Data supervision method, device, electronic device, product and storage medium
By decrypting and verifying the data watermarks in the computing power network, marking and deleting invalid data, the problem of incomplete data supervision in the computing power network is solved, and data security and supervision efficiency are improved.
Patent Information
- Application Number
- CN202410137006.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-01-31
AI Technical Summary
Existing technologies do not fully monitor data in computing networks and cannot effectively protect the security of sensitive data in unauthorized situations.
By obtaining the output data and non-output data of the computing power provider, the output data is marked with the decryption and verification results of the data watermark, invalid data in the non-output data is detected and deleted, and the alarm information of the target sensitive data is output to protect the sensitive data.
It improves the security and efficiency of computing power data, prevents unoutput data from being improperly used, and realizes comprehensive supervision of computing power data.
Smart Images

Figure CN118797585B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a data supervision method, device, electronic device, product and storage medium. Background Art
[0002] With the rapid rise of big data, artificial intelligence, and high-performance computing applications, the demand for greater computing power is intensifying. Computing networks have emerged to address this challenge, aiming to aggregate computing resources across a wide range of sectors to provide more flexible and efficient computing power for a wide range of applications, thereby meeting increasingly complex technological demands and driving the digital transformation of various industries. Computing networks are currently undergoing technological advancements and expansion, with continuous optimization of their underlying architecture, distributed computing capabilities, and load balancing technologies. However, they also face challenges in resource management, efficiency, and network security.
[0003] The transmission and processing of user data on the computing network presents various risks, requiring appropriate security measures to ensure data integrity, confidentiality, and availability. Specifically, during the use of user data within the computing network, it must be ensured that data is used and destroyed only within the computing resource nodes designated by the user. During this process, effective oversight of the computing nodes is required to ensure that sensitive user data is not accessed by other devices or individuals without authorization.
[0004] Currently, the main existing technology for monitoring the outflow of sensitive data is data loss prevention technology. This approach combines comprehensive terminal management with data packet analysis. It analyzes data from three perspectives: sensitive information content, owners of sensitive information, and operations performed on sensitive information. This data flow vector is then constructed to identify abnormal outflows of sensitive information.
[0005] In summary, the existing data supervision in the computing power network is not comprehensive. Summary of the Invention
[0006] The embodiments of the present application provide a data supervision method, device, electronic device, product and storage medium to solve the technical problem of incomplete data supervision.
[0007] In a first aspect, the present application provides a data supervision method, comprising:
[0008] Obtain the output data and unoutput data of the computing power provider;
[0009] Marking the output data message of the output data according to the decryption result and the verification result of the data watermark of the output data to obtain a marked data message;
[0010] Outputting alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message, wherein the original sensitive data includes the sensitive data provided by the data provider;
[0011] Based on the data watermark of the non-output data, invalid data in the non-output data is detected and the invalid data is deleted.
[0012] In one embodiment, the outputting alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message includes:
[0013] When the original sensitive data exists in the target sensitive data, outputting a first alarm message;
[0014] When the original sensitive data does not exist in the target sensitive data and the sensitive data exists in the data output by the supervisory party, the target sensitive data and the second alarm information are output. The supervisory party is used to supervise the processing of the data by the computing power provider. The alarm level of the first alarm information is higher than that of the second alarm information.
[0015] In one embodiment, the data watermark includes a watermark hash value and a data hash value, and marking the output data message of the output data according to the decryption result and the verification result of the data watermark of the output data to obtain the marked data message includes:
[0016] When the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification is successful and the data hash value verification fails, the output data message is marked to obtain the marked data message.
[0017] In one embodiment, deleting the invalid data based on the data watermark of the non-output data includes:
[0018] Traversing file header identifiers of the unoutput data in an independent redundant disk array, and taking the unoutput data having the same file header identifier as the failed data as target data, the independent redundant disk array being composed of hard disk resources of the supervisor and hard disk resources of the computing power provider, the file header identifier being obtained based on the data watermark;
[0019] When the hash value of the target data is the same as the hash value of the invalid data, the target data is deleted, the hash value including a watermark hash value and a data hash value.
[0020] In one embodiment, the detecting invalid data in the non-output data based on the data watermark of the non-output data includes:
[0021] determining, based on an expiration time of the data watermark, that the unoutput data is the expired data, wherein the expiration time is determined based on a timestamp of the data watermark;
[0022] Alternatively, the invalid data is determined based on the termination requirement information of the data provider and the file header identifier of the data watermark.
[0023] In one embodiment, obtaining the marked data message includes:
[0024] If the decryption result is decryption failure, the output data message is marked to obtain the marked data message.
