A data security access system, method, device and medium based on zero trust system

By generating a unique data identity identifier in the data gateway and combining digital identity key encryption technology, the problems of insufficient data source identity information recording and low public and private key encryption performance in the existing technology are solved, the traceability of data sources and the controllability of data users are realized, the usage needs of data sharing by multiple people are met, and the cost is reduced.

CN115514523BActive Publication Date: 2025-05-09BEIJING NORMAL UNIVERSITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210977160.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-15
Publication Date
2025-05-09
Estimated Expiration
2042-08-15

AI Technical Summary

Technical Problem

The existing data access system based on the zero-trust system has problems such as insufficient data source identity information recording, low public and private key encryption performance and high cost, and the inability to meet the usage of data shared by multiple people.

Method used

By generating a unique data identity in the data gateway and associating it with the digital identity and key of the data source, the traceability of the data source and the controllability of the data user is achieved. At the same time, digital identity keys are used for encryption to ensure the secure storage and dissemination of data, and unified identity management and permission authentication are carried out through a zero-trust system.

Benefits of technology

It realizes the traceability of data sources and controllability of data users, ensures the secure storage and dissemination of data, solves the problem of data sharing by multiple people, and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115514523B_ABST
    Figure CN115514523B_ABST
Patent Text Reader

Abstract

The present invention provides a data security access system, method, device and medium based on a zero-trust system, including a data source, a database, a trusted data agent, a zero-trust system, a data gateway, an application, and a client. Based on the idea of ​​user digital identity identification and data identity identification, the data source can be traced and the data user can be controlled; data dissemination can be traced; and to a certain extent, the entire data life cycle chain from data production, data storage to data use can be controlled and traced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information network data security, and specifically relates to a data security access system, method, device and medium based on a zero-trust system. Background Art

[0002] With the development of the Internet and artificial intelligence, the current network system has entered the era of the Internet of Everything, and also the era of big data, with explosive growth in data volume. While big data brings convenience and productivity to our lives, it also brings the risk of data privacy being stolen and used by illegal elements. How to do a good job of data security protection is an important topic of hot research in the information science community today.

[0003] Zero trust represents a new generation of network security protection concepts. Its key lies in breaking the default "trust". To sum it up in a popular phrase, it is "continuous verification, never trust". By default, no one, device or system inside or outside the enterprise network is trusted. The trust foundation of access control is rebuilt based on identity authentication and authorization to ensure that identities, devices, applications and links are trusted. Currently, data security based on zero trust is mainly reflected in personalized data security access control. Based on user identity, user access control to data can reach the "data table, field" level, and different people can access different data tables and fields. For fixed-point transmission and use of data, public key encryption and private key decryption are generally used to ensure that data can only be used by people with private keys.

[0004] However, the current data access system based on the zero-trust system still has the following shortcomings: (1) When storing data, the identity information of the data source is not recorded, and the data source is difficult to trace. Therefore, when tracing illegal data or forged data, it is difficult to find the provider and hold him accountable; (2) Although the public-private key scheme can be used by a dedicated person, it requires a PKI infrastructure, which is difficult to deploy, and the performance of public-private key encryption is relatively low, the cost is high, and the user experience is poor; (3) The public-private key encryption scheme cannot meet the use of data shared by multiple people. Summary of the invention

[0005] Based on the above-mentioned technical status, the purpose of the present invention is to provide a data security access system, method, device and medium based on a zero-trust system. Based on the idea of ​​user digital identity identification and data identity identification, the data source can be traced and the data user can be controlled; the data dissemination can be traced; to a certain extent, the entire data life cycle chain from data production, data storage to data use can be controlled and traced.

