A data security control method, device, equipment, medium and program product

By sending an identity authentication request for geographic location information in the data security control method and obtaining corresponding data operation authorization information, the problem of lack of geographic location attention in the existing technology is solved, data security control based on geographic location is realized, and data security and protection capabilities are improved.

CN119150320BActive Publication Date: 2025-10-10DATANG GAOHONG XINAN ZHEJIANG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411189171.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-28
Publication Date
2025-10-10
Estimated Expiration
2044-08-28

AI Technical Summary

Technical Problem

Existing data security protection solutions lack attention to the geographical location of data, making it difficult to fully guarantee data security.

Method used

An identity authentication request carrying geographic location information is sent to the identity authentication platform through the first electronic device, data operation authorization information fed back by the identity authentication platform is obtained, and data operations are controlled based on the geographic location.

Benefits of technology

Significantly improve data security, prevent data from being accessed or leaked in unauthorized geographical locations, significantly reduce data security risks, and build a multi-level, comprehensive, and real-time responsive security protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119150320B_ABST
    Figure CN119150320B_ABST
Patent Text Reader

Abstract

The application provides a data security control method, device, equipment, medium and program product, and relates to the technical field of data security. The data security control method is executed by a first electronic device, and includes: sending an identity authentication request to an identity authentication platform, the identity authentication request carrying geographical position information of the first electronic device; and obtaining an identity authentication result fed back by the identity authentication platform according to the identity authentication request, the identity authentication result including first data operation authorization information corresponding to the geographical position information. The scheme of the application can achieve the effect of controlling data security based on geographical position information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a data security control method, device, equipment, medium and program product. Background Art

[0002] With the rapid development of information technology, data has become a core asset across all sectors, and data security is a growing concern. However, existing security measures have numerous flaws in complex and volatile network environments, making it difficult to fully guarantee data security. Existing data security solutions often focus on technologies like access control and encryption, but pay insufficient attention to the legitimacy of the data's geographic location.

[0003] Therefore, a data security protection solution that focuses on the geographic location of data is needed to meet the growing network security needs. Summary of the Invention

[0004] The purpose of the technical solution of the present invention is to provide a data security control method, device, equipment, medium and program product to solve the problem in the prior art of lacking a data security protection solution that pays attention to the geographical location of data.

[0005] To achieve the above object, the present invention is achieved as follows:

[0006] In a first aspect, an embodiment of the present invention provides a data security control method, performed by a first electronic device, the method comprising:

[0007] Sending an identity authentication request to an identity authentication platform, wherein the identity authentication request carries geographic location information of the first electronic device;

[0008] An identity authentication result fed back by the identity authentication platform according to the identity authentication request is obtained, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0009] Optionally, in the data security control method, the identity authentication request further carries at least one of the following:

[0010] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0011] User identification;

[0012] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0013] Optionally, the data security control method further comprises:

[0014] The process of executing the data operation indicated by the first data operation authorization information.

[0015] Optionally, in the data security control method, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation, and a data deletion operation.

[0016] Optionally, in the data security control method, the data operation includes the data transmission operation;

[0017] The process of executing the data operation indicated by the first data operation authorization information includes:

[0018] In the case where it is necessary to perform a data transmission operation indicated by the first data operation authorization information on a second electronic device, obtaining second data operation authorization information of the second electronic device;

[0019] In a case where the data operation indicated by the second data operation authorization information includes a data transmission operation, a process of performing the data transmission operation indicated by the first data operation authorization information is performed.

[0020] Optionally, in the data security control method, after executing the data operation indicated by the first data operation authorization information, the method further includes:

[0021] A data operation log is generated, where the data operation log includes the geographic location information.

[0022] Optionally, the data security control method further comprises:

[0023] Generate an identity authentication log, the identity authentication log including at least one of the following:

[0024] the identity authentication request;

[0025] The time of sending the identity authentication request to the identity authentication platform;

[0026] The identity authentication result.

