A privacy data protection method and device and readable storage medium
Patent Information
- Application Number
- CN202311141080.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-05
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-09-05
AI Technical Summary
[0003]本发明所要解决的技术问题是针对现有技术的上述不足,提供一种隐私数据的保护方法、装置及可读存储介质,用以解决现有技术还没有如何避免用户隐私数据被设备商或服务商随意提取的相关方案的问题
[0037]本发明提供的隐私数据的保护方法、装置及可读存储介质。首先向隐私数据导航子系统发送用户标识创建请求,以使所述隐私数据导航子系统根据所述用户标识创建请求创建用户,并创建用户标识对应的机密计算单元以及相应的存储空间;所述机密计算单元基于可信执行环境TEE能力;然后当用户需要进行隐私数据上传时,向所述机密计算单元传输所述隐私数据,以使所述机密计算单元对用户上传的隐私数据进行加密,并存储于所述存储空间中;再接收所述机密计算单元根据存储的所述隐私数据生成的可访问的统一资源定位器URL地址;并通过所述URL地址访问所述隐私数据。本发明为用户提供一个私密的存储和运行环境,通过机密计算单元对用户隐私数据进行保护,使得数据不出域,从而能够避免用户隐私数据被设备商或服务商随意提取。解决了现有技术还没有如何避免用户隐私数据被设备商或服务商随意提取的相关方案的问题。
Smart Images

Figure CN117176429B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart home technology, and in particular to a method, apparatus and readable storage medium for protecting privacy data. Background Technology
[0002] With the development of smart homes, a large amount of personal privacy data is generated, and personal information protection has become a widespread issue. Most of the data generated by users is held by various device suppliers or service providers. Manufacturers treat user data as a gold mine, continuously utilizing and trading it, and user information is increasingly exposed to various interest groups, potentially posing risks to users. Currently, no effective solutions or products have been found on the market to address this problem. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a method, apparatus and readable storage medium for protecting privacy data, so as to solve the problem that the prior art does not have a solution for how to prevent user privacy data from being arbitrarily extracted by equipment manufacturers or service providers.
[0004] In a first aspect, the present invention provides a method for protecting privacy data, applied to a user terminal system, the method comprising:
[0005] A user identifier creation request is sent to the privacy data navigation subsystem, so that the privacy data navigation subsystem creates a user according to the user identifier creation request, and creates a confidential computing unit and corresponding storage space corresponding to the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability;
[0006] When a user needs to upload private data, the private data is transmitted to the confidential computing unit so that the confidential computing unit encrypts the user-uploaded private data and stores it in the storage space.
[0007] Receive the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data;
[0008] Access the privacy data via the URL address.
[0009] Furthermore, sending the user identifier creation request to the privacy data navigation subsystem specifically includes:
[0010] A user identifier creation request is sent to the privacy data navigation subsystem based on the pre-set privacy data navigation subsystem address.
[0011] Furthermore, before transmitting the privacy data to the confidential computing unit when a user needs to upload privacy data, the method further includes:
[0012] Together with the confidential computing unit, it interacts with the key subsystem to collaboratively request encryption keys for network transmission between the user terminal system and the confidential computing unit, as well as keys for the confidential computing unit to encrypt the privacy data.
[0013] Furthermore, accessing the privacy data via the URL address specifically includes:
[0014] When a user needs to access the privacy data, authentication is performed with the user authentication and resource access control subsystem;
[0015] If authentication is successful, the privacy data can be accessed via the URL address.
[0016] Secondly, the present invention provides a method for protecting privacy data, applied to a privacy data navigation subsystem, the method comprising:
[0017] Receive a user identifier creation request sent by the user terminal system;
[0018] A user is created based on the user identifier creation request, and a confidential computing unit and corresponding storage space are created corresponding to the user identifier. The confidential computing unit is based on the Trusted Execution Environment (TEE) capability. The confidential computing unit is used to trigger the user terminal system to transmit the privacy data to the confidential computing unit when the user needs to upload privacy data, so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space. The user terminal system receives the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data and accesses the privacy data through the URL address.
