Implementation method of global data security sandbox based on environment multi-factor identity authentication

By adopting environmental multi-factor identity authentication and encrypted transmission channel technology in the terminal data security sandbox, the contradiction between data security and collaboration efficiency in the existing technology is solved, and the secure sharing and collaboration of the whole-domain data security sandbox is realized.

CN115913717BActive Publication Date: 2025-05-20BEIJING TAILIXIN TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211442165.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2025-05-20
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

While ensuring the security of terminal data, the existing technology limits data coordination, resulting in reduced office and production efficiency. How to find a balance between the two has become an urgent need in the market.

Method used

The implementation method of the whole-domain data security sandbox based on environmental multi-factor identity authentication is adopted. By setting up a sandbox security and sharing control center on the server side, configuring terminal security policies, and multi-factor identity authentication through the environment perception agent, creating a logically isolated terminal data security sandbox to achieve secure sharing and collaboration of data.

Benefits of technology

It realizes that while ensuring the security of terminal data, it improves data collaboration efficiency. Through environmental multi-factor identity authentication and data encryption transmission channel technology, each terminal security sandbox is connected into a cross-terminal full-domain data security sandbox, realizing safe data distribution and safe and orderly connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913717B_ABST
    Figure CN115913717B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for implementing a global data security sandbox based on environment multi-factor identity authentication, which creates a terminal data security sandbox at a terminal through a centralized and unified terminal security policy, and uses environment multi-factor identity authentication technology and data encryption transmission channel technology to connect each terminal security sandbox into a cross-terminal global data security sandbox, and through data controlled upload and download management, realizes data security distribution between each terminal data security sandbox in the global data security sandbox, and realizes safe and orderly connection between each terminal data security sandbox. The global data security sandbox can also realize network invisibility of important business resources, data terminal leakage prevention, and data transmission security between business resources and terminals. The present invention also relates to a global data security sandbox system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to an implementation method of a global data security sandbox based on environmental multi-factor identity authentication. Background Art

[0002] With the increasing importance of data security, the application of terminal data leakage prevention technology has been gradually promoted in government offices, enterprise R & D, military offices and production sites. Terminal data leakage prevention technology can greatly improve the security of terminal data, but at the same time, it also restricts data collaboration and greatly reduces office and production efficiency. How to improve data collaboration efficiency while ensuring the security of terminal data has become an urgent need in the market. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide an implementation method of a global data security sandbox for environmental multi-factor identity authentication and a global data security sandbox system in view of the deficiencies of the prior art.

[0004] The technical solution of the present invention to solve the above technical problems is as follows:

[0005] In a first aspect, the present application provides an implementation method of a global data security sandbox based on environmental multi-factor identity authentication, and the method includes:

[0006] The sandbox security and sharing control center set on the server side configures terminal security policies, including the capacity of the terminal data security sandbox, sandbox naming, terminal and user authentication and management, terminal data security sandbox protection policies including clipboard control, outbound control, document movement control, document save-as control, printing control, peripheral control, terminal data security sandbox encryption policy, setting of document sharing approval processes between terminals, and auditing of operation behaviors within the terminal data security sandbox;

[0007] The sandbox security and sharing control center distributes the security policies that each authentication terminal needs to execute to each terminal data security sandbox;

[0008] Each terminal deploys a client uniformly distributed by the sandbox security and sharing control center to create a terminal data security sandbox through driver layer and application layer redirection technologies, and each terminal data security sandbox executes the terminal data security sandbox protection policies issued by the sandbox security and sharing center;

[0009] Before a terminal with a terminal data security sandbox is incorporated into the global data security sandbox, multi-factor identity authentication based on environmental identity information needs to be performed on the terminal. Specifically, the environmental perception agent set on the terminal collects the real-time environmental identity information of the terminal and reports it to the security control center for identity authentication of the terminal and the user, and generates a digital identity certificate for the user's terminal on this terminal. After authentication, it is saved in the security control center. The terminal that has passed the above authentication is hereinafter referred to as the "authenticated terminal". At the same time, access authorization for business resources of the user's terminal is performed, and all or part of the permissions to access the specified protected business resources are granted to the user's terminal. The types and quantities of environmental identity information specifically collected by the environmental perception agent are determined according to the pre-set verification policy.

