A data sharing system, method, apparatus, device, and medium
By utilizing the correspondence between application identifiers and access addresses, databases, and encryption keys in the data sharing system, secure data sharing among multiple applications in a computing state is achieved, solving the problem of missing data security chains in existing technologies and enhancing the security of data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNIONPAY
- Filing Date
- 2022-09-19
- Publication Date
- 2026-06-05
AI Technical Summary
When sharing data among multiple applications, how can data sharing be achieved while ensuring the data security of each application? Existing technologies lack sufficient security capabilities in the computing state, resulting in a missing data security chain.
By using the pre-saved mapping between application identifiers and access addresses, the target application identifier is determined and a sharing request is sent. The device to which the target access address belongs decrypts the data according to the mapping between the application identifier, the database, and the encryption key, and sends the decrypted data to the first application, thereby achieving secure data sharing between multiple applications.
While ensuring the data security of each application, data sharing among multiple applications is achieved, enhancing data security in the computing state.
Smart Images

Figure CN115580440B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data sharing technology, and in particular to a data sharing system, method, apparatus, device and medium. Background Technology
[0002] Traditional data protection primarily focuses on encrypting data during transmission and writing to storage media. However, current security capabilities for application data in the computing state (i.e., in use) are insufficient, resulting in a missing crucial link in the data security chain. Therefore, ensuring the security of application data in the computing state is essential.
[0003] However, even if the security of data for each application in computing mode can be guaranteed, in real-world application scenarios, there are often situations where multiple applications need to share data. Therefore, how to enable data sharing among multiple applications while ensuring the security of data for each application in computing mode is a technical problem that urgently needs to be solved. Summary of the Invention
[0004] This application provides a data sharing system, method, apparatus, device, and medium for enabling multiple applications to share data while ensuring the security of data in each application.
[0005] In a first aspect, this application provides a data sharing system, the system comprising:
[0006] The device to which the first application belongs is used to determine the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, and to send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier;
[0007] The device to which the target access address belongs is configured to receive the sharing request, determine the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases, obtain the data stored in the target database, determine the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys, decrypt the obtained data based on the target encryption key, and send the decrypted data to the device to which the first application belongs.
[0008] The target database is used to store data.
[0009] Secondly, this application provides a data sharing method, which is applied to a device to which a first application belongs, the method comprising:
[0010] Based on the pre-saved correspondence between application identifiers and access addresses, the target access address corresponding to the target application identifier of the second application is determined, and a sharing request to share the data of the second application is sent to the target access address, wherein the sharing request carries the target application identifier;
[0011] Receive the decrypted data of the second application sent by the device to which the target access address belongs.
[0012] Thirdly, this application provides a data sharing method, which is applied to the device to which the target access address belongs, the method comprising:
[0013] Receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the identifier of the target application;
[0014] Based on the stored correspondence between application identifiers and databases, determine the target database corresponding to the target application identifier; and retrieve the data stored in the target database.
[0015] Based on the saved correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined; based on the target encryption key, the acquired data is decrypted; and the decrypted data is sent to the device to which the first application belongs.
[0016] Fourthly, this application provides a data sharing method, which is applied to a device to which a second application belongs, the method comprising:
[0017] If an application is received from the management platform, display the application identifier of the first application carried in the application;
[0018] If a confirmation instruction agreeing to share data with the first application is received, the confirmation instruction is sent to the management platform.
[0019] Fifthly, this application provides a data sharing method, which is applied to a management platform, and the method includes:
[0020] Receive a request from the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application;
[0021] Send the application to the device to which the second application belongs;
[0022] If a confirmation instruction agreeing to share data with the first application is received from the device to which the second application belongs, the saved target application identifier of the second application and the target access address corresponding to the target application identifier information are sent to the device to which the first application belongs.
[0023] Sixthly, this application provides a data sharing device, the device comprising:
[0024] The first determining module is used to determine the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, and send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier.
[0025] The first receiving module is used to receive the decrypted data of the second application sent by the device to which the target access address belongs.
[0026] Seventhly, this application provides a data sharing apparatus, the apparatus comprising:
[0027] The second receiving module is used to receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the target application identifier;
[0028] The second determining module is used to determine the target database corresponding to the target application identifier based on the correspondence between the saved application identifier and the database; and to obtain the data saved in the target database.
[0029] The encryption / decryption module is used to determine the target encryption key corresponding to the target application identifier based on the stored correspondence between the application identifier and the encryption key; decrypt the acquired data based on the target encryption key; and send the decrypted data to the device to which the first application belongs.
[0030] Eighthly, this application provides a data sharing apparatus, the apparatus comprising:
[0031] The display module is used to display the application identifier of the first application carried in the application if an application is received from the management platform.
[0032] The first sending module is used to send the confirmation instruction to the management platform if it receives a confirmation instruction agreeing to share data with the first application.
[0033] Ninthly, this application provides a data sharing apparatus, the apparatus comprising:
[0034] The third receiving module is used to receive a request sent by the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application;
[0035] The second sending module is used to send the application to the device to which the second application belongs; if it receives a confirmation instruction from the device to which the second application belongs to agree to share data with the first application, it sends the saved target application identifier of the second application and the target access address corresponding to the target application identifier information to the device to which the first application belongs.
[0036] In a tenth aspect, this application provides an electronic device including a processor and a memory, wherein the memory stores program code that, when executed by the processor, causes the processor to perform the steps of the method described in any one of the second to fifth aspects above.
[0037] In one aspect, this application provides a computer-readable storage medium including program code that, when the storage medium is run on an electronic device, causes the electronic device to perform the steps of the method described in any one of the second to fifth aspects above.
[0038] In this embodiment, the device to which the first application belongs can determine the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, and send a sharing request to the target access address to share the data of the second application, the sharing request carrying the target application identifier; the device to which the target access address belongs can receive the sharing request, determine the target database corresponding to the target application identifier based on the saved correspondence between application identifiers and databases; obtain the data stored in the target database; determine the target encryption key corresponding to the target application identifier based on the saved correspondence between application identifiers and encryption keys; decrypt the obtained data based on the target encryption key; and send the decrypted data to the device to which the first application belongs; based on this, the purpose of sharing data between multiple applications can be achieved while ensuring the security of the data of each application. Attached Figure Description
[0039] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0040] Figure 1 The diagram illustrates a data sharing system provided by some embodiments;
[0041] Figure 2 A schematic diagram of a first data sharing process provided by some embodiments is shown;
[0042] Figure 3A schematic diagram of a second data sharing process provided by some embodiments is shown;
[0043] Figure 4 A schematic diagram of a third data sharing process provided in some embodiments is shown;
[0044] Figure 5 A schematic diagram of a fourth data sharing process provided in some embodiments is shown;
[0045] Figure 6 A schematic diagram of a fifth data sharing process provided in some embodiments is shown;
[0046] Figure 7 The diagram illustrates a data writing process provided by some embodiments;
[0047] Figure 8 The diagram illustrates a data reading process provided by some embodiments;
[0048] Figure 9 The diagram illustrates a data security storage process provided by some embodiments;
[0049] Figure 10 This application provides a schematic diagram of a data sharing scenario for some embodiments.
[0050] Figure 11 A schematic diagram of a sixth data sharing process provided in some embodiments is shown;
[0051] Figure 12 A schematic diagram of a seventh data sharing process provided in some embodiments is shown;
[0052] Figure 13 A schematic diagram of an eighth data sharing process provided in some embodiments is shown;
[0053] Figure 14 A schematic diagram of a ninth data sharing process provided in some embodiments is shown;
[0054] Figure 15 A schematic diagram of a first type of data sharing device provided in some embodiments is shown;
[0055] Figure 16 A schematic diagram of a second data sharing device provided in some embodiments is shown;
[0056] Figure 17 A schematic diagram of a third data sharing device provided in some embodiments is shown;
[0057] Figure 18 A schematic diagram of a fourth data sharing device provided in some embodiments is shown;
[0058] Figure 19 A schematic diagram of an electronic device structure provided by some embodiments is shown. Detailed Implementation
[0059] In order to enable data sharing among multiple applications while ensuring the security of data in each application, this application provides a data sharing system, method, apparatus, device and medium.
[0060] To make the objectives and implementation methods of this application clearer, the exemplary implementation methods of this application will be clearly and completely described below with reference to the accompanying drawings of the exemplary embodiments of this application. Obviously, the exemplary embodiments described are only some embodiments of this application, and not all embodiments.
[0061] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0062] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.
[0063] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.
[0064] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.
[0065] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0066] Figure 1 The diagram illustrates a data sharing system provided by some embodiments, such as... Figure 1 As shown, the system includes:
[0067] The device 11 to which the first application belongs is used to determine the target access address corresponding to the target application identifier of the second application according to the pre-saved correspondence between application identifiers and access addresses, and send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier;
[0068] The device 12 to which the target access address belongs is used to receive the sharing request, determine the target database 13 corresponding to the target application identifier according to the correspondence between the saved application identifier and the database; obtain the data saved in the target database 13; determine the target encryption key corresponding to the target application identifier according to the correspondence between the saved application identifier and the encryption key; decrypt the obtained data based on the target encryption key; and send the decrypted data to the device 11 to which the first application belongs.
[0069] The target database 13 is used to store data.
[0070] In one possible implementation, the data sharing system includes a device 11 belonging to a first application, a device 12 belonging to a target access address, and a target database 13. When the device belonging to the first application (e.g., application B) needs to obtain (share) data from a second application (e.g., application A), it can determine the target access address corresponding to the target application identifier of the second application based on a pre-saved correspondence between application identifiers and access addresses, and send a sharing request to the target access address to share the data of the second application. Optionally, the sharing request may carry the target application identifier of the second application.
