Cross-network document approval method, device and storage medium

By developing targeted sensitivity detection strategies for cross-network files, scanning sensitive features based on user tags of the initiator and creator, and selecting appropriate approval modes, the problem of low efficiency in cross-network file approval is solved, achieving fast, accurate sensitivity detection and secure transmission.

CN119026163BActive Publication Date: 2025-10-28HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411031835.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-30
Publication Date
2025-10-28
Estimated Expiration
2044-07-30

AI Technical Summary

Technical Problem

Existing technologies have low sensitivity detection efficiency for cross-network files, resulting in excessively long approval times, which reduces the efficiency and accuracy of cross-network file approval and affects transmission security.

Method used

By obtaining user tags from the initiator and creator, targeted sensitive detection strategies are formulated, including local, superior, and system-level detection strategies. Sensitive features of cross-network files are scanned to determine the sensitivity detection level, and appropriate approval modes are selected based on the level for approval.

Benefits of technology

It improves the efficiency and accuracy of sensitive detection of cross-network files, ensures the speed and accuracy of approval, and enhances transmission security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119026163B_ABST
    Figure CN119026163B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, and storage medium for cross-network file approval. The method includes: obtaining an outgoing request from an initiator for any cross-network file, the outgoing request carrying the cross-network file and a first user tag corresponding to the initiator; obtaining a first sensitivity detection strategy corresponding to the first user tag, the first sensitivity detection strategy being constructed based on the initiator's sensitive information, the sensitive information of the initiator's superior user, and pre-set general sensitive information; scanning the cross-network file based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network file; determining an approval mode for the cross-network file based on the sensitivity detection level, and approving the cross-network file according to the approval mode, thereby improving the efficiency and accuracy of sensitivity detection for cross-network files, making the approval of cross-network files faster and more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, specifically to a cross-network file approval method, apparatus, and storage medium. Background Technology

[0002] In existing technologies, when approving cross-network documents, all sensitive words involved by different organizations or teams are used for sensitivity detection, and the approval of cross-network documents is based on the results of the sensitivity detection.

[0003] However, based on the above scheme, when a user initiates a cross-network file transfer request, the system needs to match all sensitive words in the cross-network file. During the matching process, there may be sensitive words that have no overlap with the user's, which reduces the efficiency of sensitive detection for cross-network files and makes the approval time for cross-network files too long. This reduces the efficiency and accuracy of cross-network file approval and greatly affects the security of cross-network file transmission. Summary of the Invention

[0004] The purpose of this application is to provide a cross-network file approval method, apparatus, and storage medium to solve the problem of low approval efficiency and accuracy caused by unreasonable sensitivity detection of cross-network files in the prior art.

[0005] To achieve the above objectives, the first aspect of this application provides a cross-network document approval method, comprising:

[0006] Obtain the outbound request from the initiator for any cross-network file. The outbound request carries the cross-network file and the first user tag corresponding to the initiator.

[0007] Obtain the first sensitive detection strategy corresponding to the first user tag. The first sensitive detection strategy is constructed based on the sensitive information of the initiator, the sensitive information of the initiator's superior user, and pre-defined general sensitive information.

[0008] The first sensitivity detection strategy is used to scan cross-network files to determine the sensitivity detection level of the cross-network files.

[0009] The approval mode for cross-network documents is determined based on the sensitivity detection level, and the cross-network documents are approved according to the approval mode.

[0010] In this embodiment of the application, scanning cross-network files based on a first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files includes: determining the creator of the cross-network file and obtaining a second user tag corresponding to the creator; if the first user tag and the second user tag are inconsistent, obtaining a second sensitivity detection strategy corresponding to the second user tag, wherein the second sensitivity detection strategy is constructed based on the sensitive information of the creator and the sensitive information of the creator's superior user; and scanning cross-network files based on the first sensitivity detection strategy and the second sensitivity detection strategy to determine the sensitivity detection level of the cross-network files.

[0011] In this embodiment of the application, the first sensitivity detection strategy includes a first local-level detection strategy, a first superior-level detection strategy, and a system-level sensitivity detection strategy. The second sensitivity detection strategy includes a second local-level detection strategy and a second superior-level detection strategy. The method further includes: constructing the first local-level detection strategy and the first superior-level detection strategy based on the sensitive information of the initiator and the sensitive information of the initiator's superior user, respectively; constructing a system-level sensitivity detection strategy based on general sensitive information; and constructing the second local-level detection strategy and the second superior-level detection strategy based on the sensitive information of the creator and the sensitive information of the creator's superior user, respectively.