[0025] In one embodiment, before marking the output data message of the output data according to the decryption result and the verification result of the data watermark of the output data to obtain the marked data message, the method further includes:
[0026] If the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification is successful and the data hash value verification is successful, output a first alarm message;
[0027] If the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification fails and the data hash value verification succeeds, a second alarm message is output.
[0028] In a second aspect, the present application provides a data supervision device, comprising:
[0029] The acquisition module is used to obtain the output data and unoutput data of the computing power provider;
[0030] a marking module, configured to mark an output data message of the output data according to a decryption result and a verification result of the data watermark of the output data, to obtain a marked data message;
[0031] an alarm module, configured to output alarm information of the target sensitive data based on the target sensitive data and original sensitive data corresponding to the marked data message, wherein the original sensitive data includes sensitive data provided by a data provider;
[0032] The verification module is used to detect invalid data in the non-output data based on the data watermark of the non-output data and delete the invalid data.
[0033] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory storing a computer program, wherein when the processor executes the program, the data supervision method described in the first aspect is implemented.
[0034] In a fourth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which, when executed by a processor, implements the data supervision method described in the first aspect.
[0035] In a fifth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data supervision method described in the first aspect.
[0036] The data supervision method, device, electronic device, product and storage medium provided in the embodiments of the present application obtain the output data and non-output data of the computing power provider; mark the output data message of the output data according to the decryption result and verification result of the data watermark of the output data to obtain a marked data message; output the alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message, and the original sensitive data includes the sensitive data provided by the data provider; detect the invalid data in the non-output data based on the data watermark of the non-output data, and delete the invalid data. The embodiments of the present application determine the marked data message based on the decryption result and the verification result, monitor the marked data text, and improve the efficiency of outputting computing power data; based on the comparison result of the target sensitive data and the original sensitive data, alarm the output of the target sensitive data, which is beneficial to protecting the target sensitive data; by deleting the invalid data, it is beneficial to protect the non-output data and prevent the non-output data from being improperly used, thereby realizing comprehensive supervision of computing power data and further improving the security of computing power data. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the present application or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0038] Figure 1 This is one of the flow charts of the data supervision method provided in the embodiment of the present application;
[0039] Figure 2 This is the second flow chart of the data supervision method provided in the embodiment of the present application;
[0040] Figure 3 This is a schematic diagram of the structure of the data watermark provided in the embodiment of the present application;
[0041] Figure 4 This is the third flow chart of the data supervision method provided in the embodiment of the present application;
[0042] Figure 5 This is the fourth flowchart of verifying unoutput data provided in the embodiment of the present application;
[0043] Figure 6 Schematic diagram of the structure of the data monitoring device provided in the embodiment of the present application;
[0044] Figure 7 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0045] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0046] Figure 1 This is one of the flow charts of the data supervision method provided in the embodiment of this application. Figure 1 , this embodiment of the application provides a data supervision method, including:
[0047] Step 100: Obtain the output data and non-output data of the computing power provider.
[0048] The output data and the unoutput data are the computing power data of the computing power provider. The computing power data includes sensitive data.
[0049] The execution subject of the embodiment of the present application is the supervisory party, which specifically includes a server, processor, computer, etc. with a supervisory function. The supervisory party is responsible for supervising the outflow of computing power data processed by the computing power provider and the deletion of computing power data.
[0050] like Figure 2 As shown in Figure 1, the data provider transmits the initial data to the computing power provider. The computing power provider cleans, integrates, calculates, and stores the initial data and then outputs the computing power data.
[0051] Computing power providers are devices that provide various computing resources, including general-purpose processors such as CPUs and GPUs. Computing power providers can be physical or virtualized. They must install the corresponding computing power provider agent software, which is responsible for proxying the computing power provider's data output, identifying sensitive data, and determining the content of security domain messages. Computing power providers are supervised by the supervisory party and reside within the security domain. Data providers must access the computing power provider through the data provider agent software. In this application, the security domain is trusted by default, and sensitive data is securely cleaned, integrated, calculated, and stored within the security domain.
[0052] The supervisor is used to supervise the outflow of output data and the deletion of invalid data in the non-output data.
[0053] Step 200: Mark the output data message of the output data according to the decryption result and the verification result of the data watermark of the output data to obtain a marked data message.
[0054] Data watermarks are used to protect sensitive data within computing power data. The sensitive data, target sensitive data, and original sensitive data in this application include extremely sensitive and sensitive data within the computing power network. The classification and location of sensitive data within the computing power network are shown in Table 1.