[0006] The technical solution adopted by the present invention is as follows: a data security access system based on a zero-trust system, including a data source, a database, a trusted data agent, a zero-trust system, a data gateway, an application, and a client. The data source provides data to the data gateway through a trusted data agent, and finally stores it in the database; the trusted data agent is used to receive the data service and then authenticate the user or data source to the zero-trust system when the user or data source accesses the data through the data service. After the zero-trust system confirms that the user or data source has the authority to access the data service, it feeds back to the trusted data agent, and the trusted data agent releases the data service access request and sends the request to the data gateway; the zero-trust system is used to perform unified identity management for users, data sources, applications, and data gateways, and generate digital identity identifiers and digital identity keys for users and data sources; the data gateway is a system that provides data services, and after receiving the data service request, it interacts with the database to complete the reading and writing of the database; the client performs business access and data acquisition through the application.

[0007] The data gateway generates a unique data identity for the stored data records and files. The data identity is associated with the digital identity and digital identity key of the data source, where the data identity = (data source digital identity | MD5 (data content | data source digital identity key)). The data identity is recorded as a label in the data record, and the data identity and record index are securely stored. The data gateway also encrypts the stored data using the identity key of the data source or user.

[0008] In order to realize the functions of single-person data access and multi-person shared data access, the data gateway includes two reading modes when the user or data source reads data:

[0009] Method 1: The user or data source carries a token to call the "single-user get file" interface. The data gateway obtains the user's digital identity and digital identity key based on the token, encrypts the data using the digital identity key to generate ciphertext, and then generates an MD5 hash value. The hash value is attached to the ciphertext and the data is returned to the client.

[0010] Method 2: The user or data source carries a token to call the "Multi-person Use Get File" interface, and enters the members that can be shared on the interface displayed on the client. The data gateway obtains the user or data source digital identity and digital identity key based on the token, and then encrypts the data using the digital identity key to generate ciphertext. Then, according to the member list of the data to be shared, the MD5 hash value related to each member is generated in turn, and the hash value is attached to the ciphertext in the form of a list. At the same time, the digital identity of the user or data source is attached to the hash value list, and the sorted message is sent to the client.

[0011] The client is embedded in the sandbox, and the client verifies the data identity of the file. After successful verification, the file is decrypted and stored in the sandbox in plain text. The source file read from the data gateway can be copied out of the client, while the decrypted plain text file cannot be taken out of the client. Users who have been authenticated by the zero-trust system can open the file on the client to view the content.

[0012] The present invention also claims a data security access method based on a zero-trust system, which applies the data security access system described in this application, and the method includes two cases: a single person accessing data and multiple people sharing data, wherein a single person accessing data includes the following steps:

[0013] S1: The user starts the client, and the client accesses the zero-trust system for authentication and obtains a user token;

[0014] S2: The client accesses the application with the user token, requests to download the data file, and selects single-user download;

[0015] S3: The application calls the "single-user get file" API service interface to access the API of the data gateway;

[0016] S4: After the trusted data proxy verifies the authority, it reaches the data gateway, which extracts the user token and obtains the user's digital identity IDKey and digital identity key IDSecKey based on the token;

[0017] S5: Encrypt the data based on the IDSecKey password to generate the ciphertext SecContent, then calculate the hash value: hashVal = MD5(SecContent|IDKey), append hashVal to SecContent, and return the processed data to the client;

[0018] S6: After receiving the data, the client downloads the file and stores it in the sandbox directory, opens the file with the client, and starts processing the file: the client obtains the digital identity IDKey from the zero-trust system, reads the file content, extracts the hash value at the end as assertHashVal, removes the content to obtain the data content, calculates tmpHash=MD5(content|IDKey), and if assertHashVal=tmpHash, the message is legal;

[0019] S7: The client carries the digital identity IDKey to obtain the digital identity key IDSecKey from the zero-trust system, decrypts it using the digital identity key IDKey, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied.