[0012] In this embodiment, the sensitive information includes multiple sensitive feature dimensions, each of which corresponds to multiple sensitive feature items. Scanning cross-network files based on a first sensitive detection strategy and a second sensitive detection strategy to determine the sensitivity detection level of the cross-network files includes: sequentially scanning the cross-network files based on a first local-level detection strategy, a first higher-level detection strategy, and a system-level sensitive detection strategy to obtain the first sensitive feature items detected during the scan; sequentially scanning the cross-network files based on a second local-level detection strategy and a second higher-level detection strategy to obtain the second sensitive feature items detected during the scan; and determining the sensitivity detection level based on all the first sensitive feature items and all the second sensitive feature items.

[0013] In this embodiment of the application, each sensitive feature item corresponds to a preset level. Determining the sensitivity detection level based on all first sensitive features items and all second sensitive features items includes: obtaining the first preset level corresponding to each first sensitive feature item and obtaining the second preset level corresponding to each second sensitive feature item; selecting the highest preset level from all first preset levels and all second preset levels as the sensitivity detection level.

[0014] In this embodiment of the application, approving cross-network files according to the approval mode includes: obtaining the initiator's permission to send cross-network files; and, if the sending permission is an allowed permission, approving the cross-network files according to the approval mode.

[0015] In this embodiment of the application, the approval of cross-network files according to the approval mode includes: when the approval mode is automatic approval mode, determining that the approval result for the cross-network file is passed; when the approval mode is single-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the first-level superior user of the initiator; when the approval mode is multi-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the superior user of the initiator.

[0016] In this embodiment of the application, determining the approval mode for cross-network files based on the sensitivity detection level includes: when the sensitivity detection level is level 1, determining the approval mode for cross-network files as an automatic approval mode; when the sensitivity detection level is level 2, determining the approval mode for cross-network files as a single-level manual approval mode; and when the sensitivity detection level is level 3, determining the approval mode for cross-network files as a multi-level manual approval mode.

[0017] In this embodiment of the application, the method further includes: if the approval result of the cross-network file is passed, sending the cross-network file to the target user across the network, so as to perform file download and tag setting operations if the target user has download permissions for the cross-network file.

[0018] A second aspect of this application provides a cross-network document approval device, comprising:

[0019] The memory is configured to store instructions; and

[0020] The processor is configured to retrieve instructions from memory and, when executing instructions, to implement the aforementioned cross-network file approval method.

[0021] A third aspect of this application provides a machine-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the aforementioned cross-network file approval method.

[0022] The fourth aspect of this application provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned cross-network document approval method.

[0023] The above technical solution allows for targeted sensitivity detection strategies to be developed based on the initiator and creator of cross-network files. This enables targeted sensitivity detection of cross-network files, improving the efficiency and accuracy of sensitivity detection and making the approval of cross-network files faster and more accurate, thereby enhancing the security of cross-network file transmission.

[0024] Other features and advantages of the embodiments of this application will be described in detail in the following detailed description section. Attached Figure Description

[0025] The accompanying drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the following detailed description to explain the embodiments of this application, but do not constitute a limitation on the embodiments of this application. In the drawings:

[0026] Figure 1 The schematic diagram illustrates a flowchart of a cross-network document approval method according to an embodiment of this application;

[0027] Figure 2 The schematic diagram illustrates a cross-network document approval method according to another embodiment of this application;

[0028] Figure 3 A schematic diagram of a cross-network document approval system according to an embodiment of this application is shown.

[0029] Figure 4 The diagram illustrates the internal structure of a computer device according to an embodiment of this application. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0031] It should be noted that if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0032] Figure 1 A schematic diagram illustrating the flow of a cross-network document approval method according to an embodiment of this application is provided. Figure 1 As shown in one embodiment of this application, a cross-network document approval method is provided, including the following steps:

[0033] Step 101: Obtain the outbound request from the initiator for any cross-network file. The outbound request carries the cross-network file and the first user tag corresponding to the initiator.

[0034] Cross-network refers to networks that cannot directly connect to the Internet and a local area network (LAN). A cross-network file refers to a file that needs to be transferred across networks. The initiator can send an outbound request for any cross-network file to the processor. The processor can retrieve the outbound request sent by the initiator. The outbound request carries the cross-network file and a first user tag corresponding to the initiator. The first user tag can be customized; for example, it can be defined using letters and / or numbers and / or text.

[0035] Step 102: Obtain the first sensitivity detection strategy corresponding to the first user tag. The first sensitivity detection strategy is constructed based on the sensitive information of the initiator, the sensitive information of the initiator's superior user, and pre-set general sensitive information.