[0027] In a second aspect, an embodiment of the present invention provides a data security control method, which is executed by an identity authentication platform, and the method includes:

[0028] Obtaining an identity authentication request sent by a first electronic device, where the identity authentication request carries geographic location information of the first electronic device;

[0029] In response to the identity authentication request, an identity authentication result is sent to the first electronic device, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0030] Optionally, in the data security control method, the identity authentication request further carries at least one of the following:

[0031] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0032] User identification;

[0033] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0034] Optionally, in the data security control method, before responding to the identity authentication request and sending the identity authentication result to the first electronic device, the method further includes:

[0035] An identity authentication result of the first electronic device is determined according to the identity authentication request, the identity authentication policy, and the data operation authorization policy.

[0036] In a third aspect, an embodiment of the present invention provides a data security control device, applied to a first electronic device, the device comprising:

[0037] A first sending module, configured to send an identity authentication request to an identity authentication platform, wherein the identity authentication request carries geographical location information of the first electronic device;

[0038] A first acquisition module is configured to acquire an identity authentication result fed back by the identity authentication platform according to the identity authentication request, wherein the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0039] In a fourth aspect, an embodiment of the present invention provides a data security control device, applied to an identity authentication platform, comprising:

[0040] A second acquisition module is configured to acquire an identity authentication request sent by a first electronic device, wherein the identity authentication request carries geographic location information of the first electronic device;

[0041] The second sending module is configured to respond to the identity authentication request and send an identity authentication result to the first electronic device, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0042] In the fifth aspect, an embodiment of the present invention provides a data security control device, a processor, a memory, and a program stored in the memory and runnable on the processor. When the program is executed by the processor, it implements the data security control method as described in the first aspect, or implements the data security control method as described in the second aspect.

[0043] In a sixth aspect, an embodiment of the present invention provides a readable storage medium having a program stored thereon, which, when executed by a processor, implements the data security control method as described in the first aspect, or implements the data security control method as described in the second aspect.

[0044] In a seventh aspect, an embodiment of the present invention provides a computer program product comprising computer instructions, which, when executed by a processor, implement the data security control method as described in the first aspect, or implement the data security control method as described in the second aspect.

[0045] The beneficial effects of the above technical solution of the present invention are as follows:

[0046] In an embodiment of the present invention, a first electronic device sends an identity authentication request to an identity authentication platform, the identity authentication request carrying the geographic location information of the first electronic device; and an identity authentication result, fed back by the identity authentication platform based on the identity authentication request, is obtained, the identity authentication result including first data operation authorization information corresponding to the geographic location information. In this way, using geographic location information can control data operations, significantly improving data security and resolving the issue of a lack of data security protection solutions that address the geographic location of data. Furthermore, the platform effectively prevents data from being accessed or leaked in unauthorized locations, significantly reducing data security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 A schematic diagram of a flow chart of a data security control method according to one embodiment of the present invention;

[0048] Figure 2 This is a flow chart of a data security control method according to another embodiment of the present invention;

[0049] Figure 3 This is a structural diagram of one implementation of the data security control device according to an embodiment of the present invention;

[0050] Figure 4 This is a structural diagram of another implementation of the data security control device according to an embodiment of the present invention;

[0051] Figure 5 This is a schematic diagram of the hardware structure of the data security control device described in an embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0053] In various embodiments of the present invention, it should be understood that the size of the serial numbers of the following processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0054] The terms "first," "second," and the like in the specification and claims of the present invention are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects. For example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0055] One embodiment of the present invention, as Figure 1 As shown, a data security control method is provided, which is executed by a first electronic device, and the method includes:

[0056] S101: Send an identity authentication request to an identity authentication platform, where the identity authentication request carries geographic location information of the first electronic device.

[0057] Optionally, the first electronic device includes a mobile terminal, an Internet of Things device, such as a camera, a monitor, a server, a firewall, a switch, and a gateway.

[0058] In an embodiment of the present invention, the first electronic device includes a geographic location acquisition module, which can obtain the geographic location information of the first electronic device in real time through positioning technologies such as satellite positioning systems (such as Beidou satellite positioning system, global positioning system, Galileo satellite navigation system, etc.), wireless local area network positioning, ultra-wideband positioning, communication base stations or Bluetooth positioning.

