Data access methods, devices, equipment and storage media

CN115600235BActive Publication Date: 2026-09-01TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110772732.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-08
Publication Date
2026-09-01
Estimated Expiration
2041-07-08

AI Technical Summary

Technical Problem

[0003]但是对于部分数据而言,由于其内容具有私密性,若直接将数据分享给其他终端以便其他终端对应的用户查看该数据,则可能存在数据发生泄漏的问题

Benefits of technology

[0021] This application provides a data access method, apparatus, device, and storage medium. When a server receives a data access request from a receiving client and, based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, confirms that the receiving client has access to the data link, it sends the target data corresponding to the data identifier to the receiving client. This ensures that the target data can only be accessed by users with data access permissions, avoiding data leakage and improving data access security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115600235B_ABST
    Figure CN115600235B_ABST
Patent Text Reader

Abstract

This application discloses a data access method, apparatus, device, and storage medium. The method includes: receiving a data access request sent by a receiving client, the data access request being generated by the receiving client in response to a triggering of a data link, the data access request carrying an enterprise identifier of the receiving client, a data source enterprise identifier, and a data identifier; when it is confirmed that the receiving client has access rights to the data link based on the enterprise identifier of the receiving client and the data source enterprise identifier, the method provides the receiving client with target data corresponding to the data identifier. By employing the above method, it can be ensured that the target data can only be accessed by users with data access rights, thereby improving the security of data access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more specifically, to a data access method, apparatus, device, and storage medium. Background Technology

[0002] Currently, with the continuous development of internet technology, the ways users interact have broken through spatial limitations. For example, terminals can use live streaming software, remote conferencing software, and information exchange software to share local data with other terminals (such as the target terminal), so that users on the target terminal can view the shared data.

[0003] However, for some data, due to the privacy of its content, directly sharing the data with other terminals so that users on those terminals can view the data may lead to data leakage. Summary of the Invention

[0004] In view of this, embodiments of this application propose a data access method, apparatus, device, and storage medium that can improve the security of data access.

[0005] In a first aspect, embodiments of this application provide a data access method applied to a server. The method includes: receiving a data access request sent by a receiving client, the data access request being generated by the receiving client in response to a triggering of a data link, the data access request carrying an enterprise identifier to which the receiving client belongs, a data source enterprise identifier, and a data identifier; when it is confirmed that the receiving client has access rights to the data link based on the enterprise identifier to which the receiving client belongs and the data source enterprise identifier, feeding back target data corresponding to the data identifier to the receiving client.

[0006] Secondly, embodiments of this application provide a data access method applied to a sending client. The method includes: obtaining the enterprise identifier of the receiving client, wherein the receiving client is the receiving client corresponding to the receiving user selected when forwarding target data; when the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, generating a data link including the data source enterprise identifier and a data identifier; and sending the data link to the receiving client.

[0007] Thirdly, embodiments of this application provide a data access method applied to a receiving client. The method includes: receiving a data link sent by a sending client, carrying a data source enterprise identifier and a data identifier; displaying the data link; in response to a triggering operation on the data link, sending a data access request to a server, the data access request carrying an enterprise identifier to which the sending client belongs, the data source enterprise identifier, and the data identifier, the data access request being used to instruct the server to confirm whether the receiving client has access rights to the data link based on the data source enterprise identifier; and receiving target data corresponding to the data identifier fed back by the server, the target data corresponding to the data identifier being fed back by the server when it confirms that the receiving client has access rights.

[0008] Fourthly, embodiments of this application provide a data access device applied to a server. The device includes a request receiving module and a data feedback module. The request receiving module is used to receive a data access request sent by a receiving client. The data access request is generated by the receiving client in response to a triggering of a data link. The data access request carries an enterprise identifier to which the receiving client belongs, a data source enterprise identifier, and a data identifier. The data feedback module is used to, upon confirming that the receiving client has access rights to the data link based on the enterprise identifier to which the receiving client belongs and the data source enterprise identifier, provide the receiving client with target data corresponding to the data identifier.

[0009] In one possible implementation, the server stores enterprise identifiers and corresponding interconnected enterprise identifiers. The data feedback module includes an identifier detection submodule and an access control submodule. The identifier detection submodule is used to detect whether the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the corresponding interconnected enterprise identifier. The access control submodule is used to confirm that the receiving client has access to the data link when the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the corresponding interconnected enterprise identifier.

[0010] In one possible implementation, the data identifier and the data source enterprise identifier carried in the data access request are encrypted data obtained by encrypting the data identifier and the data source enterprise identifier. The request receiving module includes a request receiving submodule and an identifier acquisition submodule. The request receiving submodule is used to receive the data access request sent by the receiving client and decrypt the encrypted data in the data access request; the identifier acquisition submodule is used to acquire the data source enterprise identifier and the data identifier from the decrypted data when decryption is successful.

[0011] In one possible implementation, the identifier acquisition submodule includes a detection unit and an identifier acquisition unit. The detection unit is used to detect whether the decrypted data meets preset conditions; the identifier acquisition unit is used to segment the decrypted data to obtain a data source enterprise identifier and a data identifier when the decrypted data meets the preset conditions.

[0012] In one possible implementation, the detection unit is further configured to detect whether the decrypted data carries a preset field and whether the data length of the decrypted data is within a preset length range. If the decrypted data carries the preset field and the data length of the decrypted data is within the preset length range, then the decrypted data satisfies the preset conditions.

[0013] Fifthly, embodiments of this application provide a data access device applied to a sending client. The device includes: an identifier acquisition module, a link generation module, and a link sending module. The identifier acquisition module is used to acquire the enterprise identifier of the receiving client, wherein the receiving client is the client corresponding to the receiving user selected when forwarding target data; the link generation module is used to generate a data link including the data source enterprise identifier and a data identifier when the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client; the link sending module is used to send the data link to the receiving client.

[0014] In one possible implementation, the link generation module is further configured to encrypt the data source enterprise identifier and data identifier to obtain encrypted data, and generate a data link including the encrypted data.

[0015] Sixthly, embodiments of this application provide a data access device applied to a receiving client. The device includes: a link receiving module, a link display module, a request sending module, and a data receiving module. The link receiving module is used to receive a data link sent by the sending client, carrying a data source enterprise identifier and a data identifier. The link display module is used to display the data link. The request sending module is used to send a data access request to a server in response to a triggering operation on the data link. The data access request carries an enterprise identifier of the sending client, the data source enterprise identifier, and the data identifier. The data access request instructs the server to confirm whether the receiving client has access rights to the data link based on the data source enterprise identifier. The data receiving module is used to receive target data corresponding to the data identifier fed back by the server. The target data corresponding to the data identifier is fed back by the server when it confirms that the receiving client has access rights.

[0016] In one possible implementation, the link receiving module is further configured to receive a data link carrying encrypted data sent by the sending client, wherein the encrypted data is obtained by encrypting the data source enterprise identifier and the data identifier; the request sending module is further configured to send a data access request including the encrypted data and the enterprise identifier to which the sending client belongs to the server in response to the triggering operation of the data link.

[0017] In one possible implementation, the data receiving module is further configured to display the target data corresponding to the data identifier in the data link.

[0018] In a seventh aspect, embodiments of this application provide an electronic device, including a processor and a memory; one or more programs are stored in the memory and configured to be executed by the processor to implement the above-described method.