[0010] After the authentication and authorization of the user's terminal, the security control center issues through the security policy the access address or port information of the protected business resources and the terminal protection policy for the data from the business resources to the user terminal. The data and information downloaded or received by the terminal from the protected resources with authorized access can only be stored in the data security sandbox of the terminal and cannot be directly stored in other spaces of the terminal. The terminal security protection policy of the terminal data security sandbox fully implements the terminal data security sandbox protection policy issued by the security control center.

[0011] After the terminal passes the authentication and authorization and the terminal data security sandbox protection policy takes effect, when data needs to be transmitted between authenticated terminals, the real-time environmental identity information of the authenticated terminal is first collected and reported to the authentication device for verification. The authentication device compares the received real-time environmental identity information with the digital identity certificate of the terminal on file in the security control center for authentication to determine whether to allow access, whether additional verification is required, or to directly block access. Then, the authenticated user to be transmitted is selected from the global data security sandbox user list, and the authentication device establishes a secure encrypted transmission channel for communication for this data transmission. Only the authenticated terminal of this user can receive the transmitted data.

[0012] Through the above architecture, each terminal data security sandbox is connected into a global data security sandbox with a unified terminal security protection policy.

[0013] The terminal data security sandbox creates an environment that is completely logically isolated from the personal environment on the terminal through driver layer or application layer redirection technology to control the data or file operation behaviors in the sandbox. The security control component of the terminal data security sandbox receives the unified terminal security protection policy of the authentication device.

[0014] The environmental identity information refers to the hardware characteristic information, operating system characteristic information, network characteristic information, user identity information, etc. of the terminal device, including but not limited to the motherboard MAC of the hardware, CPU manufacturer and serial number, storage device capacity and serial number, operating system name and version number, network address or port, names and versions of the main application systems deployed such as browsers, user name and password, and biometric features, hereinafter referred to as "environmental identity information".

[0015] In a second aspect, a global data security sandbox system, the system includes an authentication terminal, an authentication device, a sandbox security and sharing control center, and protected service resources;

[0016] The authentication terminal includes an environment perception agent, a terminal data security sandbox, a terminal data security sandbox security control component, and a terminal data security sandbox document upload and download control component, as well as the device or virtual device on which it runs;

[0017] The environment perception agent is used to collect and report the environmental identity information of the terminal;

[0018] The environmental identity information refers to the hardware characteristic information, operating system characteristic information, network characteristic information, user identity information, etc. of the terminal device, including the motherboard MAC of the hardware, CPU manufacturer and serial number, storage device capacity and serial number, operating system name and version number, network address or port, names and versions of the main application systems deployed such as browsers, user name and password, and biometric features, hereinafter referred to as "environmental identity information";

[0019] The terminal data security sandbox creates an environment that is completely logically isolated from the personal environment on the terminal through driver layer or application layer redirection technology, and realizes the control of data or file operation behaviors in the sandbox. The terminal data security sandbox security control component receives the unified terminal security protection policy of the authentication device;

[0020] The terminal data security sandbox security control component is a program module or component that encrypts the data and landed files entering the terminal data security sandbox, and has data protection functions such as clipboard control, peripheral device management, file external distribution management, and behavior auditing;

[0021] The terminal data security sandbox document upload and download control component is responsible for controlling that the documents shared and transferred between each terminal security sandbox can only be downloaded within the terminal data security sandbox. The documents in the terminal data security sandbox are uploaded according to the terminal security policy configured by the sandbox security and sharing control center, and the decryption use and encrypted storage of the documents in the sandbox are carried out;

[0022] The authentication device includes a security control center and an access control component; it realizes identity recognition and permission verification for the access initiated by the terminal, decides whether to allow access, establishes an encrypted transmission channel, and conducts continuous verification during the continuous access of the authenticated terminal.

