A data transmission method and device, electronic equipment and storage medium

By deploying data transmission methods in the cloud system and employing transparent encryption and zero-trust authentication, the problem of insufficient security in enterprise data transmission is solved, enabling efficient, secure data transmission and flexible processing.

CN118250081BActive Publication Date: 2026-04-24PARK DO CREDIT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PARK DO CREDIT CO LTD
Filing Date
2024-04-18
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In existing technologies, the lack of effective encryption detection and control during the transmission of enterprise data increases the risk of data leakage, and the reliance on the security capabilities of email service providers is insufficient.

Method used

Deploy data transmission methods in cloud systems, employing transparent encryption, zero-trust authentication, and DLP authentication to ensure data security during reception, processing, and transmission by receiving, encrypting, decrypting, and sending data.

Benefits of technology

It improves the security and ease of operation of data transmission, reduces the risk of data leakage, enhances the flexibility and reliability of data processing, supports multiple operation modes, and detects and blocks potential security risks in real time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118250081B_ABST
    Figure CN118250081B_ABST
Patent Text Reader

Abstract

The application provides a data transmission method and device, electronic equipment and storage medium, which are applied to a cloud system. The method comprises the following steps: in response to a transmission request of first data, the first data is received, wherein the cloud system is deployed in a local area network; in response to the received first data, the first data is encrypted to obtain second data; in response to a data sending request, the second data is decrypted, and third data is generated based on the decrypted second data; and the third data is sent to a transmission target. The application can improve the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a data transmission method, apparatus, electronic device and storage medium. Background Technology

[0002] With the rapid development and widespread application of information technology, enterprises are facing increasing challenges in data security and privacy protection. How to effectively prevent data breaches and protect core corporate information assets has become an urgent problem to be solved in the field of information security.

[0003] Currently, there are no technical means to detect and control the encrypted data (sensitive personal information) that customers are required to send. Therefore, there is a possibility that unencrypted sensitive data may appear in email accounts. Once email login credentials are illegally obtained, data security will be compromised. Furthermore, data security also depends on the security capabilities of the email service providers of both the sender and recipient. Summary of the Invention

[0004] In view of this, embodiments of this application provide a data transmission method, apparatus, electronic device, and storage medium that can improve the security of data transmission.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a data transmission method, comprising the following steps:

[0007] Responding to the transmission request of the first data, the system receives the first data, wherein the cloud system is deployed on a local area network;

[0008] Upon receiving the first data, the response encrypts the first data to obtain the second data.

[0009] In response to a data outgoing request, the system decrypts the second data, generates third data based on the decrypted second data, and sends the third data to the transmission target.

[0010] Secondly, embodiments of this application also provide a data transmission apparatus, the apparatus comprising:

[0011] A receiving module is used to respond to a transmission request for first data and receive the first data, wherein the cloud system is deployed on a local area network;

[0012] The processing module is used to respond to the receipt of the first data, encrypt the first data, and obtain the second data;

[0013] The sending module is used to respond to a data outgoing request, decrypt the second data, generate third data based on the decrypted second data, and send the third data to the transmission target.

[0014] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a storage medium, and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the machine-readable instructions to perform the data transmission method described in any of the first aspects.

[0015] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the data transmission method described in any of the first aspects.

[0016] The embodiments of this application have the following beneficial effects:

[0017] (1) In the data receiving stage, the system employs a strict security verification mechanism to ensure that only authorized and verified users or systems can receive data. This effectively prevents the risks of unauthorized access and data leakage. For received data, the system can automatically detect its encryption status and transparently decrypt it. Users do not need to manually perform decryption operations, improving the convenience and efficiency of the operation. The system can automatically record the data reception time and access status, providing basic data support for subsequent data processing and management.

[0018] (2) In the data processing stage, the system employs transparent encryption technology to encrypt sensitive data, ensuring its confidentiality and integrity during processing. Even if data is illegally obtained, it cannot be easily decrypted and accessed. The data processing process supports various operations, such as generating target external links and compressed packages, to adapt to different sending needs. Simultaneously, the system can adjust security policies as needed to ensure the flexibility and scalability of data processing. DLP-based data verification processing can detect security risks in real time during data processing, such as data leakage and misoperation, and take timely blocking measures to prevent potential risks from occurring.

[0019] (3) During the data transmission process, the system employs zero-trust verification and external link validity restrictions to ensure that only verified legitimate users can access the transmitted data. This significantly reduces the risk of data being illegally intercepted or misused during transmission. The system can generate target external links or compressed packages based on different transmission needs and quickly send them to target users via email or other means. This improves the efficiency and convenience of data transmission. The system records information such as the data transmission time and recipient, facilitating data tracking and tracing. In the event of data leakage or misuse, the problem can be quickly located and appropriate measures taken.

