An application data use control method based on a zero trust concept

By applying a data usage control method based on the zero-trust concept, and through continuous verification of the data application layer and encapsulation and decryption of capsule data, combined with the verification of the data usage control engine, the problem of insufficient flexibility and granularity in existing technologies is solved, realizing flexible and granular control over dynamic data access and usage, and ensuring data security.

CN118449723BActive Publication Date: 2025-11-21CHINA CITIC BANK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410492934.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-23
Publication Date
2025-11-21
Estimated Expiration
2044-04-23

AI Technical Summary

Technical Problem

Existing application data usage control technologies lack flexibility and granularity when faced with dynamically changing data access and usage patterns, resulting in an inability to effectively control data access and usage.

Method used

The application data usage control method based on the zero-trust concept is adopted. Data access results are generated through continuous verification at the data application layer. Capsule data access verification and encapsulation are performed to check whether the capsule encapsulated data is in the trusted list. The data usage strategy is decrypted and verified by the data usage control engine, and finally the use of target application data is controlled.

Benefits of technology

It enables flexible and granular control over dynamically changing data access and usage patterns, ensuring that only authorized users and devices can access sensitive data, thereby improving the security and integrity of data use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118449723B_ABST
    Figure CN118449723B_ABST
Patent Text Reader

Abstract

The application discloses an application data use control method based on a zero-trust concept, and relates to the technical field of data processing. The method comprises the following steps: triggering judgment through a data access operation of a data application layer, continuously verifying to generate a data access result; performing access verification on capsule data according to the data access result to generate capsule encapsulated data; verifying whether the capsule encapsulated data is in a trusted list, and if the verification is passed, decrypting the capsule encapsulated data by using an encryption key to obtain a data use strategy; calling a data use control engine to verify and judge the data use strategy, and generating a verification result; and controlling the use of target application data according to the result. The application solves the technical problem that the existing application data use control technology has poor access control flexibility and precision, and thus cannot cope with dynamically changing data access and use modes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, specifically to an application data usage control method based on the zero-trust concept. Background Technology

[0002] In the wave of global informatization and digitalization, applications are widely used in our daily lives and work, providing us with convenient and innovative services. Controlling the use of application data has become an important requirement. However, with the emergence of various types of applications, a large amount of personal application data is being actively or passively collected and misused. Existing application data use control technologies often focus on the static protection of application data and cannot perform data access verification and provide sufficiently flexible and precise control when large amounts of complex and dynamically changing application data are accessed and used.

[0003] Therefore, ensuring the flexibility and precision of application data usage control to cope with dynamically changing data access and usage patterns has become an urgent problem to be solved. Summary of the Invention

[0004] Based on this, the embodiments of this application provide an application data usage control method based on the zero-trust concept, which solves the technical problem that the existing application data usage control technology has poor access control flexibility and fineness, thus making it unable to cope with dynamically changing data access and usage patterns. This achieves the technical effect of more flexible and fine data usage control to cope with dynamically changing data access and usage patterns.

[0005] A first aspect of this application provides an application data usage method based on the zero-trust concept. The application data usage method is applied to an application data usage control system based on the zero-trust concept, wherein the application data usage control system and a data usage control engine are communicatively connected. The method includes:

[0006] The judgment is triggered by data access operations at the data application layer, and the judgment result is continuously verified to generate the data access result.

[0007] Based on the data access results, the capsule data is accessed and verified to generate capsule packaging data;

[0008] The system checks whether the capsule packaging data is in the trusted list. If the check passes, the capsule data is decrypted using the data encryption key to obtain the data usage policy.

[0009] The control engine calls upon the data to verify and judge the data using a strategy, and generates verification results.

[0010] The use of target application data is controlled based on the verification results.

[0011] A second aspect of this application provides a system for application data usage control based on the zero-trust concept, the system comprising:

[0012] A data access result generation module is used to trigger judgments based on data access operations in the data application layer, continuously verify the judgment results, and generate data access results.

[0013] A capsule data access verification module is used to verify the access to capsule data based on the data access result and generate capsule packaging data.