[0023] The security control center is used to set the access permissions of the terminal after authenticating and authorizing the terminal, and add the terminal to the virtual private network according to the access permissions of the terminal; manage the authenticated terminal and the user; manage the digital certificate of the authenticated terminal; set the unified security policy of the authenticated terminal;

[0024] The access control component is used to hide the network ports of the protected service resources; receive the environmental identity information reported by the environmental perception agent and forward it to the security control center for authentication and continuous verification; control the access and data transmission between the terminal and the protected service resources according to the decision of the security control center.

[0025] The sandbox security and sharing control center is used to configure the terminal security policy, including the capacity of the terminal data security sandbox, sandbox naming, terminal and user authentication and management, terminal data security sandbox protection policy, clipboard control, outbound control, document movement control, document save as control, printing control, peripheral control, terminal data security sandbox encryption policy, setting of the document sharing approval process between terminals, and behavior auditing within the terminal data security sandbox; the sandbox security and sharing control center distributes the security policies that each authenticated terminal needs to execute to each terminal data security sandbox.

[0026] The protected service resources include business system software, business system operating environment, equipment relied on by the business system, and storage components of business data.

[0027] The beneficial effects of the present invention are as follows: A method for implementing a global data security sandbox based on environmental multi-factor identity authentication is proposed. By means of a centralized and unified terminal security policy, a terminal data security sandbox is created on the terminal, and environmental multi-factor identity authentication technology and data encrypted transmission channel technology are adopted to connect each terminal security sandbox into a cross-terminal global data security sandbox. Through data-controlled upload and download management, secure data distribution between the terminal data security sandboxes in the global data security sandbox is realized, and secure and orderly connection between the terminal data security sandboxes is achieved. The global data security sandbox can also achieve network stealth of important service resources (including business system software, business system operating environment such as operating system and other necessary components, equipment relied on by the business system, storage components or systems of business data), data terminal leakage prevention, and data transmission security between the service resources and the terminal.

[0028] Advantages of additional aspects of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments of the present invention or the prior art description will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0030] Figure 1 It is a schematic flow chart of a method for implementing a global data security sandbox based on environmental multi-factor identity authentication according to an embodiment of the present invention;

[0031] Figure 2 It is a schematic module diagram of a global data security sandbox system based on environmental multi-factor identity authentication according to another embodiment of the present invention;

[0032] Figure 3 It is a schematic system diagram of a global data security sandbox system based on environmental multi-factor identity authentication according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] As Figure 1 and Figure 3 shown, for the method for implementing a global data security sandbox based on environmental multi-factor identity authentication according to an embodiment of the present invention, the method includes the following steps 100:

[0035] 110. Create a terminal data security sandbox under unified network control on each terminal (hereinafter referred to as "terminal") that needs to be incorporated into the global data security sandbox.

[0036] 120. Connect the authentication terminal and the terminal data security sandbox through an environmental multi-factor identity authentication and data encryption transmission system to form a global data security sandbox.

[0037] Before a terminal with a terminal data security sandbox is incorporated into the global data security sandbox, multi-factor authentication based on environmental identity information needs to be performed on the terminal. Specifically, the environmental perception agent (Agent2) set on the terminal collects the real-time environmental identity information of the terminal (also known as "the first environmental identity information"), reports it to the security control center (K2) for terminal and user identity authentication, and generates the digital identity certificate of the user for this terminal. After authentication, it is saved in the security control center (K2). The terminal that has passed the above authentication is hereinafter referred to as the "authenticated terminal". At the same time, access authorization for the business resources of this user's terminal is performed, and all or part of the permissions to access the specified protected business resources are granted to this user's terminal. The types and quantities of environmental identity information specifically collected by the environmental perception agent (Agent2) are determined according to the preset verification policy.