[0019] Furthermore, the receipt of the user identifier creation request sent by the user terminal system specifically includes:
[0020] Receive a user identifier creation request sent by the user terminal system based on the address of the preset privacy data navigation subsystem.
[0021] Furthermore, the step of creating a user based on the user identifier specifically includes:
[0022] The user authentication and resource access control subsystem is requested to create the user based on the user identifier creation request.
[0023] Receive and store the user identifier and token sent by the user authentication and resource access control subsystem after the user is created;
[0024] The user identifier and token are sent to the user terminal system.
[0025] Furthermore, the creation of the confidential computing unit corresponding to the user identifier and the corresponding storage space specifically includes:
[0026] Request the creation of the confidential computing unit and its corresponding storage space from the confidential computing resource pool, so that the confidential computing resource pool can create the confidential computing unit and its corresponding storage space based on TEE capabilities.
[0027] Thirdly, the present invention provides a privacy data protection device, installed in a user terminal system, the device comprising:
[0028] A request sending module is created to send a user identifier creation request to the privacy data navigation subsystem, so that the privacy data navigation subsystem can create a user according to the user identifier creation request, and create a confidential computing unit and corresponding storage space for the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability;
[0029] The privacy data upload module is connected to the creation request sending module. When a user needs to upload privacy data, it transmits the privacy data to the confidential computing unit so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space.
[0030] An access address receiving module, connected to the privacy data uploading module, is used to receive an accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data.
[0031] A privacy data access module, connected to the access address receiving module, is used to access the privacy data via the URL address.
[0032] Fourthly, the present invention provides a privacy data protection device, disposed in a privacy data navigation subsystem, the device comprising:
[0033] Create a request receiving module to receive user identifier creation requests sent by the user terminal system;
[0034] A creation module, connected to the creation request receiving module, is used to create a user based on the user identifier creation request, and to create a confidential computing unit and corresponding storage space corresponding to the user identifier. The confidential computing unit is based on the Trusted Execution Environment (TEE) capability. The confidential computing unit is used to trigger the user terminal system to transmit the privacy data to the confidential computing unit when the user needs to upload privacy data, so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space. The user terminal system also receives the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data, and accesses the privacy data through the URL address.
[0035] Fifthly, the present invention provides a privacy data protection device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the privacy data protection method described in the first or second aspect above.
[0036] In a sixth aspect, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the privacy data protection method described in the first or second aspect above.
[0037] This invention provides a method, apparatus, and readable storage medium for protecting privacy data. First, a user identifier creation request is sent to a privacy data navigation subsystem, enabling the subsystem to create a user, a corresponding confidential computing unit, and a corresponding storage space based on the user identifier. The confidential computing unit is based on Trusted Execution Environment (TEE) capabilities. Then, when a user needs to upload privacy data, the privacy data is transmitted to the confidential computing unit, which encrypts the uploaded data and stores it in the storage space. Next, an accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data is received, and the privacy data is accessed through the URL address. This invention provides users with a private storage and operating environment, protecting user privacy data through the confidential computing unit, preventing data from leaving the domain, and thus avoiding arbitrary extraction of user privacy data by equipment manufacturers or service providers. It solves the problem that existing technologies lack solutions for preventing arbitrary extraction of user privacy data by equipment manufacturers or service providers. Attached Figure Description
[0038] Figure 1 This is a flowchart of a privacy data protection method according to Embodiment 1 of the present invention;
[0039] Figure 2This is a flowchart of a privacy data protection method according to Embodiment 2 of the present invention;
[0040] Figure 3 This is a schematic diagram of the structure of a privacy data protection device according to Embodiment 3 of the present invention;
[0041] Figure 4 This is a schematic diagram of the structure of a privacy data protection device according to Embodiment 4 of the present invention;
[0042] Figure 5 This is a schematic diagram of a privacy data protection device according to Embodiment 5 of the present invention. Detailed Implementation
[0043] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0044] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0045] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0046] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0047] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0048] It is understood that the terms "first," "second," etc., in the embodiments of the present invention are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.
