File security attribute storage method and related device

By storing file security attributes in extended format or compact format in data files, errors and dead loop problems arise during accessing files in the prior art are solved, and the effectiveness and efficiency of file access are improved.

CN115795544BActive Publication Date: 2025-07-29伟光有限公司(CN)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211546449.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-02
Publication Date
2025-07-29
Estimated Expiration
2042-12-02

AI Technical Summary

Technical Problem

In the prior art, when the security attributes of a file are stored in a record file, errors and dead loops occur during the access file, and security attributes cannot be effectively obtained.

Method used

Store the security properties of the file in the data file and store it in an extended format type or a compact format type to ensure that accessing data files of the rule reference type can effectively access the basic files.

Benefits of technology

By storing security attributes in data files, access dead loops are avoided, and the effectiveness and efficiency of file access is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115795544B_ABST
    Figure CN115795544B_ABST
Patent Text Reader

Abstract

The present application provides a method for storing file security attributes and related devices. First, in response to a target storage request for storing the first security attribute of a first data file, a first file control parameter including a first file identifier corresponding to the first data file is obtained. The first data file is used to store the second security attribute of a target basic file stored in a universal integrated circuit card. If the file type of the first data file determined according to the first file identifier is an access rule reference type, then a target storage type corresponding to this file type is queried. The target storage type includes an extended format type. Finally, the first security attribute is stored according to the target storage type to facilitate access to the target basic file. When the security attribute of the basic file is stored in the data file, the security attribute of the data file can be stored in the extended format type to ensure the effectiveness of basic file access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of storage technologies, and in particular, to a method for storing file security attributes and related devices. Background Art

[0002] A universal integrated circuit card (UICC) includes a storage space, which can store files such as user accounts and keys. When accessing a file in the universal integrated circuit card, matching security conditions need to be created, and the security conditions are created according to the corresponding security attributes. In the prior art, if the security attributes of a file are stored in a record file, and the security attributes of this record file are also stored in this record file, when accessing this file, it is necessary to first obtain the security attributes of this record file to create the security conditions for accessing this record file. However, to obtain the security attributes of the record file, it is necessary to first create the security conditions for accessing this record file, which may result in the inability to obtain the security attributes of this record file from this record file, thereby causing an error in the file access process. Summary of the Invention

[0003] In view of this, this application provides a method for storing file security attributes and related devices. When the security attributes of a basic file are stored in a data file, the security attributes of this data file can be stored in an extended format type to ensure the effectiveness of accessing the basic file.

[0004] In a first aspect, an embodiment of this application provides a method for storing file security attributes. The method includes:

[0005] In response to a target storage request for storing the first security attributes of a first data file, obtain a first file control parameter corresponding to the first data file. The first file control parameter includes a first file identifier. The first data file is used to store the second security attributes of a target basic file, and the target basic file is a file stored in a universal integrated circuit card;

[0006] If the file type of the first data file determined according to the first file identifier is an access rule reference type, query a target storage type corresponding to the access rule reference type. The target storage type includes an extended format type;

[0007] Store the first security attributes according to the target storage type to facilitate access to the target basic file.

[0008] In a second aspect, an embodiment of this application provides a device for storing file security attributes. The device includes:

[0009] An acquisition unit, configured to acquire a first file control parameter corresponding to the first data file in response to a target storage request for storing a first security attribute of the first data file, where the first file control parameter includes a first file identifier, and the first data file is used to store a second security attribute of a target basic file, and the target basic file is a file stored in a universal integrated circuit card;

[0010] A query unit, configured to query a target storage type corresponding to the access rule reference type if the file type of the first data file determined according to the first file identifier is an access rule reference type, where the target storage type includes an extended format type;

[0011] A storage unit, configured to store the first security attribute according to the target storage type, so as to facilitate access to the target basic file.

[0012] In a third aspect, an embodiment of the present application provides an electronic device, including a processor, a communication module, a memory, a communication interface, and one or more programs, where the one or more programs are stored in the memory and configured to be executed by the processor, and the programs include instructions for executing the steps in any method of the first aspect of the embodiments of the present application.