[0020] S8: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

[0021] The above data security access method includes the following steps when multiple people share data:

[0022] S1: The user starts the client, and the client accesses the zero-trust system for authentication and obtains a user token;

[0023] S2: The client accesses the application with the user token, requests to download the data file, and selects to download for multiple users;

[0024] S3: The application calls the "multi-user get file" API service interface to access the API of the data gateway;

[0025] S4: After the trusted data proxy verifies the permission, it reaches the data gateway, and the data gateway displays a page for the user to enter the available account and the account list UserList;

[0026] S5: Obtain the digital identity IDKey list of the applicant user and UserList: IDKeyList, and obtain the digital identity key IDSecKey of the applicant user;

[0027] S6: Encrypt the data based on the digital identity key IDSecKey password. The encrypted content is SecContent. Calculate the hash value list according to IDKeyList: hashValList = (MD5 (SecContent | IDKey_1, ..., IDKey_i)), where i represents the order of accounts that can use the data. After hashValList is added to SecContent, the digital identity of the applicant is added to the end, and then the data is returned to the client.

[0028] S7: After receiving the data, the client downloads the file and stores it in the sandbox directory. It opens the file with the client and starts processing the file: it obtains the digital identity assertIDKey from the end of the file. The client obtains the digital identity IDKey from the zero-trust system; it reads the file content and takes out the hash list hashList at the end, leaving only the encrypted content Seccontent; it calculates tmpHash = MD5(content|IDKey). If tmpHash is in hashList, the message is legal;

[0029] S8: The client carries assertIDKey to obtain the digital identity key IDSecKey from the zero-trust system, decrypts it using IDSecKey, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied.

[0030] S9: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

[0031] To achieve the above objectives, the present invention also proposes a data security access device based on a zero-trust system, comprising: at least one processor; at least one memory for storing at least one program; when the at least one program is executed by at least one processor, the at least one processor implements the data security access method described above.

[0032] To achieve the above objectives, the present invention also proposes a computer storage medium, which stores a program executable by a processor, characterized in that when the program executable by the processor is executed by the processor, it implements the data security access method described above.

[0033] The advantages of the technical solution of the present invention are:

[0034] (1) For the stored data, the data source is recorded by using data identification. The data source can be obtained from the stored data. Each record has its own data identification. One record has one certificate, and one file has one certificate. Through the data identification, the data source can be queried in time, and the stored files and files taken out by the user can be identified in time. The illegal data and forged data can be traced to the source, which is convenient for accountability;

[0035] (2) Record the hash check value of the stored data to prevent data tampering and promptly detect whether the data has been tampered with;

[0036] (3) The stored data can be encrypted using the key of the data source, thereby ensuring the consistency of the data storer and user;

[0037] (4) The patented technology also solves the problem that the existing technology cannot share data with multiple people or there are risks when sharing data with multiple people, and implements the following usage control for data files authorized by users: data files can only be used by authorized users; data files can only be used by multiple designated people; data files can be disseminated but cannot be used, avoiding the risk of illegal acquisition. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 This is the main networking architecture diagram of the data security access system based on the zero-trust system of the present invention;

[0039] Figure 2 It is a flow chart of storing data in a data source of a data security access system based on a zero-trust system of the present invention;

[0040] Figure 3 It is a single-person data access processing flow chart of the data security access system based on the zero-trust system of the present invention;

[0041] Figure 4 It is a multi-person data access processing flow chart of the data security access system based on the zero-trust system of the present invention;

[0042] In the figure: 1. Data source, 2. Client, 3. Application, 4. Trusted data agent, 5. Zero trust system, 6. Data gateway, 7. Database. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0044] It should be noted that, although the functional modules are divided in the system schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first", "second", etc. in the specification, claims and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0045] In the subsequent description, the suffixes such as "module", "component" or "unit" used to represent elements are only used to facilitate the description of the present invention, and have no special meanings. Therefore, "module", "component" or "unit" can be used in a mixed manner.