[0036] The processor can obtain a first sensitivity detection policy corresponding to the first user tag. The first sensitivity detection policy is constructed based on the initiator's sensitive information, the initiator's superior user's sensitive information, and pre-defined general sensitive information.

[0037] In this embodiment of the application, the first sensitive detection strategy includes a first local detection strategy, a first superior detection strategy, and a system-level sensitive detection strategy. The method further includes: constructing the first local detection strategy and the first superior detection strategy based on the sensitive information of the initiator and the sensitive information of the initiator's superior user, respectively; and constructing a system-level sensitive detection strategy based on general sensitive information.

[0038] Sensitive information of the initiator, sensitive information of the initiator's superior user, and general sensitive information can be configured in advance, and settings can be configured according to corresponding requirements. The first sensitivity detection strategy includes the first local level detection strategy, the first superior level detection strategy, and the system-level sensitivity detection strategy.

[0039] The processor can construct a first-level detection strategy and a first-level detection strategy based on the sensitive information of the initiator and the sensitive information of the initiator's superior users, respectively. The initiator may have multiple superior users; in this case, the processor can construct a first-level detection strategy corresponding to each superior user of the initiator according to the hierarchical structure of the organization to which the initiator belongs. The processor can construct a system-level sensitive detection strategy based on general sensitive information. The processor can obtain the first sensitive detection strategy corresponding to the first user tag.

[0040] Step 103: Scan cross-network files based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files.

[0041] The processor can scan cross-network files based on a first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files. Specifically, the processor can sequentially scan cross-network files based on a first local-level detection strategy, a first higher-level detection strategy, and a system-level sensitivity detection strategy to determine the sensitivity detection level of the cross-network files.

[0042] In this embodiment of the application, scanning cross-network files based on a first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files includes: determining the creator of the cross-network file and obtaining a second user tag corresponding to the creator; if the first user tag and the second user tag are inconsistent, obtaining a second sensitivity detection strategy corresponding to the second user tag, wherein the second sensitivity detection strategy is constructed based on the sensitive information of the creator and the sensitive information of the creator's superior user; and scanning cross-network files based on the first sensitivity detection strategy and the second sensitivity detection strategy to determine the sensitivity detection level of the cross-network files.

[0043] The initiator of a cross-network file transfer can be the file's creator or any other party. If the initiator is any other party, scanning the cross-network file based on the first sensitivity detection strategy may bypass the creator's sensitivity detection, leading to the subsequent unauthorized leakage of cross-network files. To ensure more accurate sensitivity detection of subsequent cross-network files, the processor can determine the file's creator and obtain a second user tag corresponding to that creator. This second user tag can be customized, for example, defined using letters and / or numbers and / or text.

[0044] The processor can determine whether the first user tag and the second user tag are consistent. If the first user tag and the second user tag are inconsistent, it means that the initiator of the cross-network file transfer is different from the creator of the cross-network file. To prevent subsequent sensitivity checks on cross-network files from bypassing the creator's sensitive information and thus causing cross-network file leaks, the processor can obtain a second sensitivity detection strategy corresponding to the second user tag. This second sensitivity detection strategy is constructed based on the creator's sensitive information and the sensitive information of the creator's superior user.

[0045] In this embodiment of the application, the second sensitivity detection strategy includes a second local detection strategy and a second superior detection strategy. The method further includes: constructing the second local detection strategy and the second superior detection strategy based on the sensitive information of the creator and the sensitive information of the creator's superior user, respectively.

[0046] Sensitive information of the creator and its parent users can be configured in advance, and settings can be configured according to specific needs. The second sensitivity detection strategy includes a second local-level detection strategy and a second parent-level detection strategy.

[0047] The processor can construct a second local detection strategy and a second superior detection strategy based on the sensitive information of the creator and the sensitive information of the creator's superior users, respectively. The creator may have multiple superior users; in this case, the processor can construct a second superior detection strategy corresponding to each creator's superior user according to the hierarchical structure of the creator's organization.

[0048] In one embodiment, if the first user tag and the second user tag are the same, it means that the initiator of the outgoing cross-network file is the same as the creator of the cross-network file. In this case, the processor does not need to build a second sensitivity detection strategy. It can scan the cross-network file based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network file.

[0049] If the first user tag and the second user tag are inconsistent, the processor scans the cross-network files based on the first sensitivity detection strategy and the determined second sensitivity detection strategy to determine the sensitivity detection level of the cross-network files. The sensitivity detection level may include high sensitivity level, medium sensitivity level, and low sensitivity level.