[0013] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program for electronic data exchange, and the computer program causes a computer to execute some or all of the steps described in any method of the first aspect of the embodiments of the present application.

[0014] In a fifth aspect, an embodiment of the present application provides a computer program product, where the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute some or all of the steps described in any method of the first aspect of the embodiments of the present application. The computer program product may be a software installation package.

[0015] It can be seen that through the above file security attribute storage method and related devices, firstly, in response to a target storage request for storing the first security attribute of the first data file, the first file control parameter including the first file identifier corresponding to the first data file is obtained. The first data file is used to store the second security attribute of the target basic file stored in the universal integrated circuit card. If the file type of the first data file determined according to the first file identifier is the access rule reference type, the target storage type corresponding to this file type is queried. The target storage type includes the extended format type. Finally, the first security attribute is stored according to the target storage type to facilitate access to the target basic file. When the security attribute of the basic file is stored in the data file, the security attribute of the data file can be stored according to the extended format type to ensure the effectiveness of basic file access. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 It is a system architecture diagram of a file security attribute storage method provided by an embodiment of the present application;

[0018] Figure 2 It is a flowchart of a file security attribute storage method provided by an embodiment of the present application;

[0019] Figure 3 It is a flowchart of another file security attribute storage method provided by an embodiment of the present application;

[0020] Figure 4 It is a structural diagram of an electronic device provided by an embodiment of the present application;

[0021] Figure 5 It is a block diagram of the functional units of a file security attribute storage device provided by an embodiment of the present application;

[0022] Figure 6 It is a block diagram of the functional units of another file security attribute storage device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of this application.

[0024] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0025] It should be understood that the term "and / or" in this article is only a correlative relationship describing related objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article indicates that the related objects before and after are in an "or" relationship. The "plurality" mentioned in the embodiments of this application refers to two or more.

[0026] The "connection" mentioned in the embodiments of this application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices. This application does not make any limitations on this.

[0027] Referring to "embodiment" in this article means that the specific features, structures, or characteristics described in connection with the embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.

[0028] The background technology and related terms of this application will be described below.

[0029] Related to background technology:

[0030] The general integrated circuit card needs to provide the context of the secure environment to ensure the security when the files on the general integrated circuit card are accessed. When the security levels of file access are different, different levels of security conditions are corresponding. When accessing a file, matching security conditions need to be created. Only when the security conditions corresponding to the access mode of the file are met, the general integrated circuit card allows access to the file. Among them, the access mode (AM) and the security condition (SC) of the file together constitute the security attributes of the file. If the security attributes of the file are stored in a data file, and the security attributes of this data file are also stored within this data file, it will cause an error in the process of accessing the file, resulting in an access dead loop.

[0031] The following explains the key concepts involved in the embodiments of the present application:

[0032] The elementary file (EF) is the basic file in the general integrated circuit card, which is used to store data. EF is the most basic data storage file, and it is used to store text messages, contact numbers, etc.

[0033] The following introduces the relevant content of three storage types of the security attributes involved in the embodiments of the present application:

[0034] In the extended format type, the security attribute includes one byte of access mode and one or more bytes of security condition.

[0035] In the compact format type, the security attribute includes n access mode data objects and a sequence of security condition data objects.

[0036] In the reference extended format type, when the security attributes of the elementary file are stored in a data file, this data file is called the access rule reference (ARR) file. The content of the file control parameter includes the file identifier (FID) of this data file and the index number storing the security attributes of the elementary file. The index number indicates the position of the security attributes of the elementary file within this data file.