[0046] like Figure 1As shown, it is a main networking architecture diagram of the data security access system based on the zero-trust system of the present invention. The data security access system based on the zero-trust system of the present invention includes a data source 1, a database 7, a trusted data agent 4, a zero-trust system 5, a data gateway 6, an application 3, and a client 2. The data source 1 provides data to the data gateway 6 through the trusted data agent 4, and finally stores it in the database 7; the trusted data agent 4 is used to receive the data service and then authenticate the user or data source to the zero-trust system 5 when the user or data source accesses the data through the data service. After the zero-trust system 5 confirms that the user or data source has the authority to access the data service (data access API), it feeds back to the trusted data agent 4, and the trusted data agent 4 releases the data service access request and sends the request to the data gateway 6; the zero-trust system 5 is used to perform unified identity management for users, data sources, applications, and data gateways, and generate digital identity identifiers for users and data sources; the data gateway 6 is a system that provides data services. After receiving the data service request, it interacts with the database 7, completes the reading and writing of the database 7, and provides the data service API; the client 2 performs business access and data acquisition through the application 3.

[0047] The zero-trust system provides support for the registration of data sources and users, generates digital identities and digital identity keys for them, identifies their unique identities through digital identities, and the unique identities correspond to unique identity keys. It also supports the authentication of data sources and users. The authentication is achieved by issuing a token to the data source or user that identifies its authentication identity. In a specific embodiment, the token format can be constructed as follows: digital identity + (Function (account name, creation time, validity period)). In addition, the zero-trust system supports the authority management of data sources and users to access data services, and provides authentication for trusted data agents to access data services.

[0048] The data gateway generates a unique data identity for the stored data records and files. The data identity is associated with the digital identity and digital identity key of the data source. Taking the data content as an example, the data identity is generated as follows: data identity = (data source digital identity | MD5 (content | data source digital identity key)). The data identity is recorded as a label in the data record, and the data identity and record index are securely stored (such as encrypted storage, blockchain storage). The data gateway can also encrypt the stored data using the identity key of the data source or user to ensure that the data stored by the data source / user is only available to the user and is prohibited from being used by others.

[0049] In order to realize the functions of single-person data access and multi-person shared data access, the data gateway supports two reading modes when the user or data source reads data:

[0050] (1) Read data for your own use only: S1. Carry the token token and call the "single-user get file" interface; S2. The data gateway obtains the user's digital identity IDKey and digital identity key IDSecKey based on the token; S3. Encrypt the data using IDSecKey to generate the ciphertext SecContent, then perform hash assignment hashVal = MD5(SecContent|IDKey), append hashVal to SecContent, and send it to the user client;

[0051] (2) Reading data for multiple people: S1. Carrying the token, call the "get file for multiple people" interface; S2. The user enters the members that can be shared in the data display interface (must be registered members); S3. The data gateway obtains the user's digital identity IDKey and digital identity key IDSecKey based on the token; S4. Encrypt the data using IDSecKey to generate the ciphertext SecContent, and then generate the hash values ​​related to each member in turn according to the list of members that can be viewed, such as: user1, user2, ..., userk, hashVali = MD5(SecContent|useri_IDKey), and append hashVali to SecContent in the form of a list; S5. Append the ID card IDKey of the applicant user after the list; S6. Send the sorted message to the client.

[0052] The client is embedded in the sandbox, and the data does not fall to the ground. The source files read from the data gateway can be copied out of the client, but the decrypted plaintext files cannot be taken out from the client. At the same time, the client verifies the data identity of the file, and decrypts the file after the verification is successful. The decrypted file is stored in the sandbox in plain text. Users who have been authenticated by the zero-trust system can open the file on the client to view the content.

[0053] Based on the data security access system of the present invention, digital identity tags are established for users and data sources. The data stored by users and data sources can be queried through the digital identity tags, and a data identity tag associated with the digital identity tag is established for the data. One certificate is used for one record and one certificate is used for one file. The source of the data can be queried in time, and the stored files, the files taken out and used by the users, and whether the data has been tampered with can be identified in time. In addition, the illegal data and forged data can be traced to the source, which is convenient for accountability.