[0019] Eighthly, embodiments of this application provide a computer-readable storage medium storing program code, wherein the above-described method is executed when the program code is run by a processor.

[0020] Ninthly, embodiments of this application provide a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device retrieves the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method described above.

[0021] This application provides a data access method, apparatus, device, and storage medium. When a server receives a data access request from a receiving client and, based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, confirms that the receiving client has access to the data link, it sends the target data corresponding to the data identifier to the receiving client. This ensures that the target data can only be accessed by users with data access permissions, avoiding data leakage and improving data access security. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 A schematic diagram of the structure of a data access system proposed in an embodiment of this application is shown;

[0024] Figure 2 A flowchart of a data access method proposed in an embodiment of this application is shown;

[0025] Figure 3 It shows Figure 2 A flowchart illustrating step S120;

[0026] Figure 4 A flowchart illustrating another data access method provided in an embodiment of this application is shown;

[0027] Figure 5 It shows Figure 4 A flowchart illustrating step S220;

[0028] Figure 6 A flowchart illustrating another data access method proposed in an embodiment of this application is shown;

[0029] Figure 7 A flowchart illustrating another data access method proposed in an embodiment of this application is shown;

[0030] Figure 8 A timing flowchart of the data access method provided in an embodiment of this application is shown;

[0031] Figure 9 Another timing flowchart of the data access method provided in an embodiment of this application is shown;

[0032] Figure 10 This document shows a view of the sender client interface provided in an embodiment of this application.

[0033] Figure 11 The interface view of the receiving client provided in the embodiments of this application is shown;

[0034] Figure 12 Another interface view of the receiving client provided in this application embodiment is shown;

[0035] Figure 13 This paper shows a connection block diagram of a data access device provided in an embodiment of this application;

[0036] Figure 14 A connection block diagram of another data access device provided in an embodiment of this application is shown;

[0037] Figure 15 This paper shows a connection block diagram of another data access device provided in an embodiment of this application;

[0038] Figure 16 A structural block diagram of an electronic device for performing the methods of embodiments of this application is shown. Detailed Implementation

[0039] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0040] Currently, electronic devices (such as mobile phones, computers, and tablets used for information display and data interaction) are widely available on the market. These devices consist of a display screen and a processor. The display screen shows images and text, and when it's a touchscreen, it also receives user touch input. The processor runs various applications to perform different functions. For example, electronic devices can typically be used to play videos, send and receive text messages, chat, and perform office tasks through installed clients. Because of their comprehensive functionality, they are widely loved by consumers.

[0041] In this context, "client" refers to various applications installed on electronic devices. These include information interaction applications (such as WeChat, QQ, and WeChat Work), video playback applications (such as Tencent Video), content interaction platform applications (such as QQ Browser), and game applications (shooting games, role-playing games, tactical competitive games, and strategy games).

[0042] In related technologies, electronic devices are typically used to display text or images to users through their installed clients, and can also forward data to other clients based on user actions. However, currently, for data with high confidentiality requirements, forwarding typically involves encrypting the data before sending it to the designated user's terminal, providing the designated user with the corresponding decryption password so they can decrypt and view the data, or directly sending the data to the designated user. If data is encrypted before transmission, the encryption and decryption process is cumbersome, and the decrypted data can be forwarded to other users for viewing. If sent directly to the designated user, the data could be forwarded again to other users. Therefore, both methods allow users without data access permissions to view the data, meaning that currently used data forwarding methods are prone to data leakage, resulting in low security.

[0043] Based on this, the inventors provide a data forwarding method applicable to a server. The server is associated with a receiving client and a sending client. In this method, the server receives a data access request sent by the receiving client. The data access request is generated by the receiving client in response to a triggering of a data link. The data access request carries the enterprise identifier of the receiving client, the enterprise identifier of the data source, and a data identifier. When the server confirms that the receiving client has access rights to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, it sends the target data corresponding to the data identifier back to the receiving client. This method ensures that when a receiving client needs to access the target data corresponding to the data identifier in the data link, the server must verify whether the receiving client has access rights to the data. Only when the receiving client's access rights are verified can the receiving client obtain the corresponding data, thereby avoiding data leakage and improving the security of data access.

[0044] The sending client refers to the client used to forward data such as images, text, and links. In this embodiment, it specifically refers to the client used to send links to the receiving client.

[0045] A receiving client refers to a client used to receive data such as images, text, and links forwarded by external devices (such as sending clients or servers). In this embodiment, it specifically refers to a client used to receive links sent by the aforementioned sending client.

[0046] A link refers to the transmission of parameters and control commands between modules of a computer program (i.e., between the sending client, receiving client, and server). Also known as a hyperlink, a link is a connection from one webpage to a target. The target can be another webpage, a different location on the same webpage, an image, an email address, a file, or even an application. Typically, a link contains a reference to another file or directory, using an absolute or relative path. In this embodiment, the link corresponds to target data (which can be text, an image, or video, etc.), and carries the data source enterprise identifier and data identifier corresponding to the target data.

[0047] The data source enterprise identifier refers to the enterprise identifier of the enterprise to which the client that created the target data belongs, or the enterprise identifier of the enterprise to which the client that first forwarded the target data belongs. The enterprise identifier is a string composed of numbers, letters, and underscores used to uniquely identify an enterprise.

[0048] Data identifiers are symbols used to identify target data. They can consist of numbers, letters, and underscores. Typically, different data within the same company will have different data identifiers.

[0049] The following describes exemplary applications of the device provided in the embodiments of the present invention for performing the above-described data access method. The data access method provided in the embodiments of the present invention can be applied to, for example... Figure 1 The server and terminal devices in the application environment (data access system) shown.

[0050] Figure 1 The application environment shown includes server 10 and at least two terminal devices connected to server 10 via a network. Figure 1 The example shown only includes two terminal devices, with one terminal device having a receiver client 30 installed and the other terminal device having a sender client 20 installed.

[0051] The aforementioned server 10 can be an independent physical server 10, a server cluster or distributed system composed of multiple physical servers 10, or a cloud server 10 that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0052] The terminal devices can be smartphones, smart TVs, tablets, laptops, desktop computers, etc. The clients installed on both terminal devices can be browser clients, instant messaging clients, educational clients, social networking clients, shopping clients, and audio / video playback clients, etc.

[0053] The terminal device and the server 10 can be connected directly or indirectly through wired or wireless communication, which is not limited herein.

[0054] When accessing data using the aforementioned data access system, the sending client 20 obtains the enterprise identifier of the receiving client corresponding to the selected receiving user when forwarding the target data. If the data source enterprise identifier of the target data is inconsistent with the enterprise identifier of the receiving client, a data link including the data source enterprise identifier and the data identifier is generated and sent to the receiving client 30. Upon receiving the data link, the receiving client 30 displays it and, upon receiving a trigger operation on the data link, sends a data access request to the server 10. This data access request carries the enterprise identifier of the sending client, the data source enterprise identifier, and the data identifier. The server 10 receives the data access request sent by the receiving client 30 and, upon confirming that the receiving client 30 has access rights to the data link based on the enterprise identifier of the receiving client and the data source enterprise identifier, returns the target data corresponding to the data identifier to the receiving client 30, thus completing the data forwarding and access operation. When the receiving client 30 needs to access the target data corresponding to the data identifier in the data link, the server 10 needs to verify whether the receiving client 30 has the access permission to the data. Only when the receiving client has the access permission to the data is the receiving client 30 able to obtain the corresponding data, thereby avoiding the problem of data leakage and improving the security of data access.