[0055] Table 1 Classification and location of sensitive data in computing power network
[0056]
[0057]
[0058] Data watermarking is a technology that embeds identification information into digital media. Data watermarking is used to protect copyright, prevent piracy and fraud. Data watermarking must ensure configurability, security, and traceability. This application arranges the content of data watermarks accordingly. Specific data watermark content is as follows: Figure 3 As shown in the figure, data watermarks are used for the overall preliminary screening of data output by the computing power provider's proxy software, as well as for sensitive data matching screening during the supervisory party's monitoring of output data packets (traffic monitoring).
[0059] like Figure 3 As shown, the data watermark includes a watermark header identifier, computing power provider ID, data type, sensitive data (including sensitive data type and quantity), timestamp, data hash value, and watermark hash value.
[0060] The file header is identified as a specific watermark header field. The watermark header identifier can be set to 16 bits to mark this field as a watermark field.
[0061] The computing power provider ID is a unique 128-bit identifier assigned to the computing power provider after it joins the computing power network.
[0062] The data type includes 16 bits, which are labeled according to the data type classification. The first 8 bits label the data classification, such as image files, text files, audio files, video files, etc., and the last 8 bits label the specific format of the data.
[0063] Sensitive Data: Based on the sensitive data classification and grading rules in Table 1, extract the extremely sensitive and sensitive data from the data provider to obtain the sensitive data. The extracted sensitive data is sequentially stored in the data watermark, separated by delimiters. If the sensitive data is too large, an MD5 hash is used instead. Timestamp: Indicates the current time, consisting of 52 bits.
[0064] The data hash value is the MD5 hash value of the data, totaling 128 bits. The watermark hash is the hash value obtained by performing an MD5 operation on the computing power provider ID, data type, sensitive data, timestamp, data hash, and other data in the data watermark, totaling 128 bits.
[0065] like Figure 2 As shown, the data provider installs the data provider agent software provided by the supervisor. The data provider agent software automatically generates a key and sends the key to the supervisor. The data provider agent software screens sensitive information based on the initial data (e.g., file data) submitted by the data provider, extracts sensitive data from the initial data, and records the type and amount of sensitive data. The data provider agent software encrypts the sensitive data based on the previously generated key. Different digital watermark embedding algorithms are selected according to the type of sensitive data to embed data watermarks (e.g., digital watermarks) in the file data. The data provider agent software sends the file data embedded with the digital watermark to the computing power provider and marks the message containing the file data.
[0066] The computing power provider processes the file data and outputs the processed file data (computing power data). The computing power provider monitors the outflow of computing power data using the computing power provider agent software.
[0067] The computing power provider installs the computing power provider proxy software provided by the supervisor to proxy network requests within the computing power provider environment. The computing power provider submits a network request to the computing power provider proxy software. If the network request is destined for the data provider of the computing power data, the computing power data is directly output to the data provider. If the network request is not destined for the data provider of the computing power data, the computing power provider proxy software initiates a request to the supervisor to obtain the watermark key initially generated by the computing power data provider proxy software. For example, Mr. Yang is the data provider, and Mr. Yang's bank transaction records are the initial data provided by Mr. Yang. If the network request is from Mr. Yang to view Mr. Yang's bank transaction records, the computing power provider proxy software directly outputs the bank transaction records. If the network request is from Ms. Li to view Mr. Yang's bank transaction records, the computing power provider proxy software must request the watermark key from the supervisor. The computing power provider proxy software extracts the data watermark based on the watermark key, decrypts the data watermark, and verifies the source, ownership, integrity, and timeliness of the computing power data. The verification result includes the verification result of the hash value in the data watermark after the data watermark is successfully decrypted.
[0068] According to the decryption result and verification result of the data watermark of the computing power data, it is determined that the computing power data of the secure computing power provider (out of domain) cannot be output, and the output data message header of the computing power data is marked.
[0069] Step 200: Based on the target sensitive data and the original sensitive data corresponding to the marked data message, output alarm information of the target sensitive data.
[0070] Original sensitive data includes sensitive data provided by the data provider.
[0071] The target sensitive data is the sensitive data corresponding to the marked data message. The supervisor detects past traffic at the gateway of the security domain and conducts a data review on the marked data message. The supervisor stores the original sensitive data in the data watermark of the data provider's data message.
[0072] The supervisory party extracts the target sensitive data from the marked data message. For example, the supervisory party extracts the target sensitive data corresponding to the marked data message through feature matching and machine learning methods.
[0073] The supervisor compares the target sensitive data with the original sensitive data and outputs an alarm message based on the comparison result. The alarm message includes different levels of alarms, such as the first alarm message and the second alarm message.