[0071] The device 12 (also known as the pre-encryption module) to which the target access address belongs can receive the sharing request and, based on the pre-saved correspondence between application identifiers and databases, determine the target database 13 corresponding to the target application identifier of the second application, thereby obtaining the data stored in the target database 13. In one possible implementation, to ensure the security of the data for each application, the data stored in the database corresponding to each application can be data encrypted based on the encryption key corresponding to that application. That is, the data obtained from the target database 13 can be data encrypted based on the encryption key of the second application (such as application A). To enable data sharing between different applications, the decrypted data can be sent to the first application (e.g., application B). Specifically, the device 12 to which the target access address belongs can pre-store the correspondence between each application identifier and encryption key. After obtaining data from the target database 13, the device 12 to which the target access address belongs can determine the target encryption key corresponding to the target application identifier of the second application (e.g., application A) based on the stored correspondence between application identifiers and encryption keys, and decrypt the obtained data based on the target encryption key. The decrypted data is then sent to the device 11 to which the first application belongs. Thus, while ensuring the security of the data of each application, multiple applications can share data.
[0072] In one possible implementation, if a first application (e.g., application B) wants to share data from a second application (e.g., application A), the device 11 belonging to the first application (e.g., application B) can first send an application request to the management platform in the data sharing system to share the data of the second application. Optionally, the application request may include the application identifier of the first application itself. After receiving the application request from the device belonging to the first application (e.g., application B), the management platform can forward the application request to the device belonging to the second application (e.g., application A). The device belonging to the second application (e.g., application A) can receive the application request sent by the management platform. In order for the administrators of the second application to approve whether to allow the first application to share data, the device belonging to the second application (e.g., application A) can display the application identifier of the first application carried in the application. Optionally, if the administrators of the second application approve the application and agree to allow the first application to share the data of the second application, they can click the approval button, etc. The device belonging to the second application can receive a confirmation instruction agreeing to allow the first application to share data and can send the confirmation instruction to the management platform upon receiving the confirmation instruction.
[0073] The management platform can receive confirmation commands sent by the device to which the second application belongs, and upon receiving the confirmation command, can send the saved target application identifier of the second application and the target access address corresponding to the target application identifier to the device 11 to which the first application belongs. Optionally, if the target application identifier of the second application includes primary identifier information and secondary identifier information, the management platform can send the secondary identifier information to the device to which the first application (e.g., application B) belongs. The device 11 to which the first application belongs stores the correspondence between the secondary identifier information of the second application and the target access address. The primary identifier information and secondary identifier information of the second application will be described in subsequent embodiments and will not be elaborated here.
[0074] In one possible implementation, the device 11 to which the first application belongs can receive the target application identifier of the second application and the target access address corresponding to the target application identifier sent by the management platform, and can save the correspondence between the target application identifier and the target access address. For example, this correspondence can be saved in the configuration file (database configuration file) of the device 11 to which the first application belongs.
[0075] For ease of understanding, the data sharing process provided in this application will be described below through a specific embodiment. Figure 2 The diagram illustrates a first data sharing process provided by some embodiments, which includes the following steps:
[0076] S201: Device 11, to which the first application belongs, sends a request to the management platform to share data of the second application. The request carries the application identifier of the first application itself.
[0077] S202: The management platform receives the application and sends it to the device to which the second application belongs.
[0078] S203: The device to which the second application belongs receives the application and displays the application identifier of the first application carried in the application. If it receives a confirmation instruction agreeing to share data with the first application, it sends the confirmation instruction to the management platform.
[0079] S204: The management platform receives the confirmation instruction and sends the saved target application identifier (such as sub-identifier information) of the second application and the target access address corresponding to the target application identifier to the device 11 to which the first application belongs.
[0080] S205: The device 11 to which the first application belongs stores the correspondence between the target application identifier and the target access address.
[0081] S206: The device 11 to which the first application belongs determines the target access address corresponding to the target application identifier of the second application according to the pre-saved correspondence between application identifiers and access addresses, and sends a sharing request to the target access address to share the data of the second application, the sharing request carrying the target application identifier.
[0082] S207: The device 12 to which the target access address belongs receives the sharing request, determines the target database 13 corresponding to the target application identifier according to the correspondence between the saved application identifier and the database; obtains the data saved in the target database 13; determines the target encryption key corresponding to the target application identifier according to the correspondence between the saved application identifier and the encryption key; decrypts the obtained data based on the target encryption key; and sends the decrypted data to the device 11 to which the first application belongs.
[0083] In one possible implementation, considering that when the first application shares data from the second application, it usually needs to configure and set usage permissions for the first application, such as the first application only being able to read data from the second application but not being able to write data to the database of the second application, or sensitive data involved in the second application needing to be anonymized before being sent to the first application, etc., while enabling different applications to share data, it can also increase the security of the data of each application. After receiving the above-mentioned sharing request sent by the device 11 to which the target access address belongs, before determining the target database 13 corresponding to the target application identifier according to the correspondence between the saved application identifier and the database, the device 12 to which the target access address belongs can also determine whether the type of the sharing request is a read data request or a write data request, and based on the type of the sharing request and the pre-saved usage permissions of the first application for the data of the second application, determine whether the sharing request conforms to the corresponding usage permissions. For example, if the first application's access permission to the second application is only to read data and not to write data, then only when the type of shared data is a read data request will the shared request be determined to meet the corresponding access permission, and then the following steps will be performed: determining the target database 13 corresponding to the target application identifier based on the correspondence between the saved application identifier and the database; obtaining the data saved in the target database 13; determining the target encryption key corresponding to the target application identifier based on the correspondence between the saved application identifier and the encryption key; decrypting the obtained data based on the target encryption key; and sending the decrypted data to the device 11 to which the first application belongs.
[0084] In one possible implementation, considering that the data obtained from the target database 13 contains sensitive data such as ID card numbers, to enhance data security, after decrypting the obtained data based on the target encryption key and before sending the decrypted data to the device 11 to which the first application belongs, the device 12 to which the target access address belongs can also perform data anonymization processing on the decrypted data and then send the anonymized data to the device 11 to which the first application belongs. Existing technologies can be used for data anonymization processing, which will not be elaborated upon here.
[0085] For ease of understanding, the data sharing process provided in this application will be described below through a specific embodiment. Figure 3 The diagram illustrates a second data sharing process provided by some embodiments, which includes the following steps:
[0086] S301: The device 11 to which the first application belongs determines the target access address corresponding to the target application identifier of the second application according to the pre-saved correspondence between application identifiers and access addresses, and sends a sharing request to the target access address to share the data of the second application, the sharing request carrying the target application identifier.
[0087] S302: Device 12, to which the target access address belongs, receives a sharing request. If it is determined that the type of the sharing request is a data read request and the sharing request meets the usage permission, then according to the correspondence between the saved application identifier and the database, the target database 13 corresponding to the target application identifier is determined; the data saved in the target database 13 is obtained; according to the correspondence between the saved application identifier and the encryption key, the target encryption key corresponding to the target application identifier is determined; and the obtained data is decrypted based on the target encryption key.
[0088] S303: If the acquired data contains set sensitive data, the device 12 to which the target access address belongs performs data desensitization processing on the decrypted data and sends the data after data desensitization processing to the device 11 to which the first application belongs.
[0089] In one possible implementation, if the target application identifier of the second application includes primary identifier information and secondary identifier information, the device 12 to which the target access address belongs can also determine whether the target application identifier carried in the sharing request is the secondary identifier information of the second application. If the target application identifier carried in the sharing request is the secondary identifier information of the second application, it can be considered that the data of a certain application needs to be shared with other applications. In order to ensure data security, the type of the sharing request can be determined as read data request or write data request in the above embodiment. Based on the type of the sharing request and the pre-saved access permissions of the first application to the data of the second application, it can be determined whether the sharing request meets the access permissions. If it meets the access permissions, then subsequent steps such as determining the target database 13 corresponding to the target application identifier based on the correspondence between the saved application identifier and the database can be performed.
[0090] For ease of understanding, the data sharing process provided in this application will be described below through a specific embodiment. Figure 4 A schematic diagram of a third data sharing process provided in some embodiments is shown, which includes the following steps:
[0091] S401: The device 11 to which the first application belongs determines the target access address corresponding to the target application identifier of the second application according to the pre-saved correspondence between application identifiers and access addresses, and sends a sharing request to the target access address to share the data of the second application, the sharing request carrying the target application identifier.
[0092] S402: The device 12 to which the target access address belongs receives the sharing request. If the target application identifier of the second application includes primary identifier information and secondary identifier information, it determines whether the target application identifier carried in the sharing request is the secondary identifier information of the second application. If so, proceed to S403.
[0093] S403: If the type of the sharing request is determined to be a read data request and the sharing request meets the usage permission, then the target database 13 corresponding to the target application identifier is determined according to the correspondence between the saved application identifier and the database; the data saved in the target database 13 is obtained; the target encryption key corresponding to the target application identifier is determined according to the correspondence between the saved application identifier and the encryption key; and the obtained data is decrypted based on the target encryption key.
[0094] S404: If the acquired data contains set sensitive data, the device 12 to which the target access address belongs performs data desensitization processing on the decrypted data and sends the data after data desensitization processing to the device 11 to which the first application belongs.
[0095] Example 2:
[0096] Traditional data protection primarily focuses on encryption during data transmission and writing to storage media. Current security capabilities for application data in the computing state (i.e., in use state) are insufficient, resulting in a missing crucial link in the data security chain. Therefore, ensuring the security of application data in the computing state is essential; however, there is currently no effective technical solution for this purpose. This application provides a technical solution that can ensure the security of application data in the computing state. For ease of understanding, the following example illustrates the security of data from the second application (e.g., application A) in the above embodiments.
[0097] In one possible implementation, the data sharing system described above may further include: a management platform and a device belonging to a second application (such as application A). To ensure data security, the device belonging to the second application may first send a data storage security protection request to the management platform. This data storage security protection request may carry the name of the second application and the target access address of the second application. The management platform may receive the data storage security protection request sent by the device belonging to the second application, generate a target application identifier and a target encryption key corresponding to the name of the second application, and save the correspondence between the target application identifier and the target encryption key. Optionally, the target application identifier corresponding to the name of the second application generated by the management platform may include the primary identifier information and secondary identifier information mentioned in the above embodiments. It is understood that the primary identifier information and the secondary identifier information may correspond to the same target encryption key.