[0059] Optionally, the identity authentication request further carries at least one of the following:

[0060] a device identifier, where the device identifier is determined based on a built-in identifier of a Trusted Cryptography Module (TCM) or a Trusted Platform Module (TPM) in the first electronic device; specifically, a unique built-in identifier in the TCM or TPM is determined as the device identifier;

[0061] User identity identifier. It should be noted that the user refers to one of the following: an operating system user in the first electronic device, an external access user, a system built-in user, or a user who has successfully logged in using a login account / password by an operator; the user identity identifier is determined by an operating system built-in user, an account, a password, or a USB interface key;

[0062] The device trusted state is determined by performing trusted computing on the first electronic device through TCM or TPM; specifically, at least one of the hardware, firmware, operating system loader, operating system, and application of the first electronic device is determined by feasible computing through TCM or TPM; the device trusted state includes a trusted or untrusted state.

[0063] Therefore, the identity authentication request may include a four-tuple vector, which is expressed as <device identifier, device trusted status, user identifier, geographic location information>.

[0064] It should be noted that, when the first electronic device is powered on, or before a data operation needs to be performed, an identity authentication request is generated, so that the identity authentication request can be sent to the identity authentication platform.

[0065] S102: Obtain an identity authentication result fed back by the identity authentication platform according to the identity authentication request, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0066] In an embodiment of the present invention, the first data operation authorization information includes user operation authorization information on data and / or first electronic device operation authorization information on data, which is used to indicate the data operations authorized (i.e., allowed) to be performed by the user and / or first electronic device corresponding to the geographic location information.

[0067] In the embodiment of the present invention, optionally, after obtaining the identity authentication result fed back by the identity authentication platform according to the identity authentication request, the method further includes:

[0068] The process of executing the data operation indicated by the first data operation authorization information.

[0069] It should be noted that since the first data operation authorization information is related to the geographic location information of the first electronic device, the process of executing the data operation indicated by the first data operation authorization information can achieve the effect of controlling data security based on geographic location information, which solves the problem that the existing technology lacks data security protection solutions that pay attention to the geographic location of data, and effectively prevents data from being accessed or leaked in unauthorized geographic locations, greatly reducing data security risks, thereby meeting the high standards for data security in the current complex network environment, and has broad application prospects and important practical value.

[0070] Optionally, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation, and a data deletion operation.

[0071] Furthermore, the data operation includes the data transmission operation.

[0072] Optionally, the process of executing the data operation indicated by the first data operation authorization information includes:

[0073] In the case where it is necessary to perform a data transmission operation indicated by the first data operation authorization information on a second electronic device, obtaining second data operation authorization information of the second electronic device;

[0074] In a case where the data operation indicated by the second data operation authorization information includes a data transmission operation, a process of performing the data transmission operation indicated by the first data operation authorization information is executed.

[0075] Here, in the case where the first electronic device needs to perform the process of data transmission operation indicated by the first data operation authorization information to the second electronic device, it is necessary to request the identity authentication result of the second electronic device from the identity authentication platform to obtain the second data operation authorization information corresponding to the current geographic location information of the second electronic device; if the data operation indicated by the second data operation authorization information includes a data transmission operation, the first electronic device can perform the process of data transmission operation indicated by the first data operation authorization information to the second electronic device.

[0076] Optionally, when the data operation indicated by the first data operation authorization information includes the data generation operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0077] New data is generated on the first electronic device.

[0078] Optionally, when the data operation indicated by the first data operation authorization information includes the data read operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0079] Data is read on the first electronic device.

[0080] Optionally, when the data operation indicated by the first data operation authorization information includes the data modification operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0081] Data is modified on the first electronic device.

[0082] Optionally, when the data operation indicated by the first data operation authorization information includes the data processing operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0083] The content or meaning of the data is changed on the first electronic device through an algorithm.

[0084] Optionally, when the data operation indicated by the first data operation authorization information includes the data encryption operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0085] The data is encrypted at the first electronic device.

[0086] Optionally, when the data operation indicated by the first data operation authorization information includes the data decryption operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0087] The data is decrypted at the first electronic device.

[0088] Optionally, when the data operation indicated by the first data operation authorization information includes the data deletion operation, the process of performing the data operation indicated by the first data operation authorization information includes:

[0089] The first electronic device deletes the data.