[0037] The following combines Figure 1 to illustrate the system architecture of a file access method in the embodiments of the present application. Figure 1The system architecture diagram of a file security attribute storage method provided by an embodiment of this application. This architecture includes a terminal device 110. Specifically, this terminal device includes a universal integrated circuit card. Among them, the universal integrated circuit card is mainly used for information such as user account information, authentication keys, short messages, and payment methods. The universal integrated circuit card can store service subscriber keys for identification purposes on terminal devices (such as mobile phones and computers). On the one hand, the universal integrated circuit card allows users to change the terminal device by simply removing the universal integrated circuit card from one mobile phone and inserting it into another mobile phone or broadband telephone device. On the other hand, the universal integrated circuit card can also be implemented as a part of the memory of the terminal device and does not need to be a separate or removable circuit, chip, or card.

[0038] The above terminal device 110 may include, but is not limited to, devices such as smartphones with data processing functions, tablets, handheld computers, laptop computers, mobile Internet devices (MID) or wearable devices, etc., and no specific limitations are made here.

[0039] The following is a detailed introduction to the embodiments of this application:

[0040] After understanding the software and hardware architecture of the embodiments of this application, the following is combined with Figure 2 to illustrate a file security attribute storage method in the embodiments of this application. Figure 2 The flowchart of a file security attribute storage method provided by this application, which specifically includes the following steps:

[0041] Step 201, in response to a target storage request for storing the first security attribute of the first data file, obtain the first file control parameter corresponding to the first data file, where the first file control parameter includes a first file identifier.

[0042] Among them, the first data file is used to store the second security attribute of the target basic file, and the target basic file is a file stored in the universal integrated circuit card. The target storage request may be received by the terminal device including the universal integrated circuit card from other device terminals, or the target storage request may be generated by the terminal device.

[0043] Specifically, after the terminal device receives or generates the target storage request, it parses the target storage request, determines the first data file and the first security attribute, obtains the first file control parameter of the first data file from the universal integrated circuit card, and then parses the first file identifier from the first file control parameter.

[0044] Further, the terminal device detects the first storage of the first security attribute and generates the target storage request, or detects that the first data file is inaccessible and generates the target storage request.

[0045] It can be seen that in this example, the file control parameter of the data file can be obtained based on the storage request. Since the file control parameter includes the file identifier of the data file, it provides data support for determining the file type of the data file.

[0046] Step 202, if the file type of the first data file determined according to the first file identifier is an access rule reference type, query the target storage type corresponding to the access rule reference type.

[0047] Among them, the target storage type includes an extended format type or a compact format type.

[0048] Specifically, after the terminal device obtains the first file control parameter, it parses the first file identifier in the first file control parameter. After that, the file type of the first data file can be determined according to the first file identifier in the following two ways, but not limited to them.

[0049] First, one file identifier corresponds to one data file, and different file identifiers correspond to different data files. The terminal device searches for the first data file according to the first file identifier. After finding the first data file, it determines the file type of the first data file to ensure the effectiveness of file type determination.

[0050] Second, the file identifier of the file and the file type of the file are associated in advance, and the associated file identifier and file type are stored in a pre-set first area. The terminal device uses the first file identifier as the query identifier to directly query the file type associated with the first file identifier in the first area, improving the efficiency of file type determination.

[0051] It can be seen that in this example, when the file type of the data file corresponding to the file identifier is determined to be an access rule reference type, the storage type of the security attribute of the data file can be queried, providing data support for the storage of the security attribute of the file.

[0052] Step 203, store the first security attribute according to the target storage type to facilitate access to the target basic file.

[0053] The terminal device obtains the second access mode and the second security condition of the first data file through a universal integrated circuit card, obtains the first security attribute based on the second access mode and the second security condition, and generates the third file control parameter of the first data file based on the first security attribute, that is, realizes storing the first security attribute in the third file control parameter of the first data file according to the target storage type.

[0054] It can be seen that in this example, when the security attribute of the basic file is stored in the data file, the security attribute of the data file is stored in the extended format type or the compact format type, avoiding a dead loop in access when both the security attribute of the basic file and the security attribute of the data file are stored in the first data file, thereby causing an error in the file access process and ensuring the effectiveness of the basic file access.