[0020] In summary, considering the three stages of data reception, processing, and transmission, implementing the described method can bring about multiple beneficial effects, including improved data security, enhanced operational convenience, increased processing flexibility, and optimized transmission efficiency. This helps enterprises manage and protect data more efficiently in the cloud environment, reduce security risks, and improve the reliability and stability of overall business operations. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart illustrating steps S101-S103 provided in the embodiments of this application;

[0023] Figure 2 This is a flowchart illustrating steps S201-S202 provided in the embodiments of this application;

[0024] Figure 3 This is a flowchart illustrating steps S301-S302 provided in the embodiments of this application;

[0025] Figure 4 This is one of the principle block diagrams provided in the embodiments of this application;

[0026] Figure 5 This is the second principle block diagram provided in the embodiments of this application;

[0027] Figure 6 This is a schematic diagram of the structure of the data transmission device provided in the embodiments of this application;

[0028] Figure 7 This is a schematic diagram of the composition structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0030] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0031] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0032] In the following description, the terms "first, second, third" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0033] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0034] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application and is not intended to limit the scope of this application.

[0035] See Figure 1 , Figure 1This is a flowchart illustrating steps S101-S103 of the data transmission method provided in this application embodiment, which will be combined with... Figure 1 Steps S101-S103 shown will be explained.

[0036] Step S101: Respond to the transmission request of the first data and receive the first data, wherein the cloud system is deployed on a local area network;

[0037] Step S102: Upon receiving the first data, encrypt the first data to obtain the second data;

[0038] Step S103: Respond to the data outgoing request, decrypt the second data, generate third data based on the decrypted second data, and send the third data to the transmission target.

[0039] The exemplary steps described above in the embodiments of this application will be explained below.

[0040] In step S101, in response to the transmission request of the first data, the first data is received, wherein the cloud system is deployed in a local area network.

[0041] Here, when the cloud system receives the first data transmission request, it responds quickly and receives the data. This step ensures that the data can be successfully captured by the cloud system, laying the foundation for subsequent processing.

[0042] In step S102, upon receiving the first data, the response encrypts the first data to obtain the second data.

[0043] Next, the cloud system encrypts the received initial data. Encryption enhances data security, preventing unauthorized access or alteration during transmission or storage. The encrypted data, known as secondary data, offers even greater confidentiality compared to the original data.

[0044] In step S103, in response to the data outgoing request, the second data is decrypted, and third data is generated based on the decrypted second data, and the third data is sent to the transmission target.

[0045] Subsequently, when the cloud system receives a data outbound request, it initiates a decryption process. The purpose of this step is to restore the encrypted second data to readable original data for subsequent processing or transmission. After decryption, the cloud system generates third data based on the decrypted data. This step may involve data format conversion, content filtering, or other processing to adapt to different transmission requirements or the requirements of the target system.

[0046] Finally, the cloud system sends third-party data to the designated transmission target. This ensures that the data is accurately delivered to its destination and meets the user's transmission needs. Throughout the process, the cloud system ensures data security and integrity through encryption and decryption. Simultaneously, generating third-party data based on the decrypted data makes data transmission more flexible and controllable. This method has broad application prospects in cloud systems, especially in scenarios requiring guaranteed data security and privacy, such as finance and healthcare.

[0047] In some embodiments, the cloud system includes a file transfer system that, in response to a transmission request for first data, receives the first data, including:

[0048] In response to the transmission side's request to send the first data, the transmission side receives the first data through the file transfer system. The first data can be sent via external link, email, SFTP, or target storage medium. When the first data is sent via external link, the transmission side accesses the local area network based on zero-trust authentication before sending the first data. Zero-trust authentication means that authentication is required each time.

[0049] Here, when the transmission side (such as a user or external system) needs to send the first piece of data, it initiates a send request. The cloud system responds to this request and receives the first piece of data through the file transfer system. The file transfer system acts as a bridge here, ensuring that data can be securely and efficiently transferred from the transmission side to the cloud system.

[0050] It is worth noting that the first data can be sent in various ways, including external links, email, SFTP (Secure File Transfer Protocol), and target storage media. This flexibility allows users to choose the most suitable transmission method based on their actual needs.

[0051] Specifically, when the initial data is sent via an external link, the transmission side needs to access the local area network (LAN) based on zero-trust authentication before sending the data. Zero-trust authentication is a security strategy that emphasizes the principle of "never trust, always verify," meaning that authentication and authorization checks are required for every access. This authentication method significantly improves system security, ensuring that only authorized users or systems can access the LAN and transmit data.

[0052] In this way, the cloud system can effectively receive initial data from different sources and in different formats, and process it through a file transfer system. This not only improves the efficiency and security of data transmission, but also provides a reliable data foundation for subsequent data processing and analysis.

[0053] In some embodiments, the cloud system includes a file transfer system that, in response to a transmission request for first data, receives the first data, including:

[0054] In response to the transmission side's request to send the first data, the transmission side receives the first data through the file transfer system. The first data can be sent via external link, email, SFTP, or target storage medium. When the first data is sent via external link, the transmission side accesses the local area network based on zero-trust authentication before sending the first data. Zero-trust authentication means that authentication is required each time.

[0055] The cloud system includes a file transfer system for receiving and transmitting data. First, the transmitting side needs to issue a send request for initial data. This request may be initiated by a user or other system, with the aim of transferring the initial data from the transmitting side to the cloud system. Once the send request is triggered, the file transfer system intervenes. Its main task is to receive the initial data from the transmitting side. This reception process ensures that the data arrives at the cloud system securely and accurately. The initial data can be sent in various ways, including external links, email, SFTP (Secure File Transfer Protocol), and target storage media. These different sending methods provide flexibility, allowing the selection of the appropriate method based on specific needs and environmental conditions. Specifically, when choosing an external link as the sending method, the transmitting side must access the local area network based on zero-trust authentication before sending the initial data. This means that authentication is required before each data transmission to ensure the sender's identity and permissions are legitimate. This zero-trust authentication method enhances system security and reduces potential security risks.