[0074] Step 300: Based on the data watermark of the non-output data, detect invalid data in the non-output data and delete the invalid data.
[0075] Unoutput data refers to computing power data that has not been output by the computing power provider. The data provider and the computing power provider sign a data destruction contract, and the supervisor oversees the destruction of computing power data. The data destruction contract stipulates that after data is sent to the computing power provider, the computing power provider must delete the expired data within an agreed-upon timeframe. Furthermore, the data destruction contract stipulates that the data provider may request the computing power provider to terminate the computation of the computing power data (abort data) and request the deletion of the computing power data at any time. Expired data includes expired data and the initial data of the terminated computing power service.
[0076] For unoutput data, the supervisor verifies whether the expired data has been deleted upon expiration. When the computing service is terminated, the supervisor verifies whether the terminated data has been deleted. The supervisor deletes the expired data from the unoutput data based on its watermark. If the expired data is not deleted, the supervisor assists in its forced deletion to protect the security of the computing data and prevent data misuse or improper exploitation.
[0077] The data supervision method provided by the embodiment of the present application obtains the output data and non-output data of the computing power provider; based on the decryption result and verification result of the data watermark of the output data, the output data message of the output data is marked to obtain a marked data message; based on the target sensitive data and the original sensitive data corresponding to the marked data message, the alarm information of the target sensitive data is output, and the original sensitive data includes the sensitive data provided by the data provider; based on the data watermark of the non-output data, the invalid data in the non-output data is detected and the invalid data is deleted. The embodiment of the present application determines the marked data message based on the decryption result and the verification result, monitors the marked data text, and improves the efficiency of outputting computing power data; based on the comparison result of the target sensitive data and the original sensitive data, an alarm is issued for the output of the target sensitive data, which is beneficial to protecting the target sensitive data; by deleting the invalid data, it is beneficial to protect the non-output data and prevent the non-output data from being improperly used, thereby realizing comprehensive supervision of the computing power data and further improving the security of the computing power data.
[0078] Based on the above embodiment, outputting alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message includes:
[0079] Step 210: When original sensitive data exists in the target sensitive data, output a first alarm message;
[0080] Step 220: When the original sensitive data does not exist in the target sensitive data and sensitive data exists in the data output by the supervisory party, the target sensitive data and the second alarm information are output. The supervisory party is used to supervise the processing of the data by the computing power provider. The alarm level of the first alarm information is higher than that of the second alarm information.
[0081] The supervisory party has pre-stored the original sensitive data provided by the data provider. If the original sensitive data is found in the target sensitive data, it indicates that the target data is highly private and cannot be freely exported. The supervisory party will issue the first alarm message (high-level alarm) for the target sensitive data. In this case, the supervisory party will not export the target sensitive data.
[0082] The supervisory party pre-records sensitive data in the output data. If the target sensitive data does not contain the original data, but the supervisory party's output data contains sensitive data, it indicates that the supervisory party has previously output sensitive data. In this case, the supervisory party outputs the target sensitive data and simultaneously issues a secondary alarm message (low-level alarm) for the target sensitive data.
[0083] The embodiment of the present invention improves the security of output target sensitive data by comparing target sensitive data with original sensitive data.
[0084] Based on the above embodiment, the data watermark includes a watermark hash value and a data hash value. According to the decryption result and verification result of the data watermark of the output data, the output data message of the output data is marked to obtain a marked data message, including:
[0085] Step 110: When the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification is successful and the data hash value verification fails, the output data message is marked to obtain a marked data message.
[0086] The Mark Data message is used to mark the computing power data that was not successfully output by the computing power provider.
[0087] If the decryption result is successful, the verification result is successful watermark hash value verification, and the data hash value verification fails, it means that the initial data corresponding to the computing power data is not fully output. In this case, the output data message needs to be marked to obtain a marked data message.
[0088] Optionally, obtaining a marked data message specifically includes: if the decryption result is decryption failure, marking the output data message to obtain a marked data message.
[0089] When the decryption result is decryption failure, it means that the output data has not been successfully extracted. At this time, the output data message is marked to obtain a marked data message.
[0090] Furthermore, if the decryption result is successful decryption, and the verification result is successful watermark hash value verification and successful data hash value verification, a first alarm message is output; if the decryption result is successful decryption, and the verification result is failed watermark hash value verification and successful data hash value verification, a second alarm message is output.
[0091] If the watermark decryption of the computing power data is successful, and both the watermark hash value and the data hash value in the data watermark are successfully verified, the original file corresponding to the computing power data has been completely output. Since the destination of the network request is not the data provider of the computing power data, an alarm is required for the computing power data output by the computing power provider, and the alarm level is high. In this case, the supervisor does not output the computing power data.