[0054] The following flowchart Figure 2-Figure 4 The data storage process and data access process of the data source of the present invention are further described as follows:

[0055] See also Figure 2, is a flow chart of data storage in a data source of a data security access system based on a zero-trust system of the present invention. The data source is registered in the zero-trust system, and the zero-trust system generates and stores a digital identity IDKey and a digital identity key SecKey for it. The data source is authenticated in the zero-trust system to obtain an identity token containing the digital identity IDKey information. Then the data source calls the data service API interface of the data gateway, carries the token for data synchronization, and after the trusted data agent verifies the authority, it reaches the data gateway. The data gateway generates a data identity for the data. If encryption is required, the digital identity key SecKey of the data source is used for encryption. The data identity is added to the record in the form of a label, and then the data identity information, data source or user information (including account name, data source or user digital identity, record index or file index) are securely stored in the database, such as: encrypted storage, blockchain storage; finally, verify whether the data record or file has been tampered with: recalculate the MD5 hash value of the record or file, obtain the data identity of the record from the data identity library to obtain the data source digital identity, and use MD5 The data identity is calculated using the hash value, identity key, and digital identity of the data source, and it is determined whether the data identity is consistent with the encrypted and stored data. If not, the data record or file has been tampered with.

[0056] Figure 3 This is a single-person data access processing flow chart of the data security access system based on the zero-trust system of the present invention. The data reading and dedicated use include the following steps:

[0057] S1: The user starts the client, which accesses the zero-trust system for authentication and obtains a user token.

[0058] S2: The client accesses the application with the user token, requests to download the data file, and selects single-user download;

[0059] S3: The application calls the "single-user get file" API service interface to access the API of the data gateway;

[0060] S4: After the trusted data proxy verifies the authority, it reaches the data gateway, which extracts the user token and obtains the user's digital identity IDKey and digital identity key IDSecKey based on the token;

[0061] S5: Encrypt the data based on the IDSecKey password to generate the ciphertext SecContent, then calculate the hash value: hashVal = MD5(SecContent|IDKey), append hashVal to SecContent, and return the processed data to the client;

[0062] S6: After receiving the data, the client downloads the file and stores it in the sandbox directory, opens the file with the client, and starts processing the file: the client obtains the digital identity IDKey from the zero-trust system, reads the file content, extracts the hash value at the end as assertHashVal, removes the content to obtain the data content, calculates tmpHash=MD5(content|IDKey), and if assertHashVal=tmpHash, the message is legal;

[0063] S7: The client carries the digital identity IDKey to obtain the digital identity key IDSecKey from the zero-trust system, decrypts it using the digital identity key IDKey, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied.

[0064] S8: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

[0065] Figure 4 This is a multi-person data access processing flow chart of the data security access system based on the zero-trust system of the present invention. When multiple people need to share data, it includes the following steps:

[0066] S1: The user starts the client, which accesses the zero-trust system for authentication and obtains a user token.

[0067] S2: The client accesses the application with the user token, requests to download the data file, and selects to download for multiple users;

[0068] S3: The application calls the "multi-user get file" API service interface to access the API of the data gateway;

[0069] S4: After the trusted data proxy verifies the permission, it reaches the data gateway, and the data gateway displays a page for the user to enter the available account and the account list UserList;

[0070] S5: Obtain the digital identity IDKey list of the applicant user and UserList: IDKeyList, and obtain the digital identity key IDSecKey of the applicant user;

[0071] S6: Encrypt the data based on the digital identity key IDSecKey password. The encrypted content is SecContent. Calculate the hash value list according to IDKeyList: hashValList = (MD5 (SecContent | IDKey_1, ..., IDKey_i)), where i represents the account that can use the data. After hashValList is added to SecContent, the digital identity of the applicant is added to the end, and then the data is returned to the client.