[0098] In one possible implementation, the device 12 to which the target access address belongs can send a key acquisition request to the management platform to obtain the target encryption key corresponding to the second application. Upon receiving the key acquisition request, the management platform can determine the target encryption key corresponding to the target application identifier of the second application based on the stored correspondence between application identifiers and encryption keys, and send the target encryption key to the device 12 to which the target access address belongs. The device 12 to which the target access address belongs can receive the target encryption key and store the correspondence between the target encryption key and the target application identifier.
[0099] For ease of understanding, the data sharing process provided in this application will be described below through a specific embodiment. Figure 5 A schematic diagram of a fourth data sharing process provided in some embodiments is shown, which includes the following steps:
[0100] S501: The device to which the second application (such as application A) belongs sends a data storage security protection request to the management platform. The data storage security protection request carries the name of the second application and the target access address of the second application.
[0101] S502: The management platform receives a data storage security protection request sent by the device to which the second application belongs, generates a target application identifier and a target encryption key corresponding to the name of the second application, and saves the correspondence between the target application identifier and the target encryption key.
[0102] S503: Device 12, belonging to the target access address, sends a key acquisition request to the management platform to obtain the target encryption key corresponding to the second application. Upon receiving the key acquisition request, the management platform determines the target encryption key corresponding to the target application identifier of the second application based on the stored correspondence between application identifiers and encryption keys, and sends the target encryption key to device 12, belonging to the target access address. Device 12, belonging to the target access address, receives the target encryption key and stores the correspondence between the target encryption key and the target application identifier.
[0103] S504: The device to which the first application (e.g., application B) belongs sends a request to the management platform to share data of the second application, the request carrying the application identifier of the first application itself.
[0104] S505: The management platform receives the application and sends it to the device to which the second application belongs. The device to which the second application belongs receives the application and displays the application identifier of the first application carried in the application. If it receives a confirmation instruction agreeing to share data with the first application, it sends the confirmation instruction to the management platform. The management platform receives the confirmation instruction and sends the saved target application identifier (such as secondary identifier information) of the second application and the target access address corresponding to the target application identifier to the device 11 to which the first application belongs.
[0105] S506: The device 11 to which the first application belongs stores the correspondence between the target application identifier and the target access address. Based on the pre-stored correspondence between the application identifier and the access address, the device 11 to which the first application belongs determines the target access address corresponding to the target application identifier of the second application, and sends a sharing request to the target access address to share the data of the second application, the sharing request carrying the target application identifier.
[0106] S507: The device 12 to which the target access address belongs receives the sharing request, determines the target database 13 corresponding to the target application identifier according to the correspondence between the saved application identifier and the database; obtains the data saved in the target database 13; determines the target encryption key corresponding to the target application identifier according to the correspondence between the saved application identifier and the encryption key; decrypts the obtained data based on the target encryption key; and sends the decrypted data to the device 11 to which the first application belongs.
[0107] In one possible implementation, to improve the security of the encryption key, the encryption key stored in the management platform may be stored in the Trusted Execution Environment (TEE) of the management platform. Taking the target encryption key of the second application as an example, the target encryption key stored in the management platform may be stored in the Trusted Execution Environment (TEE) of the management platform. Alternatively, the encryption key stored in the device 12 to which the target access address belongs may also be stored in the TEE of the device 12 to which the target access address belongs. Again, taking the target encryption key of the second application as an example, the target encryption key may be stored in the TEE of the device 12 to which the target access address belongs.
[0108] In one possible implementation, to further enhance the security of the stored encryption keys, the management platform can also encrypt the encryption keys of each application based on a set TEE physical storage root key (referred to as the first TEE physical storage root key for convenience) and then store them in its own TEE. That is, the encryption keys stored in the management platform can be keys encrypted based on the set first TEE physical storage root key. Optionally, when the management platform sends the target encryption key to the device 12 to which the target access address belongs, if the target encryption key stored in the management platform is a key encrypted based on the set first TEE physical storage root key, the management platform can decrypt the target encryption key based on the set first TEE physical storage root key and send the decrypted target encryption key to the device 12 to which the target access address belongs.
[0109] In one possible implementation, to enhance the security of the target encryption key, when the management platform sends the target encryption key to the device 12 to which the target access address belongs, it can do so via a temporarily established secure channel. In another possible implementation, to further enhance the security of the target encryption key when sending it via the temporarily established secure channel, the management platform and the device 12 to which the target access address belongs can negotiate a temporary secure channel key. The management platform can then encrypt the target encryption key using this temporary secure channel key and send the encrypted target encryption key to the device 12 to which the target access address belongs via the temporarily established secure channel. When the device 12 to which the target access address belongs receives the target encryption key encrypted using the temporary secure channel key, it can decrypt the target encryption key using the corresponding temporary secure channel key to obtain the decrypted target encryption key. In yet another possible implementation, the device 12 to which the target access address belongs can also encrypt the target encryption key using a pre-defined second TEE physical storage root key and then save the encrypted target encryption key.
[0110] For ease of understanding, the data sharing process provided in this application will be described below through a specific embodiment. Figure 6 A schematic diagram of a fifth data sharing process provided in some embodiments is shown, which includes the following steps:
[0111] S601: The device to which the second application belongs sends a data storage security protection request to the management platform. The data storage security protection request carries the name of the second application and the target access address of the second application.
[0112] S602: The management platform receives a data storage security protection request sent by the device to which the second application belongs, generates a target application identifier and a target encryption key corresponding to the name of the second application, encrypts the target encryption key based on the set first TEE physical storage root key, saves the encrypted target encryption key in the Trusted Execution Environment (TEE) of the management platform, and saves the correspondence between the target application identifier and the target encryption key.
[0113] Since the target encryption key is generated and stored in the TEE, and the target encryption key is encrypted based on the first TEE physical storage root key before being stored, the plaintext of the encryption key can be guaranteed not to leave the TEE, thus ensuring the security of the TEE.
[0114] S603: Device 12, to which the target access address belongs, sends a key acquisition request to the management platform to obtain the target encryption key corresponding to the second application. The management platform receives the key acquisition request from device 12, and determines the target encryption key corresponding to the target application identifier of the second application based on the stored correspondence between application identifiers and encryption keys. The management platform decrypts the target encryption key based on the first TEE physical storage root key, and encrypts the target encryption key based on the temporary secure channel key negotiated with device 12, to which the target access address belongs. Based on the temporarily established secure channel, the management platform sends the encrypted target encryption key to device 12, to which the target access address belongs.
[0115] Compared to related technologies where the plaintext of the encryption key appears in the application memory outside the encryption machine, and the security of the encryption key during transmission cannot be guaranteed, this application not only generates and stores the target encryption key in the TEE, but also encrypts the target encryption key based on the first TEE physical storage root key before storage, ensuring that the plaintext of the encryption key does not leave the TEE and guaranteeing the security of the TEE. Furthermore, this application can send the target encryption key to the device 12 belonging to the target access address via a secure channel, ensuring the security of the target encryption key during transmission. Additionally, when sending the target encryption key via a secure channel, this application can further encrypt the target encryption key based on a temporary secure channel key before transmission, further ensuring that the plaintext of the target encryption key is not leaked during transmission and further guaranteeing the security of the target encryption key during transmission.
[0116] S604: The device 12 to which the target access address belongs receives the target encryption key encrypted based on the temporary security channel key, decrypts the target encryption key based on the temporary security channel key, encrypts the target encryption key based on the set second TEE physical storage root key, stores the encrypted target encryption key in the TEE of the device 12 to which the target access address belongs, and stores the correspondence between the target encryption key and the target application identifier.
[0117] Since the device 12 to which the target access address belongs can store the target encryption key in the TEE, and encrypt the target encryption key based on the second TEE physical storage root key before storing it, the plaintext of the encryption key can be guaranteed not to leave the TEE, thus ensuring the security of the TEE.
[0118] In this embodiment, the encryption key is generated, transmitted, and stored within the TEE and in an encrypted state throughout its entire lifecycle. The plaintext of the encryption key does not leave the TEE, thus ensuring the security of the encryption key.
[0119] In one possible implementation, after receiving a data storage security protection request from the device to which the second application belongs, the management platform generates a target application identifier corresponding to the name of the second application, and then sends the target application identifier to the device to which the second application belongs. For example, the main identifier information in the target application identifier can be sent to the device to which the second application belongs.
[0120] In one possible implementation, when the second application needs to write data into the corresponding database (target database 13), the device to which the second application belongs can send a write data request to the target access address. This write data request carries the data to be written into the database and the target application identifier (such as main identifier information) of the second application. The device 12 to which the target access address belongs can receive the write data request and, based on the stored correspondence between the application identifier and the encryption key, determine the target encryption key corresponding to the target application identifier. Based on the target encryption key, the device 12 encrypts the data to be written into the database and saves the encrypted data into the corresponding target database 13.
[0121] In one possible implementation, to achieve fine-grained encryption of the data to be written to the database and increase encryption flexibility, administrators of the second application can set corresponding encryption strategies, such as the fields to be encrypted, the encryption algorithm used, and encryption rules. These encryption strategies can be flexibly set according to requirements, and this application does not impose specific limitations on them. The data storage security protection request sent by the device to the management platform to the second application can carry this encryption strategy. Optionally, the device 12 to which the target access address belongs can send a request to the management platform to obtain the encryption strategy of the second application. This encryption strategy request can carry the target application identifier corresponding to the second application. If the data storage security protection request carries an encryption strategy for the data, the management platform can send the encryption strategy to the device 12 to which the target access address belongs. The device 12 to which the target access address belongs receives the encryption strategy sent by the management platform and saves the correspondence between the target application identifier and the encryption strategy. If it receives a write data request from the device to which the second application belongs, the device 12 to which the target access address belongs can determine the target encryption strategy corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption strategy, and encrypt the data to be written to the database based on the target encryption key and the target encryption strategy.
[0122] For example, Figure 7 The diagram illustrates a data writing process provided by some embodiments, such as Figure 7 As shown, the device to which the second application belongs (referred to as the application in the figure for illustrative purposes) sends a write data request to the target access address (referred to as the pre-encryption module in the figure). The write data request carries the data to be written to the database and the target application identifier of the second application.