[0038] After the authentication and authorization of this user's terminal, the security control center (K2) issues through the security policy, and distributes the access address or port information of the protected business resources and the terminal protection policy for the data from the business resources to this user terminal. The data and information downloaded or received by this terminal from the protected resources of the authorized access can only be stored in the data security sandbox of this terminal, and cannot be directly stored in other spaces of this terminal; the terminal security protection policy of the terminal data security sandbox fully implements the terminal data security sandbox protection policy issued by the security control center (K2) (the terminal can have other security policies other than the security policies uniformly issued by the security control center K2, but it should ensure the full implementation of the security policies uniformly issued by the security control center).

[0039] After the terminal passes the authentication and authorization and the terminal data security sandbox protection policy takes effect, when data needs to be transmitted between the authenticated terminals, first collect the real-time environmental identity information of the authenticated terminal (also known as "the second environmental identity information"), and report it to the authentication device (or system) that performs the verification. The authentication device (or system) compares the received real-time environmental identity information (also known as "the second environmental identity information") with the digital identity certificate of this terminal authenticated and filed by the security control center (K2) to determine whether to allow access, or whether additional verification is required, or directly block access. Then, select the authenticated user who needs to transmit from the list of global data security sandbox users, and the authentication device (or system) establishes a secure encrypted transmission channel (such as the single-packet authorization encryption tunnel technology SPA) for this data transmission to communicate. Only the authenticated terminal of this user can receive the transmitted data.

[0040] Through the above architecture, each terminal data security sandbox is connected into a global data security sandbox with a unified terminal security protection policy.

[0041] 130. Establish document security collaboration between the data security sandboxes of the global data security sandbox.

[0042] Deploy a data collaboration agent (Agengt3) on each authentication terminal, which is responsible for controlling that the documents shared and transferred between the security sandboxes of each terminal can only be downloaded within the terminal data security sandbox of that terminal. The documents within the terminal data security sandbox are uploaded according to the terminal security policies configured by the sandbox security and sharing control center (K1). The decryption, use, and encrypted storage of the documents within the sandbox are carried out.

[0043] 140. Establish a secure connection between the global data security sandbox and the business resources to be protected.

[0044] When an authentication terminal accesses protected business resources, it first collects the real-time environment identity information of the authentication terminal (also known as "second environment identity information") and reports it to the authentication device (or system) for verification. The authentication device (or system) compares the received real-time environment identity information (also known as "second environment identity information") with the digital identity certificate of the terminal filed for authentication by the security control center (K2) to determine whether to allow access, whether additional verification is required, or to directly block access. When the gateway component (or system) allows the terminal to access the authorized business resources after verification and meets the access control requirements, a secure encrypted transmission channel (such as the single-packet authorization tunnel encryption technology SPA) is established for the protected business resources and the authentication, and communication is carried out through the two-way encrypted tunnel established between the access control gateway and the business resources.

[0045] The protected business resources include business system software, the operating environment of the business system (such as the operating system and other necessary components such as the security system), the devices relied on by the business system, and the storage components or systems of business data;

[0046] Through the foregoing architecture and technical means, a secure transmission channel is established between the protected business resources and the global data security sandbox. Only the authentication terminals can access the protected business resources. The data originating from accessing the protected business resources can only be downloaded to the terminal data security sandbox of the authentication terminal. The data stored in the terminal data security sandboxes of each terminal can only be transmitted between the authentication terminals within the global data security sandbox, thus realizing the terminal security, internal sharing, and security during data sharing of the data of the protected business resources.

[0047] As Figure 2 shown, a global data security sandbox system, the system includes an authentication terminal, an authentication device, a sandbox security and sharing control center, and protected business resources;

[0048] The authentication terminal includes an environment perception agent, a terminal data security sandbox, a terminal data security sandbox security control component, and a terminal data security sandbox document upload and download control component, as well as the device or virtual device on which it runs;

[0049] The environment perception agent is used to collect and report the environment identity information of the terminal;

[0050] The environment identity information refers to the hardware feature information, operating system feature information, network feature information, user identity information, etc. of the terminal device, including the motherboard MAC of the hardware, CPU manufacturer and serial number, storage device capacity and serial number, operating system name and version number, network address or port, names and versions of the main application systems deployed such as browsers, user name and password, and biometric features, hereinafter referred to as "environment identity information";

