decryption toolkit;

[0181] The control of the target user 51's use of data in the encrypted data file includes:

[0182] By running the decryption toolkit, the use of data in the encrypted data file is controlled according to the security management policy and using the key file.

[0183] Optionally, as an embodiment, controlling the target user 51's use of data in the encrypted data file includes:

[0184] Obtain the target access permissions corresponding to the target user 51 in the security control policy;

[0185] Based on the target access permissions, the encrypted data file is used to obtain ciphertext results;

[0186] Based on the target access permissions, the encrypted result is processed using the key file to obtain the data processing result fed back to the target user 51.

[0187] Furthermore, the data utilizes methods including querying or dense computation.

[0188] Furthermore, the target access permissions include data usage patterns, which indicate the types of operations that the target user is allowed to perform;

[0189] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0190] Perform the cryptographic calculation of the operation type on the encrypted data file to obtain the ciphertext result.

[0191] Furthermore, the target access permissions include the frequency of data usage allowed by the target user 51;

[0192] The step of using the encrypted data file according to the target access permissions to obtain the ciphertext result includes:

[0193] Data is used on the encrypted data file if the current usage frequency is not higher than the allowed data usage frequency.

[0194] Furthermore, the target access permissions include data usage control, which indicates permission to display data usage results in plaintext;

[0195] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user 51 includes:

[0196] The ciphertext result is decrypted using the key file to obtain the plaintext result, which is used as the data processing result.

[0197] Furthermore, the target access permissions include data usage control, which displays the results of data usage in an anonymized manner;

[0198] The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user 51 includes:

[0199] The ciphertext result is decrypted using the key file to obtain the plaintext result;

[0200] The plaintext result is anonymized to obtain the anonymized result, which is used as the data processing result.

[0201] Optionally, as an embodiment, the target access permission is the access permission to a target field of the encrypted data file, and the use of the data is the use of data in the target field.

[0202] Optionally, as an embodiment, the second area further includes a blockchain network; the secure usage platform 52 is also used to store the evidence file on the blockchain network;

[0203] In response to the data usage request, the secure usage platform 52 reads the evidence file from the blockchain network.

[0204] Furthermore, the secure access platform 52 is also used to obtain updated evidence files from the first area through the gateway, and store the updated evidence files in the blockchain network;

[0205] The step of reading the evidence file from the blockchain network includes: reading the latest recorded evidence file in the blockchain network as the evidence file.

[0206] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed in a computer, causes the computer to perform a combination Figure 2 or Figure 3 The method described.

[0207] According to another embodiment, a computing device is also provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements a combination... Figure 2 or Figure 3 The method described.

[0208] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0209] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for secure sharing of data between a first region and a second region, wherein, The first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform. The method is performed in the first region, including: The plaintext data to be shared with multiple users of the secure platform is encrypted to generate an encrypted data file; Based on the target user's target access permissions to the encrypted data file among the multiple users, a corresponding key file is generated; wherein, the encrypted data file needs to be accessed through the secure usage platform using the key file; A certificate of authenticity is generated based on the security control policy configured for the encrypted data file; wherein, the security control policy includes the access permissions of each of the multiple users; the target access permission corresponding to the target user includes a data usage mode, which indicates the types of operations allowed for the target user; The encrypted data file and the key file are transmitted to the target user through the network gateway; The evidence file is transmitted to the secure usage platform through the network gateway, so that the secure usage platform controls the target user to perform the encrypted calculation of the operation type on the encrypted data file according to the security control policy in the evidence file, to obtain the ciphertext result, and to process the ciphertext result using the key file.

2. The method of claim 1, wherein, The security level of the first area is higher than that of the second area.

3. The method of claim 1, wherein, The encrypted data file is encrypted using an initial key; the key file contains a derived key obtained using the initial key.

4. The method of claim 1, wherein, The target access permission refers to the access permission for a target field of the encrypted data file, and the key file is used to decrypt the data usage result of the target field.

5. The method of claim 1, wherein, The step of encrypting plaintext data to be shared with multiple users of the secure platform to generate an encrypted data file includes: For plaintext data shared with multiple users of the secure platform, plaintext data files are generated according to predefined file generation formats and rules; The plaintext data file is encrypted to generate the encrypted data file.

6. The method of claim 1, wherein, The access permissions include at least one of the following: Data usage frequency, and data usage control used to indicate whether the data usage result is displayed in plain text or de-identified.

7. The method of claim 1, wherein, The step of generating an evidence storage file based on the security control policy configured for the encrypted data file includes: The security control strategy is encrypted to generate the evidence storage file.

8. The method of claim 1, wherein, The second area also includes a blockchain network; the evidence file is stored on the blockchain network by the secure usage platform.

9. The method of claim 1, wherein, The method further includes: Based on the updated security control policy, generate updated evidence storage files; The updated evidence storage file is transmitted to the secure usage platform through the network gateway, so that the platform can perform security management according to the security management policy in the updated evidence storage file.