[0056] The above method provides an efficient and secure data transfer mechanism through the file transfer system. Whether data is sent via external links, email, SFTP, or the target storage medium, the system ensures data integrity and security. In particular, the introduction of zero-trust authentication further enhances the system's security capabilities when sending data via external links.

[0057] In some embodiments, after receiving the first data but before encrypting the first data, the method further includes:

[0058] If the first data is sent via email, an email password is generated based on at least two cloud system users, wherein the email password is used to retrieve the first data in the email, and each of the at least two cloud system users holds a sub-password;

[0059] If the first data is sent via SFTP, each of at least two cloud system users receives the SFTP password sent in segments by the sender, wherein each system user's subsystem has an SFTP client installed and a password bound to it.

[0060] If the first data is sent via the target storage medium, the decompression password is received by at least two cloud system users respectively, and decompression is performed in the subsystem of any of the at least two cloud system users.

[0061] Here, when the first data is sent via email:

[0062] (1) Generate email password: If the initial data is sent via email, the system needs to generate an email password based on at least two cloud system users. The purpose of this email password is to allow cloud system users to access the email and retrieve the initial data from it.

[0063] (2) Password Distribution and Holding: The generated email password is split into multiple sub-passwords, each held by one of at least two cloud system users. This design increases security because the complete email password can only be obtained and emails accessed when all users holding sub-passwords cooperate.

[0064] When the first data is sent using SFTP:

[0065] (1) Segmented transmission of SFTP password: If the first data is sent via SFTP, then each of at least two cloud system users needs to receive the SFTP password sent in segments by the sender. This means that the SFTP password is divided into multiple parts, and each part is sent to a different cloud system user.

[0066] (2) SFTP client and password binding: An SFTP client is installed in each user's subsystem and a password is bound to it. This ensures that only users with the appropriate permissions and the correct password can access and receive data through the SFTP client.

[0067] When the first data is sent via the target storage medium:

[0068] (1) Receiving the decompression password: If the first data is sent via the target storage medium (e.g., via a USB drive or external hard drive), then at least two cloud system users need to receive the decompression password separately. This decompression password is used to unlock or decompress the data on the storage medium.

[0069] (2) Decompression within the subsystem: Upon receiving the decompression password, any one of at least two cloud system users can perform the decompression operation within their subsystem to access the primary data. This design ensures data integrity and security because even if one user cannot participate, other users can still collaborate to complete the decompression process.

[0070] The above methods not only enhance the security of data transmission but also improve the reliability and robustness of the system through multi-user collaboration. By ensuring that each critical step requires the participation and verification of multiple users, the system can more effectively prevent unauthorized access and data leakage.

[0071] In some embodiments, in the cloud system, the following operations are prohibited on the first data:

[0072] Export the first data, download the first data, copy the first data, and print the first data.

[0073] To ensure the security and confidentiality of the primary data, the following restrictions need to be placed on operations on the primary data:

[0074] (1) Exporting primary data is prohibited: This means that users cannot export primary data from the cloud system to external devices or systems. This prevents data leakage and unauthorized sharing.

[0075] (2) Prohibit downloading initial data: Similar to exporting, downloading is also a process of transferring data from the cloud system to the user's local device. Prohibiting downloading ensures that data always remains in a controlled cloud environment, thereby reducing the risk of data leakage.

[0076] (3) Prohibit copying of primary data: Copying operations may increase the risk of data leakage because copied data may be misused or improperly disseminated. Therefore, prohibiting copying is an important measure to protect the security of primary data.

[0077] (4) Prohibit printing the first data: Printing may result in data existing in physical form, which increases the possibility of data being improperly obtained or misused. Therefore, prohibiting printing is also a necessary step to ensure data security.

[0078] These prohibited actions ensure the security and controllability of primary data within the cloud system. They reduce the risk of data leakage, misuse, and unauthorized access, thereby protecting data integrity and confidentiality. At the same time, these regulations also remind users and administrators to always pay attention to data security issues and take necessary measures to prevent potential security threats.

[0079] In some embodiments, the cloud system includes at least one subsystem, each subsystem corresponding to a cloud system user; the method further includes:

[0080] In response to a user's request to process the second data, the second data is stored in a designated location within the cloud system, and writing of the second data is prohibited in any other location within the cloud system besides the designated location.

[0081] Here, when a cloud system user requests the processing of secondary data, the system responds to the request according to preset rules and procedures. Specifically, the secondary data is stored in a designated location within the cloud system. This designated location may be determined based on various factors, such as user permissions, the nature of the data, and security policies.

[0082] Meanwhile, to ensure data security and ease of management, no secondary data writing is permitted in any location outside of designated areas within the cloud system. This design prevents data from being accidentally or maliciously placed in inappropriate locations, thereby reducing the risk of data leakage or tampering. This approach not only ensures the orderly storage of data within the cloud system but also enhances data security by restricting write locations. Furthermore, since each subsystem corresponds to a cloud system user, this provides a clear division of permissions and accountability for data access and management.