[0055] It should be understood that the device types of the terminal device in the aforementioned installation of the receiving client 30 and the terminal device in the installation of the sending client 20 may be the same or different, and the device type may include at least one of the following: smartphones, desktop computers, tablet computers, laptop computers, etc., which have touch screens. No specific limitation is made here.

[0056] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0057] Please see Figure 2 , Figure 2 The figure shown is a data access method proposed in an embodiment of this application, which can be applied to... Figure 1 Server 10 in the middle, the method includes:

[0058] Step S110: Receive a data access request sent by the receiving client 30.

[0059] The data access request is generated by the receiving client 30 in response to the triggering of the data link. The data access request carries the enterprise identifier of the receiving client, the enterprise identifier of the data source, and the data identifier.

[0060] In this embodiment, each client corresponds to a user ID (i.e., user identifier), and each user ID (user identifier) ​​typically belongs to a company. Different user IDs (user identifiers) may belong to the same or different companies. Each company typically has a unique company ID (company identifier), and different companies have different company identifiers. Therefore, when the user identifier corresponding to a client is obtained, the company to which that user identifier belongs can be obtained, as well as the company identifier corresponding to that company; that is, when the user identifier corresponding to a client is obtained, the company identifier to which that client belongs can be obtained.

[0061] It should be understood that the term "enterprise" can refer to a company, a school, an institution, or a department, etc., without any specific limitation here.

[0062] The data identifier for target data can consist of letters, numbers, or symbols, and it is unique. Multiple files stored at the same storage address will have different data identifiers. Target data can be documents, images, videos, etc.

[0063] The data source enterprise identifier refers to the source or forwarding source of the target data corresponding to the data identifier. In other words, the data source enterprise identifier is used to identify which enterprise generated the target data or which enterprise performed the forwarding operation. The enterprise performing the forwarding operation can be the enterprise that performs the forwarding operation for the first time or the enterprise that performs the forwarding operation again.

[0064] The data link includes the IP address of server 10 (or the domain name system (DNS) hostname of server 10), the data transmission protocol used, the path to the target data to be accessed, the data source enterprise identifier of the target data, and the data identifier (or file name), etc.

[0065] When the receiving client 30 receives an operation such as a click, gesture selection, or voice selection that instructs it to access the data corresponding to the data link, it performs a domain name resolution operation to resolve the data link and obtain the IP address of server 10. After obtaining the IP address of server 10, the receiving client 30 needs to check whether the connection between the receiving client 30 and server 10 is open. If it is not open and the data transmission protocol used between the receiving client 30 and server 10 is HTTP, then a TCP three-way handshake is required to establish a connection. It should be understood that if HTTPS is used and the connection is not open, then a TLS handshake is required before the TCP three-way handshake. After confirming that a connection has been established between the receiving client 30 and server 10, or after the connection has been established, the receiving client 30 sends a data access request to server 10 carrying the enterprise identifier of the receiving client, the enterprise identifier of the data source, and the data identifier.

[0066] Specifically, the receiving client 30 can send a data access request to the server 10 in the form of a data stream or a message, depending on the data transmission protocol between the receiving client 30 and the server 10. Correspondingly, the data access request received by the server 10 is also in the form of a data stream or a message protocol.

[0067] It should be understood that if the receiving client 30 sends a data access request to the server 10 in the form of a data stream, then the data access request received by the server 10 will also be in the form of a data stream; if the receiving client 30 sends a data access request to the server 10 in the form of a message, then the data access request received by the server 10 will also be in the form of a message. When the server 10 receives a data access request sent in the form of a data stream, it can parse the data stream to obtain the data access request. When the server 10 receives a data access request sent in the form of a message, it can parse the message to obtain the data access request.

[0068] Step S120: When it is confirmed that the receiving client 30 has access to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, the target data corresponding to the data identifier is fed back to the receiving client 30.

[0069] There are several ways to confirm that the receiving client 30 has access to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source.

[0070] As one possible implementation, it is detected whether the enterprise identifier of the receiving client and the enterprise identifier of the data source are the same. If they are the same, it is confirmed that the receiving client 30 has access to the data link.

[0071] As another implementation, it is detected whether the enterprise identifier of the receiving client and the enterprise identifier of the data source have the same fields or identifiers. If they have the same fields or strings, it is confirmed that the receiving client 30 has access to the data link.

[0072] The same field or identifier is used to indicate that the enterprise identifier of the receiving client and the enterprise identifier of the data source belong to the same parent company.

[0073] Please see Figure 3 In another implementation, server 10 stores an enterprise identifier and an interconnected enterprise identifier corresponding to that enterprise identifier. Step S120 includes:

[0074] Step S122: Detect whether the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the interconnection enterprise identifier corresponding to the data source enterprise identifier.

[0075] Among them, the interconnection enterprise identifier corresponding to the data source enterprise identifier is used to indicate the enterprise that has a data sharing relationship with the enterprise corresponding to the data source enterprise identifier.

[0076] For example, companies A, B, and C can share data, but company D cannot share data with any of them. Therefore, companies A, B, and C can be considered interconnected. Company D, however, is not interconnected with any of the other three companies. If the data source company identifier is that of company A, then the interconnected company identifiers corresponding to that data source company identifier include the company identifiers corresponding to companies B and C. For data sent by a client corresponding to company A, clients corresponding to companies B and C can both access that data.

[0077] Step S124: When the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the interconnection enterprise identifier corresponding to the data source enterprise identifier, confirm that the receiving client 30 has access rights to the data link.

[0078] When server 10 confirms that receiving client 30 has access to the data link, it can find the location of the target data through the path of the target data to be accessed, obtain the target data corresponding to the data identifier (e.g., file name) from that location, and feed the target data back to receiving client 30 so that receiving client 30 can display the target data.

[0079] By adopting the data access method provided in this application embodiment, the server 10 receives a data access request sent by the receiving client 30, and when it confirms that the receiving client 30 has access rights to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, it sends the target data corresponding to the data identifier to the receiving client 30. This ensures that the target data can only be accessed by users with data access rights, avoids the problem of data leakage, and improves the security of data access.

[0080] like Figure 4 Another embodiment of this application provides a data access method, including:

[0081] Step S210: Receive a data access request sent by the receiving client 30, and decrypt the encrypted data in the data access request.

[0082] The data access request is generated by the receiving client 30 in response to the triggering of the data link. The data access request carries the enterprise identifier of the receiving client, the enterprise identifier of the data source, and the data identifier. The data identifier and the enterprise identifier of the data source carried in the data access request are encrypted data obtained by encrypting the data identifier and the enterprise identifier of the data source.

[0083] The encryption of the data identifier and the data source enterprise identifier can be performed by the sending client 20 when forwarding the data. Specifically, the sending client 20 can obtain the receiving client 30 corresponding to the receiving user selected when receiving the user's forwarding operation, and obtain the enterprise identifier of the receiving client. When the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, the data source enterprise identifier and the data identifier are encrypted to obtain encrypted data, and a data link including the encrypted data is generated.