10. A method for secure data sharing between a first region and a second region, wherein, The first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform. The method is performed in the second region, including: A target user among multiple users of the secure access platform obtains an encrypted data file and a key file through a network gateway; wherein, the encrypted data file is plaintext data from the first region that has been encrypted; the key file corresponds to the target user's target access permission to the encrypted data file; the encrypted data file needs to be accessed through the secure access platform using the key file; The secure access platform obtains the evidence file from the first area through the network gateway; the evidence file is generated according to the security control policy configured for the encrypted data file, wherein the security control policy includes the respective access permissions of the multiple users; The target user issues a data access request, requesting access to the encrypted data file using the key file; In response to the data usage request, the secure usage platform controls the target user's use of data in the encrypted data file according to the security control policy in the evidence file; The control of the target user's use of data in the encrypted data file includes: Obtain the target access permissions corresponding to the target user in the security control policy; the target access permissions include data usage patterns, which indicate the types of operations that the target user is allowed to perform. Perform the cryptographic calculation of the operation type on the encrypted data file to obtain the ciphertext result; Based on the target access permissions, the encrypted result is processed using the key file to obtain the data processing result fed back to the target user.

11. The method of claim 10, wherein, The method further includes: The secure platform authenticates the target user's identity, and if the authentication is successful, controls the target user's use of data in the encrypted data file.

12. The method of claim 10, wherein, The secure platform is equipped with a decryption toolkit. The target user issues a data usage request, including: The target user requests to invoke the decryption toolkit; The control of the target user's use of data in the encrypted data file includes: By running the decryption toolkit, the use of data in the encrypted data file is controlled according to the security management policy and using the key file.

13. The method of claim 10, wherein, The use of the data also includes querying.

14. The method of claim 10, wherein, The target access permissions include the frequency of data usage allowed by the target user; Based on the target access permissions, the encrypted data file is used to obtain ciphertext results, including: Data is used on the encrypted data file if the current usage frequency is not higher than the allowed data usage frequency.

15. The method of claim 10, wherein, The target access permissions include data usage controls, which indicate that data usage results are allowed to be displayed in plaintext. The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes: The ciphertext result is decrypted using the key file to obtain the plaintext result, which is used as the data processing result.

16. The method of claim 10, wherein, The target access permissions include data usage control, which shows the results of data usage in an anonymized manner; The step of processing the ciphertext result using the key file according to the target access permissions to obtain the data processing result fed back to the target user includes: The ciphertext result is decrypted using the key file to obtain the plaintext result; The plaintext result is anonymized to obtain the anonymized result, which is used as the data processing result.

17. The method of claim 10, wherein, The target access permission refers to the access permission to a target field of the encrypted data file, and the use of the data refers to the use of data in the target field.

18. The method of claim 10, wherein, The second area also includes a blockchain network; the method further includes: The secure usage platform stores the evidence files on the blockchain network; The secure usage platform responds to the data usage request by reading the evidence file from the blockchain network.

19. The method of claim 18, wherein, The method further includes: The secure access platform obtains the updated evidence storage file from the first area through the network gateway and stores the updated evidence storage file in the blockchain network; The step of reading the evidence file from the blockchain network includes: reading the latest recorded evidence file in the blockchain network as the evidence file.

20. A system for secure data sharing between a first region and a second region, wherein, The first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform. The system is located in the first area and includes: The encryption unit is used to encrypt plaintext data to be shared with multiple users of the secure platform, and generate an encrypted data file; A key generation unit is used to generate a corresponding key file based on the target user's target access permissions to the encrypted data file generated by the encryption unit among the plurality of users; wherein the encrypted data file needs to be accessed through the secure usage platform using the key file; The evidence generation unit is used to generate an evidence file according to the security control policy configured for the encrypted data file generated by the encryption unit; wherein, the security control policy includes the access permissions of the plurality of users respectively; the target access permission corresponding to the target user includes a data usage mode, which indicates the types of operations allowed to be performed by the target user; The transmission unit is used to transmit the encrypted data file and the key file to the target user through the network gateway; and to transmit the evidence file to the secure use platform through the network gateway, so that the secure use platform controls the target user to perform the encrypted calculation of the operation type on the encrypted data file according to the security control policy in the evidence file, to obtain the ciphertext result, and to process the ciphertext result using the key file.

21. A system for secure data sharing between a first region and a second region, wherein, The first and second areas are physically isolated and equipped with a network gateway; the second area is equipped with a secure access platform. The system is located in the second area and includes: The target user among the multiple users of the secure usage platform is used to obtain encrypted data files and key files through a network gateway; wherein, the encrypted data file is obtained by encrypting plaintext data in the first area; the key file corresponds to the target user's target access permissions to the encrypted data file; the encrypted data file needs to be accessed through the secure usage platform using the key file; The secure access platform is used to obtain evidence files from the first area through the network gateway; the evidence files are generated according to the security control policy configured for the encrypted data files, wherein the security control policy includes the respective access permissions of the multiple users; The target user is also used to issue a data usage request, requesting access to the encrypted data file using the key file; The secure usage platform is also used to respond to the data usage request and control the target user's use of data in the encrypted data file according to the security control policy in the evidence file; The control of the target user's use of data in the encrypted data file includes: Obtain the target access permissions corresponding to the target user in the security control policy; the target access permissions include data usage patterns, which indicate the types of operations that the target user is allowed to perform. Perform the cryptographic calculation of the operation type on the encrypted data file to obtain the ciphertext result; Based on the target access permissions, the encrypted result is processed using the key file to obtain the data processing result fed back to the target user.

22. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-19.

23. A computing device comprising a memory and a processor, wherein the memory stores executable code, and the processor, when executing the executable code, implements the method of any one of claims 1-19.

Citation Information

Patent Citations

  • Secure file sharing system

    CN103561034A

  • Cross-network data transmission method and device

    CN110417756A