[0049] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0050] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0051] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0052] Example 1:
[0053] This embodiment provides a method for protecting privacy data, applied to a user terminal system, such as... Figure 1 As shown, the method includes:
[0054] Step S101: Send a user identifier creation request to the privacy data navigation subsystem, so that the privacy data navigation subsystem can create a user according to the user identifier creation request, and create a confidential computing unit and corresponding storage space corresponding to the user identifier; the confidential computing unit is based on TEE (Trusted Execution Environment) capability.
[0055] It should be noted that this invention is intended for home users, whose privacy data can include video, audio, text, etc. User identification is based on the username on the user terminal or mobile app (i.e., the user terminal system), or can be a mobile phone number as a unified identifier, establishing the association and uniqueness between the user and the privacy data.
[0056] It should be noted that existing user applications require the uploading of a lot of user privacy-related data, such as data from home surveillance cameras, smart doorbells, and home appliance status information, all of which are uploaded to the cloud. To prevent user privacy data from being arbitrarily extracted by equipment manufacturers or service providers, this invention first sends a user identifier creation request to the privacy data navigation subsystem. The privacy data navigation subsystem then creates the user and the confidential computing unit and corresponding storage space corresponding to the user identifier, so as to provide users with a private storage and operating environment.
[0057] Optionally, sending a user identifier creation request to the privacy data navigation subsystem specifically includes:
[0058] A user identifier creation request is sent to the privacy data navigation subsystem based on the pre-set privacy data navigation subsystem address.
[0059] In this embodiment, the address of the privacy data navigation subsystem can be pre-set in the privacy configuration of the user terminal system, serving as the navigation entry point for users to upload and access their privacy data. Upon initial service deployment, the user terminal system registers a user. Based on the pre-set privacy data navigation subsystem address, the user terminal system sends a user identifier creation request consisting of the username and terminal (or terminal APP) characteristic values. The privacy data navigation subsystem then requests the user authentication and resource access control subsystem to create the user based on the received user identifier creation request. The privacy data navigation subsystem receives and stores the user identifier and token sent by the user authentication and resource access control subsystem after creating the user, and then sends the user identifier and token to the user terminal system.
[0060] In this embodiment, after a user is successfully created, the privacy data navigation subsystem requests the creation of a confidential computing unit and corresponding storage space from the confidential computing resource pool. This allows the confidential computing resource pool to create the confidential computing unit and corresponding storage space based on TEE capabilities. Specifically, the confidential computing resource pool can select to create a confidential computing unit for the user based on the user's location or resource distribution, and save the corresponding address and access method in the privacy data navigation subsystem, while also sending it to the corresponding user.
[0061] Step S102: When a user needs to upload private data, the private data is transmitted to the confidential computing unit so that the confidential computing unit encrypts the user-uploaded private data and stores it in the storage space.
[0062] In this embodiment, encryption is used during both transmission and storage to further protect the security of user privacy data.
[0063] Optionally, before transmitting the privacy data to the confidential computing unit when a user needs to upload privacy data, the method further includes:
[0064] Together with the confidential computing unit, it interacts with the key subsystem to collaboratively request encryption keys for network transmission between the user terminal system and the confidential computing unit, as well as keys for the confidential computing unit to encrypt the privacy data.