[0090] In addition, the first data operation authorization information may also indicate a data operation on the target data. Therefore, the embodiment of the present invention can perform data security control on some sensitive target data.

[0091] In the embodiment of the present invention, optionally, after executing the data operation indicated by the first data operation authorization information, the method further includes:

[0092] A data operation log is generated, where the data operation log includes the geographic location information.

[0093] It is understood that after the first electronic device performs the data operation indicated by the first data operation authorization information, a data operation log may be generated to record the data operation. The data operation log includes the current geographic location information of the first electronic device to associate the performed data operation with the geographic location information. In addition, the data operation log may also include at least one of the data operation time, the identity authentication information of the operating user, the application used to operate the data, the operation content, and the operation result.

[0094] In the embodiment of the present invention, optionally, after obtaining the identity authentication result fed back by the identity authentication platform according to the identity authentication request, the method further includes:

[0095] Generate an identity authentication log, the identity authentication log including at least one of the following:

[0096] the identity authentication request;

[0097] The time of sending the identity authentication request to the identity authentication platform;

[0098] The identity authentication result.

[0099] It should be noted that after the first electronic device obtains the identity authentication result, an identity authentication log can be generated to record the identity authentication operation. The identity authentication log may include the identity authentication request sent by the first electronic device to the identity authentication platform, the time when the first electronic device sends the identity authentication request to the identity authentication platform, and at least one of the identity authentication results fed back by the identity authentication platform to the first electronic device.

[0100] In this example of the present invention, optionally, after executing the data operation indicated by the first data operation authorization information, the method further includes:

[0101] Generate an audit report, which includes audit records generated based on dimensions such as identity authentication information, data, and equipment.

[0102] Below is a summary of the above data operation logs, identity authentication logs and audit reports.

[0103] The first data operation authorization information in the identity authentication result is used to indicate that the first electronic device is allowed to perform data operations. After the data operation indicated by the first data operation authorization information is performed, a data operation log is generated.

[0104] After sending an identity authentication request to the identity authentication platform and obtaining the identity authentication result fed back by the identity authentication platform, an identity authentication log is generated.

[0105] The first data operation authorization information in the identity authentication result is used to instruct the first electronic device not to allow data operations to be performed and to generate an audit report.

[0106] Another embodiment of the present invention, as Figure 2 As shown, a data security control method is also provided, which is executed by the identity authentication platform, and the method includes:

[0107] S201: Obtain an identity authentication request sent by a first electronic device, where the identity authentication request carries geographic location information of the first electronic device.

[0108] Optionally, the identity authentication request further carries at least one of the following:

[0109] a device identifier, where the device identifier is determined based on a built-in identifier of a TCM or TPM in the first electronic device;

[0110] User identification;

[0111] The device trust status is determined by performing trusted computing on the first electronic device through TCM or TPM.

[0112] It should be noted that the identity authentication platform can also obtain identity authentication requests sent by electronic devices other than the first electronic device, that is, the identity platform is a platform that can process multi-node requests.

[0113] S202: In response to the identity authentication request, send an identity authentication result to the first electronic device, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0114] In the embodiment of the present invention, optionally, before responding to the identity authentication request and sending the identity authentication result to the first electronic device, the method further includes:

[0115] An identity authentication result of the first electronic device is determined according to the identity authentication request, the identity authentication policy, and the data operation authorization policy.

[0116] It should be noted that the identity authentication platform pre-sets an identity authentication policy and sets a safe geographical location area for each electronic device based on the business needs, management requirements, etc. of the electronic device; in simple terms, the identity authentication policy includes the identity authentication levels corresponding to different geographical location information of the electronic device, for example, when the first electronic device is in geographical location information 1, it corresponds to identity authentication level 1, and when the first electronic device is in geographical location information 2, it corresponds to identity authentication level 2.

[0117] Furthermore, the identity authentication platform pre-sets a data operation policy to specify data operation permissions for each electronic device; in simple terms, the data operation authorization policy includes identity authentication results corresponding to different identity authentication levels of electronic devices, and the identity authentication results include data operation authorization information. For example, the identity authentication level 1 of the first electronic device corresponds to the identity authentication result 1, and the identity authentication result 1 includes data operation authorization information 1. The data operation authorization information 1 is used to indicate the data operation authorized to be performed by the first electronic device corresponding to the geographic location information 1.