[0123] Optionally, the device 12 (front-end encryption module) to which the target access address belongs includes an encryption / decryption module and an encryption proxy module. The encryption / decryption module can be deployed in the TEE of the device 12 to which the target access address belongs. The encryption / decryption module stores the encryption key (target encryption key). Subsequently, the corresponding data can be encrypted or decrypted in the TEE based on the target encryption key to ensure the security of the data and the encryption key.
[0124] In one possible implementation, the encryption proxy module can intercept and parse write data requests, i.e., Structured Query Language (SQL), where SQL is a database query and programming language used for data access. The encryption proxy module can determine the target encryption policy corresponding to the target application identifier of the second application based on the stored mapping between application identifiers and encryption policies. Based on this target encryption policy, the encryption proxy module can determine the sub-data that needs to be encrypted within the data to be written to the database. It can extract the sub-data that needs encryption from the data to be written to the database and send the plaintext data of the sub-data to be encrypted and the target application identifier of the second application to the encryption / decryption module. Upon receiving the sub-data to be encrypted and the target application identifier, the encryption / decryption module can determine the target encryption key corresponding to the target application identifier based on the stored mapping between application identifiers and encryption keys. In the TEE (Transaction Execution Environment), based on the target encryption key, the sub-data to be encrypted is encrypted, and the encrypted ciphertext data of the sub-data is returned to the encryption proxy module. The encryption proxy module reassembles the encrypted sub-data into the data to be written to the database. In other words, a portion of the data written to the database can be encrypted ciphertext data, or all the sub-data in the data to be written to the database can be encrypted. It can be flexibly set according to the requirements. This application does not make specific limitations on this. The encryption proxy module can save the encrypted data based on the target encryption key and the target encryption strategy to the corresponding target database 13.
[0125] When using the database security storage service, the application of this application (such as the second application) only needs to modify the database access address (target access address) in the database configuration file to point to the pre-encryption module (device 12 to which the target access address belongs). Then, it can directly call the existing database interface through the target access address. The application's (second application's) access to the database (target database 13) first goes through the pre-encryption module. The pre-encryption module intercepts and parses SQL statements and matches encryption policies, and encrypts the data (data to be written to the database) in the TEE. Then, the encrypted data (ciphertext) is sent to the target database 13 for corresponding processing and storage. Compared with related technologies that send plaintext to the database for corresponding processing and only encrypt and save the processing results in the database, since this application sends the encrypted data to the database for corresponding processing, even database privileged accounts or maintenance personnel cannot access the application's plaintext data at the database level, thus more effectively protecting the security of the computation and storage of user privacy data.
[0126] In addition, the data sharing method provided in this application is compatible with existing databases. It can convert plaintext data into ciphertext without changing the existing database client call interface and server database system, thus realizing a secure database. Even database privileged accounts or maintenance personnel cannot access the application's plaintext data at the database level, which can conveniently and effectively protect the security of user privacy data calculation and storage.
[0127] In one possible implementation, when the second application needs to read data, the device to which the second application belongs can send a data read request to the target access address. This data read request may carry the target application identifier of the second application. The device 12 to which the target access address belongs receives the data read request and, based on the stored correspondence between application identifiers and databases, determines the target database 13 corresponding to the target application identifier. The device 12 to which the target access address belongs can then obtain the data stored in the target database 13, and, based on the stored correspondence between application identifiers and encryption keys, determine the target encryption key corresponding to the target application identifier. Based on the target encryption key, the obtained data is decrypted, and the decrypted data is sent to the device to which the second application belongs.
[0128] In one possible implementation, similar to the above embodiments, the device 12 to which the target access address belongs can send a request to the management platform to obtain the encryption policy of the second application. This encryption policy request may carry the target application identifier corresponding to the second application. If the data storage security protection request sent by the device to which the second application belongs carries an encryption policy for the data, the management platform can send the encryption policy to the device 12 to which the target access address belongs. The device 12 to which the target access address belongs receives the encryption policy and saves the correspondence between the target application identifier and the encryption policy. Subsequently, if it receives the aforementioned data read request from the device to which the second application belongs, the device 12 to which the target access address belongs can determine the target encryption policy corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption policy. Based on the target encryption key and the target encryption policy, it decrypts the data obtained from the target database 13 and sends the decrypted data to the device to which the second application belongs.
[0129] For example, Figure 8 The diagram illustrates a data reading process provided by some embodiments, such as Figure 8 As shown, the device to which the second application belongs (referred to as the application in the figure) sends a data read request to the target access address (referred to as the pre-encryption module in the figure). The data read request carries the target application identifier of the second application. Optionally, the device 12 (pre-encryption module) to which the target access address belongs includes an encryption / decryption module and an encryption proxy module. The encryption proxy module can intercept and parse the data read request, i.e., SQL.
[0130] The encryption proxy module determines the target database 13 corresponding to the target application identifier based on the stored correspondence between application identifiers and databases; it then retrieves the data stored in the target database 13. Based on the stored correspondence between application identifiers and encryption policies, the encryption proxy module determines the target encryption policy corresponding to the target application identifier of the second application. Based on this target encryption policy, the encryption proxy module can determine the encrypted sub-data from the data retrieved from the target database 13, extract the encrypted sub-data, and send the encrypted sub-data and the target application identifier of the second application to the encryption / decryption module. Upon receiving the encrypted sub-data and the target application identifier, the encryption / decryption module can determine the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys. Based on the target encryption key, it decrypts the encrypted sub-data and returns the plaintext data of the decrypted sub-data to the encryption proxy module. The encryption proxy module then reassembles the decrypted sub-data into the data retrieved from the target database 13 and sends the decrypted data to the device to which the second application belongs.
[0131] Similarly, as in the above embodiments, the device 12 to which the target access address belongs sends a request to the management platform to obtain the encryption policy of the second application. This encryption policy request carries the target application identifier corresponding to the second application. If the data storage security protection request sent by the device to which the second application belongs carries an encryption policy for the data, the management platform sends the encryption policy to the device 12 to which the target access address belongs. The device 12 to which the target access address belongs receives the encryption policy, saves the correspondence between the target application identifier and the encryption policy, and if the device 12 to which the target access address belongs receives a sharing request sent by the device to which the first application belongs, the device 12 to which the target access address belongs can determine the target encryption policy corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption policy. Based on the target encryption key and the target encryption policy, the device 12 decrypts the data obtained from the target database 13 and sends the decrypted data to the device to which the first application belongs. The process of decrypting the data obtained from the target database 13 based on the target encryption key and the target encryption policy is the same as in the above embodiments and will not be described again here.
[0132] In one possible implementation, the device 12 (pre-encryption module) to which the target access address belongs can be integrated into the device to which the second application belongs, or the device 12 (pre-encryption module) to which the target access address belongs can be deployed in an encryption gateway cluster. For example, when providing security storage services only for one application, the device 12 (pre-encryption module) to which the target access address belongs can be integrated into the device to which that application belongs. See also... Figure 9 , Figure 9 The diagram illustrates a data security storage process according to some embodiments. When multiple applications require data storage security protection services (also known as secure storage services), the device 12 (front-end encryption module) belonging to the target access address can be deployed in an encryption gateway cluster. That is, when there are multiple second applications, for each second application's device, a write data request can be sent to the device 12 (front-end encryption module) of the target access address deployed in the encryption gateway cluster. The data to be written to the database carried in the write data request is plaintext data. For each second application, the device 12 (front-end encryption module) of the target access address can determine the target encryption key corresponding to the target application identifier of that second application based on the stored correspondence between application identifiers and encryption keys. Based on the target encryption key, the data to be written to the database of that second application is encrypted, and the encrypted data (ciphertext) is saved to the target database 13 corresponding to that second application. In one possible implementation, different applications can correspond to different databases; that is, each application can correspond to its own dedicated database.
[0133] Since this application can encrypt data of different second applications based on different encryption keys, it can achieve automatic secure isolation of data between applications according to the different applications, thereby increasing data security.
[0134] In addition, each device belonging to a second application can send a data read request to device 12 (pre-encryption module) belonging to the target access address deployed in the encryption gateway cluster. For each second application, device 12 (pre-encryption module) belonging to the target access address can determine the target database 13 corresponding to the target application identifier of the second application based on the correspondence between the saved application identifier and the database; obtain the corresponding data of the second application stored in the target database 13. It can be understood that the data obtained from the database is encrypted data, i.e., ciphertext data; device 12 (pre-encryption module) belonging to the target access address determines the target encryption key corresponding to the target application identifier of the second application based on the correspondence between the saved application identifier and the encryption key; based on the target encryption key, decrypt the obtained data and send the decrypted data (plaintext) to the device belonging to the second application.
[0135] In one possible implementation, the management platform can be deployed on a separate device, or on the device 11 to which the first application belongs, or on the device to which the second application belongs. This application does not make any specific limitations on this, and it can be flexibly configured according to needs.
[0136] For ease of understanding, the data sharing process provided in this application will be illustrated below through a specific embodiment. Figure 10 This application provides a schematic diagram of a data sharing scenario for some embodiments, such as... Figure 10 As shown, the process may include: (1) registration and authorization process of the second application (application A), (2) target encryption key transmission process, (3) data writing or reading process of the second application, (4) application of the first application (application B) requesting to share the data of the second application, and (5) data sharing of the first application by the second application.
[0137] Among them: (1) The registration and authorization process for the second application (application A) may include:
[0138] The device owning the second application sends a data storage security protection request to the management platform. This request includes the name of the second application and its target access address. The management platform receives the request, generates a target application identifier and a target encryption key corresponding to the name of the second application, and saves the mapping between the target application identifier and the target encryption key. Optionally, the generated target encryption key can be stored in the management platform's TEE (Transaction Engine). Optionally, the target application identifier generated by the management platform includes primary identifier information and secondary identifier information. The primary identifier information is sent to the device owning the second application, and the device stores the mapping between the primary identifier information and the target access address in its database configuration file. The target access address can be the address of the front-end encryption module.