[0051] The terminal data security sandbox creates an environment that is completely logically isolated from the personal environment on the terminal through driver layer or application layer redirection technology to control the data or file operation behaviors in the sandbox. The security control component of the terminal data security sandbox receives the unified terminal security protection policy of the authentication device;

[0052] The security control component of the terminal data security sandbox is a program module or component that encrypts the data and landed files entering the terminal data security sandbox, and has data protection functions such as clipboard control, peripheral device control, file external transmission control, and behavior auditing;

[0053] The document upload and download control component of the terminal data security sandbox is responsible for controlling that the documents shared and transmitted between each terminal security sandbox can only be downloaded within the terminal data security sandbox. The documents within the terminal data security sandbox are uploaded according to the terminal security policy configured by the sandbox security and sharing control center, and the decryption use and encrypted storage of the documents within the sandbox are performed;

[0054] The authentication device includes a security control center and an access control component; it realizes identity recognition, permission verification for the access initiated by the terminal, decides whether to allow access, establishes an encrypted transmission channel, and performs continuous verification during the continuous access of the authenticated terminal;

[0055] The security control center is used to set the access permission of the terminal after authenticating and authorizing the terminal, and add the terminal to the virtual private network according to the access permission of the terminal; manage the authenticated terminal and the user; manage the digital certificate of the authenticated terminal; set the unified security policy of the authenticated terminal;

[0056] The access control component is used to hide the network ports of the protected service resources; receive the environment identity information reported by the environment perception agent and forward it to the security control center for authentication and continuous verification; control the access and data transmission between the terminal and the protected service resources according to the decision of the security control center;

[0057] The Sandbox Security and Sharing Control Center is used to configure terminal security policies, including the capacity of the terminal data security sandbox, sandbox naming, terminal and user authentication and management, terminal data security sandbox protection policies, clipboard control, outbound control, document movement control, document save-as control, printing control, peripheral control, terminal data security sandbox encryption policies, setting of document sharing approval processes between terminals, and behavior auditing within the terminal data security sandbox; the Sandbox Security and Sharing Control Center distributes the security policies that each authenticated terminal needs to execute to each terminal data security sandbox;

[0058] The protected business resources include business system software, business system operating environments, devices on which the business systems rely, and storage components of business data.

[0059] Further, the authenticated terminal serves as two independent terminal agents: an environment perception agent and a terminal data security sandbox component, and the terminal data security sandbox component includes a terminal data security sandbox, a terminal data security sandbox security control component, and a terminal data security sandbox document upload / download control component.

[0060] Further, the authentication device is split into two devices: including a security control center and an access control component.

[0061] Further, the authentication device and the protected business system together form an integrated system.

[0062] Further, the access control component and the protected business system together form an integrated system.

[0063] An implementation method of a global data security sandbox based on environment multi-factor identity authentication proposed based on the above embodiments creates a terminal data security sandbox on the terminal through a centralized and unified terminal security policy, and uses environment multi-factor identity authentication technology and data encrypted transmission channel technology to connect each terminal security sandbox into a cross-terminal global data security sandbox, and realizes secure data distribution between each terminal data security sandbox in the global data security sandbox through data-controlled upload / download management, and realizes secure and orderly connection between each terminal data security sandbox. The global data security sandbox can also achieve network stealth of important business resources (including business system software, business system operating environments such as operating systems and other necessary components, devices on which the business systems rely, storage components or systems of business data), data terminal anti-leakage, and secure data transmission between business resources and terminals.

[0064] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0065] In the embodiments provided by the present invention, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the device or unit can be in electrical, mechanical or other forms.

[0066] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0067] In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0068] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.

[0069] Based on such understanding, all or part of the processes in the above-described embodiment methods of the present invention can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0070] The above-described embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the protection scope of the present invention.