[0084] In one possible implementation, the data source enterprise identifier and data identifier can be encrypted by first concatenating the data source enterprise identifier and data identifier to obtain concatenated data, and then encrypting the concatenated data using a preset encryption algorithm to obtain encrypted data. The preset encryption algorithm can be any one or more of the following: MD5, SHA1, HMAC, AES, DES, 3DES, RSA, and ECC algorithms.

[0085] Accordingly, when the server 10 decrypts the encrypted data, the decryption algorithm it uses should correspond to the encryption algorithm used by the receiving client 30. That is, when the server 10 and the client (receiving client 30 and sending client 20) perform encryption and decryption operations on the data they transmit to each other, they use the same encryption and decryption algorithm.

[0086] Considering that the length of the encrypted data obtained by using a partial encryption algorithm (such as the DES algorithm) is within a certain length range, in one possible implementation, before decrypting the encrypted data in the data access request, the following steps can also be performed: obtaining the encrypted data in the data access request, detecting that the length of the encrypted data is within a preset length range, and only when the length of the encrypted data is detected to be within the preset length range can the step of decrypting the encrypted data in the data access request be performed.

[0087] Step S220: If decryption is successful, obtain the data source enterprise identifier and data identifier from the decrypted data.

[0088] Please see Figure 5 Considering that the decrypted data obtained using partial encryption algorithms (such as DES) may contain specific prefixes or fields, and / or have special composition, the methods for decrypting encrypted data in data access requests mentioned above can include:

[0089] Step S222: Check whether the decrypted data meets the preset conditions.

[0090] The above-mentioned detection of whether the decrypted data meets the preset conditions can be one or more of the following: whether the decrypted data includes a preset field, a preset prefix, or a preset composition method.

[0091] Step S224: When the decrypted data meets the preset conditions, the decrypted data is segmented to obtain the data source enterprise identifier and the data identifier.

[0092] Since the decrypted data includes a prefix or preset fields, and the decrypted data includes the concatenated data source enterprise identifier and data identifier, the data, enterprise identifier, and data identifier can be obtained by segmenting the decrypted data.

[0093] Step S230: When it is confirmed that the receiving client 30 has access to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, the target data corresponding to the data identifier is fed back to the receiving client 30.

[0094] This application provides a data access method in which a server 10 receives a data access request from a receiving client 30, which includes the enterprise identifier of the receiving client, encrypted data obtained by encrypting the data source enterprise identifier and the data identifier. Upon successful decryption of the encrypted data in the data access request, the server 10 obtains the data source enterprise identifier and the data identifier from the decrypted data. Based on the enterprise identifier of the receiving client and the data source enterprise identifier, and confirming that the receiving client 30 has data link access permissions, the server 10 sends the target data corresponding to the data identifier to the receiving client 30. This effectively prevents data leakage during data transmission between the server 10 and the receiving client 30, and ensures that the target data can only be accessed by users with data access permissions, further preventing data leakage and improving data access security.

[0095] like Figure 6 As shown, another embodiment of this application provides a data access method, which should be used as follows: Figure 1 The sending client 20 in the middle includes the following methods:

[0096] Step S310: Obtain the enterprise identifier of the receiving client. The receiving client 30 is the client corresponding to the receiving user selected when forwarding the target data.

[0097] Specifically, the method for obtaining the enterprise identifier of the receiving client can be as follows: the sending client 20 obtains the user identifier corresponding to the receiving client 30 selected by the sending user when forwarding the target data, and obtains the enterprise to which the user identifier belongs, thereby obtaining the enterprise identifier corresponding to the enterprise; that is, when the user identifier corresponding to the receiving client 30 is obtained, the enterprise identifier to which the receiving client belongs can be obtained.

[0098] Step S320: When the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, a data link including the data source enterprise identifier and the data identifier is generated.

[0099] If the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, it indicates that the enterprise corresponding to the data source enterprise identifier and the enterprise of the receiving client 30 are not the same enterprise. Therefore, it is necessary to confirm whether the receiving client 30 has access rights to the target data, that is, it is necessary to perform the step of generating a data link including the data source enterprise identifier and the data identifier.

[0100] To prevent the leakage of the enterprise identifier corresponding to the sending client 20 and the data source enterprise identifier when the sending client 20 forwards the data link with the receiving client 30, and when the receiving client 30 sends a data access request to the server 10, in one possible implementation, the above step S320 includes: encrypting the data source enterprise identifier and the data identifier to obtain encrypted data, and generating a data link including the encrypted data.

[0101] Specifically, encrypting the data source enterprise identifier and data identifier to obtain encrypted data can be achieved by first concatenating the data source enterprise identifier and data identifier to obtain concatenated data, and then encrypting the concatenated data using a preset encryption algorithm to obtain encrypted data. The preset encryption algorithm can be any one or more of the following: MD5, SHA1, HMAC, AES, DES, 3DES, RSA, and ECC algorithms. For details, please refer to the previous description of step S210; it will not be elaborated upon here.

[0102] Step S330: Send a data link to the receiving client 30.

[0103] By sending a data link to the receiver, the receiver client 30 can generate a data access request in response to the triggering of the data link when receiving the data link, and send the data access request to the server 10 to instruct the server 10 to perform the verification operation as in Embodiment 1, and to feed back the corresponding target data to the receiver client when the verification is successful.

[0104] It should be understood that, in one embodiment of this application, if the data source enterprise identifier corresponding to the target data is consistent with the enterprise identifier of the receiving client, a data link including the data identifier can be directly generated. When the receiving client 30 receives the data link, the user of the receiving client 30 can trigger the data link. In response to the triggering operation of the data link, the receiving client 30 sends a data access request including the data identifier to the server 10, instructing the server 10 to return the target data corresponding to the data identifier, thereby completing the data acquisition operation.

[0105] This application provides a data access method in which the sending client 20 obtains the enterprise identifier of the receiving client corresponding to the selected receiving user when forwarding target data. If the enterprise identifier of the receiving client 30 is inconsistent with the enterprise identifier of the data source, it confirms that the enterprise corresponding to the receiving client 30 and the enterprise corresponding to the data source enterprise identifier are not the same enterprise. Then, it sends a data link carrying the data source enterprise identifier and the data identifier to the receiving client 30. This requires the receiving client 30 to use the server 10 to verify whether the receiving client 30 has the access permission to the target data when accessing the data corresponding to the data link. The target data can only be displayed when the receiving client 30 has the access permission, thereby ensuring that the target data can only be accessed by the receiving client 30 with the access permission, thus improving the security of data access.

[0106] Please see Figure 7 Another embodiment of this application provides a data access method, which should be used as follows: Figure 1 The receiving client 30 in the middle includes the following methods:

[0107] Step S410: Receive a data link sent by the sending client 20, which carries the data source enterprise identifier and data identifier.

[0108] In one possible implementation, the data source enterprise identifier and data identifier carried in the data link can be obtained by encrypting the encrypted data by encrypting the data source enterprise identifier and data identifier.

[0109] That is, step S410 above may include receiving a data link carrying encrypted data sent by the sending client 20.

[0110] For details regarding the specific process of the sending client 20 sending the data link, please refer to the detailed description of steps S320-330 in the aforementioned embodiments, which will not be repeated here.

[0111] Step S420: Display the data link.

[0112] Step S430: In response to the triggering operation of the data link, send a data access request to server 10.

[0113] The data access request carries the enterprise identifier of the sending client, the enterprise identifier of the data source, and the data identifier. The data access request is used to instruct the server 10 to confirm whether the receiving client 30 has access rights to the data link based on the enterprise identifier of the data source.