[0065] In this embodiment, for user privacy data to be uploaded, the user terminal system and the confidential computing unit need to interact with the key subsystem to collaboratively apply for a consistent key. Multiple keys may be required, such as the encryption key for network transmission between the user terminal system and the confidential computing unit, and the key used by the confidential computing unit to encrypt privacy data. The former key is the same key used by both the user terminal system and the confidential computing unit; for example, using the same symmetric key. For small amounts of text data, a symmetric key pair can also be used for encryption. The latter key is only used within the confidential computing unit to encrypt the user-uploaded privacy data and store it in storage space generated for the user. This latter key needs to be stored in the confidential computing unit. Simultaneously, the key subsystem also stores the user identifier and key, generates a key identifier, and returns it to the user's confidential computing unit. The key identifier corresponds to the privacy data stored in the resource pool to ensure data recovery in case of confidential computing unit failure.
[0066] Step S103: Receive the accessible URL (Uniform Resource Locator) address generated by the confidential computing unit based on the stored privacy data;
[0067] Step S104: Access the privacy data via the URL address.
[0068] In this embodiment, the confidential computing unit is also responsible for generating an accessible URL from the stored user privacy data, and providing service functions corresponding to the URL. The confidential computing unit returns the URL address of the user privacy data to the user terminal system.
[0069] Optionally, accessing the privacy data via the URL address specifically includes:
[0070] When a user needs to access the privacy data, authentication is performed with the user authentication and resource access control subsystem;
[0071] If authentication is successful, the privacy data can be accessed via the URL address.
[0072] In this embodiment, when a user accesses their own private data, they first authenticate with the user authentication and resource access control subsystem. After authentication, the user accesses their private data via a URL. When reading the private data, the confidential computing unit is responsible for decrypting it using a key previously stored in the unit. If the confidential computing unit has been reset, it can be retrieved from the key subsystem. After decryption, the user requests a transmission key from the key subsystem and sends it to the confidential computing unit, which uses this key to encrypt the transmitted data. After the data is transmitted to the user's terminal system, it is decrypted and read within the user's terminal system.
[0073] This invention provides neutral access to privacy data configuration through a privacy data navigation subsystem, pre-setting the address in the user terminal or terminal APP configuration, navigating the user into a privacy-protected environment, and creating confidential computing resources based on the user's privacy data parameters, and associating the user with the confidential computing resources, etc., so that the data does not leave the domain, thereby preventing the user's privacy data from being arbitrarily extracted by equipment manufacturers or service providers.
[0074] In one specific embodiment, the privacy data protection method is applied to a privacy data protection system, which includes a confidential computing resource pool, a key subsystem, a user authentication and resource access control subsystem, a privacy data navigation subsystem, and a user terminal system. The key subsystem and the user authentication and resource access control subsystem can be co-located with the privacy data navigation subsystem. The functions of each part are as follows:
[0075] (1) Confidential Computing Resource Pool: Based on TEE capabilities, it is used to construct confidential computing units, which can be a single or group of confidential virtual machines, or a group of confidential containers. Its main feature is to utilize TEE capabilities to create confidential computing capabilities for users. A certain capacity of storage can be mounted according to the type and size of the privacy data to store user privacy data.
[0076] (2) Key Subsystem: Distributes keys or key pairs according to user or resource usage needs.
[0077] (3) User authentication and resource access control subsystem: responsible for user authentication of the privacy data protection system and storing the URLs of corresponding privacy data resources.
[0078] (4) Privacy Data Navigation Subsystem: This subsystem is used to locate and allocate the address of the confidential computing resource pool. It issues instructions to configure the confidential computing resource pool based on the nearest or optimal principle, thereby generating the confidential computing unit corresponding to the user. The address of the privacy data navigation subsystem can be preset in the privacy configuration of the user terminal or terminal APP. It serves as the navigation entry point for users to upload and access their privacy data.
[0079] (5) User terminal system: refers to the system on the user terminal connected to the privacy data navigation subsystem, which may be the terminal APP system.