[0055] In a possible example, the querying the target storage type corresponding to the access rule reference type includes: obtaining a target association relationship, where the target association relationship is used to indicate the association relationship between the access rule reference type and the target storage type; determining the target storage type according to the target association relationship.

[0056] Among them, the access rule reference type and the target storage type are associated in advance to obtain the target association relationship, and the target association relationship is stored in a pre-set second area. The first area and the second area can be the same or different, without specific limitation. The terminal device uses the access rule reference type as the query identifier to directly query the second area to obtain the target storage type associated with the access rule reference type, improving the determination efficiency of the storage type of the security attribute.

[0057] In a possible example, after storing the first security attribute according to the target storage type, the method further includes: obtaining the third file identifier of the target basic file; querying whether there is a security attribute associated with the third file identifier in the target cache area; if not, associating the third file identifier with the second security attribute; storing the associated third file identifier and the second security attribute in the target cache area.

[0058] Among them, since the target basic file is stored in the universal integrated circuit card, the third file identifier of the target basic file can be read from the universal integrated circuit card. Using the third file identifier as the query identifier, query the pre-set target cache area. If the third file identifier does not exist in the target cache area or the third file identifier existing in the target cache area has no associated security attribute, then associate the third file identifier with the second security attribute in the first data file, and store the associated third file identifier and the second security attribute in the target cache area.

[0059] In addition, after querying whether there is a security attribute associated with the third file identifier in the target cache area, if so, the current process is ended. It can be understood that at this time, the associated third file identifier and the second security attribute have been stored in the target cache area.

[0060] It can be seen that in this example, by associating the security attribute of the basic file with the file identifier and storing the associated security attribute and file identifier of the basic file in the target cache area, when accessing the basic file, the security attribute of the basic file can be directly queried from the target cache area according to the file identifier of the basic file, improving the access speed of the basic file and thus enhancing the user experience.

[0061] In a possible example, after storing the first security attribute according to the target storage type to facilitate access to the target basic file, the method further includes steps A1 to A6:

[0062] Step A1, in response to a second access request for accessing the target basic file, obtain the first file control parameter.

[0063] Wherein, the first file control parameter further includes a first index number, and the first index number is used to indicate the position of the second security attribute in the first data file. The second security attribute includes a first security condition and a first access mode. After receiving the second access request for accessing the target basic file, parse the second access request to determine the third file identifier of the target basic file, and obtain the first file control parameter associated with the third file identifier stored in the universal integrated circuit card according to the third file identifier.

[0064] Step A2, obtain the third file control parameter corresponding to the first file identifier.

[0065] Wherein, the third file control parameter is a file control parameter obtained by storing the first security attribute according to the target storage type, and the first security attribute includes a second security condition and a second access mode.

[0066] Specifically, after obtaining the first file control parameter, parse the first file identifier from the first file control parameter, and obtain the third file control parameter associated with the first file identifier stored in the universal integrated circuit card according to the first file identifier.

[0067] Step A3, create the second security condition that meets the second access mode according to the first security attribute in the third file control parameter.

[0068] Among them, accessing the first data file requires creating a second security condition that meets the second access mode corresponding to the first data file.

[0069] Step A4: When the creation of the second security condition is completed, read the second security attribute in the first data file according to the first index number.

[0070] Specifically, after obtaining the first file control parameter, parse the first index number from the first file control parameter.

[0071] Step A5: Create the first security condition that meets the first access mode according to the second security attribute.

[0072] Among them, accessing the target basic file requires creating a first security condition that meets the first access mode corresponding to the target basic file.

[0073] Step A6: When the creation of the first security condition is completed, access the target basic file.

[0074] It can be seen that in this example, when the security attribute of the basic file is stored in the data file, the security attribute of the data file is stored in the extended format type and / or the compact format type. When accessing the basic file, the security attribute of the data file can be obtained first to create the security condition of the access mode corresponding to the data file, and then the security attribute of the basic file can be read from the data file to create the security condition of the access mode corresponding to the basic file, and finally the access to the basic file is completed.