[0050] In this embodiment, the sensitive information includes multiple sensitive feature dimensions, each of which corresponds to multiple sensitive feature items. Scanning cross-network files based on a first sensitive detection strategy and a second sensitive detection strategy to determine the sensitivity detection level of the cross-network files includes: sequentially scanning the cross-network files based on a first local-level detection strategy, a first higher-level detection strategy, and a system-level sensitive detection strategy to obtain the first sensitive feature items detected during the scan; sequentially scanning the cross-network files based on a second local-level detection strategy and a second higher-level detection strategy to obtain the second sensitive feature items detected during the scan; and determining the sensitivity detection level based on all the first sensitive feature items and all the second sensitive feature items.

[0051] Sensitive information includes multiple sensitive feature dimensions, each with multiple sensitive feature items. The sensitive feature dimension can include the file size, file type, file name, file content, sender, and receiver of cross-network files. Sensitive feature items corresponding to the file name and file content can include ID card number, mobile phone number, and "top secret" status, etc. Sensitive feature items corresponding to the file type can include file extensions for text files, audio files, video files, image files, compressed files, animation files, spreadsheet files, and PowerPoint presentations, etc.

[0052] The processor can sequentially scan cross-network files based on a first-level detection strategy, a first-level detection strategy, and a system-level sensitive detection strategy to obtain the first sensitive features detected during the scan. The processor can also sequentially scan cross-network files based on a second-level detection strategy and a second-level detection strategy to obtain the second sensitive features detected during the scan. That is, when scanning cross-network files based on detection strategies, if data matching the corresponding sensitive feature exists in the cross-network file, it is determined that the sensitive feature has been detected, and the processor can retain this detected sensitive feature. The processor can determine the sensitivity detection level based on all first and second sensitive features.

[0053] In this embodiment of the application, each sensitive feature item corresponds to a preset level. Determining the sensitivity detection level based on all first sensitive features items and all second sensitive features items includes: obtaining the first preset level corresponding to each first sensitive feature item and obtaining the second preset level corresponding to each second sensitive feature item; selecting the highest preset level from all first preset levels and all second preset levels as the sensitivity detection level.

[0054] Each sensitive feature corresponds to a preset level. That is, both the first and second sensitive features will have preset levels. The processor can obtain the first preset level corresponding to each first sensitive feature and the second preset level corresponding to each second sensitive feature. The processor can select the highest preset level from all the first and second preset levels as the sensitivity detection level for cross-network files.

[0055] For example, if the sensitive features under general sensitive information include ID card number, mobile phone number, and "top secret," the preset level for "ID card number" is level 3, the preset level for "mobile phone number" is level 2, and the preset level for "top secret" is level 6. The initiator is team A, and the sensitive features under team A's sensitive information include "buying" and "GDP growth rate," with "buying" having a preset level of level 1 and "GDP growth rate" having a preset level of level 2. Team A's superior is team B, and the sensitive features under team B's sensitive information include file types with the .exe extension.

[0056] After Team A initiates a cross-network file outbound request for itself, sensitive information detection can be performed asynchronously on that cross-network file. Specifically, the cross-network file can first be scanned based on Team A's sensitivity detection strategy to determine if any sensitive features under Team A's sensitive information exist in the file. Then, the cross-network file can be scanned based on Team B's sensitivity detection strategy to determine if any sensitive features under Team B's sensitive information exist in the file. Next, the cross-network file can be scanned based on a system-level sensitivity detection strategy to determine if any sensitive features under general sensitive information exist in the file.

[0057] If the cross-network file is asynchronously checked for sensitive information, and the scanned sensitive features include "buy" and "top secret", with the level of "buy" being level 1 and the level of "top secret" being level 6, then the sensitivity detection level of the cross-network file can be determined to be level 6 based on the principle of choosing the higher level.

[0058] Step 104: Determine the approval mode for cross-network files based on the sensitivity detection level, and approve cross-network files according to the approval mode.

[0059] The processor can determine the approval mode for cross-network files based on the sensitivity detection level. The sensitivity detection level can include high sensitivity, medium sensitivity, and low sensitivity. Different sensitivity detection levels correspond to different approval modes. The higher the sensitivity detection level, the more stringent the approval process. The processor can then approve cross-network files according to the approval mode.