[0014] The data usage policy acquisition module is used to verify whether the capsule packaged data is in the trusted list. If the verification is successful, the capsule data is decrypted using the data encryption key to obtain the data usage policy.

[0015] The verification result acquisition module is used to call the data usage control engine to verify and judge the data usage strategy and generate a verification result.

[0016] The target application data usage control module is used to control the use of target application data based on the verification results.

[0017] A third aspect of this application provides an electronic device including a memory and a processor, the processor being coupled to the memory, the memory being used to store a computer program, which, when executed by the processor, causes the electronic device to perform the steps of the method described in the first aspect.

[0018] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.

[0019] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0020] This application triggers judgments through data access operations at the data application layer, continuously verifies the judgment results, generates data access results, verifies access to capsule data based on the data access results, generates capsule-packaged data, checks whether the capsule-packaged data is in the trusted list, and if the verification passes, decrypts the capsule data using the data encryption key to obtain the data usage policy, calls the data usage control engine to verify and judge the data usage policy, generates verification results, and controls the use of target application data based on the verification results. This solves the technical problem of poor access control flexibility and granularity in existing application data usage control technologies, which leads to an inability to cope with dynamically changing data access and usage patterns. Thus, it achieves the technical effect of more flexible and granular data usage control to cope with dynamically changing data access and usage patterns. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 A flowchart illustrating an application data usage control method based on the zero-trust concept provided in this application embodiment;

[0023] Figure 2 This application provides a schematic diagram of the process for generating capsule encapsulation data in an application data usage control method based on the zero-trust concept.

[0024] Figure 3 A schematic diagram of a system architecture for application data usage control based on the zero-trust concept is provided for embodiments of this application;

[0025] Figure 4 This is a schematic diagram of an exemplary electronic device structure for this application.

[0026] Explanation of reference numerals in the attached figures: Data access result generation module 10, capsule data access verification module 20, data usage strategy acquisition module 30, verification result acquisition module 40, target application data usage control module 50, input device 11, memory 12, processor 13, output device 14. Detailed Implementation

[0027] This application provides an application data usage control method based on the zero-trust concept, which solves the technical problem that existing application data usage control technologies have poor access control flexibility and granularity, thus making them unable to cope with dynamically changing data access and usage patterns.

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative effort are within the scope of protection of the present application.

[0029] It should be noted that the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such process, method, product, or device.

[0030] Example 1

[0031] like Figure 1 As shown, this application provides a method for application data usage control based on the zero-trust concept. The application data usage control method is applied to an application data usage control system based on the zero-trust concept. The application data usage control system is communicatively connected to a data usage control engine. The method includes:

[0032] Specifically, application data usage control based on the zero-trust concept is a brand-new security strategy that protects application data from unauthorized access and misuse. It implements a unified data usage control engine based on the zero-trust concept at the application layer. Through the data usage engine, multi-dimensional and fine-grained authorization of application data usage is achieved during the access authorization phase, while continuous verification and review are carried out during each use of the data.

[0033] The judgment is triggered by data access operations at the data application layer, and the judgment result is continuously verified to generate the data access result.

[0034] Preferably, triggering judgments through data access operations at the data application layer, and continuously verifying the results to generate data access results, is key to achieving application data usage control based on the zero-trust concept. Specifically, when a user or device initiates a data access request, triggering judgments can be achieved through access control policies, data permission configurations, and rule engines within the application at the data application layer. The judgment results verify whether the data access request meets authorization requirements. During continuous verification, the user's or device's identity, permissions, and context information are further verified. For example, identity verification services verify user authentication, device health status checks, network behavior analysis, and security log monitoring. The results of continuous verification determine whether authorization requirements are met. If the user or device passes verification, an authorized data access result is generated, allowing access to specific data resources. If continuous verification detects any anomalies, a corresponding data access denial or warning result is generated. By triggering judgments through data access operations at the data application layer and generating data access results through continuous verification, more granular data access control can be achieved, ensuring that only authorized and verified users can access sensitive data.

[0035] Furthermore, the data access operation at the data application layer triggers the judgment, and continuous verification is performed based on the judgment result to generate the data access result. The methods include:

[0036] Extract data access requests based on the data access operations of the data application layer;

[0037] Based on the zero-trust principle, the data access request is authorized and the corresponding data permissions are generated.