[0114] The aforementioned triggering operations for data links can include voice operations, click operations, or gesture operations.

[0115] In one possible implementation, the triggering operation is a voice operation. When the receiving client 30 displays the data link, it can send a data access request to the server 10 when it receives voice information such as "open link" or "view link" input by the user to indicate access to the data link.

[0116] In another possible implementation, the triggering operation is a click operation. When the receiving client 30 displays the data link, it can send a data access request to the server 10 when a click operation on the data link is detected.

[0117] In another possible implementation, the triggering operation is a gesture operation. When the receiving client 30 displays the data link, it can send a data access request to the server 10 when it detects that the user's gesture operation is a specified operation, such as a pinch operation or a swipe operation in a specified direction.

[0118] It should be understood that if the data source enterprise identifier and data identifier carried in the data link are encrypted data obtained by encrypting the data source enterprise identifier and data identifier, then the above step S430 may specifically be: in response to the triggering operation of the data link, sending a data access request including the encrypted data and the enterprise identifier of the sending client to the server 10.

[0119] By adopting the above method, even if the data link and data access request are hijacked or leaked during transmission, the specific data source enterprise identifier and data identifier cannot be obtained. Therefore, the security of the target data can be further improved, and the target data can be prevented from being accessed by clients that do not have the right to access the data.

[0120] For details on the specific process by which server 10 confirms whether the receiving client 30 has the scheme permission based on the enterprise identifier and data identifier of the data source, please refer to the detailed description of step S120 above, which will not be repeated here.

[0121] Step S440: Receive the target data corresponding to the data identifier from the server 10.

[0122] The target data corresponding to the data identifier is fed back by the server 10 when it confirms that the receiving client 30 has the access rights.

[0123] To facilitate the viewing of target data by the client corresponding to the receiving client 30, in one possible implementation, the above step S140, receiving the target data corresponding to the data identifier fed back by the server 10, further includes: displaying the target data corresponding to the data identifier in the data link.

[0124] For details regarding the target data corresponding to the data identifier fed back by server 10, please refer to the previous description of step S120; it will not be elaborated upon here.

[0125] By adopting the data access method of this application, when the receiving client 30 receives a data link sent by the data sending client 20 carrying a data source enterprise identifier and a data identifier, the receiving client 30 sends an access request to the server 10 carrying the enterprise identifier of the sending client, the data source enterprise identifier, and the data identifier, instructing the server 10 to return the target data corresponding to the data identifier when it confirms that the receiving client 30 has access rights to the data link based on the data source enterprise identifier. This ensures that the receiving client 30 can only obtain the target data when it has access rights to the target data, thereby improving the security of target data access.

[0126] Furthermore, when the data source enterprise identifier and data identifier carried in the data link are encrypted data obtained by encrypting the data source enterprise identifier and data identifier, by sending a data access request including the encrypted data and the enterprise identifier corresponding to the receiving client 30 to the server 10, the leakage or hijacking of the data source enterprise identifier and data identifier can be avoided when the receiving client 30 interacts with the server 10 and the sending client 20. This prevents clients without access rights from accessing the target data based on the leaked or hijacked data source enterprise identifier and data identifier. Therefore, transmitting encrypted data obtained by encrypting the data source enterprise identifier and data identifier can effectively improve the security of the target data.

[0127] Please see Figure 8 This application provides a data access method applied to a data access system including a sending client 20, a receiving client 30, and a server 10. The method includes:

[0128] Step S510: The sending client 20 obtains the enterprise identifier of the receiving client.

[0129] Among them, the receiving client 30 is the receiving client 30 corresponding to the receiving user selected by the sending client 20 when forwarding the target data.

[0130] Step S520: When the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, the sending client 20 generates a data link including the data source enterprise identifier and the data identifier.

[0131] Step S530: The sending client 20 sends a data link to the receiving client 30.

[0132] In one possible implementation, the method for generating a data link that includes a data source enterprise identifier and a data identifier can be as follows: encrypt the data source enterprise identifier and the data identifier to obtain encrypted data, and then generate a data link that includes the encrypted data.

[0133] Step S540: The receiving client 30 receives the data link sent by the sending client 20, which carries the data source enterprise identifier and the data identifier, and displays the data link.

[0134] Step S550: In response to the triggering operation of the data link, the receiving client 30 sends a data access request to the server 10.

[0135] The data access request carries the enterprise identifier of the sending client, the enterprise identifier of the data source, and the data identifier. The data access request is used to instruct the server 10 to confirm whether the receiving client 30 has access rights to the data link based on the enterprise identifier of the data source.

[0136] In one possible implementation, if the data source enterprise identifier and data identifier carried in the data access request are encrypted, the encrypted data is included in the data access request sent to the server 10 when the encrypted data is obtained.

[0137] Step S560: When the server 10 confirms that the receiving client 30 has access to the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source, the server 10 sends the target data corresponding to the data identifier back to the receiving client 30.

[0138] In one possible implementation, if the data identifier and data source enterprise identifier carried in the data access request are encrypted data obtained by encrypting the data identifier and data source enterprise identifier, then the above step S550 may be receiving the data access request sent by the receiving client 30, decrypting the encrypted data in the data access request; if the decryption is successful, then obtaining the data source enterprise identifier and data identifier in the decrypted data.

[0139] The receiving client 30 receives the target data corresponding to the data identifier from the server 10.

[0140] In one possible implementation, if the target data corresponding to the data identifier is received from the server 10, the method further includes: displaying the target data corresponding to the data identifier in the data link.

[0141] Please see Figure 9Taking the above data access system, where both the receiving client 30 and the sending client 20 are WeChat Enterprise clients, and the target data is a report document, specifically a report approval document containing the statement "User f and User g submitted an amount of 27,273,737.00 yuan (two thousand seven million two hundred and seventy thousand three thousand seven hundred and thirty-seven yuan) on XX month XX day" as an example, this will be explained further.

[0142] The sender client 20 corresponds to user a. When the sender client 20 needs to forward the aforementioned report document, it can obtain the recipient user (user b) selected by user a when performing the forwarding operation. If it confirms that the enterprise identifier (re-corp_id) of the recipient client corresponding to the recipient user (user b) is inconsistent with the enterprise identifier (corp_id) of the data source of the report document, it can identify the recipient user as an external employee. At this time, it cannot be determined whether the external employee has access rights. Therefore, it is necessary to encrypt the data source enterprise identifier (corp_id) and the data identifier (journal_id) (e.g., using the DES encryption algorithm) to obtain encrypted data (journal_uuid) and generate a data link carrying the encrypted data (journal_uuid). That is, as shown in the figure... Figure 10 The interface shown includes a data link, and a data link carrying encrypted data (journal_uuid) is sent to the receiving client 30.

[0143] When the receiving client 30 establishes a data connection, it displays the following: Figure 11 The interface shown includes specific information about the data link and the time when user a sent the data link. If the user corresponding to the receiving client 30 needs to access the target data corresponding to the data link, user b can perform a trigger operation (e.g., click operation) on the data link to make the receiving client 30 respond to the trigger operation to obtain its corresponding enterprise identifier (re-corp_id) and extract encrypted data (journal_uuid) from the data link, and generate a data access request including the enterprise identifier (re-corp_id) and encrypted data (journal_uuid) of the receiving client and send it to the server 10.