[0071] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or replacements, and these modifications or replacements should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for implementing a global data security sandbox based on environment multi-factor identity authentication, characterized in that: The method comprises: The sandbox security and sharing control center set up on the server side configures terminal security policies, including the capacity of the terminal data security sandbox, sandbox naming, terminal and user authentication and management, terminal data security sandbox protection policies including clipboard control, outbound control, document movement control, document save control, printing control, peripheral control, terminal data security sandbox encryption policy, document sharing approval process settings between terminals, and operation behavior auditing within the terminal data security sandbox; The sandbox security and sharing control center sends the security policies that each authentication terminal needs to execute to each terminal data security sandbox; Each terminal deploys a client uniformly issued by the Sandbox Security and Sharing Control Center to create a terminal data security sandbox through driver layer and application layer redirection technology. Each terminal data security sandbox executes the terminal data security sandbox protection strategy issued by the Sandbox Security and Sharing Center. Before a terminal that has established a terminal data security sandbox is included in the global data security sandbox, it is necessary to perform multi-factor identity authentication based on environmental identity information on the terminal: the specific method is that the environmental perception agent set up on the terminal collects the real-time environmental identity information of the terminal and reports it to the security control center for terminal and user identity authentication, and generates a digital identity certificate for the user's terminal, which is saved in the security control center after authentication. The terminal that has passed the above authentication is hereinafter referred to as an "authenticated terminal". At the same time, the user's terminal is authorized to access business resources, and the user's terminal is granted full or partial access to designated protected business resources. The specific type and quantity of environmental identity information collected by the environmental perception agent is determined according to the pre-set verification strategy. After the user's terminal is authenticated and authorized, the security control center will issue the access address or port information of the protected business resources and the terminal protection policy for the data from the business resources to the user terminal through the security policy. The data and information downloaded or received by the terminal from the protected resources with authorized access can only be stored in the data security sandbox of the terminal and cannot be directly stored in other spaces of the terminal. The terminal security protection policy of the terminal data security sandbox fully implements the terminal data security sandbox protection policy issued by the security control center. After the terminal is authenticated and authorized and the terminal data security sandbox protection strategy takes effect, when data needs to be transmitted between the authentication terminals, the real-time environment identity information of the authentication terminal is first collected and reported to the authentication device for verification. The authentication device compares the received real-time environment identity information with the terminal digital identity certificate authenticated and filed by the security control center to decide whether to allow access, whether to increase verification, or directly block access; then, select the authenticated user who needs to transmit from the global data security sandbox user list, and the authentication device establishes a secure encrypted transmission channel for communication for this data transmission. Only the authentication terminal of the user receives the transmitted data; Through the above architecture, each terminal data security sandbox is connected to form a global data security sandbox with a unified terminal security protection strategy; The terminal data security sandbox is to create an environment on the terminal that is completely logically isolated from the personal environment through driver layer or application layer redirection technology, so as to control the data or file operation behavior in the sandbox. The terminal data security sandbox security control component is to receive the unified terminal security protection strategy of the authentication device; The environmental identity information refers to the hardware feature information, operating system feature information, network feature information, and user identity information of the terminal device, including but not limited to the hardware motherboard MAC, CPU manufacturer and serial number, storage device capacity and serial number, operating system name and version number, network address or port, the main application system deployed is the name and version of the browser, user name and password, and biometric features.

2. The method for implementing a global data security sandbox based on environment multi-factor identity authentication according to claim 1, characterized in that: The method further comprises: Establish document security collaboration among all data security sandboxes in the global data security sandbox; A data collaboration agent is deployed on each authentication terminal to control the shared documents between the security sandboxes of each terminal. The documents can only be downloaded from the data security sandbox of the terminal. The documents in the data security sandbox of the terminal are uploaded according to the terminal security policy configured by the sandbox security and sharing control center. The documents in the sandbox are decrypted for use and encrypted for storage.