[0080] Based on the above system, the method for protecting this privacy data may include the following steps:
[0081] 1) When the service is initially launched, the user terminal or mobile APP (i.e., the user terminal system) will register a user. Based on the pre-set privacy data navigation subsystem address, the user terminal or mobile APP sends a user identifier creation request consisting of the username and terminal (or terminal APP) characteristic value. The privacy data navigation subsystem creates the user from the user authentication and resource access control subsystem based on the received user identifier. During user creation, secondary authentication, such as SMS verification codes, may be required. If the user authentication is successful, the user authentication and resource access control subsystem requests a token from the key subsystem (e.g., a numeric string with a certain expiration date). This token and the user identifier are then sent to the privacy data navigation subsystem, which forwards them to the user terminal or terminal APP. The privacy data navigation subsystem and the user terminal or terminal APP store the token and user identifier in their respective environments.
[0082] 2) After a user is successfully created, the privacy data navigation subsystem uses the user's identifier to request the creation of a confidential computing unit and corresponding storage space in the confidential computing resource pool. The created confidential computing unit has processing functions and computing power for the corresponding privacy data type, such as meeting the encryption algorithm and computing performance requirements for privacy videos. The confidential computing resource pool can select to create a confidential computing unit for the user based on the user's location or resource distribution, and save the corresponding address and access method in the privacy data navigation subsystem, while also sending it to the corresponding user.
[0083] 3) The above completes the privacy service initialization. During operation, user privacy data must be uploaded. The user and the confidential computing unit need to interact with the key subsystem to collaboratively apply for a consistent key. Multiple keys may be required, such as those for network transmission encryption protection between the user terminal or terminal app and the confidential computing unit, and keys used by the confidential computing unit to encrypt privacy data. The former key is the same key used by the user terminal or terminal app and the confidential computing unit. For example, using the same symmetric key, a symmetric key pair can be used to encrypt small amounts of text data. The latter key is only used within the confidential computing unit to encrypt the user-uploaded privacy data and store it in storage space generated for the user. This latter key needs to be stored in the confidential computing unit. Simultaneously, the key subsystem also stores the user identifier and key, generates a key identifier, and returns it to the user's confidential computing unit. The key identifier corresponds to the privacy data stored in the resource pool to ensure data recovery in case of confidential computing unit failure.
[0084] 4) The confidential computing unit is also responsible for generating accessible URLs from the stored user privacy data, and providing corresponding service functions for these URLs. The URLs of the user privacy data are returned to the user terminal or terminal app, and simultaneously synchronized to the user authentication and resource access control subsystem. The user authentication and resource access control subsystem stores user identifiers and a list of URLs, serving as a quick navigation tool for users to access their privacy data.
[0085] 5) Finally, when a user accesses their own private data, they first authenticate with the user authentication and resource access control subsystem, following the same authentication process as before. After authentication, the user accesses their private data via a URL. When reading the private data, the confidential computing unit is responsible for decrypting it using a key previously stored within the unit. If the confidential computing unit has been reset, it can be retrieved from the key subsystem. After decryption, the user requests a transmission key from the key subsystem and simultaneously sends it to the confidential computing unit, which uses this key to encrypt the transmission network. Once the data is transmitted to the user's terminal or mobile app, it is decrypted and read from the user's terminal or mobile app.
[0086] 6) If other organizations or individuals need to access the user's privacy data, the user needs to authenticate with the user authentication and resource access control subsystem. After authentication, the user needs to authorize other organizations or individuals. The authorized other organizations or individuals hold the user's temporary identity, which is the same as the access method in the previous step. The temporary identity has a short validity period.
[0087] This system forms a neutral system for storing user privacy data, ensuring that no other organization or individual can access this data without the user's explicit authorization. The administrator of the confidential computing resource pool also has no right to read user data, thus effectively protecting user privacy.