[0118] Among them, the authorization level of data operation authorization information 1 corresponding to identity authentication level 1 is higher than the authorization level of data operation authorization information 2 corresponding to identity authentication level 2. A higher authorization level means that the electronic device is authorized to perform more data operations.

[0119] Specifically, the identity authentication result may include a triplet vector, which is expressed as <identity authentication level, geographic location information, data operation authorization information>.

[0120] Taking the geographic location information 1 as a domestic area as an example, the geographic location information 1 of the first electronic device corresponds to identity authentication level 1, and the identity authentication level 1 corresponds to identity authentication result 1. The identity authentication result 1 includes data operation authorization information 1. The data operation authorization information 1 is used to indicate that the data operations authorized to be performed by the first electronic device corresponding to the geographic location information 1 include data transmission operations, data generation operations, data reading operations, data modification operations, data processing operations, data encryption operations, data decryption operations, and data deletion operations.

[0121] Taking the geographic location information 2 as an example of a foreign area, the geographic location information 2 of the first electronic device corresponds to the identity authentication level 2, the identity authentication level 2 corresponds to the identity authentication result 2, and the identity authentication result 2 includes data operation authorization information 2. The data operation authorization information 2 is used to indicate that the data operations authorized to be performed by the first electronic device corresponding to the geographic location information 2 include data reading operations.

[0122] In addition, the identity authentication policy preset by the identity authentication platform also includes the identity authentication level corresponding to the device trust status of the electronic device. For example, the device trust status 1 of the first electronic device corresponds to the identity authentication level 1, and the device trust status 1 is a trustworthy state.

[0123] Of course, the identity authentication policy preset by the identity authentication platform also includes the identity authentication level corresponding to the device identification of the electronic device or the user identification.

[0124] In summary, the data security control method described in the embodiments of the present invention integrates geolocation information with security protection technologies such as trusted computing to securely control data operations, significantly improving data security and effectively preventing data from being accessed or leaked in unauthorized locations, significantly reducing data security risks. Furthermore, by employing flexible identity authentication and data operation authorization strategies, a multi-layered, comprehensive, and real-time responsive security protection system is constructed, meeting the high standards for data security in today's complex network environments. This system has broad application prospects and significant practical value.

[0125] like Figure 3 As shown, an embodiment of the present invention further provides a data security control device, applied to a first electronic device, the device comprising:

[0126] A first sending module 301 is configured to send an identity authentication request to an identity authentication platform, wherein the identity authentication request carries geographic location information of the first electronic device;

[0127] The first acquisition module 302 is configured to acquire an identity authentication result fed back by the identity authentication platform according to the identity authentication request, wherein the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0128] Optionally, in the data security control device, the identity authentication request further carries at least one of the following:

[0129] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0130] User identification;

[0131] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0132] Optionally, the data security control device further comprises:

[0133] An execution module is used to execute the process of the data operation indicated by the first data operation authorization information.

[0134] Optionally, the data security control device, wherein the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation and a data deletion operation.

[0135] Optionally, in the data security control device, the data operation includes the data transmission operation;

[0136] The execution module is specifically used to:

[0137] In the case where it is necessary to perform a data transmission operation indicated by the first data operation authorization information on a second electronic device, obtaining second data operation authorization information of the second electronic device;

[0138] In a case where the data operation indicated by the second data operation authorization information includes a data transmission operation, a process of performing the data transmission operation indicated by the first data operation authorization information is executed.

[0139] Optionally, the data security control device further comprises:

[0140] The first generating module is configured to generate a data operation log, wherein the data operation log includes the geographic location information.

[0141] Optionally, the data security control device further comprises:

[0142] The second generating module is configured to generate an identity authentication log, wherein the identity authentication log includes at least one of the following:

[0143] the identity authentication request;

[0144] The time of sending the identity authentication request to the identity authentication platform;

[0145] The identity authentication result.