[0038] The data access request is determined to be in accordance with the preset data access rules to determine whether its data permissions comply with the access permissions.

[0039] If the conditions are met, it is considered a data access operation has been triggered;

[0040] If it does not meet the requirements, access will be denied and the corresponding log information will be recorded.

[0041] Add the data access operation or the log information to the judgment result.

[0042] Preferably, data access requests are extracted based on data access operations at the data application layer. These requests may include user identity information (e.g., username, user ID, email address) for verifying user identity and permissions, the type of operation to be performed (e.g., read, write, modify, delete), the user's access purpose, specific data identifiers (e.g., filename, database, and table names), data access conditions or restrictions (e.g., query conditions, filters), and context information (e.g., user device information, IP address, access timestamp). Based on the zero-trust principle, data permissions for the data access requests are authorized, generating corresponding data permissions. Then, according to preset data access rules, it is determined whether the data permissions corresponding to the data access requests comply with access permissions. User authentication in the data access requests includes username and password verification, as well as stronger verification methods such as facial recognition and fingerprint recognition. Preset data access rules refer to access rules pre-defined based on user identity. Application data strategies, such as defining user permissions, data sensitivity levels, and access time ranges, are used to determine data access permissions based on the matching results of access policies. For example, verifying whether a user has read, write, modify, or delete permissions can be done using Access Control Lists (ACLs) or Role-Based Access Control (RBAC). If the conditions are met, a data access operation is triggered, including the type of data access operation, the identifier of the data resource, and the data permission authorization result (permission). If the conditions are not met, access is denied, and corresponding log information is recorded. The access denial log information should record the identity of the request initiator, the time of access, the requested resource and operation type, and the reason for the access denial. Finally, the data access operation or access denial log information is added to the judgment result to generate the final data access result, providing more comprehensive data access information for subsequent security analysis and data usage control.

[0043] Based on the data access results, the capsule data is accessed and verified to generate capsule packaging data;

[0044] Preferably, the capsule data is access-verified based on the data access results to generate capsule-encapsulated data. Capsule data refers to the data format after preprocessing the original data to ensure data security during transmission and storage. This may include verification of data integrity and consistency, such as checking whether the data has been tampered with or whether it complies with specific access policies and data security standards. Based on the access verification results of the capsule data, an encapsulated data format or structure is generated to improve data security and integrity, providing a secure form of data transmission and storage. For example, key encryption, digital signatures, and data digests are used to protect data from tampering and unauthorized access operations. For sensitive data and critical information, this capsule-encapsulation effectively increases the data security level.

[0045] Furthermore, such as Figure 2 As shown, the method for verifying access to capsule data based on the data access results and generating capsule packaging data includes:

[0046] The data is activated by integrating it into the system using a control engine.

[0047] The control engine uses the data to identify whether the data access result is a cross-domain access.

[0048] If so, the data access result is considered to have the right to access the capsule data, and the data is encapsulated according to the data structure of the capsule data to generate the capsule encapsulation data.

[0049] Preferably, the data access control engine is integrated into the system for activation. The engine identifies and determines whether the data access result is cross-domain access. If so, the data access result is considered to have the right to access the capsule data, and the data is encapsulated according to the capsule data's data structure. The data access control engine is a software or integrated module that monitors and controls data access and usage operations by defining and executing access control rules, permission management, and data protection policies. This includes functions such as access control lists, role-based access control, data classification and tagging, and encryption to prevent unauthorized data access, prevent data leakage, and manage the privacy and integrity of sensitive data. When the data access control engine determines that the data access result is cross-domain access, it considers the data access result to have the right to access the capsule data and encapsulates the data according to the capsule data's data structure. Data that has been encrypted, digitally signed, or processed with access control policies is encapsulated according to a predefined data structure. Encrypted data and metadata information can be combined to form an encapsulated data format or structure, i.e., generating capsule-encapsulated data, thereby improving data security and integrity.

[0050] The system checks whether the capsule packaging data is in the trusted list. If the check passes, the capsule data is decrypted using the data encryption key to obtain the data usage policy.