[0060] In this embodiment of the application, determining the approval mode for cross-network files based on the sensitivity detection level includes: when the sensitivity detection level is level 1, determining the approval mode for cross-network files as an automatic approval mode; when the sensitivity detection level is level 2, determining the approval mode for cross-network files as a single-level manual approval mode; and when the sensitivity detection level is level 3, determining the approval mode for cross-network files as a multi-level manual approval mode.

[0061] The approval modes include automatic approval, single-level manual approval, and multi-level manual approval. Single-level manual approval refers to approval by the initiator's first-level superior user. Multi-level manual approval refers to approval by all of the initiator's superior users.

[0062] When the sensitivity detection level is Level 1, the processor can determine that the approval mode for cross-network files is automatic approval mode. When the sensitivity detection level is Level 2, the processor can determine that the approval mode for cross-network files is single-level manual approval mode. When the sensitivity detection level is Level 3, the processor can determine that the approval mode for cross-network files is multi-level manual approval mode.

[0063] For example, if the sensitivity detection level is 0 to 2, it corresponds to an automatic approval mode; if the sensitivity detection level is 3 to 5, it corresponds to a single-level manual approval mode; if the sensitivity detection level is 5 or above, it corresponds to a multi-level manual approval mode. If the sensitivity detection level is 6, then the approval mode can be determined to be a multi-level manual approval mode.

[0064] If the party initiating the cross-network file request does not have the necessary permissions to share it, and the approval process for cross-network files is set to automatic, the file will be approved directly, potentially leading to file leakage. To prevent this, the initiator's permissions to share the cross-network file should be verified before the file is approved according to the automatic approval process.

[0065] Specifically, in this embodiment of the application, approving cross-network files according to the approval mode includes: obtaining the initiator's permission to send cross-network files; and, if the sending permission is an allowed permission, approving the cross-network files according to the approval mode.

[0066] The processor can obtain the initiator's permission to send cross-network files. This permission includes allow and disallow permissions. If the initiator's permission to send cross-network files is "allow," then even if the approval mode for the cross-network file is automatic, approving the file according to the approval mode will not lead to file leakage. If the initiator's permission to send cross-network files is "disallow," then subsequent automatic approval may lead to file leakage. In this case, subsequent approval operations can be eliminated, saving efficiency and resources used in approving cross-network files.

[0067] In this embodiment of the application, the approval of cross-network files according to the approval mode includes: when the approval mode is automatic approval mode, determining that the approval result for the cross-network file is passed; when the approval mode is single-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the first-level superior user of the initiator; when the approval mode is multi-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the superior user of the initiator.

[0068] When the approval mode is automatic, it indicates that the sensitivity detection level of the cross-network file is low, and there is no risk of leakage. The processor can determine the approval result for the cross-network file as passed. When the approval mode is single-level manual, it indicates that the sensitivity detection level of the cross-network file is medium, and there is a possibility of file leakage. The processor can determine the approval result of the cross-network file based on the approval result of the initiator's first-level superior user. Specifically, if the initiator's first-level superior user approves, the cross-network file is approved. If the initiator's first-level superior user rejects, meaning the cross-network file fails the review, the approval result is rejected.

[0069] In a multi-level manual approval mode, the sensitivity level of cross-network files is high, making them highly susceptible to leakage. In this case, the processor can determine the approval result of the cross-network file based on the approval results of the initiating party's superiors. The initiating party may have multiple superiors; in this case, the cross-network file can be approved sequentially from lowest to highest level. If all superiors approve the file, the cross-network file is approved. If any superior rejects the file, the cross-network file fails the review.

[0070] In this embodiment of the application, the method further includes: if the approval result of the cross-network file is passed, sending the cross-network file to the target user across the network, so as to perform file download and tag setting operations if the target user has download permissions for the cross-network file.

[0071] If the cross-network file is approved, the processor can send the file to the target user across the network. Upon receiving the file, the target user can preview it. If the target user needs to download the file, download permissions can be obtained from the user to manage the file's initiator.

[0072] If the target user's download permission for the cross-network file is denied, then the download of the cross-network file by the target user can be prohibited. If the target user's download permission for the cross-network file is allowed, then the download of the cross-network file by the target user can be allowed. In this case, a tag can also be set for the cross-network file when it is downloaded. The tag can include a watermark, which can be the name of the organization where the cross-network file is located, the name of the creator of the cross-network file, or other custom tags related to the cross-network file.

[0073] like Figure 2 As shown, a flowchart illustrating another cross-network document approval method is provided.