[0092] If the watermark decryption of the computing power data is successful and the watermark hash value verification is successful, but the watermark hash value verification fails, it means that the computing power data output by the computing power provider is complete, but the data watermark of the computing power data may have been tampered with. In this case, the supervisor will not output the computing power data. The supervisor will issue an alarm for the computing power data output by the computing power provider, and the alarm level is high.
[0093] The embodiment of the present invention determines the marked data message based on the decryption result, the verification result of the watermark hash value, and the verification result of the data hash value, thereby improving the efficiency of outputting defective computing power data. The embodiment of the present invention issues an alarm for the output of computing power data based on the decryption result, the verification result of the watermark hash value, and the verification result of the data hash value, which is conducive to protecting computing power data and preventing it from being improperly used.
[0094] Based on the above embodiment, deleting invalid data based on the data watermark of the unoutput data includes:
[0095] Step 310: Traverse the file header identifiers of unoutput data in the independent redundant disk array, and use the unoutput data with the same file header identifier as the failed data as the target data. The independent redundant disk array is composed of the hard disk resources of the supervisor and the hard disk resources of the computing power provider. The file header identifier is obtained based on the data watermark.
[0096] Step 320: When the hash value of the target data is the same as the hash value of the invalid data, the target data is deleted, where the hash value includes the watermark hash value and the data hash value.
[0097] Based on the data watermark of the unoutput data, invalid data in the unoutput data is detected. Specifically, based on the expiration time of the data watermark, the unoutput data is determined to be invalid data, and the expiration time is determined based on the timestamp of the data watermark; or, based on the termination request information of the data provider and the file header identifier of the data watermark, the invalid data is determined.
[0098] The data provider first initiates a request to use the computing power network. The computing power provider then initializes the computing power resource environment and constructs a dedicated supervisory managed hard drive environment. After initialization is complete, the data provider enters initial data. Upon receipt of the initial data from the computing power provider, the supervisor records the expiration date of the initial data. Once the computing power service is terminated or the computing power data expires, the supervisor verifies the deletion of the expired data to ensure complete removal.
[0099] The initialization process of the computing power resource environment includes: (1) The data provider initiates a request to use the computing power network provided by the computing power provider, and the supervisor randomly selects the initial data submitted by a data provider as the supervision target. The retention time of the initial data is set according to the data retention time specified in the data destruction contract. (2) The data provider initiates a request to use the computing power network. After the data provider's agent software marks the use request, it sends the use request message to the computing power provider. (3) After receiving the marked use request, the computing power provider allocates a virtual computing power environment for the use request. While allocating hard disk resources, the computing power provider extracts an empty hard disk of the same specification from the supervisor's virtual hard disk pool, and forms an independent redundant disk array (RAID) with the hard disk resources of the virtual computing power environment, thereby completing the initialization of the computing power resource environment.
[0100] Computing power service usage process: (1) The data provider sends the initial data to the computing power provider. (2) The data provider's agent software extracts the initial data and generates a data watermark for the initial data. At the same time, the data provider's agent software sends the watermark header identifier (file header identifier), data type, data hash value, watermark hash value, and timestamp in the data watermark to the supervisor. (3) The supervisor records the information in the received data watermark and calculates the expiration time of this initial data based on the timestamp in the data watermark. (4) During the calculation of the initial data, the supervisor continuously monitors the expiration time (expiration time) of the initial data in the unoutput data of the computing power provider. If the initial data expires (expires) or the data provider stops using the initial data, the supervisor executes the destruction result verification alarm procedure.
[0101] Verification and alarm procedure for the destruction of unoutput data: (1) The supervisory party physically copies the supervisory party's hard disk that constitutes the RAID to a new verification hard disk through the computing power provider's host. (2) The supervisory party traverses and searches all sectors on the verification hard disk based on the file header identifier of the expired initial data (invalid data), traverses the file header identifiers of all unoutput data in the RAID, and uses the unoutput data with the same file header identifier as the expired data as the target data. Calculate the hash value of the target data, including calculating the watermark hash value and data hash value of the target data. If the hash value of the target data is the same as the hash value of the expired data (including the same watermark hash value and the same data hash value), it means that the target data has not been deleted at the expiration date, and an alarm is issued for the target data. (3) The supervisory party obtains the file header identifier of the terminated initial data based on the termination request information of the data provider. The supervisor searches all sectors on the verification hard drive based on the file header identifier of the aborted initial data. The supervisor searches the file header identifiers of all undeleted data in the RAID array and selects the undeleted data with the same file header identifier as the aborted initial data as the target data. The supervisor calculates the hash value of the target data. If the hash value of the target data matches the hash value of the invalid data, it indicates that the target data has not been deleted, and an alarm is issued for the target data.