[0083] The above method, by specifying the data storage location and restricting write permissions, achieves effective control and security protection of the processing of secondary data in the cloud system.

[0084] In some embodiments, encrypting the first data includes:

[0085] The first data is encrypted using transparent encryption, so that when the first data is opened, the unencrypted first data is automatically encrypted, and the encrypted second data is automatically decrypted.

[0086] Here, transparent encryption technology is used to encrypt the first piece of data. Specifically, when a user opens the first piece of data in the cloud system, the transparent encryption technology automatically detects the encryption status of the data. If the data is unencrypted, the system will automatically encrypt it to ensure data confidentiality. When the user needs to read or use the encrypted second piece of data, the transparent encryption technology will automatically decrypt it in the background, allowing the user to seamlessly access and use the data without manual decryption.

[0087] The aforementioned transparent encryption method not only enhances data security but also significantly improves the user experience. Users don't need to worry about data encryption and decryption, allowing them to focus on data processing and usage. Furthermore, since the encryption and decryption processes are completed automatically in the background, they do not interfere with or delay user operations.

[0088] In some embodiments, see Figure 2 , Figure 2 This is a flowchart illustrating steps S201-S202 provided in the embodiments of this application. The steps of decrypting the second data, generating third data based on the decrypted second data, and sending the third data to the transmission target can be implemented through steps S201-S202, which will be explained in conjunction with each step.

[0089] In step S201, in response to the decryption request, the decryption request is approved, and the second data is decrypted after the approval is granted.

[0090] In step S202, a target external link is generated based on the decrypted second data, and the target external link is sent to the transmission target; wherein, the target external link is allowed to be accessed after the transmission target passes zero-trust verification and accesses the local area network, and the target external link is valid within the validity period; or, a target compressed package is generated based on the decrypted second data, and the compressed package is sent to the transmission target via a target email; wherein, the target email contains a password for decompression.

[0091] In conjunction with steps S201-S202, when the system receives a decryption request for the second data, it needs to go through an approval process. This approval process includes multiple steps, such as verifying the requester's identity and confirming the rationality and necessity of the request. Only after the approval is passed will the second data be decrypted.

[0092] Once the decryption request is approved, the system will decrypt the second data. The decryption process uses secure algorithms and keys to ensure the integrity and confidentiality of the data.

[0093] After decryption, the system will generate a target external link based on the decrypted data. This external link is specifically created for the transmission target and is used to access the decrypted data.

[0094] The target external link can only be accessed after the target device has passed zero-trust authentication and connected to the local area network. This zero-trust authentication ensures that only verified legitimate users can access the data. In addition, the target external link has an expiration period; the link will become invalid after the expiration period, which further enhances data security.

[0095] As another method of transmission, the system can also generate a target compressed package based on the decrypted second data. The compressed package can effectively reduce data size, facilitating transmission and storage.

[0096] The target compressed file is sent to the recipient via a targeted email. This email contains a password for decompression, which the recipient must use to decompress the file upon receiving the email. This method ensures that only the recipient who knows the password can access the data, increasing data security.

[0097] The above method securely and efficiently sends decrypted data to the target, while ensuring the confidentiality and integrity of the data during transmission. Whether sent via external link or email, the system employs multiple security measures to prevent data leakage and unauthorized access.

[0098] In some embodiments, see Figure 3 , Figure 3 This is a flowchart illustrating steps S301-S302 provided in the embodiments of this application. The method further includes steps S301-S302, which will be explained in conjunction with each step.

[0099] In step S301, the third data is verified based on DLP.

[0100] In step S302, if the third data does not conform to the preset security policy, the transmission of the third data is blocked.

[0101] In conjunction with steps S301-S302, this embodiment of the application employs Data Leakage Prevention (DLP) to verify third-party data. The preset security policy may include a series of rules and standards used to determine whether data contains sensitive information, meets specific format requirements, and can be accessed by a specific user or system.

[0102] When third-party data undergoes DLP verification, if the system finds that the data does not comply with the preset security policy, it will immediately block the transmission of the third-party data. This step is crucial because it prevents potential data leakage risks and ensures that sensitive data is not sent to unauthorized targets or spread in insecure environments.

[0103] By combining DLP authentication and transmission blocking mechanisms, this method provides additional security for data transmission. It not only protects the confidentiality and integrity of data but also prevents misuse or leakage of data if it does not comply with security policies. This is crucial for protecting critical enterprise information and user privacy, and helps improve the overall security of the system.

[0104] In some embodiments, the method further includes:

[0105] If the first data is not accessed within a preset time, the first data is deleted.

[0106] Here, the system automatically deletes the first piece of data if it has not been accessed within a preset time. Specifically, the preset time is a period that can be set according to actual needs; it is used to determine whether the first piece of data has not been used for an extended period. If the first piece of data is not accessed or manipulated by any cloud system user within this time period, the system will consider this data to be redundant or no longer needed.

[0107] In this scenario, the system will automatically delete the first data that hasn't been accessed for a long time. This helps free up storage space, optimize system performance, and reduce unnecessary data accumulation. It also reduces security risks associated with excessive data, such as data leaks or misuse. It's important to note that the system may perform additional verification steps before deleting data to ensure that important data is not mistakenly deleted. For example, the system may check if the data is backed up or associated with other data to ensure that the deletion operation will not affect the normal operation of the system or the integrity of other data.