[0075] Next, in combination with Figure 3 Another method for storing file security attributes in the embodiments of the present application will be described by way of example. Figure 3 The following is a schematic flowchart of another method for storing file security attributes provided by the embodiments of the present application, which specifically includes the following steps:

[0076] Step 301: In response to a first access request for accessing a target basic file, obtain a first file control parameter corresponding to a first data file.

[0077] Among them, the first file control parameter includes a first file identifier. The first data file is used to store the second security attribute of the target basic file, and the target basic file is a file stored in a universal integrated circuit card.

[0078] Step 302: Determine the first file identifier in the first file control parameter.

[0079] Step 303: Obtain a second file control parameter associated with the first file identifier.

[0080] Among them, the second file control parameter includes a second file identifier of a second data file.

[0081] Among them, the second data file is used to store a first security attribute of the first data file.

[0082] Step 304, if the second file identifier in the second file control parameter is the same as the first file identifier, then generate a target storage request for storing the first security attribute of the first data file.

[0083] Step 305, in response to the target storage request, obtain the first file control parameter.

[0084] Step 306, if the file type of the first data file determined according to the first file identifier is an access rule reference type, then query a target storage type corresponding to the access rule reference type.

[0085] Among them, the target storage type includes an extended format type or a compact format type.

[0086] Step 307, store the first security attribute according to the target storage type, so as to facilitate access to the target basic file.

[0087] Among them, steps 305 to 307 are substantially the same as steps 201 to 203. Please refer to the above description for steps 201 to 203, and details will not be repeated here.

[0088] It can be seen that in this example, through the above file security attribute storage method, during the access process of the basic file, when it is determined that the file identifier of the data file storing the security attribute of the basic file is the same as the file identifier of the data file storing the security attribute of this data file, that is, when it is determined that both the security attribute of the basic file and the security attribute of the data file are stored in this data file, a target storage request for storing the security attribute of this data file is generated to store the security attribute of this data file in the extended format type or the compact format type to realize the access to the basic file. This improves the intelligence of basic file access and enhances the user experience.

[0089] In a possible example, after generating the target storage request, the method further includes: deleting the first security attribute in the second data file; and / or deleting the second file control parameter.

[0090] When the security information of the basic file and the data file is stored in the data file, a corresponding storage request is generated to store the security attributes of the data file in an extended format type or a compact format type. In this case, the security attributes of the data file in the data file are deleted in a timely manner to save the storage resources of the universal integrated circuit card, ensure the validity of the data in the data file, and delete the file control parameters indicating the storage location of the security attributes in the data file in a timely manner. This can avoid querying the security attributes of the data file in the data file again and further ensure the validity of file access.

[0091] The following will combine Figure 4 to describe an electronic device in an embodiment of the present application. Figure 4 FIG. is a schematic structural diagram of another electronic device provided in an embodiment of the present application. As Figure 4 shown, the electronic device 400 includes a processor 401, a communication module 402, and a memory 403. The processor 401, the communication module 402, and the memory 403 are interconnected. Among them, the electronic device 400 may further include a bus 404. The processor 401, the communication module 402, and the memory 403 may be interconnected through the bus 404. The bus 404 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus 404 may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 4 only a thick line is shown in, but it does not mean that there is only one bus or one type of bus. The memory 403 is used to store a computer program. The computer program includes program instructions. The processor is configured to call the program instructions to execute all or part of the methods described above Figure 2 、 Figure 3 in.

[0092] The above mainly introduces the solution of the embodiment of the present application from the perspective of the execution process on the method side. It can be understood that in order for the electronic device to implement the above functions, it includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments provided in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but this implementation should not be considered to exceed the scope of the present application.