[0074] Users can fill in the recipient information for the files. After completing this information, they can initiate an outbound request for the uploaded personal files. Upon receiving the user's outbound request, the system can retrieve the team tag from the personal file, i.e., the team to which the user who initiated the process belongs. Then, the system can obtain the security detection policy corresponding to the team tag, i.e., the sensitivity detection policy, and use this policy to asynchronously perform sensitive information detection on the personal files.

[0075] The security detection strategy can include sensitive file identification policies at the user's team level, the user's superior team level, and the system level. Security detection policies can be formulated before a user initiates an outbound file request. Specifically, system administrators can set system-level sensitive file identification policies, which are public and apply to every personal file. Team administrators can set sensitive file identification policies at the user's team level; the superior team's sensitive file identification policy applies to the sensitive files of subordinate teams. The security detection strategy supports sensitive feature dimensions including file size, file type, file name, file content, initiator, and recipient. Each sensitive feature dimension corresponds to specific sensitive feature items, and each specific sensitive feature item defines a sensitivity level.

[0076] Because cross-network file sharing checks are performed on sensitive keywords related to the user's team, their superior team, and system-wide keywords, it's possible that if a file shared by team A is sent to someone in team B, and team B then initiates a cross-network exchange, they could bypass team A's security checks, leading to unauthorized file leaks. This occurs even when the user is sending a non-personal file. In this case, when retrieving the security checks, if the initiator of the file sharing is different from the file creator, the creator's sensitivity detection policy can also be retrieved. Based on both the retrieved security checks and the creator's sensitivity detection policy, sensitive information checks are performed on the file to prevent unauthorized leaks of non-personal files. If the initiator of the file sharing is the same as the file creator, then retrieving the creator's sensitivity detection policy is unnecessary.

[0077] The approval strategy is derived based on the results of sensitive information detection. The detection result refers to the sensitivity level of the personal document. Sensitivity levels include low, medium, and high sensitivity. Different sensitivity levels correspond to different approval strategies, including automated approval, multi-level manual approval, and single-level manual approval. If a document matches a sensitive feature, the sensitive feature and sensitivity level are retained. The final sensitivity level of the document is determined according to the highest sensitivity level, and the highest sensitivity level is used for approval strategy matching. If the detection result is low sensitivity, the approval strategy is automated. If the detection result is medium sensitivity, the approval strategy is single-level manual approval. If the detection result is high sensitivity, the approval strategy is multi-level manual approval. Afterward, a corresponding approval process can be generated based on the approval strategy, and file permissions can be set. File permissions include download permissions and outgoing permissions.

[0078] The above technical solution allows for targeted sensitivity detection strategies to be developed based on the initiator and creator of cross-network files. This enables targeted sensitivity detection of cross-network files, improving the efficiency and accuracy of sensitivity detection and making the approval of cross-network files faster and more accurate, thereby enhancing the security of cross-network file transmission.

[0079] Figure 1 and 2 This is a flowchart illustrating a cross-network document approval method in one embodiment. It should be understood that, although... Figure 1 and 2 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise explicitly stated herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1 and 2 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0080] In one embodiment, a cross-network document approval device is provided, comprising:

[0081] The memory is configured to store instructions; and

[0082] The processor is configured to retrieve instructions from memory and, when executing instructions, to implement the aforementioned cross-network file approval method.

[0083] In one embodiment, a storage medium is provided on which a program is stored, which, when executed by a processor, implements the above-described cross-network file approval method.

[0084] In one embodiment, a processor is provided for running a program, wherein the program executes the aforementioned cross-network file approval method during runtime.

[0085] In one embodiment, such as Figure 3 The diagram illustrates a cross-network file approval system. Teams A and B, as shown, need to perform cross-network file transfers with teams C and D. Any one of teams A, B, C, or D can initiate the outgoing file transfer.

[0086] For example, Team A or Team B can manipulate personal files, uploading them to one end of the cross-network file approval process and initiating a cross-network outbound request to send the files to Team C or Team D. The cross-network file approval end can then approve the files to be sent based on the aforementioned approval method. If approved, the cross-network file approval end can send the files to Team C or Team D. When Team A or Team B uploads their personal files to the cross-network file approval end, they can also store those files in their local database.

[0087] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor A01, a network interface A02, memory (not shown), and a database (not shown) connected via a system bus. The processor A01 provides computing and control capabilities. The memory includes internal memory A03 and a non-volatile storage medium A04. The non-volatile storage medium A04 stores an operating system B01, a computer program B02, and a database (not shown). The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 stored in the non-volatile storage medium A04. The database stores data such as sensitivity detection levels and approval modes. The network interface A02 communicates with external terminals via a network connection. When the computer program B02 is executed by the processor A01, it implements a cross-network document approval method.