[0146] It should be noted that the data security control device provided in the embodiment of the present invention is a device capable of executing the above-mentioned data security control method. All embodiments of the above-mentioned data security control method are applicable to the device and can achieve the same or similar technical effects.

[0147] like Figure 4 As shown, an embodiment of the present invention further provides a data security control device, which is applied to an identity authentication platform, and the device includes:

[0148] A second obtaining module 401 is configured to obtain an identity authentication request sent by a first electronic device, where the identity authentication request carries geographic location information of the first electronic device;

[0149] The second sending module 402 is configured to respond to the identity authentication request and send an identity authentication result to the first electronic device, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0150] Optionally, in the data security control device, the identity authentication request further carries at least one of the following:

[0151] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0152] User identification;

[0153] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0154] Optionally, the data security control device further comprises:

[0155] The determination module is used to determine the identity authentication result of the first electronic device according to the identity authentication request, the identity authentication policy and the data operation authorization policy.

[0156] It should be noted that the data security control device provided in the embodiment of the present invention is a device capable of executing the above-mentioned data security control method. All embodiments of the above-mentioned data security control method are applicable to the device and can achieve the same or similar technical effects.

[0157] like Figure 5 As shown, an embodiment of the present invention also provides a data security control device, including: a processor 501; and a memory 502 connected to the processor 501 through a bus interface, the memory 502 being used to store programs and data used by the processor 501 when performing operations, and the processor 501 calls and executes the programs and data stored in the memory 502.

[0158] The data security control device further includes a transceiver 503, which is connected to the bus interface and is configured to execute the following processes under the control of the processor 501:

[0159] Sending an identity authentication request to an identity authentication platform, wherein the identity authentication request carries geographic location information of the first electronic device;

[0160] An identity authentication result fed back by the identity authentication platform according to the identity authentication request is obtained, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0161] Among them, Figure 5 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 501 and memory represented by memory 502. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and therefore will not be described further herein. The bus interface provides a user interface 504. The transceiver 503 may be a plurality of components, i.e., including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium. The processor 501 is responsible for managing the bus architecture and general processing, and the memory 502 may store data used by the processor 501 when performing operations.

[0162] The processor 501 is responsible for managing the bus architecture and general processing, and the memory 502 can store data used by the processor 501 when performing operations.

[0163] Optionally, the identity authentication request further carries at least one of the following:

[0164] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0165] User identification;

[0166] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0167] Optionally, the processor 501 is configured to read the computer program and execute the following steps:

[0168] The process of executing the data operation indicated by the first data operation authorization information.

[0169] Optionally, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation, and a data deletion operation.

[0170] Optionally, the data operation includes the data transmission operation;

[0171] The processor 501 is specifically configured to read the computer program and execute the following steps:

[0172] In the case where it is necessary to perform a data transmission operation indicated by the first data operation authorization information on a second electronic device, obtaining second data operation authorization information of the second electronic device;

[0173] In a case where the data operation indicated by the second data operation authorization information includes a data transmission operation, a process of performing the data transmission operation indicated by the first data operation authorization information is executed.

[0174] Optionally, the processor 501 is further configured to read the computer program and execute the following steps:

[0175] A data operation log is generated, where the data operation log includes the geographic location information.

[0176] Optionally, the processor 501 is further configured to read the computer program and execute the following steps:

[0177] Generate an identity authentication log, the identity authentication log including at least one of the following:

[0178] the identity authentication request;

[0179] The time of sending the identity authentication request to the identity authentication platform;

[0180] The identity authentication result.

[0181] In addition, the embodiment of the present invention also provides a data security control device, the structure of which is similar to Figure 5 The data security control device shown is the same, including: a processor; and a memory connected to the processor through a bus interface, the memory being used to store programs and data used by the processor when performing operations, and the processor calling and executing the programs and data stored in the memory.

[0182] The data security control device further includes a transceiver connected to the bus interface and configured to execute the following process under the control of the processor:

[0183] Obtaining an identity authentication request sent by a first electronic device, where the identity authentication request carries geographic location information of the first electronic device;

[0184] In response to the identity authentication request, an identity authentication result is sent to the first electronic device, where the identity authentication result includes first data operation authorization information corresponding to the geographic location information.