[0108] By automatically deleting data that has not been accessed for a long time, the above method can more effectively manage data in the cloud system and improve system security and performance.

[0109] Please see Figure 4 , Figure 4 This is one of the principle block diagrams provided in the embodiments of this application, which will be combined with Figure 4 The embodiments of this application will be described in full.

[0110] like Figure 4 As shown, the embodiments of this application achieve data transmission through at least one of the following means:

[0111] 1. Receive test sample data sent by customers within the cloud desktop; exporting, downloading, copying, and printing are prohibited.

[0112] 2. If the client has no special requirements, we recommend using the file transfer system's external cloud drive link function to upload files. Clients need to access the external cloud drive link after connecting to the intranet through a zero-trust system. To facilitate user access, the zero-trust system supports B / S mode access and allows for two-factor authentication via SMS. Our staff will send the external link URL via online channels and the password via SMS to the client. These external links can be set to have an expiration date, typically one day. Our staff will then log in to the file transfer system within the cloud desktop to download the files uploaded by the client.

[0113] 3. If received via email, the email password is generated back-to-back by two or more people, and the email password is only bound to the cloud desktop used by the relevant personnel.

[0114] 4. If receiving via SFTP, two or more relevant employees receive the SFTP password sent by the client in segments back-to-back. The SFTP client is only installed on the cloud desktop used by the relevant personnel and the password is bound.

[0115] 5. If the file is received via a mobile medium, and two or more employees receive the file decompression password back-to-back, the file will only be decompressed on the cloud desktop used by the relevant personnel.

[0116] 6. Non-administrator accounts assigned to employees as cloud desktops can only store files in designated directories within the cloud desktop; writing to other directories is prohibited.

[0117] 7. Files accessed on the cloud desktop are automatically encrypted using a transparent document encryption / decryption tool. They are automatically decrypted when viewed within the cloud desktop environment, but require approval for decryption when leaving the cloud desktop environment.

[0118] 8. When manually sending to the data source, first apply for file decryption, then log in to the file transfer system, upload the file, generate an external link, send the URL via network channels, and send the password via SMS to the customer. The validity period of this type of external link is generally 1 day. The customer can only access the cloud drive external link after accessing the intranet through the zero-trust system.

[0119] 9. When sending files using the test platform, the uploaded files will be automatically decrypted. The test platform connects to a file transfer system to generate external links. Files sent via email should be sent as a password-protected compressed file.

[0120] 10. Use DLP to block the outgoing email of compressed files without passwords;

[0121] 11. Set up a batch processing scheduled task to automatically delete files that have not been accessed for more than one week.

[0122] Please see Figure 5 , Figure 5 This is the second principle block diagram provided in the embodiments of this application, in the implementation Figure 4 Prior to the data transmission method shown, the following can also be implemented in a transitional form:

[0123] like Figure 5 As shown, as a temporary solution, with Figure 4 The difference is:

[0124] The main differences from the above embodiments are as follows:

[0125] 1. Allowing partners to access external links via the Internet requires exposing the access interface on the public Internet, which puts some pressure on network security. After the zero-trust system is launched, the network security interface will be: (Partner -- IPS -- WAF -- F5 -- Reverse Proxy -- File Transfer System External Machine; Operations Personnel -- Cloud Desktop -- File Transfer System Internal Machine).

[0126] 2. Files accessed on the cloud desktop or contract files created by business personnel on their office terminals will not be automatically encrypted; they will remain in plaintext and can still be opened outside the company network environment without requiring approval for decryption.

[0127] 3. Test samples can be sent to data source partners via email, but a password must be set for the compressed file.

[0128] In summary, the embodiments of this application have the following beneficial effects:

[0129] (1) In the data receiving stage, the system employs a strict security verification mechanism to ensure that only authorized and verified users or systems can receive data. This effectively prevents the risks of unauthorized access and data leakage. For received data, the system can automatically detect its encryption status and transparently decrypt it. Users do not need to manually perform decryption operations, improving the convenience and efficiency of the operation. The system can automatically record the data reception time and access status, providing basic data support for subsequent data processing and management.

[0130] (2) In the data processing stage, the system employs transparent encryption technology to encrypt sensitive data, ensuring its confidentiality and integrity during processing. Even if data is illegally obtained, it cannot be easily decrypted and accessed. The data processing process supports various operations, such as generating target external links and compressed packages, to adapt to different sending needs. Simultaneously, the system can adjust security policies as needed to ensure the flexibility and scalability of data processing. DLP-based data verification processing can detect security risks in real time during data processing, such as data leakage and misoperation, and take timely blocking measures to prevent potential risks from occurring.

[0131] (3) During the data transmission process, the system employs zero-trust verification and external link validity restrictions to ensure that only verified legitimate users can access the transmitted data. This significantly reduces the risk of data being illegally intercepted or misused during transmission. The system can generate target external links or compressed packages based on different transmission needs and quickly send them to target users via email or other means. This improves the efficiency and convenience of data transmission. The system records information such as the data transmission time and recipient, facilitating data tracking and tracing. In the event of data leakage or misuse, the problem can be quickly located and appropriate measures taken.