3. The method for implementing a global data security sandbox based on environment multi-factor identity authentication according to claim 1, characterized in that: The method further comprises: Establish a secure connection between the global data security sandbox and the business resources that need to be protected; When the authentication terminal accesses the protected business resources, the real-time environment identity information of the authentication terminal is first collected and reported to the authentication device for performing verification. The authentication device compares the received real-time environment identity information with the digital identity certificate of the terminal registered by the security control center to decide whether to allow access, whether to increase verification, or directly block access; when the gateway component is verified to meet the access control requirements and allows the terminal to access the authorized business resources, a secure encrypted transmission channel is established for the protected business resources and the authentication, and a two-way encrypted tunnel established by the access control gateway and the business resources is used for communication; The protected business resources include business system software, business system operating environment, equipment on which the business system relies, and storage components or systems for business data.

4. A global data security sandbox system, characterized in that: The system includes an authentication terminal, an authentication device, a sandbox security and sharing control center, and protected business resources; The authentication terminal includes an environment perception agent, a terminal data security sandbox, a terminal data security sandbox security control component, and a terminal data security sandbox document upload and download control component, as well as the device or virtual device on which it runs; The environment perception agent is used to collect and report the environment identity information of the terminal; The environmental identity information refers to the hardware feature information, operating system feature information, network feature information, and user identity information of the terminal device, including the hardware motherboard MAC, CPU manufacturer and serial number, storage device capacity and serial number, operating system name and version number, network address or port, the name and version of the main application system deployed, such as the browser, user name and password, and biometric features; The terminal data security sandbox is to create an environment on the terminal that is completely logically isolated from the personal environment through driver layer or application layer redirection technology, so as to control the data or file operation behavior in the sandbox. The terminal data security sandbox security control component is to receive the unified terminal security protection strategy of the authentication device; The terminal data security sandbox security control component encrypts the data and landing files entering the terminal data security sandbox, and is a program module or component with clipboard control, peripheral control, file outbound control, and behavior audit data protection functions; The terminal data security sandbox document upload and download control component is responsible for controlling the shared documents between the terminal security sandboxes to be downloaded only in the terminal data security sandbox, and the documents in the terminal data security sandbox are uploaded according to the terminal security policy configured by the sandbox security and sharing control center, and the documents in the sandbox are decrypted for use and encrypted for storage; The authentication device includes a security control center and an access control component; it realizes identity recognition and authority verification of the access initiated by the terminal, and decides whether to allow access, establishes an encrypted transmission channel, and continuously verifies the continuous access process of the authentication terminal; The security control center is used to set the access rights of the terminal after authenticating and authorizing the terminal, and add the terminal to the virtual internal network according to the access rights of the terminal; Manage authentication terminals and users; Manage authentication terminal digital certificates; Set a unified security policy for authentication terminals; The access control component is used to hide the network port of the protected business resource; receive the environmental identity information reported by the environmental perception agent and forward it to the security control center for authentication and continuous verification; control the access and data transmission between the terminal and the protected business resource according to the decision of the security control center; The sandbox security and sharing control center is used to configure terminal security policies, including the capacity of the terminal data security sandbox, sandbox naming, terminal and user authentication and management, terminal data security sandbox protection policy, clipboard control, outbound control, document movement control, document save control, printing control, peripheral control, terminal data security sandbox encryption policy, document sharing approval process settings between terminals, and behavior auditing within the terminal data security sandbox; the sandbox security and sharing control center sends the security policies that each authenticated terminal needs to execute to each terminal data security sandbox; The protected business resources include business system software, business system operating environment, equipment on which the business system relies, and storage components of business data.

5. The global data security sandbox system according to claim 4, characterized in that: The authentication terminal acts as two independent terminal agents: an environment perception agent and a terminal data security sandbox component. The terminal data security sandbox component includes a terminal data security sandbox, a terminal data security sandbox security control component and a terminal data security sandbox document upload and download control component.

6. The global data security sandbox system according to claim 4, characterized in that: The authentication device is divided into two devices: a security control center and an access control component.

7. The global data security sandbox system according to claim 4, characterized in that: The authentication device and the protected business system together form an integral system.

8. The global data security sandbox system according to claim 4, characterized in that: The access control component and the protected business system together form an overall system.

Citation Information

Patent Citations

  • Security sandbox system supporting security fusion of multiple data sources

    CN113114685A

  • Malware detection by a sandbox service by utilizing contextual information

    US20210200859A1