[0144] When server 10 receives a data access request, it first checks the length of the encrypted data (journal_uuid). If the length is within a preset range, it decrypts the data (e.g., using the DES algorithm). If the decrypted data includes preset fields, it segments the data to obtain the data source enterprise identifier (corp_id) and the data identifier (journal_id). After obtaining the data source enterprise identifier (corp_id) and the enterprise identifier (re-corp_id) of the receiving client, it determines whether the data source enterprise identifier (corp_id) and the enterprise identifier (re-corp_id) of the receiving client have an enterprise interconnection relationship. Specifically, this can be done by checking whether the data source enterprise identifier (corp_id) and the enterprise identifier (re-corp_id) of the receiving client belong to the same interconnected enterprise set (group_id). If they do, it can be determined that there is an enterprise interconnection relationship between the data source enterprise identifier (corp_id) and the enterprise identifier (re-corp_id) of the receiving client.

[0145] When server 10 confirms that there is an enterprise interconnection relationship between the data source enterprise identifier (corp_id) and the enterprise identifier (re-corp_id) to which the receiving client belongs, it obtains the target data (reporting and approval documents) corresponding to the data identifier (journal_id) and sends the target data to the receiving client 30.

[0146] When receiving target data, the receiving client 30 displays as follows: Figure 12 The target data (reporting and approval document) "Users f and g submitted a reporting and approval document on XX month XX day for an amount of 27,273,737.00 yuan (twenty-seven million two hundred and seventy thousand three thousand seven hundred and thirty-seven yuan)" is used to complete the data access.

[0147] It should be understood that when the receiving client obtains the target data, a data display window can be generated on top of the window displaying the data link, and the target data can be displayed in the data display window.

[0148] Please see Figure 13 This application provides a data access device 600 for use on a server 10. The device 600 includes a request receiving module 610 and a data feedback module 620.

[0149] The request receiving module 610 is used to receive data access requests sent by the receiving client 30. The data access request is generated by the receiving client 30 in response to the triggering of the data link. The data access request carries the enterprise identifier of the receiving client, the enterprise identifier of the data source, and the data identifier.

[0150] In one possible implementation, the data identifier and data source enterprise identifier carried in the data access request are encrypted data obtained by encrypting the data identifier and data source enterprise identifier, and the request receiving module 610 includes a request receiving submodule and an identifier acquisition submodule.

[0151] The request receiving submodule is used to receive data access requests sent by the receiving client 30 and decrypt the encrypted data in the data access request.

[0152] The identifier acquisition submodule is used to retrieve the data source enterprise identifier and data identifier from the decrypted data upon successful decryption.

[0153] In one possible implementation, the identifier acquisition submodule includes a detection unit and an identifier acquisition unit.

[0154] The detection unit is used to detect whether the decrypted data meets preset conditions.

[0155] In one possible implementation, the detection unit is specifically used to detect whether the decrypted data carries a preset field and whether the data length of the decrypted data is within a preset length range. If the decrypted data carries a preset field and the data length of the decrypted data is within the preset length range, then the decrypted data meets the preset conditions.

[0156] The identifier acquisition unit is used to segment the decrypted data to obtain the data source enterprise identifier and the data identifier when the decrypted data meets the preset conditions.

[0157] The data feedback module 620 is used to provide the target data corresponding to the data identifier to the receiving client 30 when it is confirmed that the receiving client 30 has the right to access the data link based on the enterprise identifier of the receiving client and the enterprise identifier of the data source.

[0158] In one possible implementation, server 10 stores enterprise identifiers and corresponding interconnected enterprise identifiers, and data feedback module 620 includes: an identifier detection submodule and an authorization confirmation submodule.

[0159] The identifier detection module is used to detect whether the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the interconnection enterprise identifier corresponding to the data source enterprise identifier.

[0160] The permission confirmation submodule is used to confirm that the receiving client 30 has access permissions for data links when the enterprise identifier of the receiving client belongs to the data source enterprise identifier or the interconnection enterprise identifier corresponding to the data source enterprise identifier.

[0161] Please see Figure 14 This application also provides a data access device 700 applied to a sending client 20. The device 700 includes: an identifier acquisition module 710, a link generation module 720, and a link sending module 730.

[0162] The identifier acquisition module 710 is used to acquire the enterprise identifier of the receiving client. The receiving client 30 is the client corresponding to the receiving user selected when forwarding the target data.

[0163] The link generation module 720 is used to generate a data link that includes the data source enterprise identifier and the data identifier when the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client.

[0164] In one possible implementation, the link generation module 720 is further used to encrypt the data source enterprise identifier and data identifier to obtain encrypted data, and generate a data link including the encrypted data.

[0165] The link sending module 730 is used to send a data link to the receiving client 30.

[0166] Please see Figure 15 This application also provides a data access device 800 for a receiving client 30. The device 800 includes: a link receiving module 810, a link display module 820, a request sending module 830, and a data receiving module 840.

[0167] The link receiving module 810 is used to receive a data link sent by the sending client 20, which carries a data source enterprise identifier and a data identifier.

[0168] Link display module 820 is used to display data links.

[0169] The request sending module 830 is used to send a data access request to the server 10 in response to the triggering operation of the data link. The data access request carries the enterprise identifier of the sending client, the enterprise identifier of the data source, and the data identifier. The data access request is used to instruct the server 10 to confirm whether the receiving client 30 has the right to access the data link based on the enterprise identifier of the data source.

[0170] The data receiving module 840 is used to receive the target data corresponding to the data identifier fed back by the server 10. The target data corresponding to the data identifier is fed back by the server 10 when it confirms that the receiving client 30 has the access rights.

[0171] In one possible implementation, the link receiving module 810 is further configured to receive a data link carrying encrypted data sent by the sending client 20, wherein the encrypted data is obtained by encrypting the data source enterprise identifier and the data identifier. The request sending module 830 is further configured to, in response to a triggering operation of the data link, send a data access request to the server 10, including the encrypted data and the enterprise identifier of the sending client.

[0172] In one possible implementation, the data receiving module 840 is also used to display the target data corresponding to the data identifier in the data link.

[0173] It should be noted that the device embodiments in this application correspond to the aforementioned method embodiments. The specific principles in the device embodiments can be found in the content of the aforementioned method embodiments, and will not be repeated here.

[0174] The following will combine Figure 16 This application describes an electronic device.

[0175] Please see Figure 16 Based on the data access method provided in the above embodiments, this application embodiment also provides another electronic device 100 including a processor 102 capable of executing the aforementioned method. The electronic device 100 can be a server 10 or a terminal device, and the terminal device can be a smartphone, tablet computer, computer or portable computer or other devices.

[0176] The electronic device 100 also includes a memory 104. The memory 104 stores a program that can execute the contents of the foregoing embodiments, and the processor 102 can execute the program stored in the memory 104.

[0177] The processor 102 may include one or more cores for data processing and message matrix units. The processor 102 connects to various parts within the electronic device 100 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 104, and by calling data stored in the memory 104. Optionally, the processor 102 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 102 may integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 102 and may be implemented separately using a communication chip.

[0178] The memory 104 may include random access memory (RAM) or read-only memory (ROM). The memory 104 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 104 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function, instructions for implementing the various method embodiments described below, etc. The data storage area may also store data acquired by the electronic device 100 during use (e.g., recommended data and operating methods).