[0132] In summary, considering the three stages of data reception, processing, and transmission, implementing the described method can bring about multiple beneficial effects, including improved data security, enhanced operational convenience, increased processing flexibility, and optimized transmission efficiency. This helps enterprises manage and protect data more efficiently in the cloud environment, reduce security risks, and improve the reliability and stability of overall business operations.

[0133] Based on the same inventive concept, this application also provides a data transmission device corresponding to the data transmission method in the first embodiment. Since the principle of the device in this application is similar to that of the above-mentioned data transmission method, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0134] like Figure 6 As shown, Figure 6 This is a schematic diagram of the structure of the data transmission device 600 provided in an embodiment of this application. The data transmission device 600 includes:

[0135] The receiving module 601 is used to respond to the transmission request of the first data and receive the first data, wherein the cloud system is deployed in a local area network;

[0136] Processing module 602 is used to encrypt the first data in response to receiving the first data to obtain the second data;

[0137] The sending module 603 is used to respond to a data outgoing request, decrypt the second data, generate third data based on the decrypted second data, and send the third data to the transmission target.

[0138] Those skilled in the art should understand that Figure 6 The functions of each unit in the data transmission device 600 shown can be understood by referring to the relevant description of the aforementioned data transmission method. Figure 6 The functions of each unit in the data transmission device 600 shown can be implemented by a program running on a processor or by specific logic circuits.

[0139] In one possible implementation, the cloud system includes a file transfer system, wherein the receiving module 601 responds to a transmission request for first data and receives the first data, including:

[0140] In response to the transmission side's request to send the first data, the transmission side receives the first data through the file transfer system. The first data can be sent via external link, email, SFTP, or target storage medium. When the first data is sent via external link, the transmission side accesses the local area network based on zero-trust authentication before sending the first data. Zero-trust authentication means that authentication is required each time.

[0141] In one possible implementation, before encrypting the first data after receiving it, the processing module 602 further includes:

[0142] If the first data is sent via email, an email password is generated based on at least two cloud system users, wherein the email password is used to retrieve the first data in the email, and each of the at least two cloud system users holds a sub-password;

[0143] If the first data is sent via SFTP, each of at least two cloud system users receives the SFTP password sent in segments by the sender, wherein each system user's subsystem has an SFTP client installed and a password bound to it.

[0144] If the first data is sent via the target storage medium, the decompression password is received by at least two cloud system users respectively, and decompression is performed in the subsystem of any of the at least two cloud system users.

[0145] In one possible implementation, the cloud system prohibits the following operations on the first data:

[0146] Export the first data, download the first data, copy the first data, and print the first data.

[0147] In one possible implementation, the cloud system includes at least one subsystem, each subsystem corresponding to a cloud system user; the processing module 602 further includes:

[0148] In response to a user's request to process the second data, the second data is stored in a designated location within the cloud system, and writing of the second data is prohibited in any other location within the cloud system besides the designated location.

[0149] In one possible implementation, the processing module 602 encrypts the first data, including:

[0150] The first data is encrypted using transparent encryption, so that when the first data is opened, the unencrypted first data is automatically encrypted, and the encrypted second data is automatically decrypted.

[0151] In one possible implementation, the sending module 603 decrypts the second data, generates third data based on the decrypted second data, and sends the third data to the transmission target, including:

[0152] In response to the decryption request, the decryption request is approved, and the second data is decrypted after the approval is granted;

[0153] A target external link is generated based on the decrypted second data, and the target external link is sent to the transmission target; wherein, the target external link is allowed to be accessed after the transmission target passes zero-trust verification and connects to the local area network, and the target external link is valid within the validity period;

[0154] Alternatively, a target compressed package can be generated based on the decrypted second data, and the compressed package can be sent to the transmission target via a target email; wherein the target email contains a password for decompression.

[0155] In one possible implementation, the sending module 603 further includes:

[0156] The third data is verified based on DLP.

[0157] If the third data does not conform to the preset security policy, the transmission of the third data will be blocked.

[0158] In one possible implementation, the processing module 602 further includes:

[0159] If the first data is not accessed within a preset time, the first data is deleted.

[0160] The above-mentioned data transmission device has the following beneficial effects:

[0161] (1) In the data receiving stage, the system employs a strict security verification mechanism to ensure that only authorized and verified users or systems can receive data. This effectively prevents the risks of unauthorized access and data leakage. For received data, the system can automatically detect its encryption status and transparently decrypt it. Users do not need to manually perform decryption operations, improving the convenience and efficiency of the operation. The system can automatically record the data reception time and access status, providing basic data support for subsequent data processing and management.

[0162] (2) In the data processing stage, the system employs transparent encryption technology to encrypt sensitive data, ensuring its confidentiality and integrity during processing. Even if data is illegally obtained, it cannot be easily decrypted and accessed. The data processing process supports various operations, such as generating target external links and compressed packages, to adapt to different sending needs. Simultaneously, the system can adjust security policies as needed to ensure the flexibility and scalability of data processing. DLP-based data verification processing can detect security risks in real time during data processing, such as data leakage and misoperation, and take timely blocking measures to prevent potential risks from occurring.