[0139] (2) The target encryption key transmission process may include:
[0140] The device 12 (front-end encryption module) to which the target access address belongs sends a key retrieval request to the management platform to obtain the target encryption key corresponding to the second application. The management platform receives the key retrieval request, determines the target encryption key corresponding to the target application identifier of the second application based on the stored mapping between application identifiers and encryption keys, and sends the target encryption key to the device 12 to which the target access address belongs through the established secure encryption channel. The device 12 to which the target access address belongs receives the target encryption key, stores the target encryption key in the TEE, and also stores the mapping between the target encryption key and the target application identifier of the second application.
[0141] (3) The process of writing or reading data in the second application is as follows:
[0142] The process of writing data for the second application is as follows: The device to which the second application belongs sends a write data request to the target access address. The write data request carries the data to be written to the database and the target application identifier of the second application (such as main identifier information). The encryption proxy module in the device 12 (pre-encryption module) to which the target access address belongs receives the write data request and recognizes that the target application identifier carried in the write data request is the main identifier information of the second application. Therefore, it can be considered that the write data request is a compliant request for the second application to write data to its own database. Based on the application's main logic (main schema), the corresponding data writing process can be performed. That is, the data to be written to the database (plaintext) can be sent to the encryption / decryption module in the device 12 (pre-encryption module) to which the target access address belongs. This encryption / decryption module is configured in the TEE, and the encryption key is stored in this encryption / decryption module. The encryption / decryption module determines the target encryption key corresponding to the target application identifier based on the stored correspondence between the application identifier and the encryption key. Based on the target encryption key, the data to be written to the database is encrypted, and the encrypted data (ciphertext) is sent to the encryption proxy module. The encryption proxy module stores the encrypted data in the target database 13 corresponding to the second application.
[0143] The process of the second application reading data is as follows: The device to which the second application belongs sends a data read request to the target access address. The data read request carries the target application identifier (such as main identifier information) of the second application. The encryption proxy module in the device 12 (pre-encryption module) to which the target access address belongs receives the data read request and recognizes that the target application identifier carried in the data read request is the main identifier information of the second application. Therefore, it can be considered that the data read request is a compliant request for the second application to read data in its own database. The corresponding data read process can be performed based on the application's main logic (main schema). That is, based on the saved correspondence between the application identifier and the database, the target database 13 corresponding to the target application identifier is determined; and the data saved in the target database 13 is obtained. The encryption proxy module sends the obtained data (ciphertext) to the encryption / decryption module. The encryption / decryption module determines the target encryption key corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption key. Based on the target encryption key, the obtained data is decrypted, and the decrypted data is sent to the encryption proxy module. The encryption proxy module then sends the decrypted data to the device to which the second application belongs.
[0144] (4) The process by which the first application (application B) requests to share data from the second application may include:
[0145] The device belonging to the first application (Application B) sends a request to the management platform to share data from the second application (Application A). This request includes the application identifier of the first application. The management platform receives the request and forwards it to the device belonging to the second application. The device belonging to the second application receives the request and displays the application identifier of the first application included in the request. If it receives a confirmation instruction agreeing to share data with the first application, it sends the confirmation instruction to the management platform. The management platform receives the confirmation instruction and sends the secondary identifier information from the target application identifier of the second application, along with the target access address corresponding to the target application identifier information, to the device belonging to the first application. The device belonging to the first application stores the mapping between the secondary identifier information of the second application and the target access address.
[0146] (5) The process of the first application sharing data from the second application includes:
[0147] The device belonging to the first application (application B) determines the target access address corresponding to the target application identifier (such as secondary identifier information) of the second application based on the pre-saved correspondence between application identifiers and access addresses, and sends a sharing request to the target access address to share the data of the second application. The sharing request carries the target application identifier (such as secondary identifier information).
[0148] The encryption proxy module in device 12, the terminal to which the target access address belongs, determines whether the target application identifier carried in the sharing request is a secondary identifier of the second application. If so, it performs the corresponding data sharing process based on the application secondary logic (secondary schema). That is, it can determine whether the sharing request is a read data request or a write data request. If the sharing request is a read data request, and the pre-saved usage permissions of the first application for the second application's data include that the first application can read the second application's data, then the sharing request is considered to meet the usage permissions. Based on the saved correspondence between the application identifier and the database, it determines the target database 13 corresponding to the target application identifier and retrieves the data stored in the target database 13. The encryption proxy module sends the data retrieved from the target database 13 to the encryption / decryption module. The encryption / decryption module determines the target encryption key corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption key, decrypts the retrieved data based on the target encryption key, and sends the decrypted data to the encryption proxy module. The encryption proxy module sends the decrypted data to device 11, to which the first application belongs.
[0149] Example 3:
[0150] Based on the same technical concept, this application provides a data sharing method, which is applied to the device to which the first application belongs. Figure 11 A schematic diagram of a sixth data sharing process provided in some embodiments is shown, which includes the following steps:
[0151] S1101: Based on the pre-saved correspondence between application identifiers and access addresses, determine the target access address corresponding to the target application identifier of the second application, and send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier.
[0152] S1102: Receive the decrypted data of the second application sent by the device to which the target access address belongs.
[0153] The device to which the first application belongs can be a PC, a mobile terminal, or a server.
[0154] In one possible implementation, before determining the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, the method further includes:
[0155] Send a request to the management platform to share data of the second application, the request carrying the application identifier of the first application;
[0156] If the management platform receives the target application identifier of the second application and the target access address corresponding to the target application identifier information, the correspondence between the target application identifier and the target access address is saved.
[0157] Based on the same technical concept, this application provides a data sharing method, which is applied to the device to which the target access address belongs. Figure 12 A schematic diagram of a seventh data sharing process provided in some embodiments is shown, which includes the following steps:
[0158] S1201: Receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the identifier of the target application.
[0159] S1202: Based on the correspondence between the saved application identifier and the database, determine the target database corresponding to the target application identifier; obtain the data saved in the target database.
[0160] S1203: Determine the target encryption key corresponding to the target application identifier based on the saved correspondence between the application identifier and the encryption key; decrypt the acquired data based on the target encryption key; and send the decrypted data to the device to which the first application belongs.
[0161] The device to which the target access address belongs can be a PC, a mobile terminal, or a server.
[0162] In one possible implementation, after receiving the sharing request sent by the device to which the first application belongs, and before determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases, the method further includes:
[0163] Determine whether the type of the sharing request is a read data request or a write data request. Based on the type of the sharing request and the pre-saved usage permissions of the first application for the second application's data, determine whether the sharing request conforms to the usage permissions. If so, proceed to the next step of determining the target database corresponding to the target application identifier based on the saved correspondence between the application identifier and the database.
[0164] In one possible implementation, after decrypting the acquired data based on the target encryption key and before sending the decrypted data to the device to which the first application belongs, the method further includes:
[0165] If the acquired data contains set sensitive data, then the decrypted data will be subjected to data desensitization processing;
[0166] Sending the decrypted data to the device to which the first application belongs includes:
[0167] The data, after being anonymized, is sent to the device to which the first application belongs.
[0168] In one possible implementation, after receiving the sharing request sent by the device to which the first application belongs, and before determining whether the type of the sharing request is a read data request or a write data request, the method further includes:
[0169] If the target application identifier of the second application includes primary identifier information and secondary identifier information, determine whether the target application identifier carried in the sharing request is the secondary identifier information of the second application. If so, proceed with the subsequent steps.
[0170] In one possible implementation, before receiving the sharing request sent by the device to which the first application belongs, the method further includes:
[0171] Send a key retrieval request to the management platform to obtain the target encryption key corresponding to the second application;
[0172] If the target encryption key corresponding to the second application is received from the management platform, the correspondence between the target encryption key and the target application identifier is saved.
[0173] In one possible implementation, after receiving the target encryption key corresponding to the second application sent by the management platform, and before saving the correspondence between the target encryption key and the target application identifier, the method further includes:
[0174] If the received target encryption key is a target encryption key encrypted based on a temporary secure channel key negotiated with the management platform, the target encryption key is decrypted based on the temporary secure channel key.
[0175] In one possible implementation, storing the target encryption key includes:
[0176] The target encryption key is encrypted based on the set second TEE physical storage root key, and the encrypted target encryption key is saved.
[0177] In one possible implementation, the method further includes:
[0178] Receive a write data request sent by the device to which the second application belongs, wherein the write data request carries the data to be written to the database and the target application identifier of the second application;
[0179] Based on the saved correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined. Based on the target encryption key, the data to be written to the database is encrypted, and the encrypted data is saved to the corresponding target database.
[0180] In one possible implementation, encrypting the data to be written to the database based on the target encryption key includes:
[0181] Based on the pre-saved correspondence between application identifiers and encryption policies, the target encryption policy corresponding to the target application identifier is determined; based on the target encryption key and the target encryption policy, the data to be written into the database is encrypted.
[0182] In one possible implementation, the method further includes:
[0183] Receive a data read request sent by the device to which the second application belongs, wherein the data read request carries the target application identifier of the second application;
[0184] Based on the stored correspondence between application identifiers and databases, determine the target database corresponding to the target application identifier; and retrieve the data stored in the target database.
[0185] Based on the stored correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined. Based on the target encryption key, the acquired data is decrypted, and the decrypted data is sent to the device to which the second application belongs.
[0186] In one possible implementation, the step of decrypting the acquired data based on the target encryption key includes:
[0187] Based on the pre-saved correspondence between application identifiers and encryption policies, the target encryption policy corresponding to the target application identifier is determined;
[0188] The acquired data is decrypted based on the target encryption key and the target encryption strategy.
[0189] Based on the same technical concept, this application provides a data sharing method, which is applied to the device to which the second application belongs. Figure 13 The diagram illustrates an eighth data sharing process provided in some embodiments, which includes the following steps:
[0190] S1301: If an application is received from the management platform, display the application identifier of the first application carried in the application.
[0191] S1302: If a confirmation instruction agreeing to share data with the first application is received, the confirmation instruction is sent to the management platform.
[0192] The device to which the second application belongs can be a PC, a mobile terminal, or a server.