[0093] In the embodiments of the present application, the functional units of the electronic device can be divided according to the above method examples. For example, each functional unit can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0094] In the case of dividing each functional module corresponding to each function, the following will be combined with Figure 5 A file security attribute storage device in an embodiment of the present application will be described in detail. Figure 5 FIG. 5 is a block diagram of the functional units of a file security attribute storage device provided by an embodiment of the present application. The file security attribute storage device 500 includes:

[0095] An obtaining unit 510, configured to obtain a first file control parameter corresponding to the first data file in response to a target storage request for storing a first security attribute of the first data file, where the first file control parameter includes a first file identifier, and the first data file is used to store a second security attribute of a target basic file, and the target basic file is a file stored in a universal integrated circuit card;

[0096] A query unit 520, configured to query a target storage type corresponding to the access rule reference type if the file type of the first data file determined according to the first file identifier is an access rule reference type, where the target storage type includes an extended format type;

[0097] A storage unit 530, configured to store the first security attribute according to the target storage type, so as to facilitate access to the target basic file.

[0098] It can be seen that through the above file security attribute storage device, first, in response to a target storage request for storing a first security attribute of a first data file, a first file control parameter including a first file identifier corresponding to the first data file is obtained. The first data file is used to store a second security attribute of a target basic file stored in a universal integrated circuit card. If the file type of the first data file determined according to the first file identifier is an access rule reference type, then a target storage type corresponding to this file type is queried, and the target storage type includes an extended format type. Finally, the first security attribute is stored according to the target storage type, so as to facilitate access to the target basic file. When the security attribute of the basic file is stored in the data file, the security attribute of the data file can be stored according to the extended format type to ensure the effectiveness of accessing the basic file.

[0099] In the case of adopting an integrated unit, the following combines Figure 6 Another file security attribute storage device 600 in the embodiments of the present application will be described in detail. The file security attribute storage device 600 includes a processing unit 601 and a communication unit 602. Among them, the processing unit 601 is used to execute any step in the above method embodiments, and when performing file security attribute storage such as sending, the communication unit 602 can be selectively called to complete the corresponding operation.

[0100] Among them, the file security attribute storage device 600 may further include a storage unit 603 for storing program codes and data. The processing unit 601 may be a processor, the communication unit 602 may be a wireless communication module, and the storage unit 603 may be a memory.

[0101] The processing unit 601 is specifically configured to: in response to a target storage request for storing a first security attribute of a first data file, obtain a first file control parameter corresponding to the first data file, where the first file control parameter includes a first file identifier, and the first data file is used to store a second security attribute of a target basic file, and the target basic file is a file stored in a universal integrated circuit card;

[0102] If the file type of the first data file determined according to the first file identifier is an access rule reference type, query a target storage type corresponding to the access rule reference type, where the target storage type includes an extended format type;

[0103] Store the first security attribute according to the target storage type to facilitate access to the target basic file.

[0104] It can be seen that through the above file security attribute storage device, first, in response to a target storage request for storing a first security attribute of a first data file, obtain a first file control parameter corresponding to the first data file, which includes a first file identifier, and the first data file is used to store a second security attribute of a target basic file stored in a universal integrated circuit card. If the file type of the first data file determined according to the first file identifier is an access rule reference type, query a target storage type corresponding to this file type, where the target storage type includes an extended format type. Finally, store the first security attribute according to the target storage type to facilitate access to the target basic file. When the security attribute of the basic file is stored in the data file, the security attribute of the data file can be stored in the extended format type to ensure the effectiveness of accessing the basic file.

[0105] The embodiments of the present application also provide a computer storage medium. The computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute some or all of the steps of any of the methods described in the foregoing method embodiments. The above computer includes an electronic device.

[0106] The embodiments of the present application also provide a computer program product. The computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute some or all of the steps of any of the methods described in the foregoing method embodiments. The computer program product can be a software installation package, and the above computer includes an electronic device.

[0107] It should be noted that, for the foregoing method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.

[0108] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0109] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0110] The units described as separate components above may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0111] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, may exist separately as individual physical units, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0112] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable memory. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the above methods in each embodiment of the present application. The aforementioned memory includes various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.