[0163] (3) During the data transmission process, the system employs zero-trust verification and external link validity restrictions to ensure that only verified legitimate users can access the transmitted data. This significantly reduces the risk of data being illegally intercepted or misused during transmission. The system can generate target external links or compressed packages based on different transmission needs and quickly send them to target users via email or other means. This improves the efficiency and convenience of data transmission. The system records information such as the data transmission time and recipient, facilitating data tracking and tracing. In the event of data leakage or misuse, the problem can be quickly located and appropriate measures taken.

[0164] In summary, considering the three stages of data reception, processing, and transmission, implementing the described method can bring about multiple beneficial effects, including improved data security, enhanced operational convenience, increased processing flexibility, and optimized transmission efficiency. This helps enterprises manage and protect data more efficiently in the cloud environment, reduce security risks, and improve the reliability and stability of overall business operations.

[0165] like Figure 7 As shown, Figure 7 This is a schematic diagram of the composition structure of the electronic device 700 provided in the embodiments of this application. The electronic device 700 includes:

[0166] The device 700 includes a processor 701, a storage medium 702, and a bus 703. The storage medium 702 stores machine-readable instructions that can be executed by the processor 701. When the electronic device 700 is running, the processor 701 communicates with the storage medium 702 via the bus 703. The processor 701 executes the machine-readable instructions to perform the steps of the data transmission method described in the embodiments of this application.

[0167] In practical applications, the various components in the electronic device 700 are coupled together via a bus 703. It is understood that the bus 703 is used to achieve communication between these components. In addition to a data bus, the bus 703 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 7The general designated all buses as Bus 703.

[0168] The above-mentioned electronic devices have the following beneficial effects:

[0169] (1) In the data receiving stage, the system employs a strict security verification mechanism to ensure that only authorized and verified users or systems can receive data. This effectively prevents the risks of unauthorized access and data leakage. For received data, the system can automatically detect its encryption status and transparently decrypt it. Users do not need to manually perform decryption operations, improving the convenience and efficiency of the operation. The system can automatically record the data reception time and access status, providing basic data support for subsequent data processing and management.

[0170] (2) In the data processing stage, the system employs transparent encryption technology to encrypt sensitive data, ensuring its confidentiality and integrity during processing. Even if data is illegally obtained, it cannot be easily decrypted and accessed. The data processing process supports various operations, such as generating target external links and compressed packages, to adapt to different sending needs. Simultaneously, the system can adjust security policies as needed to ensure the flexibility and scalability of data processing. DLP-based data verification processing can detect security risks in real time during data processing, such as data leakage and misoperation, and take timely blocking measures to prevent potential risks from occurring.

[0171] (3) During the data transmission process, the system employs zero-trust verification and external link validity restrictions to ensure that only verified legitimate users can access the transmitted data. This significantly reduces the risk of data being illegally intercepted or misused during transmission. The system can generate target external links or compressed packages based on different transmission needs and quickly send them to target users via email or other means. This improves the efficiency and convenience of data transmission. The system records information such as the data transmission time and recipient, facilitating data tracking and tracing. In the event of data leakage or misuse, the problem can be quickly located and appropriate measures taken.

[0172] In summary, considering the three stages of data reception, processing, and transmission, implementing the described method can bring about multiple beneficial effects, including improved data security, enhanced operational convenience, increased processing flexibility, and optimized transmission efficiency. This helps enterprises manage and protect data more efficiently in the cloud environment, reduce security risks, and improve the reliability and stability of overall business operations.

[0173] This application also provides a computer-readable storage medium storing executable instructions, which, when executed by at least one processor 701, implement the data transmission method described in this application.

[0174] In some embodiments, the storage medium may be a magnetic random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CDROM), etc.; or it may be a device that includes one or any combination of the above-mentioned memories.

[0175] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0176] As an example, executable instructions may, but do not necessarily, correspond to files in the file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple collaborating files (e.g., a file that stores one or more modules, subroutines, or code sections).

[0177] As an example, executable instructions can be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.

[0178] The aforementioned computer-readable storage media have the following beneficial effects:

[0179] (1) In the data receiving stage, the system employs a strict security verification mechanism to ensure that only authorized and verified users or systems can receive data. This effectively prevents the risks of unauthorized access and data leakage. For received data, the system can automatically detect its encryption status and transparently decrypt it. Users do not need to manually perform decryption operations, improving the convenience and efficiency of the operation. The system can automatically record the data reception time and access status, providing basic data support for subsequent data processing and management.

[0180] (2) In the data processing stage, the system employs transparent encryption technology to encrypt sensitive data, ensuring its confidentiality and integrity during processing. Even if data is illegally obtained, it cannot be easily decrypted and accessed. The data processing process supports various operations, such as generating target external links and compressed packages, to adapt to different sending needs. Simultaneously, the system can adjust security policies as needed to ensure the flexibility and scalability of data processing. DLP-based data verification processing can detect security risks in real time during data processing, such as data leakage and misoperation, and take timely blocking measures to prevent potential risks from occurring.

[0181] (3) During the data transmission process, the system employs zero-trust verification and external link validity restrictions to ensure that only verified legitimate users can access the transmitted data. This significantly reduces the risk of data being illegally intercepted or misused during transmission. The system can generate target external links or compressed packages based on different transmission needs and quickly send them to target users via email or other means. This improves the efficiency and convenience of data transmission. The system records information such as the data transmission time and recipient, facilitating data tracking and tracing. In the event of data leakage or misuse, the problem can be quickly located and appropriate measures taken.