[0102] If the data provider's initial data is not deleted after the expiration date, the supervisor can issue a command to the computing power provider to supervise the RAID disk array to forcibly delete the target data, overwriting the target data's physical location in the RAID with random data multiple times to prevent data recovery. Similarly, if the computing power service is terminated, all contents on the computing power provider's hard drive and the supervisor's hard drive will be forcibly deleted, and the random data will be overwritten multiple times to prevent data recovery.
[0103] The embodiment of the present application determines the target data that has not been deleted in time based on the file header identifier and data watermark, realizes comprehensive supervision of the computing power data, and further improves the security of the computing power data.
[0104] In order to further explain the data supervision method provided in the embodiment of the present application, the following examples and Figure 4 、 5 To explain:
[0105] like Figure 4 、 5As shown, a data supervision method includes the following steps: (1) the data provider inputs the initial data. (2) the computing power receiver receives the initial data and processes the initial data. (3) the computing power provider outputs the initial data to the computing power data agent software. (4) if the destination of the computing power data output is not the data provider of the computing power data, the supervisor supervises the output data of the computing power provider. The supervisor determines whether the output data (computing power data) contains the input original sensitive data. If the computing power data contains the original sensitive data, the supervisor issues a high-level alarm for the computing power data. (5) if the original sensitive data does not exist in the computing power data, the supervisor determines whether the data watermark of the computing power data has been tampered with: if the watermark hash value verification of the computing power data fails but the data hash value verification succeeds, it means that the data watermark of the computing power data has been tampered with. At this time, the supervisor does not output the computing power data and issues a high-level alarm for the computing power data. (6) if the data watermark has not been tampered with, the supervisor determines whether there is sensitive data in the data already output by the supervisor. If there is sensitive data in the data already output by the supervisor, a low-level alarm is issued. (7) Verify that the computing power provider has not output data. The data provider initiates a computing power network usage request to the computing power provider. The computing power provider initializes the computing power resource environment based on the usage request. The supervisor checks whether the expired data in the RAID is deleted. If the expired data is not deleted, the supervisor forcibly deletes the expired data. The supervisor checks whether the suspended data in the RAID is deleted. If the suspended data is not deleted, an alarm is issued for the suspended data and data is cleared on the disk corresponding to the suspended data.
[0106] This application supports targeted data tracking and management. Most existing technologies are from the perspective of data management, managing the inflow and outflow of data within the entire domain; this application stands from the perspective of the data owner and conducts corresponding tracking and monitoring from the beginning of data inflow. The existing technology cannot confirm the integrity and tampering of the initial data itself, while the present invention will monitor the integrity of the files flowing in and out of the data, and use data watermarks to determine whether the computing power data has been tampered with. While monitoring the inflow and outflow of file data, it can also effectively determine whether there is an attack on the computing power. While monitoring the transmission and tampering of computing power data through data watermark technology, this application also uses data classification and grading and traffic monitoring to determine the outflow of sensitive data in the computing power data, and conducts data security outflow supervision and trusteeship at different levels. The method has a relatively complete coverage and is more in line with the actual application scenarios of the computing power network. The existing technical means of data log investigation and deletion policy auditing to determine whether the file is retained cannot confirm the validity of the actual deletion. The deletion operation itself may only delete the file index, and cannot prove that the file has been completely erased from the disk and cannot be recovered. This application searches the disk based on the file header index, finds the beginning of the file, and restores the file, which can verify the file's irrecoverability to a certain extent. At the same time, this solution uses the disk array to attempt to delete and restore files without affecting the normal disk reading and writing of computing power users, effectively monitoring the real-time data destruction.
[0107] The following describes the data supervision device provided by the embodiment of the present application. The data supervision device described below and the data supervision method described above can be referenced to each other. Figure 6 , Figure 6 Schematic diagram of the structure of the data monitoring device provided in the embodiment of the present application. A data monitoring device includes:
[0108] Acquisition module 601, used to obtain the output data and unoutput data of the computing power provider;
[0109] The marking module 602 is used to mark the output data message of the output data according to the decryption result and the verification result of the data watermark of the output data to obtain a marked data message;
[0110] An alarm module 603 is configured to output alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message, where the original sensitive data includes the sensitive data provided by the data provider;
[0111] The verification module 604 is configured to detect invalid data in the non-output data based on the data watermark of the non-output data and delete the invalid data.