[0051] Preferably, the process involves verifying whether the capsule-packaged data is on a trusted list. If the verification passes, the capsule data is decrypted using the data encryption key to obtain the data usage policy. Specifically, for received capsule-packaged data, the process first verifies whether the data is on a trusted list. This can be done by comparing the identification information or key in the data with the information in the trusted list. If the identification information or key matches the trusted list, the capsule-packaged data passes the verification. The trusted list refers to an authorization management tool or a list of trusted entities used to determine which entities have the right to access specific resources, perform specific operations, or have specific permissions to access or manipulate certain sensitive data or resources. For example, the trusted list can be a whitelist or access control... Access control lists (ACLs) or access permission matrices, etc., are used to encrypt or decrypt data. A data encryption key is used to convert readable plaintext data into ciphertext data or decrypt unreadable ciphertext data back into the original plaintext data. When the capsule data verification passes, the data encryption key (DEK) is obtained online or offline. This key is used to decrypt the capsule-encapsulated data and obtain the data usage policy. The data usage policy is a set of rules about how and how data is used and accessed, defining the data usage pattern and access control. It primarily focuses on fine-grained control and multi-dimensional verification of data access. For example, the data usage policy includes multiple dimensions and finer-grained data usage control policy information such as user roles, data usage time, usage location, type of application used, data usage frequency, and usage method.

[0052] Furthermore, the method for verifying whether the capsule packaging data is in the trusted list includes:

[0053] During the data encapsulation process of the capsule data, corresponding credential information is generated synchronously.

[0054] The capsule packaging data is used to perform credential verification, and a credential verification result is generated, wherein the credential verification result includes credential validity and credential matching.

[0055] When there are no signs of tampering with the capsule packaging data, the existence of the capsule packaging data in the trusted list is determined based on the validity of the credentials and the matching of the credentials.

[0056] Preferably, during the data encapsulation process of the capsule data, corresponding credential information is generated simultaneously. Credential verification is performed on the capsule-encapsulated data, generating a credential verification result. When the capsule-encapsulated data shows no signs of tampering, the existence of the capsule-encapsulated data in the trusted list is determined based on credential validity and credential matching. Specifically, during data encapsulation, credential information for verifying and accessing the capsule-encapsulated data is generated. This credential information is used for subsequent access and operations on the capsule-encapsulated data and can be a symmetric encryption key, digital signature, or access token, etc. The credential verification result is the result of credential verification of the capsule-encapsulated data, determining whether access to the encapsulated capsule data and reverse access operations are allowed. The credential verification result includes credential validity and credential matching. Credential validity determines whether the credential verification result is valid, typically including verification... The verification process includes checking whether the format and structure of the credentials meet expectations, the signature of the credentials, whether they have expired or been revoked, and the validity period of the credentials. Credential matching refers to verifying whether the credentials match the capsule-packaged data, that is, matching the credentials submitted by the user with the credentials stored on the server to ensure the consistency of the credential information. For example, by comparing the identifier, token, or key in the credentials with the association identifier of the capsule-packaged data, if the match is successful, it means that the credentials and capsule-packaged data correspond. If there are no signs of tampering in the capsule data and the validity and credential matching of the credentials have been verified, it is further determined whether the capsule-packaged data exists in a trusted list. For example, by comparing the identifier, encrypted digest, etc. of the capsule-packaged data, when the verification information of the capsule-packaged data completely matches the records in the trusted list, it is determined that the capsule-packaged data exists in the trusted list, thereby ensuring the integrity and trustworthiness of the data.

[0057] Furthermore, methods for determining whether capsule packaging data has been tampered with include:

[0058] The target digital certificate is obtained by using the capsule-encapsulated data, wherein the target digital certificate contains target identity information and target public key;

[0059] Data is signed using the private key contained within the capsule-encapsulated data;

[0060] After the target identity verification is successful, the data signature is verified using the target public key. If the verification is successful, it is considered that there are no traces of tampering in the capsule-encapsulated data.