[0088] The privacy data protection method provided in this invention first sends a user identifier creation request to a privacy data navigation subsystem, enabling the subsystem to create a user, a confidential computing unit corresponding to the user identifier, and a corresponding storage space. The confidential computing unit is based on a Trusted Execution Environment (TEE) capability. Then, when a user needs to upload privacy data, the user transmits the privacy data to the confidential computing unit, which encrypts the uploaded data and stores it in the storage space. Next, the user receives an accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data and accesses the privacy data through the URL address. This invention provides users with a private storage and operating environment, protecting user privacy data through a confidential computing unit, preventing data from leaving the domain, and thus avoiding arbitrary extraction of user privacy data by equipment manufacturers or service providers. It solves the problem that existing technologies lack solutions for preventing arbitrary extraction of user privacy data by equipment manufacturers or service providers.
[0089] Example 2:
[0090] like Figure 2 As shown, this embodiment provides a method for protecting privacy data, applied to a privacy data navigation subsystem, the method comprising:
[0091] Step S201: Receive a user identifier creation request sent by the user terminal system;
[0092] Step S202: Create a user based on the user identifier creation request, and create a confidential computing unit and corresponding storage space corresponding to the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability, and is used to trigger the user terminal system to transmit the privacy data to the confidential computing unit when the user needs to upload privacy data, so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space, and enables the user terminal system to receive the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data, and access the privacy data through the URL address.
[0093] Optionally, receiving the user identifier creation request sent by the user terminal system specifically includes:
[0094] Receive a user identifier creation request sent by the user terminal system based on the address of the preset privacy data navigation subsystem.
[0095] Optionally, creating a user based on the user identifier creation request specifically includes:
[0096] The user authentication and resource access control subsystem is requested to create the user based on the user identifier creation request.
[0097] Receive and store the user identifier and token sent by the user authentication and resource access control subsystem after the user is created;
[0098] The user identifier and token are sent to the user terminal system.
[0099] Optionally, the creation of the confidential computing unit corresponding to the user identifier and the corresponding storage space specifically includes:
[0100] Request the creation of the confidential computing unit and its corresponding storage space from the confidential computing resource pool, so that the confidential computing resource pool can create the confidential computing unit and its corresponding storage space based on TEE capabilities.
[0101] Example 3:
[0102] like Figure 3 As shown, this embodiment provides a privacy data protection device, installed in a user terminal system, for executing the privacy data protection method in Embodiment 1 above. The device includes:
[0103] The request sending module 11 is used to send a user identifier creation request to the privacy data navigation subsystem, so that the privacy data navigation subsystem can create a user according to the user identifier creation request, and create a confidential computing unit and corresponding storage space corresponding to the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability;
[0104] The privacy data upload module 12 is connected to the creation request sending module 11 and is used to transmit the privacy data to the confidential computing unit when the user needs to upload privacy data, so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space.
[0105] Access address receiving module 13, connected to the privacy data uploading module 12, is used to receive the accessible Uniform Resource Locator URL address generated by the confidential computing unit based on the stored privacy data;
[0106] The privacy data access module 14 is connected to the access address receiving module 13 and is used to access the privacy data through the URL address.
[0107] Optionally, the creation request sending module 11 is specifically used for:
[0108] A user identifier creation request is sent to the privacy data navigation subsystem based on the pre-set privacy data navigation subsystem address.
[0109] Optionally, the device further includes:
[0110] The encryption key acquisition module is used to interact with the key subsystem together with the confidential computing unit to collaboratively apply for the encryption key for network transmission between the user terminal system and the confidential computing unit, as well as the key for the confidential computing unit to encrypt the privacy data.
[0111] Optionally, the privacy data access module 14 includes:
[0112] The authentication unit is used to authenticate the user authentication and resource access control subsystem when the user needs to access the privacy data.
[0113] An access unit is used to access the privacy data via the URL address if authentication is successful.