[0193] In one possible implementation, the method further includes:
[0194] Send a data storage security protection request to the management platform. The data storage security protection request carries the name of the second application and the target access address of the second application.
[0195] In one possible implementation, the method further includes:
[0196] Send a write data request to the target access address. The write data request carries the data to be written to the database and the target application identifier of the second application.
[0197] In one possible implementation, the method further includes:
[0198] Send a read data request to the target access address, wherein the read data request carries the target application identifier of the second application;
[0199] Receive decrypted data sent by the device to which the target access address belongs.
[0200] Based on the same technical concept, this application provides a data sharing method applied to a management platform. Figure 14 A schematic diagram of a ninth data sharing process provided in some embodiments is shown, which includes the following steps:
[0201] S1401: Receive a request from the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application.
[0202] S1402: Send the application to the device to which the second application belongs.
[0203] S1403: If a confirmation instruction agreeing to share data with the first application is received from the device to which the second application belongs, the target application identifier of the second application and the target access address corresponding to the target application identifier information are sent to the device to which the first application belongs.
[0204] In one possible implementation, before receiving the request from the device to which the first application belongs to share data of the second application, the method further includes:
[0205] Receive a data storage security protection request sent by the device to which the second application belongs, wherein the data storage security protection request carries the name of the second application and the target access address of the second application;
[0206] Upon receiving the data storage security protection request, generate a target application identifier and a target encryption key corresponding to the name of the second application, and save the correspondence between the target application identifier and the target encryption key;
[0207] If a key retrieval request is received from the device to which the target access address belongs, requesting the target encryption key corresponding to the second application;
[0208] Based on the stored correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier of the second application is determined, and the target encryption key is sent to the device to which the target access address belongs.
[0209] In one possible implementation, after determining the target encryption key corresponding to the target application identifier of the second application, and before sending the target encryption key to the device to which the target access address belongs, the method further includes:
[0210] If the saved target encryption key is a key encrypted based on the set first TEE physical storage root key, the target encryption key is decrypted based on the first TEE physical storage root key;
[0211] Sending the target encryption key to the device to which the target access address belongs includes:
[0212] The decrypted target encryption key is sent to the device to which the target access address belongs.
[0213] In one possible implementation, sending the target encryption key to the device to which the target access address belongs includes:
[0214] Based on the established secure channel, the target encryption key is sent to the device to which the target access address belongs.
[0215] In one possible implementation, sending the target encryption key to the device to which the target access address belongs, based on the established secure channel, includes:
[0216] Based on the temporary secure channel key negotiated with the device to which the target access address belongs, the target encryption key is encrypted, and the encrypted target encryption key is sent to the device to which the target access address belongs based on the secure channel.
[0217] In one possible implementation, the method further includes:
[0218] Receive a request from the device to which the target access address belongs to obtain the encryption policy of the second application, wherein the encryption policy request carries the target application identifier corresponding to the second application;
[0219] If the data storage security protection request sent by the device to which the second application corresponding to the target application identifier belongs carries an encryption policy for the data, the encryption policy is sent to the device to which the target access address belongs, so that the device to which the target access address belongs saves the correspondence between the target application identifier and the encryption policy.
[0220] Example 4:
[0221] Based on the same technical concept, this application provides a data sharing device, applied to the device to which the first application belongs. Figure 15 A schematic diagram of a first data sharing apparatus provided in some embodiments is shown, the apparatus comprising:
[0222] The first determining module 151 is used to determine the target access address corresponding to the target application identifier of the second application according to the pre-saved correspondence between application identifiers and access addresses, and send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier.
[0223] The first receiving module 152 is used to receive the decrypted data of the second application sent by the device to which the target access address belongs.
[0224] In one possible implementation, the first determining module 151 is further configured to send an application to the management platform to share the data of the second application, the application carrying the application identifier of the first application; if the management platform sends the target application identifier of the second application and the target access address corresponding to the target application identifier information, the module saves the correspondence between the target application identifier and the target access address.
[0225] Based on the same technical concept, this application provides a data sharing device, applied to the device to which the target access address belongs. Figure 16 A schematic diagram of a second data sharing device provided in some embodiments is shown, the device comprising:
[0226] The second receiving module 161 is used to receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the target application identifier;
[0227] The second determining module 162 is used to determine the target database corresponding to the target application identifier based on the correspondence between the stored application identifier and the database; and to obtain the data stored in the target database.
[0228] The encryption / decryption module 163 is used to determine the target encryption key corresponding to the target application identifier based on the stored correspondence between the application identifier and the encryption key; decrypt the acquired data based on the target encryption key; and send the decrypted data to the device to which the first application belongs.
[0229] In one possible implementation, the second determining module 162 is further configured to determine whether the type of the sharing request is a read data request or a write data request, and based on the type of the sharing request and the pre-saved usage permissions of the first application for the second application's data, determine whether the sharing request conforms to the usage permissions. If so, proceed to the subsequent step of determining the target database corresponding to the target application identifier based on the saved correspondence between the application identifier and the database.
[0230] In one possible implementation, the encryption / decryption module 163 is further configured to perform data desensitization processing on the decrypted data if the acquired data contains set sensitive data; and send the data after data desensitization processing to the device to which the first application belongs.
[0231] In one possible implementation, the second determining module 162 is further configured to determine whether the target application identifier carried in the sharing request is the secondary identifier of the second application if the target application identifier of the second application includes primary identifier information and secondary identifier information; if so, proceed to the subsequent step of determining whether the type of the sharing request is a read data request or a write data request.
[0232] In one possible implementation, the second receiving module 161 is further configured to send a key acquisition request to the management platform to obtain the target encryption key corresponding to the second application; if the target encryption key corresponding to the second application is received from the management platform, the corresponding relationship between the target encryption key and the target application identifier is saved.
[0233] In one possible implementation, the second receiving module 161 is further configured to decrypt the target encryption key based on the temporary secure channel key if the received target encryption key is a target encryption key encrypted based on a temporary secure channel key negotiated with the management platform.
[0234] In one possible implementation, the second receiving module 161 is specifically used to encrypt the target encryption key based on the set second TEE physical storage root key, and save the encrypted target encryption key.
[0235] In one possible implementation, the encryption / decryption module 163 is further configured to receive a write data request sent by the device to which the second application belongs, the write data request carrying data to be written to the database and the target application identifier of the second application; determine the target encryption key corresponding to the target application identifier according to the saved correspondence between the application identifier and the encryption key; encrypt the data to be written to the database based on the target encryption key; and save the encrypted data to the corresponding target database.
[0236] In one possible implementation, the encryption / decryption module 163 is specifically used to determine the target encryption policy corresponding to the target application identifier based on the pre-saved correspondence between application identifiers and encryption policies; and to encrypt the data to be written to the database based on the target encryption key and the target encryption policy.
[0237] In one possible implementation, the encryption / decryption module 163 is further configured to receive a data read request sent by the device to which the second application belongs, the data read request carrying a target application identifier of the second application; determine the target database corresponding to the target application identifier according to the stored correspondence between the application identifier and the database; obtain the data stored in the target database; determine the target encryption key corresponding to the target application identifier according to the stored correspondence between the application identifier and the encryption key; decrypt the obtained data based on the target encryption key; and send the decrypted data to the device to which the second application belongs.
[0238] In one possible implementation, the encryption / decryption module 163 is specifically used to determine the target encryption policy corresponding to the target application identifier based on the pre-saved correspondence between application identifiers and encryption policies; and to decrypt the acquired data based on the target encryption key and the target encryption policy.
[0239] Based on the same technical concept, this application provides a data sharing device, which is applied to the device to which the second application belongs. Figure 17 A schematic diagram of a third data sharing device provided in some embodiments is shown, the device comprising:
[0240] The display module 171 is used to display the application identifier of the first application carried in the application if an application is received from the management platform.
[0241] The first sending module 172 is used to send the confirmation instruction to the management platform if it receives a confirmation instruction agreeing to share data with the first application.
[0242] In one possible implementation, the first sending module 172 is further configured to send a data storage security protection request to the management platform, wherein the data storage security protection request carries the name of the second application and the target access address of the second application.
[0243] In one possible implementation, the first sending module 172 is further configured to send a write data request to the target access address, the write data request carrying data to be written to the database and the target application identifier of the second application.
[0244] In one possible implementation, the first sending module 172 is further configured to send a read data request to the target access address, the read data request carrying the target application identifier of the second application; and receive decrypted data sent by the device to which the target access address belongs.
[0245] Based on the same technical concept, this application provides a data sharing device for use in a management platform.Figure 18 A schematic diagram of a fourth data sharing device provided in some embodiments is shown, the device comprising:
[0246] The third receiving module 181 is used to receive a request sent by the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application;
[0247] The second sending module 182 is used to send the application to the device to which the second application belongs; if it receives a confirmation instruction from the device to which the second application belongs to agree to share data with the first application, it sends the saved target application identifier of the second application and the target access address corresponding to the target application identifier information to the device to which the first application belongs.
[0248] In one possible implementation, the third receiving module 181 is further configured to receive a data storage security protection request sent by the device to which the second application belongs, the data storage security protection request carrying the name of the second application and the target access address of the second application; upon receiving the data storage security protection request, generate a target application identifier and a target encryption key corresponding to the name of the second application, and save the correspondence between the target application identifier and the target encryption key; if a key acquisition request is received from the device to which the target access address belongs to obtain the target encryption key corresponding to the second application; based on the saved correspondence between the application identifier and the encryption key, determine the target encryption key corresponding to the target application identifier of the second application, and send the target encryption key to the device to which the target access address belongs.
[0249] In one possible implementation, the third receiving module 181 is further configured to, if the stored target encryption key is a key encrypted based on a set first TEE physical storage root key, decrypt the target encryption key based on the first TEE physical storage root key; and send the decrypted target encryption key to the device to which the target access address belongs.
[0250] In one possible implementation, the third receiving module 181 is specifically used to send the target encryption key to the device to which the target access address belongs, based on the established secure channel.
[0251] In one possible implementation, the third receiving module 181 is specifically used to encrypt the target encryption key based on a temporary secure channel key negotiated with the device to which the target access address belongs, and send the encrypted target encryption key to the device to which the target access address belongs based on the secure channel.