[0061] Preferably, the target digital certificate is obtained by encapsulating data in a capsule, and then the data is signed using the private key within the capsule. Once the target identity is verified, the data signature is verified using the target public key. If the verification is successful, it is considered that the capsule data has not been tampered with. Specifically, obtaining the target digital certificate by encapsulating data in a capsule includes using a suitable decapsulation method to decapsulate the capsule data, restoring the original capsule data, and extracting the target digital certificate from it. The target digital certificate contains identity information and a target public key. The target identity information can be used to verify the target user's identity, and the target public key can be used for subsequent data signature verification. The data is signed using the private key within the capsule, i.e., the data is encrypted, generating a digital signature associated with the data. Digital signing using the private key ensures the data's integrity. The authenticity and integrity of the data are verified. After the target's identity information is verified, the data signature, i.e., the target digital certificate, is verified using the target's public key to ensure the trustworthiness of the target digital certificate. The target public key is a key type generated by two mathematically related large prime numbers, including a public key and a confidential private key. The public key is used to verify the validity of the data signature and can be widely shared and used without disclosing the private key or data information, ensuring the integrity of the data and the identity authentication operation. The obtained target public key is used to verify the data signature of the capsule-encapsulated data. If the data signature verification is successful, that is, the data signature matches the integrity of the capsule-encapsulated data, then it is determined that there is no trace of data tampering in the capsule-encapsulated data. Conversely, if the data signature verification fails, it means that the data may have been tampered with or lost, thus determining whether the capsule-encapsulated data is trustworthy.

[0062] The control engine calls upon the data to verify and judge the data using a strategy, and generates verification results.

[0063] Preferably, the data usage control engine is invoked to verify and judge the data usage policy and generate a verification result. The data usage control engine is responsible for performing the verification and control operations on data usage. The data usage control engine's verification and judgment of the data usage policy may involve multiple dimensions such as user authentication, access permissions, time limits, data classification, and device security status. This can ensure that data usage complies with the predetermined control policy. The required data and related data usage policies are passed to the data usage control engine for the verification and judgment operations. The data usage control engine will generate a verification result, which is usually a Boolean value (pass or reject) generated according to the policy rules, indicating whether the data usage complies with the data usage policy.

[0064] Furthermore, the data usage control engine is a software system used to manage and enforce data access control policies. It includes an access permission management module, a data anonymization and desensitization module, an encryption and key management module, and an auditing and monitoring module. The access permission management module manages and controls data access permissions based on factors such as user roles, data classification tags, and time limits, ensuring that only authorized users can access specific data or resources. The data anonymization and desensitization module processes sensitive data using data anonymization and desensitization technologies to protect the security of personal privacy data while ensuring data availability and integrity. The encryption and key management module encrypts data to protect its security during storage and transmission, while managing and protecting the keys required for encryption and decryption, and verifying data using keys when necessary. The auditing and monitoring module tracks data usage, records log information of successful or denied data access, monitors abnormal behavior throughout the entire data usage and access process, and promptly detects potential security risks and provides real-time warnings and responses.

[0065] Finally, based on the verification results obtained from the data use engine to verify and judge the data usage strategy, the use of data in the target application is controlled.

[0066] In summary, the embodiments of this application have at least the following technical effects:

[0067] This application embodiment triggers judgment through data access operations at the data application layer, continuously verifies based on the judgment result, generates a data access result, verifies access to capsule data based on the data access result, generates capsule-packaged data, checks whether the capsule-packaged data is in the trusted list, and if the verification passes, decrypts the capsule data using the data encryption key to obtain the data usage policy, calls the data usage control engine to verify and judge the data usage policy, generates a verification result, and controls the use of target application data based on the verification result. This solves the technical problem of poor access control flexibility and granularity in existing application data usage control technologies, which leads to an inability to cope with dynamically changing data access and usage patterns. Thus, it achieves the technical effect of more flexible and granular data usage control to cope with dynamically changing data access and usage patterns.

[0068] Example 2

[0069] Based on the same inventive concept as the application data usage control method based on the zero-trust principle in the foregoing embodiments, such as Figure 3 As shown, this application provides an application data usage control system based on the zero-trust concept. The system and method embodiments in this application are based on the same inventive concept, wherein the system includes:

[0070] The data access result generation module 10 is used to trigger judgment through data access operations in the data application layer, continuously verify based on the judgment result, and generate data access results.