[0114] Example 4:
[0115] like Figure 4 As shown, this embodiment provides a privacy data protection device, which is set in the privacy data navigation subsystem and is used to execute the privacy data protection method in Embodiment 2 above. The device includes:
[0116] Create a request receiving module 21, which is used to receive a user identifier creation request sent by the user terminal system;
[0117] The creation module 22, connected to the creation request receiving module 21, is used to create a user based on the user identifier creation request, and to create a confidential computing unit and corresponding storage space corresponding to the user identifier. The confidential computing unit is based on the Trusted Execution Environment (TEE) capability. The confidential computing unit is used to trigger the user terminal system to transmit the privacy data to the confidential computing unit when the user needs to upload privacy data, so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space. The user terminal system also receives the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data, and accesses the privacy data through the URL address.
[0118] Optionally, the creation request receiving module 21 is specifically used for:
[0119] Receive a user identifier creation request sent by the user terminal system based on the address of the preset privacy data navigation subsystem.
[0120] Optionally, the creation module 22 includes:
[0121] The first request unit is configured to request the creation of the user from the user authentication and resource access control subsystem based on the user identifier;
[0122] A receiving and storage unit is used to receive and store the user identifier and token sent by the user authentication and resource access control subsystem after the user is created;
[0123] A sending unit is used to send the user identifier and token to the user terminal system.
[0124] Optionally, the creation module 22 further includes:
[0125] The second request unit is used to request the creation of the confidential computing unit and the corresponding storage space from the confidential computing resource pool, so that the confidential computing resource pool can create the confidential computing unit and the corresponding storage space based on the TEE capability.
[0126] Example 5:
[0127] refer to Figure 5 This embodiment provides a privacy data protection device, including a memory 31 and a processor 32. The memory 31 stores a computer program, and the processor 32 is configured to run the computer program to execute the privacy data protection method in Embodiment 1 or Embodiment 2.
[0128] The memory 31 is connected to the processor 32. The memory 31 can be a flash memory, a read-only memory or other memory, and the processor 32 can be a central processing unit or a microcontroller.
[0129] Example 6:
[0130] This embodiment provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the privacy data protection method described in Embodiment 1 or Embodiment 2 above.
[0131] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0132] In summary, the privacy data protection method, apparatus, and readable storage medium provided in this invention first send a user identifier creation request to a privacy data navigation subsystem, enabling the subsystem to create a user, a confidential computing unit corresponding to the user identifier, and a corresponding storage space. The confidential computing unit is based on a Trusted Execution Environment (TEE) capability. Then, when a user needs to upload privacy data, the user transmits the privacy data to the confidential computing unit, which encrypts the uploaded data and stores it in the storage space. Next, the user receives an accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data and accesses the privacy data through the URL address. This invention provides users with a private storage and operating environment, protecting user privacy data through a confidential computing unit, preventing data from leaving the domain, and thus avoiding arbitrary extraction of user privacy data by equipment manufacturers or service providers. It solves the problem that existing technologies lack solutions for preventing arbitrary extraction of user privacy data by equipment manufacturers or service providers.
[0133] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A method for protecting privacy data, characterized in that, Applied to a user terminal system, the method includes: A user identifier creation request is sent to the privacy data navigation subsystem, so that the privacy data navigation subsystem creates a user according to the user identifier creation request, and creates a confidential computing unit and corresponding storage space corresponding to the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability; When a user needs to upload private data, the private data is transmitted to the confidential computing unit so that the confidential computing unit encrypts the user-uploaded private data and stores it in the storage space. Receive the accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data; Access the privacy data via the URL address.
2. The method according to claim 1, characterized in that, Sending the user identifier creation request to the privacy data navigation subsystem specifically includes: A user identifier creation request is sent to the privacy data navigation subsystem based on the pre-set privacy data navigation subsystem address.
3. The method according to claim 1, characterized in that, Before transmitting the privacy data to the confidential computing unit when a user needs to upload privacy data, the method further includes: Together with the confidential computing unit, it interacts with the key subsystem to collaboratively request encryption keys for network transmission between the user terminal system and the confidential computing unit, as well as keys for the confidential computing unit to encrypt the privacy data.