[0252] In one possible implementation, the second sending module 182 is further configured to receive a request from the device to which the target access address belongs to obtain an encryption policy for the second application, wherein the encryption policy request carries a target application identifier corresponding to the second application; if the data storage security protection request sent by the device to which the target application identifier belongs carries an encryption policy for the data, the encryption policy is sent to the device to which the target access address belongs, so that the device to which the target access address belongs saves the correspondence between the target application identifier and the encryption policy.
[0253] Based on the same technical concept, this application also provides an electronic device. Figure 19 The diagram illustrates a schematic representation of an electronic device structure provided in some embodiments, such as... Figure 19 As shown, it includes: processor 191, communication interface 192, memory 193 and communication bus 194, wherein processor 191, communication interface 192 and memory 193 communicate with each other through communication bus 194;
[0254] In one possible implementation, the memory 193 stores a computer program that, when executed by the processor 191, causes the processor 191 to perform the steps of any of the data sharing methods described above.
[0255] Since the principle of solving the problem by the above-mentioned electronic devices is similar to that of data sharing methods, the implementation of the above-mentioned electronic devices can be referred to the implementation of the method, and the repeated parts will not be repeated.
[0256] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0257] Communication interface 192 is used for communication between the above-mentioned electronic device and other devices.
[0258] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0259] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0260] Based on the same technical concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device. When the program is run on the electronic device, it causes the electronic device to execute the steps of any of the above-described data sharing methods.
[0261] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.
[0262] Based on the same technical concept and the above embodiments, this application provides a computer program product, which includes computer program code that, when run on a computer, causes the computer to perform the steps of any of the data sharing methods described above.
[0263] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0264] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0265] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0266] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0267] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data sharing system, characterized in that, The system includes: The device to which the first application belongs is used to determine the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, and to send a sharing request to the target access address to share the data of the second application, wherein the sharing request carries the target application identifier; The device to which the target access address belongs is configured to receive the sharing request, determine the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases, obtain the data stored in the target database, determine the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys, decrypt the obtained data based on the target encryption key, and send the decrypted data to the device to which the first application belongs. The target database is used to store data.
2. The system according to claim 1, characterized in that, The system also includes: a management platform and the device to which the second application belongs; The device to which the first application belongs is also used to send a request to the management platform to share data of the second application, the request carrying the application identifier of the first application; The management platform is used to receive the application and send the application to the device to which the second application belongs; The device to which the second application belongs is used to receive the application and display the application identifier of the first application carried in the application. If a confirmation instruction agreeing to the first application sharing data is received, the confirmation instruction is sent to the management platform. The management platform is also used to receive the confirmation instruction and send the saved target application identifier of the second application and the target access address corresponding to the target application identifier information to the device to which the first application belongs; The device to which the first application belongs is also used to store the correspondence between the target application identifier and the target access address.
3. The system according to claim 1, characterized in that, The device to which the target access address belongs is also used to determine whether the type of the sharing request is a read data request or a write data request. Based on the type of the sharing request and the pre-saved usage permissions of the first application for the second application's data, it is determined whether the sharing request conforms to the usage permissions. If so, the step of determining the target database corresponding to the target application identifier is performed according to the correspondence between the saved application identifier and the database.
4. The system according to any one of claims 1-3, characterized in that, The device to which the target access address belongs is also configured to perform data desensitization processing on the decrypted data if the acquired data contains set sensitive data, and send the data after data desensitization processing to the device to which the first application belongs.
5. The system according to claim 3, characterized in that, The device to which the target access address belongs is further configured to determine whether the target application identifier carried in the sharing request is the secondary identifier of the second application if the target application identifier of the second application includes primary identifier information and secondary identifier information. If so, the device is configured to determine whether the type of the sharing request is a read data request or a write data request, and to determine whether the sharing request conforms to the usage permission based on the type of the sharing request and the pre-saved usage permission of the first application for the data of the second application.
6. The system according to claim 1, characterized in that, The system also includes: a management platform and the device to which the second application belongs; The device to which the second application belongs is used to send a data storage security protection request to the management platform. The data storage security protection request carries the name of the second application and the target access address of the second application. The management platform is also used to receive the data storage security protection request, generate a target application identifier and a target encryption key corresponding to the name of the second application, and save the correspondence between the target application identifier and the target encryption key; The device to which the target access address belongs is also used to send a key acquisition request to the management platform to obtain the target encryption key corresponding to the second application; The management platform is used to receive the key acquisition request, determine the target encryption key corresponding to the target application identifier of the second application according to the stored correspondence between application identifiers and encryption keys, and send the target encryption key to the device to which the target access address belongs; The device to which the target access address belongs is also used to receive the target encryption key and save the correspondence between the target encryption key and the target application identifier.
7. The system according to claim 6, characterized in that, The target encryption key stored in the management platform is stored in the Trusted Execution Environment (TEE) of the management platform; and / or, The target encryption key stored in the device to which the target access address belongs is stored in the TEE of the device to which the target access address belongs.
8. The system according to any one of claims 6-7, characterized in that, The management platform is further configured to, if the stored target encryption key is a key encrypted based on a set first TEE physical storage root key, decrypt the target encryption key based on the first TEE physical storage root key, and send the decrypted target encryption key to the device to which the target access address belongs.
9. The system according to any one of claims 6-7, characterized in that, The management platform is specifically used to send the target encryption key to the device to which the target access address belongs, based on the established secure channel.
10. The system according to claim 9, characterized in that, The management platform is specifically used to encrypt the target encryption key based on a temporary security channel key negotiated with the device to which the target access address belongs, and send the encrypted target encryption key to the device to which the target access address belongs based on the security channel. The device to which the target access address belongs is also used to receive the target encryption key encrypted based on the temporary security channel key negotiated with the management platform, and to decrypt the target encryption key based on the temporary security channel key.
11. The system according to claim 6, 7, or 10, characterized in that, The device to which the target access address belongs is also used to encrypt the target encryption key based on the set second TEE physical storage root key, and save the encrypted target encryption key.
12. The system according to claim 6, characterized in that, The device to which the second application belongs is also used to send a write data request to the target access address, wherein the write data request carries the data to be written to the database and the target application identifier of the second application; The device to which the target access address belongs is also used to receive the write data request, determine the target encryption key corresponding to the target application identifier according to the correspondence between the saved application identifier and the encryption key, encrypt the data to be written to the database based on the target encryption key, and save the encrypted data to the corresponding target database.
13. The system according to claim 12, characterized in that, The device to which the target access address belongs is also used to send a request to the management platform to obtain the encryption policy of the second application, wherein the encryption policy request carries the target application identifier corresponding to the second application; The management platform is also used to receive the encryption policy request, and if the data storage security protection request sent by the device to which the second application corresponding to the target application identifier belongs carries an encryption policy for the data, the platform will send the encryption policy to the device to which the target access address belongs. The device to which the target access address belongs is also used to receive the encryption policy and save the correspondence between the target application identifier and the encryption policy; if the write data request is received, the target encryption policy corresponding to the target application identifier is determined according to the saved correspondence between the application identifier and the encryption policy. The data to be written to the database is encrypted based on the target encryption key and the target encryption strategy.
14. The system according to claim 6, characterized in that, The device to which the second application belongs is also used to send a read data request to the target access address, wherein the read data request carries the target application identifier of the second application; The device to which the target access address belongs is also used to receive the data read request, determine the target database corresponding to the target application identifier according to the correspondence between the saved application identifier and the database; obtain the data saved in the target database; determine the target encryption key corresponding to the target application identifier according to the correspondence between the saved application identifier and the encryption key; decrypt the obtained data based on the target encryption key; and send the decrypted data to the device to which the second application belongs.
15. The system according to claim 14, characterized in that, The device to which the target access address belongs is also used to send a request to the management platform to obtain the encryption policy of the second application, wherein the encryption policy request carries the target application identifier corresponding to the second application; The management platform is also used to receive the encryption policy request, and if the data storage security protection request sent by the device to which the second application corresponding to the target application identifier belongs carries an encryption policy for the data, the platform will send the encryption policy to the device to which the target access address belongs. The device to which the target access address belongs is also used to receive the encryption policy and save the correspondence between the target application identifier and the encryption policy; if the read data request is received, the target encryption policy corresponding to the target application identifier is determined according to the saved correspondence between the application identifier and the encryption policy. The acquired data is decrypted based on the target encryption key and the target encryption strategy.
16. A data sharing method, characterized in that, The method is applied to a device to which the first application belongs, and the method includes: Based on the pre-saved mapping between application identifiers and access addresses, the target access address corresponding to the target application identifier of the second application is determined. A sharing request for sharing data of the second application is sent to the target access address, the sharing request carrying the target application identifier. The device to which the target access address belongs receives the sharing request sent by the device to which the first application belongs. Based on the pre-saved mapping between application identifiers and databases, the target database corresponding to the target application identifier is determined. Data stored in the target database is retrieved. Based on the pre-saved mapping between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined. Based on the target encryption key, the retrieved data is decrypted. The decrypted data is sent to the device to which the first application belongs. Receive the decrypted data of the second application sent by the device to which the target access address belongs.
17. The method according to claim 16, characterized in that, Before determining the target access address corresponding to the target application identifier of the second application based on the pre-saved correspondence between application identifiers and access addresses, the method further includes: Send a request to the management platform to share data of the second application, the request carrying the application identifier of the first application; If the management platform receives the target application identifier of the second application and the target access address corresponding to the target application identifier information, the correspondence between the target application identifier and the target access address is saved.
18. A data sharing method, characterized in that, The method is applied to the device to which the target access address belongs, and the method includes: Receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the target application identifier; Based on the stored correspondence between application identifiers and databases, determine the target database corresponding to the target application identifier; and retrieve the data stored in the target database. Based on the saved correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined; based on the target encryption key, the acquired data is decrypted; and the decrypted data is sent to the device to which the first application belongs.