[0071] Capsule data access verification module 20, which is used to verify the access of capsule data according to the data access result and generate capsule packaging data;

[0072] The data usage policy acquisition module 30 is used to verify whether the capsule encapsulation data is in the trusted list. If the verification is successful, the capsule data is decrypted using the data encryption key to obtain the data usage policy.

[0073] The verification result acquisition module 40 is used to call the data usage control engine to verify and judge the data usage strategy and generate a verification result.

[0074] The target application data usage control module 50 is used to control the use of target application data based on the verification results.

[0075] Furthermore, the data access result generation module 10 is also used to perform the following method:

[0076] Extract data access requests based on the data access operations of the data application layer;

[0077] Based on the zero-trust principle, the data access request is authorized and the corresponding data permissions are generated.

[0078] The data access request is determined to be in accordance with the preset data access rules to determine whether its data permissions comply with the access permissions.

[0079] If the conditions are met, it is considered a data access operation has been triggered;

[0080] If it does not meet the requirements, access will be denied and the corresponding log information will be recorded.

[0081] Add the data access operation or the log information to the judgment result.

[0082] Furthermore, the capsule data access verification module 20 is also used to perform the following method:

[0083] The data is activated by integrating it into the system using a control engine.

[0084] The control engine uses the data to identify whether the data access result is a cross-domain access.

[0085] If so, the data access result is considered to have the right to access the capsule data, and the data is encapsulated according to the data structure of the capsule data to generate the capsule encapsulation data.

[0086] Furthermore, the data acquisition strategy module 30 is also used to perform the following methods:

[0087] During the data encapsulation process of the capsule data, corresponding credential information is generated synchronously.

[0088] The capsule packaging data is used to perform credential verification, and a credential verification result is generated, wherein the credential verification result includes credential validity and credential matching.

[0089] When there are no signs of tampering with the capsule packaging data, the existence of the capsule packaging data in the trusted list is determined based on the validity of the credentials and the matching of the credentials.

[0090] Furthermore, the data acquisition strategy module 30 is also used to perform the following methods:

[0091] The target digital certificate is obtained by using the capsule-encapsulated data, wherein the target digital certificate contains target identity information and target public key;

[0092] Data is signed using the private key contained within the capsule-encapsulated data;

[0093] After the target identity verification is successful, the data signature is verified using the target public key. If the verification is successful, it is considered that there are no traces of tampering in the capsule-encapsulated data.

[0094] Furthermore, the verification result acquisition module 40 also needs to call the data usage control engine, which is a software system for managing and executing data access control policies, including:

[0095] Access control module, data anonymization and desensitization module, encryption and key management module, auditing and monitoring module.

[0096] Furthermore, the verification result acquisition module 40 is also used to perform the following method:

[0097] The data usage control engine is invoked to verify the data usage policy. If the verification passes, the data access request is considered allowed, and dynamic access and usage control of the target application data is implemented. If the verification fails, an access denial instruction is generated, and access to the target application data is prohibited according to the access denial instruction. The permissions within the data usage policy are then checked a second time.

[0098] Example 3

[0099] Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 3 of the present invention, showing a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of the present invention. Figure 4 As shown, the electronic device includes an input device 11, a memory 12, a processor 13, and an output device 14. The electronic device can have one or more input devices. In this embodiment, the input device is used for inputting data related to the target capsule packaging. Figure 4 Taking a central processing unit 13 as an example, the input device 11, memory 12, processor 13, and output device 14 in the electronic device can be connected by a bus or other means.

[0100] The memory 12, as a computer-readable storage medium, can be used to store data, computer-executable programs, and modules, such as capsule-packaged data, a trusted list, data usage policies, data access results, and a data usage control engine module in this embodiment of the invention. The processor 13 executes the functions of the computer device and performs data processing by running the computer program stored in the memory 12. For example, in this embodiment of the invention, it triggers judgments and generates data access results through data access operations, verifies access to capsule data to generate capsule-packaged data, and decrypts capsule-packaged data using a data encryption key to obtain data usage policies, thereby controlling the use of application data. The output device 14 is used to output the verification results of the data usage control engine's verification of the data usage policy.