[0088] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0089] This application provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: obtaining an outbound request from an initiator for any cross-network file, the outbound request carrying the cross-network file and a first user tag corresponding to the initiator; obtaining a first sensitivity detection strategy corresponding to the first user tag, the first sensitivity detection strategy being constructed based on the initiator's sensitivity information, the initiator's superior user's sensitivity information, and pre-set general sensitivity information; scanning the cross-network file based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network file; determining an approval mode for the cross-network file based on the sensitivity detection level, and approving the cross-network file according to the approval mode.

[0090] In this embodiment of the application, scanning cross-network files based on a first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files includes: determining the creator of the cross-network file and obtaining a second user tag corresponding to the creator; if the first user tag and the second user tag are inconsistent, obtaining a second sensitivity detection strategy corresponding to the second user tag, wherein the second sensitivity detection strategy is constructed based on the sensitive information of the creator and the sensitive information of the creator's superior user; and scanning cross-network files based on the first sensitivity detection strategy and the second sensitivity detection strategy to determine the sensitivity detection level of the cross-network files.

[0091] In this embodiment of the application, the first sensitivity detection strategy includes a first local-level detection strategy, a first superior-level detection strategy, and a system-level sensitivity detection strategy. The second sensitivity detection strategy includes a second local-level detection strategy and a second superior-level detection strategy. The method further includes: constructing the first local-level detection strategy and the first superior-level detection strategy based on the sensitive information of the initiator and the sensitive information of the initiator's superior user, respectively; constructing a system-level sensitivity detection strategy based on general sensitive information; and constructing the second local-level detection strategy and the second superior-level detection strategy based on the sensitive information of the creator and the sensitive information of the creator's superior user, respectively.

[0092] In one embodiment, sensitive information includes multiple sensitive feature dimensions, each of which corresponds to multiple sensitive feature items. Scanning cross-network files based on a first sensitive detection strategy and a second sensitive detection strategy to determine the sensitivity detection level of the cross-network files includes: sequentially scanning the cross-network files based on a first local detection strategy, a first superior detection strategy, and a system-level sensitive detection strategy to obtain the first sensitive feature items hit during the scan; sequentially scanning the cross-network files based on the second local detection strategy and the second superior detection strategy to obtain the second sensitive feature items hit during the scan; and determining the sensitivity detection level based on all the first sensitive feature items and all the second sensitive feature items.

[0093] In one embodiment, each sensitive feature item corresponds to a preset level. Determining the sensitivity detection level based on all first sensitive features items and all second sensitive features items includes: obtaining a first preset level corresponding to each first sensitive feature item and obtaining a second preset level corresponding to each second sensitive feature item; selecting the highest preset level from all first preset levels and all second preset levels as the sensitivity detection level.

[0094] In one embodiment, approving a cross-network file according to an approval mode includes: obtaining the initiator's permission to send the cross-network file outwards; and, if the outward sending permission is an allowed permission, approving the cross-network file according to the approval mode.

[0095] In one embodiment, approving cross-network files according to the approval mode includes: when the approval mode is automatic approval mode, determining the approval result of the cross-network file as passed; when the approval mode is single-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the initiator's first-level superior user; when the approval mode is multi-level manual approval mode, determining the approval result of the cross-network file based on the approval result of the initiator's superior user.

[0096] In one embodiment, determining the approval mode for cross-network documents based on the sensitivity detection level includes: when the sensitivity detection level is Level 1, determining the approval mode for cross-network documents as an automatic approval mode; when the sensitivity detection level is Level 2, determining the approval mode for cross-network documents as a single-level manual approval mode; and when the sensitivity detection level is Level 3, determining the approval mode for cross-network documents as a multi-level manual approval mode.

[0097] In one embodiment, the method further includes: if the approval result of the cross-network file is passed, sending the cross-network file to the target user across the network, so as to perform file download and tag setting operations if the target user has download permissions for the cross-network file.

[0098] This application also provides a computer program product that, when executed on a data processing device, is suitable for executing a program that initializes a cross-network file approval method step.

[0099] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0100] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 a process or multiple processes and / or boxes Figure 1A device that provides the functions specified in one or more boxes.

[0101] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0102] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0103] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0104] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0105] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0106] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0107] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A cross-network document approval method, characterized in that, The method includes: Obtain the outbound request from the initiator for any cross-network file, wherein the outbound request carries the cross-network file and a first user tag corresponding to the initiator; Obtain a first sensitivity detection strategy corresponding to the first user tag. The first sensitivity detection strategy is constructed based on the sensitive information of the initiator, the sensitive information of the initiator's superior user, and pre-set general sensitive information. The cross-network files are scanned based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network files; The approval mode for the cross-network file is determined based on the sensitivity detection level, and the cross-network file is approved according to the approval mode.