[0072] S7: After receiving the data, the client downloads the file and stores it in the sandbox directory. It opens the file with the client and starts processing the file: it obtains the digital identity assertIDKey from the end of the file. The client obtains the digital identity IDKey from the zero-trust system; it reads the file content and takes out the hash list hashList at the end, leaving only the encrypted content Seccontent; it calculates tmpHash = MD5(content|IDKey). If tmpHash is in hashList, the message is legal;

[0073] S8: The client carries assertIDKey to obtain the digital identity key IDSecKey from the zero-trust system, decrypts it using IDSecKey, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied.

[0074] S9: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

[0075] The technical solution of the present invention is that for the retrieved data files, the plaintext data visible after decryption cannot be retrieved from the client, and the plaintext data can be prohibited from being spread. The ciphertext can be spread, but only users authenticated by the zero-trust system can open it on a dedicated client. The entire process is encrypted and transmitted, and the encryption key is uniformly managed by the zero-trust system to ensure the security of the key. Only authenticated trusted users can obtain the key decryption from the zero-trust system. Whether a single person accesses the data or multiple people share the data, it can meet the functional requirements and ensure the security of the data.

[0076] It can be seen from the specific implementation methods of the present application and the contents in the given examples that the method of the present application can be stored or loaded onto a computer or other programmable data processing device through computer program instructions, that is, these computer programs can be provided to the computer or other programmable data processing device to generate a machine, and the machine executable instructions implement the functions specified in one or more processes of the flowchart.

[0077] The method of the present application can be stored or loaded onto a computer or other programmable data processing device through computer program instructions, so that the computer or other programmable data processing device executes a series of operation steps by reading the instructions to produce computer-implemented processing, thereby executing the instructions in the computer or other programmable data processing device to provide steps for implementing the functions specified in one or more processes of the flowchart.

[0078] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.

Claims

1. A data security access system based on a zero-trust system, including a data source, a database, a trusted data agent, a zero-trust system, a data gateway, an application, and a client; The data source provides data and stores it in the database; The trusted data proxy is used to receive data services and then authenticate the user or data source to the zero-trust system when the user or data source accesses data through the data service. After the zero-trust system confirms that the user or data source has the authority to access the data service, it will feedback to the trusted data proxy. The trusted data proxy will release the data service access request and send the request to the data gateway. The zero-trust system is used to perform unified identity management on users, data sources, applications, and data gateways, and to generate digital identity tags and digital identity keys for users and data sources; The data gateway is a system that provides data services. After receiving a data service request, it interacts with the database to complete the reading and writing of the database. The client accesses services and acquires data through the application; The data gateway generates a unique data identity for the stored data records and files. The data identity is associated with the digital identity and digital identity key of the data source. The data identity is recorded in the data record as a tag, and the data identity and record index are securely stored. The data gateway also encrypts the stored data using the identity key of the data source or user. When the data gateway reads data from a user or data source, there are two reading modes: Method 1: The user or data source carries a token and calls the "single-user get file" interface. The data gateway obtains the user's digital identity and digital identity key based on the token, encrypts the data using the digital identity key to generate ciphertext, then generates a hash value, appends the hash value to the ciphertext, and returns the data to the client. Method 2: The user or data source carries a token to call the "Multi-person Use Get File" interface, and enters the members that can be shared on the interface displayed on the client. The data gateway obtains the digital identity and digital identity key of the user or data source based on the token, and then encrypts the data using the digital identity key to generate ciphertext. Then, based on the member list of the data to be shared, the hash value related to each member is generated in turn, and the hash value is attached to the ciphertext in the form of a list. At the same time, the digital identity of the user or data source is attached to the list of hash values, and the sorted message is sent to the client.