4. The method according to claim 2, characterized in that, Accessing the privacy data via the URL address specifically includes: When a user needs to access the privacy data, authentication is performed with the user authentication and resource access control subsystem; If authentication is successful, the privacy data can be accessed via the URL address.
5. A method for protecting privacy data, characterized in that, The method, applied to a privacy data navigation subsystem, includes: Receive a user identifier creation request sent by the user terminal system; A user is created based on the user identifier creation request, and a confidential computing unit and corresponding storage space are created corresponding to the user identifier. The confidential computing unit is based on the Trusted Execution Environment (TEE) capability. The confidential computing unit is used to receive the privacy data transmitted by the user terminal system when the user needs to upload privacy data, encrypt the privacy data, store it in the storage space, generate an accessible Uniform Resource Locator (URL) address based on the stored privacy data, and send the URL address to the user terminal system so that the user terminal system can access the privacy data through the URL address.
6. The method according to claim 5, characterized in that, The process of receiving a user identifier creation request sent by the user terminal system specifically includes: Receive a user identifier creation request sent by the user terminal system based on the address of the preset privacy data navigation subsystem.
7. The method according to claim 5, characterized in that, The step of creating a user based on the user identifier creation request specifically includes: The user authentication and resource access control subsystem is requested to create the user based on the user identifier creation request. Receive and store the user identifier and token sent by the user authentication and resource access control subsystem after the user is created; The user identifier and token are sent to the user terminal system.
8. The method according to claim 6, characterized in that, The creation of the confidential computing unit corresponding to the user identifier and the corresponding storage space specifically includes: Request the creation of the confidential computing unit and its corresponding storage space from the confidential computing resource pool, so that the confidential computing resource pool can create the confidential computing unit and its corresponding storage space based on TEE capabilities.
9. A privacy data protection device, characterized in that, The device, configured in a user terminal system, includes: A request sending module is created to send a user identifier creation request to the privacy data navigation subsystem, so that the privacy data navigation subsystem can create a user according to the user identifier creation request, and create a confidential computing unit and corresponding storage space for the user identifier; the confidential computing unit is based on the Trusted Execution Environment (TEE) capability; The privacy data upload module is connected to the creation request sending module. When a user needs to upload privacy data, it transmits the privacy data to the confidential computing unit so that the confidential computing unit encrypts the privacy data uploaded by the user and stores it in the storage space. An access address receiving module, connected to the privacy data uploading module, is used to receive an accessible Uniform Resource Locator (URL) address generated by the confidential computing unit based on the stored privacy data. A privacy data access module, connected to the access address receiving module, is used to access the privacy data via the URL address.
10. A privacy data protection device, characterized in that, The device, located in the privacy data navigation subsystem, includes: Create a request receiving module to receive user identifier creation requests sent by the user terminal system; A creation module, connected to the creation request receiving module, is used to create a user based on the user identifier creation request, and to create a confidential computing unit and corresponding storage space corresponding to the user identifier. The confidential computing unit is based on the Trusted Execution Environment (TEE) capability. The confidential computing unit is used to receive the privacy data transmitted by the user terminal system when the user needs to upload privacy data, encrypt the privacy data, store it in the storage space, generate an accessible Uniform Resource Locator (URL) address based on the stored privacy data, and send the URL address to the user terminal system so that the user terminal system can access the privacy data through the URL address.
11. A privacy data protection device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the privacy data protection method as described in any one of claims 1-4, or to implement the privacy data protection method as described in any one of claims 5-8.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the privacy data protection method as described in any one of claims 1-4, or implements the privacy data protection method as described in any one of claims 5-8.
Citation Information
Patent Citations
Video file enciphering / deciphering system and method
CN101296349A
System and method for data privacy and authentication
US11343080B1