[0101] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0102] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0103] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A method for controlling application data usage based on the zero-trust principle, characterized in that, The method is applied to an application data usage control system based on the zero-trust concept, wherein the application data usage control system is communicatively connected to a data usage control engine, and the method includes: The judgment is triggered by data access operations at the data application layer, and the judgment result is continuously verified to generate the data access result. Based on the data access results, the capsule data is accessed and verified to generate capsule packaging data; The system checks whether the capsule packaging data is in the trusted list. If the check passes, the capsule data is decrypted using the data encryption key to obtain the data usage policy. The control engine calls upon the data to verify and judge the data using a strategy, and generates verification results. The use of target application data is controlled based on the verification results.

2. The method as described in claim 1, characterized in that, The judgment is triggered by data access operations at the data application layer, and continuous verification is performed based on the judgment result to generate data access results. The methods include: Extract data access requests based on the data access operations of the data application layer; Based on the zero-trust principle, the data access request is authorized and the corresponding data permissions are generated. The data access request is determined to be in accordance with the preset data access rules to determine whether its data permissions comply with the access permissions. If the conditions are met, it is considered a data access operation has been triggered; If it does not meet the requirements, access will be denied and the corresponding log information will be recorded. Add the data access operation or the log information to the judgment result.

3. The method as described in claim 1, characterized in that, Based on the data access results, the capsule data is accessed and verified to generate capsule packaging data. The method includes: The data is activated by integrating it into the system using a control engine. The control engine uses the data to identify whether the data access result is a cross-domain access. If so, the data access result is considered to have the right to access the capsule data, and the data is encapsulated according to the data structure of the capsule data to generate the capsule encapsulation data.

4. The method as described in claim 1, characterized in that, The data access control engine is a software system used to manage and enforce data access control policies, including an access permission management module, a data desensitization and anonymization module, an encryption and key management module, and an auditing and monitoring module.

5. The method as described in claim 1, characterized in that, The method for verifying whether the capsule packaging data is in the trusted list includes: During the data encapsulation process of the capsule data, corresponding credential information is generated synchronously. The capsule packaging data is used to perform credential verification, and a credential verification result is generated, wherein the credential verification result includes credential validity and credential matching. When there are no signs of tampering with the capsule packaging data, the existence of the capsule packaging data in the trusted list is determined based on the validity of the credentials and the matching of the credentials.

6. The method as described in claim 5, characterized in that, The methods include: The target digital certificate is obtained by using the capsule-encapsulated data, wherein the target digital certificate contains target identity information and target public key; Data is signed using the private key contained within the capsule-encapsulated data; After the target identity verification is successful, the data signature is verified using the target public key. If the verification is successful, it is considered that there are no traces of tampering in the capsule-encapsulated data.

7. The method as described in claim 1, characterized in that, The data usage control engine is invoked to verify the data usage policy. If the verification passes, the data access request is considered allowed, and dynamic access and usage control of the target application data is implemented. If the verification fails, an access denial instruction is generated, and access to the target application data is prohibited according to the access denial instruction. The permissions within the data usage policy are then checked a second time.

8. An application data usage control system based on the zero-trust concept, communicating with a data usage control engine, characterized in that, The system includes: A data access result generation module is used to trigger judgments based on data access operations in the data application layer, continuously verify the judgment results, and generate data access results. A capsule data access verification module is used to verify the access to capsule data based on the data access result and generate capsule packaging data. The data usage policy acquisition module is used to verify whether the capsule packaged data is in the trusted list. If the verification is successful, the capsule data is decrypted using the data encryption key to obtain the data usage policy. The verification result acquisition module is used to call the data usage control engine to verify and judge the data usage strategy and generate a verification result. The target application data usage control module is used to control the use of target application data based on the verification results.

9. An electronic device comprising a memory and a processor, the processor being coupled to the memory, the memory being used to store a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Diaphragm for secondary battery, preparation method of diaphragm and secondary battery

    CN114497891A

  • Kernel-level transparent proxy method based on universal protocol analysis engine

    CN1604540A