[0112] The data supervision device provided by the embodiment of the present application obtains the output data and non-output data of the computing power provider; marks the output data message of the output data according to the decryption result and verification result of the data watermark of the output data to obtain a marked data message; outputs the alarm information of the target sensitive data based on the target sensitive data and the original sensitive data corresponding to the marked data message, and the original sensitive data includes the sensitive data provided by the data provider; detects invalid data in the non-output data based on the data watermark of the non-output data, and deletes the invalid data. The embodiment of the present application determines the marked data message based on the decryption result and the verification result, monitors the marked data text, and improves the efficiency of outputting computing power data; based on the comparison result of the target sensitive data and the original sensitive data, alarms the output of the target sensitive data, which is beneficial to protecting the target sensitive data; by deleting the invalid data, it is beneficial to protect the non-output data and prevent the non-output data from being improperly used, thereby realizing comprehensive supervision of the computing power data and further improving the security of the computing power data.
[0113] In one embodiment, the alarm module 603 is used to: output a first alarm message when original sensitive data exists in the target sensitive data; output the target sensitive data and a second alarm message when original sensitive data does not exist in the target sensitive data and sensitive data exists in the data output by the supervisory party. The supervisory party is used to supervise the processing of data by the computing power provider, and the alarm level of the first alarm message is higher than that of the second alarm message.
[0114] In one embodiment, the data watermark includes a watermark hash value and a data hash value. The marking module 602 is used to mark the output data message to obtain a marked data message when the decryption result is successful decryption and the verification result is successful watermark hash value verification and failed data hash value verification.
[0115] In one embodiment, the verification module 604 is used to: delete invalid data based on the data watermark of the unoutput data, including: traversing the file header identifier of the unoutput data in the independent redundant disk array, and taking the unoutput data with the same file header identifier as the invalid data as the target data, the independent redundant disk array is composed of the hard disk resources of the supervisory party and the hard disk resources of the computing power provider, and the file header identifier is obtained based on the data watermark; when the hash value of the target data is the same as the hash value of the invalid data, deleting the target data, the hash value includes the watermark hash value and the data hash value.
[0116] In one embodiment, the verification module 604 is used to: determine that the unoutput data is invalid data based on the expiration time of the data watermark, and the expiration time is determined based on the timestamp of the data watermark; or determine the invalid data based on the termination requirement information of the data provider and the file header identifier of the data watermark.
[0117] In one embodiment, the marking module 602 is configured to obtain a marked data message, including marking the output data message if the decryption result is decryption failure, to obtain a marked data message.
[0118] In one embodiment, the marking module 602 is also used to: if the decryption result is successful decryption, and the verification result is that the watermark hash value verification is successful and the data hash value verification is successful, then output a first alarm message; if the decryption result is successful decryption, and the verification result is that the watermark hash value verification fails and the data hash value verification is successful, then output a second alarm message.
[0119] Figure 7 An example of a physical structure diagram of an electronic device is shown below. Figure 7 As shown, the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740, wherein the processor 710, the communication interface 720, and the memory 730 communicate with each other via the communication bus 740. The processor 710 may call a computer program in the memory 730 to execute a data supervision method, for example, including:
[0120] Obtain the output data and non-output data of the computing power provider; mark the output data message of the output data according to the decryption result and verification result of the data watermark of the output data to obtain the marked data message; based on the target sensitive data and original sensitive data corresponding to the marked data message, output the alarm information of the target sensitive data, and the original sensitive data includes the sensitive data provided by the data provider; based on the data watermark of the non-output data, detect the invalid data in the non-output data and delete the invalid data.
[0121] In addition, the logic instructions in the above-mentioned memory 730 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0122] On the other hand, embodiments of the present application further provide a computer program product, comprising a computer program. The computer program may be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the data supervision method provided in each of the above embodiments, for example, including:
[0123] Obtain the output data and non-output data of the computing power provider; mark the output data message of the output data according to the decryption result and verification result of the data watermark of the output data to obtain the marked data message; based on the target sensitive data and original sensitive data corresponding to the marked data message, output the alarm information of the target sensitive data, and the original sensitive data includes the sensitive data provided by the data provider; based on the data watermark of the non-output data, detect the invalid data in the non-output data and delete the invalid data.
[0124] On the other hand, an embodiment of the present application further provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores a computer program, wherein the computer program is configured to cause a processor to execute the data supervision method provided in each of the above embodiments, for example, including:
[0125] Obtain the output data and non-output data of the computing power provider; mark the output data message of the output data according to the decryption result and verification result of the data watermark of the output data to obtain the marked data message; based on the target sensitive data and original sensitive data corresponding to the marked data message, output the alarm information of the target sensitive data, and the original sensitive data includes the sensitive data provided by the data provider; based on the data watermark of the non-output data, detect the invalid data in the non-output data and delete the invalid data.