[0179] The electronic device 100 may also include a network module and a screen. The network module is used to receive and transmit electromagnetic waves, converting electromagnetic waves into electrical signals, thereby enabling communication with communication networks or other devices, such as audio playback devices. The network module may include various existing circuit elements used to perform these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, SIM cards, memory, etc. The network module can communicate with various networks such as the Internet, corporate intranets, and wireless networks, or communicate with other devices via wireless networks. The aforementioned wireless networks may include cellular telephone networks, wireless local area networks, or metropolitan area networks. The screen can display interface content and facilitate data interaction.

[0180] In some embodiments, the electronic device 100 may further include a peripheral interface 106 and at least one peripheral device. The processor 102, memory 104, and peripheral interface 106 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral interface via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency component 108, a positioning component 112, a camera 114, an audio component 116, a display screen 118, and a power supply 122.

[0181] Peripheral interface 106 can be used to connect at least one I / O (Input / Output) related peripheral device to processor 102 and memory 104. In some embodiments, processor 102, memory 104 and peripheral interface 106 are integrated on the same chip or circuit board; in some other embodiments, any one or two of processor 102, memory 104 and peripheral interface 106 can be implemented on separate chips or circuit boards, and this application embodiment does not limit this.

[0182] The radio frequency (RF) component 108 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF component 108 communicates with communication networks and other communication devices via electromagnetic signals. The RF component 108 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. Optionally, the RF component 108 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The RF component 108 can communicate with other terminals via at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: the World Wide Web, metropolitan area networks, intranets, various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks, and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF component 108 may also include circuitry related to NFC (Near Field Communication), which is not limited in this application.

[0183] Positioning component 112 is used to locate the current geographic location of an electronic device to enable navigation or LBS (Location Based Service). Positioning component 112 can be a positioning component based on the US GPS (Global Positioning System), China's BeiDou system, or Russia's Galileo system.

[0184] Camera 114 is used to capture images or videos. Optionally, camera 114 includes a front-facing camera and a rear-facing camera. Typically, the front-facing camera is located on the front panel of the electronic device 100, and the rear-facing camera is located on the back of the electronic device 100. In some embodiments, there are at least two rear-facing cameras, which are any one of a main camera, a depth-sensing camera, a wide-angle camera, and a telephoto camera, to achieve background blurring by fusion of the main camera and the depth-sensing camera, panoramic shooting by fusion of the main camera and the wide-angle camera, VR (Virtual Reality) shooting, or other fusion shooting functions. In some embodiments, camera 114 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cool light flash, which can be used for light compensation at different color temperatures.

[0185] Audio component 116 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals that are input to processor 102 for processing, or input to radio frequency component 108 for voice communication. For stereo acquisition or noise reduction purposes, there may be multiple microphones, each located at a different part of electronic device 100. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert electrical signals from processor 102 or radio frequency component 108 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into sound waves that humans can hear, but also into sound waves that humans cannot hear for purposes such as ranging. In some embodiments, audio component 114 may also include a headphone jack.

[0186] Display screen 118 is used to display a UI (User Interface). This UI may include graphics, text, icons, videos, and any combination thereof. When display screen 118 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 102 for processing. In this case, display screen 118 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 118, which serves as the front panel of electronic device 100; in other embodiments, there may be at least two display screens, respectively disposed on different surfaces of electronic device 100 or in a folded design; in still other embodiments, display screen 118 may be a flexible display screen, disposed on a curved or folded surface of electronic device 100. Furthermore, display screen 118 may be configured as a non-rectangular irregular shape, i.e., a non-rectangular screen. Display screen 118 may be made of materials such as LCD (Liquid Crystal Display) or OLED (Organic Light-Emitting Diode).

[0187] Power supply 122 is used to supply power to various components in electronic device 100. Power supply 122 can be alternating current, direct current, a disposable battery, or a rechargeable battery. When power supply 122 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged via a wired line, while a wireless rechargeable battery is a battery that is charged via a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0188] This application also provides a computer-readable storage medium. This computer-readable medium stores program code that can be called by a processor to execute the methods described in the above method embodiments.

[0189] Computer-readable storage media can be electronic storage devices such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. Optionally, computer-readable storage media includes non-transitory computer-readable storage medium. The computer-readable storage medium has storage space for program code that performs any of the method steps described above. This program code can be read from or written to one or more computer program products. The program code can be compressed, for example, in a suitable form.

[0190] This application also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods described in the various optional implementations above.

[0191] In summary, this application provides a data access method, apparatus, device, and storage medium. The sending client 20 obtains the enterprise identifier of the receiving client corresponding to the selected receiving user when forwarding target data. When the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, a data link including the data source enterprise identifier and a data identifier is generated and sent to the receiving client 30. Upon receiving the data link, the receiving client 30 displays it. When a trigger operation for the data link is received, it sends a data access request to the server 10. This data access request carries the enterprise identifier of the sending client, the data source enterprise identifier, and the data identifier. The server 10 receives the data access request sent by the receiving client 30. When it confirms that the receiving client 30 has access rights to the data link based on the enterprise identifier of the receiving client and the data source enterprise identifier, it returns the target data corresponding to the data identifier to the receiving client 30, thereby completing the data forwarding and access operation. This system ensures that when the receiving client 30 needs to access the target data corresponding to the data identifier in the data link, the server 10 verifies whether the receiving client 30 has the necessary access permissions. Only after verifying that the receiving client has the required access permissions can the receiving client 30 obtain the corresponding data. This avoids data leakage and improves the security of data access.

[0192] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A data access method, characterized by, Applied to a server, the method includes: The system receives a data access request sent by a receiving client. This request is generated by the receiving client in response to a triggered data link. The data access request carries the enterprise identifier of the receiving client and encrypted data within the data link. Specifically, when the sending client forwards target data, if it determines that the enterprise identifier of the receiving client does not match the data source enterprise identifier corresponding to the target data, it encrypts the data source enterprise identifier and the data identifier of the target data to obtain encrypted data, and then sends the data link containing the encrypted data to the receiving client. The data source enterprise identifier corresponding to the target data identifies the enterprise that generated the target data. Both the sending client and the receiving client are enterprise instant messaging clients. The target data is a reporting document. The encrypted data in the data access request is decrypted. If the decryption is successful, the data source enterprise identifier and data identifier are obtained from the decrypted data. When the enterprise identifier of the receiving client and the enterprise identifier of the data source are detected to be in the same set of interconnected enterprises, and it is confirmed that the receiving client has access to the data link, the target data corresponding to the data identifier is fed back to the receiving client; the enterprises represented by different enterprise identifiers in the same set of interconnected enterprises have an interconnection relationship.

2. The method according to claim 1, characterized in that, If the enterprise identifier of the receiving client belongs to the enterprise identifier of the data source, it is confirmed that the receiving client has access to the data link.

3. The method of claim 1, wherein, The step of obtaining the data source enterprise identifier and data identifier from the decrypted data includes: Check whether the decrypted data meets the preset conditions; When the decrypted data meets the preset conditions, the decrypted data is segmented to obtain the data source enterprise identifier and the data identifier.

4. The method of claim 3, wherein, The detection of whether the decrypted data meets preset conditions includes: The system detects whether the decrypted data carries a preset field and whether the length of the decrypted data is within a preset length range. If the decrypted data carries the preset field and the length of the decrypted data is within the preset length range, then the decrypted data meets the preset conditions.