[0182] In summary, considering the three stages of data reception, processing, and transmission, implementing the described method can bring about multiple beneficial effects, including improved data security, enhanced operational convenience, increased processing flexibility, and optimized transmission efficiency. This helps enterprises manage and protect data more efficiently in the cloud environment, reduce security risks, and improve the reliability and stability of overall business operations.

[0183] In the several embodiments provided in this application, it should be understood that the disclosed methods and electronic devices can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components may be combined, or integrated into another system, or some features may be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0184] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0185] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0186] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a platform server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0187] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data transmission method, characterized in that, Applied to cloud systems, the method includes: Responding to the transmission request of the first data, the system receives the first data, wherein the cloud system is deployed on a local area network; Upon receiving the first data, the response encrypts the first data to obtain the second data. In response to a data outgoing request, the system decrypts the second data, generates third data based on the decrypted second data, and sends the third data to the transmission target. The cloud system includes a file transfer system, which responds to a first data transmission request and receives the first data, including: In response to the transmission side's request to send the first data, the transmission side receives the first data through the file transfer system. The first data is sent via external link, email, SFTP, or target storage medium. When the first data is sent via external link, the transmission side accesses the local area network based on zero-trust authentication before sending the first data. Zero-trust authentication means that authentication is required every time. The encryption process for the first data includes: The first data is encrypted using transparent encryption so that when the first data is opened, the unencrypted first data is automatically encrypted and the encrypted second data is automatically decrypted. The steps of decrypting the second data, generating third data based on the decrypted second data, and sending the third data to the transmission target include: In response to the decryption request, the decryption request is approved, and the second data is decrypted after the approval is granted; A target external link is generated based on the decrypted second data, and the target external link is sent to the transmission target; wherein, the target external link is allowed to be accessed after the transmission target passes zero-trust verification and connects to the local area network, and the target external link is valid within the validity period; Alternatively, a target compressed package can be generated based on the decrypted second data, and the compressed package can be sent to the transmission target via a target email; wherein the target email contains a password for decompression.

2. The data transmission method according to claim 1, characterized in that, After receiving the first data but before encrypting it, the method further includes: If the first data is sent via email, an email password is generated based on at least two cloud system users, wherein the email password is used to retrieve the first data in the email, and each of the at least two cloud system users holds a sub-password; If the first data is sent via SFTP, each of at least two cloud system users receives the SFTP password sent in segments by the sender, wherein each system user's subsystem has an SFTP client installed and a password bound to it. If the first data is sent via the target storage medium, the decompression password is received by at least two cloud system users respectively, and decompression is performed in the subsystem of any of the at least two cloud system users.

3. The data transmission method according to claim 1, characterized in that, In the cloud system, the following operations are prohibited on the first data: Export the first data, download the first data, copy the first data, and print the first data.

4. The data transmission method according to claim 1, characterized in that, The cloud system includes at least one subsystem, and each subsystem corresponds to a cloud system user; the method further includes: In response to a user's request to process the second data, the second data is stored in a designated location within the cloud system, and writing of the second data is prohibited in any other location within the cloud system besides the designated location.

5. The data transmission method according to claim 1, characterized in that, The method further includes: The third data is verified based on DLP. If the third data does not conform to the preset security policy, the transmission of the third data will be blocked.

6. The data transmission method according to claim 1, characterized in that, The method further includes: If the first data is not accessed within a preset time, the first data is deleted.

7. A data transmission device, characterized in that, The device, applied to a cloud system, includes: A receiving module is used to respond to a transmission request for first data and receive the first data, wherein the cloud system is deployed on a local area network; the cloud system includes a file transfer system, and responding to the transmission request for the first data and receiving the first data includes: responding to a transmission side's sending request for the first data and receiving the first data through the file transfer system, wherein the sending method of the first data includes external links, email, SFTP, and target storage media; when the sending method of the first data is an external link, the transmission side accesses the local area network based on zero-trust authentication before sending the first data, and the zero-trust authentication means that authentication is required every time; The processing module is configured to respond to receiving the first data, encrypt the first data, and obtain the second data; the encryption of the first data includes: encrypting the first data based on transparent encryption, so that when the first data is opened, the unencrypted first data is automatically encrypted, and the encrypted second data is automatically decrypted. A sending module is configured to respond to a data outgoing request, decrypt the second data, generate third data based on the decrypted second data, and send the third data to a transmission target; the steps of decrypting the second data, generating third data based on the decrypted second data, and sending the third data to the transmission target include: responding to a decryption request, approving the decryption request, and decrypting the second data after approval; generating a target external link based on the decrypted second data, and sending the target external link to the transmission target; wherein the target external link is allowed to be accessed after the transmission target passes zero-trust verification and accesses the local area network, and the target external link is valid within its validity period; or, generating a target compressed package based on the decrypted second data, and sending the compressed package to the transmission target via a target email; wherein the target email contains a password for decompression.

Citation Information

Patent Citations

  • Power communication network data management method and device, electronic equipment and storage medium

    CN117807576A