2. The system according to claim 1, further characterized in that: The relationship between the data identity identifier and the digital identity identifier and digital identity key of the data source is as follows: data identity identifier=(data source digital identity identifier|MD5(data content|data source digital identity key)).

3. The system according to claim 1, further characterized in that: The client is embedded in the sandbox, and the client verifies the data identity of the file. After successful verification, the file is decrypted and stored in the sandbox in plain text. The source file read from the data gateway can be copied out of the client, while the decrypted plain text file cannot be taken out of the client. Users who have been authenticated by the zero-trust system can open the file on the client to view the content.

4. A data security access method based on a zero-trust system, which is applied to the system according to any one of claims 1 to 3, and the method comprises the following steps: S1: The user starts the client, and the client accesses the zero-trust system for authentication and obtains a user token; S2: The client accesses the application with the user token, requests to download the data file, and selects single-user download; S3: The application calls the "single-user get file" API service interface to access the API of the data gateway; S4: After the trusted data proxy verifies the permission, it reaches the data gateway, which extracts the user token and obtains the user's digital identity and digital identity key based on the token; S5: Encrypt the data based on the user's digital identity key password to generate ciphertext, then calculate the hash value based on the user's digital identity, append the hash value to the ciphertext, and return the processed data to the client; S6: After receiving the data, the client downloads the file and stores it in the sandbox directory, opens the file with the client, and starts processing the file: the client obtains the digital identity from the zero-trust system, reads the file content, extracts the hash value at the end as assertHashVal, removes the hash value at the end to obtain the data content, and calculates tmpHash based on the obtained data content and the user's digital identity. If assertHashVal = tmpHash, the message is legal; S7: The client carries the digital identity to obtain the digital identity key from the zero-trust system, decrypts it using the digital identity key, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied. S8: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

5. A data security access method based on a zero-trust system, which is applied to the system according to any one of claims 1 to 3, and the method comprises the following steps: S1: The user starts the client, and the client accesses the zero-trust system for authentication and obtains a user token; S2: The client accesses the application with the user token, requests to download the data file, and selects to download for multiple users; S3: The application calls the "multi-user get file" API service interface to access the API of the data gateway; S4: After the trusted data proxy verifies the permission, it reaches the data gateway, and the data gateway displays a page for the user to enter the available account and the account list UserList; S5: Obtain the digital identity IDKey list of the applicant user and UserList: IDKeyList, and obtain the digital identity key IDSecKey of the applicant user; S6: Encrypt the data based on the digital identity key IDSecKey. The encrypted content is SecContent. Calculate the hash value list: hashValList according to IDKeyList. After adding hashValList to SecContent, add the digital identity of the applicant to the end, and then return the data to the client. S7: After receiving the data, the client downloads the file and stores it in the sandbox directory. It opens the file with the client and starts processing the file: it obtains the digital identity assertIDKey from the end of the file, and the client obtains the digital identity IDKey from the zero-trust system; it reads the file content and takes out the hash value list hashValList at the end, leaving only the encrypted content Seccontent; it calculates tmpHash based on the data content and the user's digital identity. If tmpHash is in the hash value list hashValList, the message is legal; S8: The client carries assertIDKey to obtain the digital identity key from the zero-trust system, decrypts it using the digital identity key, obtains the plaintext file, and stores it in the sandbox directory. The plaintext file is protected by the client's sandbox and cannot be copied. S9: Users can view plain text files on the client. If the client changes the account, the file will be automatically cleared.

6. A data security access device based on a zero-trust system, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by at least one processor, the at least one processor implements the data security access method as claimed in claim 4 or 5.

7. A computer storage medium storing a program executable by a processor, characterized in that: The program executable by the processor implements the data security access method as claimed in claim 4 or 5 when executed by the processor.

Citation Information

Patent Citations

  • Zero-trust access permission control system and method based on trusted computing

    CN113901499A

  • Zero-trust API gateway dynamic trust evaluation and access control method and system based on machine learning

    CN114465807A