5. A data access method, characterized by, Applied to the sending client, the method includes: Obtain the enterprise identifier of the receiving client, wherein the receiving client is the receiving client corresponding to the receiving user selected when forwarding the target data; When the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, the data source enterprise identifier and the data identifier of the target data are encrypted to obtain encrypted data. A data link containing the encrypted data is sent to the receiving client. In response to the triggering operation of the data link, the receiving client sends a data access request to the server. The data access request carries the enterprise identifier of the receiving client and the encrypted data obtained from the data link. Upon receiving the data access request, the server decrypts the encrypted data and obtains the data source enterprise identifier and the data identifier from the decrypted data. If the enterprise identifier of the receiving client and the data source enterprise identifier are detected to be in the same interconnected enterprise set, and the receiving client is confirmed to have access to the data link, the server returns the target data corresponding to the data identifier to the receiving client. Enterprises represented by different enterprise identifiers in the same interconnected enterprise set are interconnected. The data source enterprise identifier corresponding to the target data is used to identify the enterprise that generated the target data. The sending client and the receiving client are enterprise instant messaging clients. The target data is a reporting document.

6. A data access method, characterized by, Applied to the receiving client, the method includes: The system receives a data link sent by a sending client. When the sending client forwards target data, if it determines that the enterprise identifier of the receiving client is inconsistent with the data source enterprise identifier corresponding to the target data, it encrypts the data source enterprise identifier and the data identifier of the target data to obtain encrypted data, and sends the data link including the encrypted data to the receiving client. The data source enterprise identifier corresponding to the target data is used to identify the enterprise that generated the target data. The sending client and the receiving client are enterprise instant messaging clients. The target data is a reporting document. Display the data link; In response to the triggering operation of the data link, a data access request is sent to the server, the data access request carrying the enterprise identifier of the receiving client and the encrypted data; The server receives target data corresponding to the data identifier, which is fed back by the server when it confirms that the receiving client has access rights. When the server detects that the enterprise identifier to which the receiving client belongs and the data source enterprise identifier are in the same set of interconnected enterprises, it confirms that the receiving client has access rights to the data link. Enterprises represented by different enterprise identifiers in the same set of interconnected enterprises have an interconnection relationship.

7. The method of claim 6, wherein, After receiving the target data corresponding to the data identifier from the server, the method further includes: displaying the target data corresponding to the data identifier in the data link.

8. A data access device applied to a server, the device comprising: A request receiving module is used to receive data access requests sent by a receiving client. The data access request is generated by the receiving client in response to a triggering of a data link. The data access request carries the enterprise identifier of the receiving client and encrypted data in the data link. Specifically, when the sending client forwards target data, if the sending client determines that the enterprise identifier of the receiving client is inconsistent with the data source enterprise identifier corresponding to the target data, it encrypts the data source enterprise identifier and the data identifier of the target data to obtain encrypted data, and sends the data link including the encrypted data to the receiving client. The data source enterprise identifier corresponding to the target data is used to identify the enterprise that generated the target data. The sending client and the receiving client are enterprise instant messaging clients. The target data is a reporting document. The request receiving module is further configured to: decrypt the encrypted data in the data access request; if the decryption is successful, obtain the data source enterprise identifier and data identifier from the decrypted data. The data feedback module is used to provide target data corresponding to the data identifier to the receiving client when it is detected that the enterprise identifier of the receiving client and the enterprise identifier of the data source are in the same set of interconnected enterprises, and it is confirmed that the receiving client has access to the data link; the enterprises represented by different enterprise identifiers in the same set of interconnected enterprises have an interconnection relationship.

9. The apparatus according to claim 8, characterized in that, The data feedback module is further configured to: when the enterprise identifier of the receiving client belongs to the enterprise identifier of the data source, confirm that the receiving client has access rights to the data link.

10. The apparatus according to claim 8, characterized in that, The request receiving module includes: The detection unit is used to detect whether the decrypted data meets preset conditions. The identifier acquisition unit is used to segment the decrypted data to obtain the data source enterprise identifier and the data identifier when the decrypted data meets the preset conditions.

11. The apparatus according to claim 10, characterized in that, The detection unit is also used for: The system detects whether the decrypted data carries a preset field and whether the length of the decrypted data is within a preset length range. If the decrypted data carries the preset field and the length of the decrypted data is within the preset length range, then the decrypted data meets the preset conditions.

12. A data access device, applied to a sending client, the device comprising: The identifier acquisition module is used to acquire the enterprise identifier of the receiving client, wherein the receiving client is the client corresponding to the receiving user selected when forwarding the target data; The link generation module is used to encrypt the data identifier of the data source enterprise identifier and the data identifier of the target data when the data source enterprise identifier corresponding to the target data is inconsistent with the enterprise identifier of the receiving client, so as to obtain encrypted data. A link sending module is used to send a data link including the encrypted data to the receiving client. In response to the triggering operation of the data link, the receiving client sends a data access request to the server. The data access request carries the enterprise identifier of the receiving client and the encrypted data obtained from the data link. After receiving the data access request, the server decrypts the encrypted data and obtains the data source enterprise identifier and the data identifier from the decrypted data. If the server detects that the enterprise identifier of the receiving client and the data source enterprise identifier are in the same set of interconnected enterprises, and confirms that the receiving client has access to the data link, the server sends the target data corresponding to the data identifier back to the receiving client. Enterprises represented by different enterprise identifiers located in the same set of interconnected enterprises have interconnection relationships; the data source enterprise identifier corresponding to the target data is used to identify the enterprise that generates the target data; the sending client and the receiving client are enterprise instant messaging clients; The target data refers to the reporting documents.

13. A data access device, applied to a receiving client, the device comprising: A link receiving module is used to receive a data link sent by a sending client. When the sending client forwards target data, if it determines that the enterprise identifier of the receiving client is inconsistent with the data source enterprise identifier corresponding to the target data, it encrypts the data source enterprise identifier and the data identifier of the target data to obtain encrypted data, and sends the data link including the encrypted data to the receiving client. The receiving client is the receiving client corresponding to the receiving user selected when forwarding the target data. The data source enterprise identifier corresponding to the target data is used to identify the enterprise that generated the target data. The link display module is used to display the data link; The request sending module is used to send a data access request to the server in response to a triggering operation on the data link. The data access request carries the enterprise identifier of the receiving client and the encrypted data. The data receiving module is used to receive target data corresponding to the data identifier fed back by the server. The target data corresponding to the data identifier is fed back by the server when it confirms that the receiving client has access rights. When the server detects that the enterprise identifier to which the receiving client belongs and the data source enterprise identifier are in the same set of interconnected enterprises, it confirms that the receiving client has access rights to the data link. Enterprises represented by different enterprise identifiers in the same set of interconnected enterprises have an interconnection relationship.

14. The apparatus according to claim 13, characterized in that, The data receiving module is also used to display the target data corresponding to the data identifier in the data link.

15. An electronic device, characterized in that, It includes a processor and a memory; one or more programs are stored in the memory and configured to be executed by the processor to implement the method of any one of claims 1-7.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program code, wherein the program code, when executed by a processor, performs the method described in any one of claims 1-7.

17. A computer program product, characterized in that, It includes computer instructions, which, when executed by a processor, implement the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Data access method, device and equipment and storage medium

    CN110598381A