[0113] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory may include: flash drives, read-only memories (abbreviated as ROM in English), random access memories (abbreviated as RAM in English), magnetic disks, or optical discs, etc.

[0114] The above has introduced the embodiments of the present application in detail. Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A method for storing file security attributes, characterized in that, The method includes: In response to a target storage request for storing the first security attribute of the first data file, obtaining a first file control parameter corresponding to the first data file, where the first file control parameter includes a first file identifier, and the first data file is used to store the second security attribute of a target basic file, and the target basic file is a file stored in a universal integrated circuit card; If the file type of the first data file determined according to the first file identifier is an access rule reference type, querying a target storage type corresponding to the access rule reference type, where the target storage type includes an extended format type; Storing the first security attribute according to the target storage type, so as to facilitate access to the target basic file.

2. The method according to claim 1, wherein The target storage type further includes a compact format type.

3. The method according to claim 1 or 2, characterized in that, The querying the target storage type corresponding to the access rule reference type includes: Obtaining a target association relationship, where the target association relationship is used to indicate the association relationship between the access rule reference type and the target storage type; Determining the target storage type according to the target association relationship.

4. The method according to claim 1 or 2, characterized in that Before the obtaining the first file control parameter corresponding to the first data file in response to the target storage request for storing the first security attribute of the first data file, the method further includes: In response to a first access request for accessing the target basic file, obtaining the first file control parameter; Determining the first file identifier in the first file control parameter; Obtaining a second file control parameter associated with the first file identifier, where the second file control parameter includes a second file identifier of a second data file, and the second data file is used to store the first security attribute; If the second file identifier is the same as the first file identifier, generating the target storage request.

5. The method according to claim 4, wherein After the generating the target storage request, the method further includes: Deleting the first security attribute in the second data file; and / or Deleting the second file control parameter.

6. The method according to claim 1, characterized in that After the storing the first security attribute according to the target storage type, the method further includes: Obtaining a third file identifier of the target basic file; Querying whether there is a security attribute associated with the third file identifier in a target cache area; If not, associating the third file identifier with the second security attribute; Storing the associated third file identifier and the second security attribute into the target cache area.

7. The method according to claim 1, characterized in that, After the storing the first security attribute according to the target storage type, so as to facilitate access to the target basic file, the method further includes: In response to a second access request for accessing the target basic file, obtaining the first file control parameter, where the first file control parameter further includes a first index number, and the first index number is used to indicate the position of the second security attribute in the first data file, and the second security attribute includes a first security condition and a first access mode; Obtain a third file control parameter corresponding to the first file identifier, where the third file control parameter is a file control parameter obtained by storing the first security attribute according to the target storage type, and the first security attribute includes a second security condition and a second access mode; Create the second security condition that meets the second access mode according to the first security attribute in the third file control parameter; When the creation of the second security condition is completed, read the second security attribute in the first data file according to the first index number; Create the first security condition that meets the first access mode according to the second security attribute; When the creation of the first security condition is completed, access the target basic file.

8. A file security attribute storage device, characterized in that The device includes: An obtaining unit, configured to, in response to a target storage request for storing the first security attribute of a first data file, obtain a first file control parameter corresponding to the first data file, where the first file control parameter includes a first file identifier, and the first data file is used to store a second security attribute of a target basic file, and the target basic file is a file stored in a universal integrated circuit card; A querying unit, configured to, if the file type of the first data file determined according to the first file identifier is an access rule reference type, query a target storage type corresponding to the access rule reference type, where the target storage type includes an extended format type; A storage unit, configured to store the first security attribute according to the target storage type, so as to facilitate access to the target basic file.

9. An electronic device, characterized in that, Including: A processor, a memory, and one or more programs; the one or more programs are stored in the memory and configured to be executed by the processor, and the programs include instructions for performing the steps in the method according to any one of claims 1-7.

10. A computer storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Universal IC card and security attribute verification method

    JP2015060302A

  • Method and apparatus for enhancing security of system file in uicc

    KR1020100079799A