[0126] The non-transitory computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid-state drives (SSDs)), etc.
[0127] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data supervision method, characterized in that: include: Obtain the output data and unoutput data of the computing power provider; The output data is computing power data that has been output from the computing power provider, and the unoutput data is computing power data that has not been output from the computing power provider; the computing power data includes sensitive data; Obtaining a decryption result and a verification result of the data watermark of the output data, and when the decryption result is a successful decryption and the verification result is a successful watermark hash value verification and a failed data hash value verification, marking an output data message of the output data to obtain a marked data message; the data watermark includes the watermark hash value and the data hash value; When the original sensitive data exists in the target sensitive data, a first alarm message is output; when the original sensitive data does not exist in the target sensitive data and the sensitive data exists in the data output by the supervisor, the target sensitive data and a second alarm message are output. The supervisor is used to supervise the processing of the data by the computing power provider. The alarm level of the first alarm message is higher than that of the second alarm message. The original sensitive data includes the sensitive data provided by the data provider; the sensitive data corresponding to the marked data message is the target sensitive data; Based on the data watermark of the unoutput data, invalid data in the unoutput data is detected and deleted. The invalid data includes expired data and initial data of the terminated computing power service. The initial data is data transmitted by the data provider to the computing power provider.
2. The data supervision method according to claim 1, characterized in that Deleting the invalid data based on the data watermark of the non-output data includes: Traversing file header identifiers of the unoutput data in an independent redundant disk array, and taking the unoutput data having the same file header identifier as the failed data as target data, the independent redundant disk array being composed of hard disk resources of the supervisor and hard disk resources of the computing power provider, the file header identifier being obtained based on the data watermark; When the hash value of the target data is the same as the hash value of the invalid data, the target data is deleted, the hash value including a watermark hash value and a data hash value.
3. The data supervision method according to claim 1, characterized in that The detecting invalid data in the non-output data based on the data watermark of the non-output data includes: determining, based on an expiration time of the data watermark, that the unoutput data is the expired data, wherein the expiration time is determined based on a timestamp of the data watermark; Alternatively, the invalid data is determined based on the termination requirement information of the data provider and the file header identifier of the data watermark.
4. The data supervision method according to claim 1, characterized in that Obtaining the marked data message includes: If the decryption result is decryption failure, the output data message is marked to obtain the marked data message.
5. The data supervision method according to claim 1, characterized in that Before marking the output data message of the output data to obtain the marked data message, the method further includes: If the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification is successful and the data hash value verification is successful, output a first alarm message; If the decryption result is that the decryption is successful, and the verification result is that the watermark hash value verification fails and the data hash value verification succeeds, a second alarm message is output.
6. A data supervision device, characterized in that: include: The acquisition module is used to obtain the output data and unoutput data of the computing power provider; The output data is computing power data that has been output from the computing power provider, and the unoutput data is computing power data that has not been output from the computing power provider; the computing power data includes sensitive data; a marking module, configured to obtain a decryption result and a verification result of the data watermark of the output data, and when the decryption result is a successful decryption and the verification result is a successful watermark hash value verification and a failed data hash value verification, mark the output data message of the output data to obtain a marked data message; the data watermark includes the watermark hash value and the data hash value; An alarm module is configured to output a first alarm message when original sensitive data exists in the target sensitive data; and output the target sensitive data and a second alarm message when the original sensitive data does not exist in the target sensitive data and the sensitive data exists in the data output by the supervisory party. The supervisory party is configured to supervise the processing of the data by the computing power provider. The alarm level of the first alarm message is higher than that of the second alarm message. The original sensitive data includes the sensitive data provided by the data provider. The sensitive data corresponding to the marked data message is the target sensitive data. A verification module is used to detect invalid data in the unoutput data based on the data watermark of the unoutput data and delete the invalid data. The invalid data includes expired data and initial data of the terminated computing power service. The initial data is the data transmitted by the data provider to the computing power provider.
7. An electronic device comprising a processor and a memory storing a computer program, characterized in that: When the processor executes the computer program, the data supervision method according to any one of claims 1 to 5 is implemented.
8. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the data supervision method according to any one of claims 1 to 5 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the data supervision method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Method and apparatus of DRM systems for protecting enterprise confidentiality
US20170329942A1
Data processing method and device, and computer device and readable storage medium
WO2024001558A1