[0185] Optionally, the identity authentication request further carries at least one of the following:

[0186] a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device;

[0187] User identification;

[0188] The device trusted state is determined by performing trusted computing on the first electronic device through the trusted cryptographic module or the trusted platform module.

[0189] Optionally, the processor is configured to read the computer program and execute the following steps:

[0190] An identity authentication result of the first electronic device is determined according to the identity authentication request, the identity authentication policy, and the data operation authorization policy.

[0191] A specific embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps in the above-mentioned data security control method are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0192] In addition, an embodiment of the present invention further provides a computer program product, including computer instructions, which, when executed by a processor, implement the above Figure 1 or Figure 2 The various processes of the method embodiment shown can achieve the same technical effect, and to avoid repetition, they will not be described here.

[0193] In the several embodiments provided in this application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection of some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0194] In addition, the functional units in various embodiments of the present invention may be integrated into a single processing unit, each unit may be physically included separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional units.

[0195] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to perform some of the steps of the sending and receiving methods described in various embodiments of the present invention. The aforementioned storage medium includes: a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, and other media that can store program code.

[0196] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A data security control method, characterized in that: The method is performed by a first electronic device and includes: Before the first electronic device needs to perform a data operation, an identity authentication request is generated and sent to an identity authentication platform, where the identity authentication request carries geographic location information of the first electronic device; the identity authentication request also carries at least one of the following: a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device; and a device trusted state, where the device trusted state is determined by performing trusted calculations on at least one of the hardware, firmware, operating system loader, operating system, and application of the first electronic device by the trusted cryptographic module or the trusted platform module, where the device trusted state includes a trusted or untrusted state. Obtaining an identity authentication result corresponding to an identity authentication level fed back by the identity authentication platform based on the identity authentication request, the identity authentication level being related to the geographic location information, and the identity authentication level being further related to at least one of the following: the device identification; the device trustworthy status, the identity authentication result including first data operation authorization information corresponding to the geographic location information, and the identity authentication result also including first data operation authorization information corresponding to at least one of the following: the device identification; the device trustworthy status, different identity authentication levels corresponding to different data operation authorization information, and a higher identity authentication level indicating more data operations indicated by the corresponding data operation authorization information; The process of executing the data operation indicated by the first data operation authorization information; wherein the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation, and a data deletion operation.

2. The data security control method according to claim 1, characterized in that: The identity authentication request also carries: User identity identifier.

3. The data security control method according to claim 1, characterized in that: The data operation includes the data transmission operation; The process of executing the data operation indicated by the first data operation authorization information includes: In the case where it is necessary to perform a data transmission operation indicated by the first data operation authorization information on a second electronic device, obtaining second data operation authorization information of the second electronic device; In a case where the data operation indicated by the second data operation authorization information includes a data transmission operation, a process of performing the data transmission operation indicated by the first data operation authorization information is performed.

4. The data security control method according to claim 1, wherein: After executing the data operation indicated by the first data operation authorization information, the method further includes: A data operation log is generated, where the data operation log includes the geographic location information.

5. The data security control method according to claim 1, characterized in that: The method further comprises: Generate an identity authentication log, the identity authentication log including at least one of the following: the identity authentication request; The time of sending the identity authentication request to the identity authentication platform; The identity authentication result.

6. A data security control method, characterized in that: Executed by the identity authentication platform, the method includes: Obtain an identity authentication request sent by a first electronic device, where the identity authentication request is generated before the first electronic device needs to perform a data operation, and the identity authentication request carries geographic location information of the first electronic device; the identity authentication request also carries at least one of the following: a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device; and a device trusted state, where the device trusted state is determined by performing trusted computing by the trusted cryptographic module or the trusted platform module on at least one of the hardware, firmware, operating system loader, operating system, and application of the first electronic device, and the device trusted state includes a trusted or untrusted state. In response to the identity authentication request, sending an identity authentication result corresponding to an identity authentication level to the first electronic device, the identity authentication level being related to the geographic location information, and the identity authentication level being further related to at least one of the following: the device identification; the device trust status, the identity authentication result including first data operation authorization information corresponding to the geographic location information, and the identity authentication result also including first data operation authorization information corresponding to at least one of the following: the device identification; the device trust status, different identity authentication levels corresponding to different data operation authorization information, and a higher identity authentication level indicating more data operations indicated by the corresponding data operation authorization information; After obtaining the identity authentication result, the first electronic device executes the data operation process indicated by the first data operation authorization information; wherein, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation and a data deletion operation.