2. The cross-network document approval method according to claim 1, characterized in that, The step of scanning the cross-network file based on the first sensitivity detection strategy to determine the sensitivity detection level of the cross-network file includes: Determine the creator of the cross-network file and obtain the second user tag corresponding to the creator; If the first user tag and the second user tag are inconsistent, a second sensitivity detection strategy corresponding to the second user tag is obtained. The second sensitivity detection strategy is constructed based on the sensitive information of the creator and the sensitive information of the creator's superior user. The cross-network files are scanned based on the first and second sensitivity detection strategies to determine the sensitivity detection level of the cross-network files.

3. The cross-network document approval method according to claim 2, characterized in that, The first sensitive detection strategy includes a first local-level detection strategy, a first higher-level detection strategy, and a system-level sensitive detection strategy; the second sensitive detection strategy includes a second local-level detection strategy and a second higher-level detection strategy; the method further includes: The first local detection strategy and the first superior detection strategy are constructed based on the sensitive information of the initiator and the sensitive information of the initiator's superior user, respectively. The system-level sensitivity detection strategy is constructed based on the general sensitivity information; The second local detection strategy and the second superior detection strategy are constructed based on the sensitive information of the creator and the sensitive information of the creator's superior user, respectively.

4. The cross-network document approval method according to claim 3, characterized in that, Sensitive information includes multiple sensitive feature dimensions, each with multiple sensitive feature items. The step of scanning the cross-network file based on the first and second sensitive detection strategies to determine the sensitivity detection level of the cross-network file includes: Based on the first local detection strategy, the first superior detection strategy, and the system-level sensitive detection strategy, the cross-network files are scanned sequentially to obtain the first sensitive feature item hit during the scan; Based on the second local detection strategy and the second superior detection strategy, the cross-network files are scanned sequentially to obtain the second sensitive feature items hit during the scan; The sensitivity detection level is determined based on all the first sensitive features and all the second sensitive features.

5. The cross-network document approval method according to claim 4, characterized in that, Each sensitive feature item corresponds to a preset level, and determining the sensitivity detection level based on all the first sensitive features items and all the second sensitive features items includes: Obtain the first preset level corresponding to each first sensitive feature item, and obtain the second preset level corresponding to each second sensitive feature item; The highest preset level is selected from all the first preset levels and all the second preset levels as the sensitivity detection level.

6. The cross-network document approval method according to claim 1, characterized in that, The approval of the cross-network document according to the approval mode includes: Obtain the initiator's permission to send the cross-network file; If the outbound permission is set to allow, the cross-network file is approved according to the approval mode.

7. The cross-network document approval method according to claim 1, characterized in that, The approval of the cross-network document according to the approval mode includes: If the approval mode is set to automatic approval mode, the approval result for the cross-network document is determined to be passed. In the case where the approval mode is a single-level manual approval mode, the approval result of the cross-network file is determined based on the approval result of the initiator's first-level superior user; In the case where the approval mode is a multi-level manual approval mode, the approval result of the cross-network file is determined based on the approval result of the initiator's superior user.

8. The cross-network document approval method according to claim 1, characterized in that, The step of determining the approval mode for the cross-network file based on the sensitivity detection level includes: When the sensitivity detection level is set to Level 1, the approval mode for the cross-network file is determined to be the automatic approval mode. When the sensitivity detection level is Level 2, the approval mode for the cross-network file is determined to be a single-level manual approval mode. When the sensitivity detection level is level three, the approval mode for the cross-network file is determined to be a multi-level manual approval mode.

9. The cross-network document approval method according to claim 1, characterized in that, The method further includes: If the approval result of the cross-network file is "passed", the cross-network file is sent to the target user across the network, so that if the target user has download permission for the cross-network file, the file download and tag setting operations can be performed.

10. A cross-network document approval device, characterized in that, The device includes: The memory is configured to store instructions; and A processor is configured to retrieve the instructions from the memory and, when executing the instructions, to implement the cross-network document approval method according to any one of claims 1 to 9.

11. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores instructions for causing the machine to perform the cross-network document approval method according to any one of claims 1 to 9.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the cross-network document approval method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Cooperative office management and control method and device and readable storage medium

    CN111815301A

  • Intranet information cross-network transfer method and device and electronic equipment

    CN113381908A