19. The method according to claim 18, characterized in that, After receiving the sharing request sent by the device to which the first application belongs, and before determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases, the method further includes: Determine whether the type of the sharing request is a read data request or a write data request. Based on the type of the sharing request and the pre-saved usage permissions of the first application for the second application, determine whether the sharing request meets the usage permissions. If so, proceed to the next step of determining the target database corresponding to the target application identifier based on the saved correspondence between the application identifier and the database.
20. The method according to claim 18 or 19, characterized in that, After decrypting the data obtained based on the target encryption key, and before sending the decrypted data to the device to which the first application belongs, the method further includes: If the acquired data contains set sensitive data, then the decrypted data will be subjected to data desensitization processing; Sending the decrypted data to the device to which the first application belongs includes: The data, after being anonymized, is sent to the device to which the first application belongs.
21. The method according to claim 19, characterized in that, After receiving the sharing request sent by the device to which the first application belongs, and before determining whether the sharing request is a read data request or a write data request, the method further includes: If the target application identifier of the second application includes primary identifier information and secondary identifier information, determine whether the target application identifier carried in the sharing request is the secondary identifier information of the second application. If so, proceed with the subsequent steps.
22. The method according to claim 18, characterized in that, Before receiving the sharing request sent by the device to which the first application belongs, the method further includes: Send a key retrieval request to the management platform to obtain the target encryption key corresponding to the second application; If the target encryption key corresponding to the second application is received from the management platform, the correspondence between the target encryption key and the target application identifier is saved.
23. The method according to claim 22, characterized in that, After receiving the target encryption key corresponding to the second application sent by the management platform, before saving the correspondence between the target encryption key and the target application identifier, the method further includes: If the received target encryption key is a target encryption key encrypted based on a temporary secure channel key negotiated with the management platform, the target encryption key is decrypted based on the temporary secure channel key.
24. The method according to claim 22 or 23, characterized in that, Storing the target encryption key includes: The target encryption key is encrypted based on the set second TEE physical storage root key, and the encrypted target encryption key is saved.
25. The method according to claim 22, characterized in that, The method further includes: Receive a write data request sent by the device to which the second application belongs, wherein the write data request carries the data to be written to the database and the target application identifier of the second application; Based on the saved correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined. Based on the target encryption key, the data to be written to the database is encrypted, and the encrypted data is saved to the corresponding target database.
26. The method according to claim 25, characterized in that, The step of encrypting the data to be written to the database based on the target encryption key includes: Based on the pre-saved correspondence between application identifiers and encryption policies, the target encryption policy corresponding to the target application identifier is determined; based on the target encryption key and the target encryption policy, the data to be written into the database is encrypted.
27. The method according to claim 22, characterized in that, The method further includes: Receive a data read request sent by the device to which the second application belongs, wherein the data read request carries the target application identifier of the second application; Based on the stored correspondence between application identifiers and databases, determine the target database corresponding to the target application identifier; and retrieve the data stored in the target database. Based on the stored correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier is determined. Based on the target encryption key, the acquired data is decrypted, and the decrypted data is sent to the device to which the second application belongs.
28. The method according to claim 27, characterized in that, The step of decrypting the acquired data based on the target encryption key includes: Based on the pre-saved correspondence between application identifiers and encryption policies, the target encryption policy corresponding to the target application identifier is determined; The acquired data is decrypted based on the target encryption key and the target encryption strategy.
29. A data sharing method, characterized in that, The method is applied to a device to which a second application belongs, and the method includes: If an application is received from the management platform, display the application identifier of the first application carried in the application; If a confirmation instruction agreeing to share data with the first application is received, the confirmation instruction will be sent to the management platform; The process involves the device belonging to the target access address receiving a sharing request sent by the device to which the first application belongs, the sharing request carrying the target application identifier of the second application; determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases; acquiring the data stored in the target database; determining the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys; decrypting the acquired data based on the target encryption key; and sending the decrypted data to the device to which the first application belongs.
30. The method according to claim 29, characterized in that, The method further includes: Send a data storage security protection request to the management platform. The data storage security protection request carries the name of the second application and the target access address of the second application.
31. The method according to claim 30, characterized in that, The method further includes: Send a write data request to the target access address. The write data request carries the data to be written to the database and the target application identifier of the second application.
32. The method according to claim 30, characterized in that, The method further includes: Send a read data request to the target access address, wherein the read data request carries the target application identifier of the second application; Receive decrypted data sent by the device to which the target access address belongs.
33. A data sharing method, characterized in that, The method is applied to a management platform, and the method includes: Receive a request from the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application; Send the application to the device to which the second application belongs; If a confirmation instruction agreeing to share data with the first application is received from the device to which the second application belongs, the saved target application identifier of the second application and the target access address corresponding to the target application identifier information are sent to the device to which the first application belongs. The process involves the device belonging to the target access address receiving a sharing request sent by the device to which the first application belongs, the sharing request carrying the target application identifier of the second application; determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases; acquiring the data stored in the target database; determining the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys; decrypting the acquired data based on the target encryption key; and sending the decrypted data to the device to which the first application belongs.
34. The method according to claim 33, characterized in that, Before receiving the request from the device to which the first application belongs to share data of the second application, the method further includes: Receive a data storage security protection request sent by the device to which the second application belongs, wherein the data storage security protection request carries the name of the second application and the target access address of the second application; Upon receiving the data storage security protection request, generate a target application identifier and a target encryption key corresponding to the name of the second application, and save the correspondence between the target application identifier and the target encryption key; If a key retrieval request is received from the device to which the target access address belongs, requesting the target encryption key corresponding to the second application; Based on the stored correspondence between application identifiers and encryption keys, the target encryption key corresponding to the target application identifier of the second application is determined, and the target encryption key is sent to the device to which the target access address belongs.
35. The method according to claim 34, characterized in that, After determining the target encryption key corresponding to the target application identifier of the second application, and before sending the target encryption key to the device to which the target access address belongs, the method further includes: If the saved target encryption key is a key encrypted based on the set first TEE physical storage root key, the target encryption key is decrypted based on the first TEE physical storage root key; Sending the target encryption key to the device to which the target access address belongs includes: The decrypted target encryption key is sent to the device to which the target access address belongs.
36. The method according to claim 34 or 35, characterized in that, Sending the target encryption key to the device to which the target access address belongs includes: Based on the established secure channel, the target encryption key is sent to the device to which the target access address belongs.
37. The method according to claim 36, characterized in that, The step of sending the target encryption key to the device to which the target access address belongs, based on the established secure channel, includes: Based on the temporary secure channel key negotiated with the device to which the target access address belongs, the target encryption key is encrypted, and the encrypted target encryption key is sent to the device to which the target access address belongs based on the secure channel.
38. The method according to claim 34, characterized in that, The method further includes: Receive a request from the device to which the target access address belongs to obtain the encryption policy of the second application, wherein the encryption policy request carries the target application identifier corresponding to the second application; If the data storage security protection request sent by the device to which the second application corresponding to the target application identifier belongs carries an encryption policy for the data, the encryption policy is sent to the device to which the target access address belongs, so that the device to which the target access address belongs saves the correspondence between the target application identifier and the encryption policy.
39. A data sharing device, characterized in that, The device includes: The first determining module is configured to: determine the target access address corresponding to the target application identifier of the second application based on a pre-saved correspondence between application identifiers and access addresses; send a sharing request to the target access address to share data of the second application, wherein the sharing request carries the target application identifier; enable the device to which the target access address belongs to receive the sharing request sent by the device to which the first application belongs; determine the target database corresponding to the target application identifier based on a pre-saved correspondence between application identifiers and databases; acquire the data stored in the target database; determine the target encryption key corresponding to the target application identifier based on a pre-saved correspondence between application identifiers and encryption keys; decrypt the acquired data based on the target encryption key; and send the decrypted data to the device to which the first application belongs. The first receiving module is used to receive the decrypted data of the second application sent by the device to which the target access address belongs.
40. A data sharing device, characterized in that, The device includes: The second receiving module is used to receive a sharing request sent by the device to which the first application belongs, wherein the sharing request carries the target application identifier of the second application; The second determining module is used to determine the target database corresponding to the target application identifier based on the correspondence between the saved application identifier and the database; and to obtain the data saved in the target database. The encryption / decryption module is used to determine the target encryption key corresponding to the target application identifier based on the stored correspondence between the application identifier and the encryption key; decrypt the acquired data based on the target encryption key; and send the decrypted data to the device to which the first application belongs.
41. A data sharing device, characterized in that, The device includes: The display module is used to display the application identifier of the first application carried in the application if an application is received from the management platform. The first sending module is configured to send the confirmation instruction to the management platform if it receives a confirmation instruction agreeing to share data with the first application. The process involves the device belonging to the target access address receiving a sharing request sent by the device to which the first application belongs, the sharing request carrying the target application identifier of the second application; determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases; acquiring the data stored in the target database; determining the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys; decrypting the acquired data based on the target encryption key; and sending the decrypted data to the device to which the first application belongs.
42. A data sharing device, characterized in that, The device includes: The third receiving module is used to receive a request sent by the device to which the first application belongs to share data of the second application, wherein the request carries the application identifier of the first application; The second sending module is used to send the application to the device to which the second application belongs; if it receives a confirmation instruction from the device to which the second application belongs to agree to share data with the first application, it sends the saved target application identifier of the second application and the target access address corresponding to the target application identifier information to the device to which the first application belongs. The process involves the device belonging to the target access address receiving a sharing request sent by the device to which the first application belongs, the sharing request carrying the target application identifier of the second application; determining the target database corresponding to the target application identifier based on the stored correspondence between application identifiers and databases; acquiring the data stored in the target database; determining the target encryption key corresponding to the target application identifier based on the stored correspondence between application identifiers and encryption keys; decrypting the acquired data based on the target encryption key; and sending the decrypted data to the device to which the first application belongs.
43. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores program code that, when executed by the processor, causes the processor to perform the steps of the method according to any one of claims 16 to 38.
44. A computer-readable storage medium, characterized in that, It includes program code that, when the storage medium is running on an electronic device, causes the electronic device to perform the steps of the method according to any one of claims 16 to 38.