7. The data security control method according to claim 6, characterized in that: The identity authentication request also carries: User identity identifier.

8. The data security control method according to claim 7, characterized in that: Before responding to the identity authentication request and sending the identity authentication result to the first electronic device, the method further includes: An identity authentication result of the first electronic device is determined according to the identity authentication request, the identity authentication policy, and the data operation authorization policy.

9. A data security control device, characterized in that: Applied to a first electronic device, the device includes: A first sending module is configured to generate an identity authentication request and send the identity authentication request to an identity authentication platform before the first electronic device needs to perform a data operation, wherein the identity authentication request carries geographic location information of the first electronic device; the identity authentication request also carries at least one of the following: a device identifier, which is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device; and a device trusted state, which is determined by performing trusted calculation on at least one of the hardware, firmware, operating system loader, operating system, and application of the first electronic device through the trusted cryptographic module or the trusted platform module, and the device trusted state includes a trusted or untrusted state. a first acquisition module, configured to acquire an identity authentication result corresponding to an identity authentication level fed back by the identity authentication platform based on the identity authentication request, the identity authentication level being related to the geographic location information, and further being related to at least one of the following: the device identification; and the device trust status; the identity authentication result including first data operation authorization information corresponding to the geographic location information, and further including first data operation authorization information corresponding to at least one of the following: the device identification; and the device trust status; different identity authentication levels corresponding to different data operation authorization information, and a higher identity authentication level indicating more data operations indicated by the corresponding data operation authorization information; An execution module is used to execute the process of the data operation indicated by the first data operation authorization information; wherein, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation and a data deletion operation.

10. A data security control device, characterized in that: Applied to an identity authentication platform, the device includes: a second acquisition module, configured to acquire an identity authentication request sent by a first electronic device, where the identity authentication request is generated before the first electronic device needs to perform a data operation, and the identity authentication request carries geographic location information of the first electronic device; the identity authentication request also carries at least one of the following: a device identifier, where the device identifier is determined based on a built-in identifier of a trusted cryptographic module or a trusted platform module in the first electronic device; and a device trusted state, where the device trusted state is determined by performing trusted calculations on at least one of the hardware, firmware, operating system loader, operating system, and application of the first electronic device through the trusted cryptographic module or the trusted platform module, and the device trusted state includes a trusted or untrusted state; a second sending module, configured to respond to the identity authentication request and send, to the first electronic device, an identity authentication result corresponding to an identity authentication level, the identity authentication level being related to the geographic location information, and the identity authentication level being further related to at least one of the following: the device identification; and the device trustworthy status; the identity authentication result including first data operation authorization information corresponding to the geographic location information, and the identity authentication result also including first data operation authorization information corresponding to at least one of the following: the device identification; and the device trustworthy status; different identity authentication levels corresponding to different data operation authorization information, and a higher identity authentication level indicating more data operations indicated by the corresponding data operation authorization information; After obtaining the identity authentication result, the first electronic device executes the data operation process indicated by the first data operation authorization information; wherein, the data operation includes at least one of a data transmission operation, a data generation operation, a data reading operation, a data modification operation, a data processing operation, a data encryption operation, a data decryption operation and a data deletion operation.

11. A data security control device, characterized in that: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the data security control method according to any one of claims 1 to 5, or implements the data security control method according to any one of claims 6 to 8.

12. A readable storage medium, characterized in that: The readable storage medium stores a program, and when the program is executed by the processor, it implements the data security control method according to any one of claims 1 to 5, or implements the data security control method according to any one of claims 6 to 8.

13. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the data security control method according to any one of claims 1 to 5, or implement the data security control method according to any one of claims 6 to 8.

Citation Information

Patent Citations

  • File protection method, device and system, medium and electronic equipment

    CN113282901A

  • User permission adjustment method and device, electronic equipment and storage medium

    CN115695015A