Data access method, device, equipment and readable storage medium
By implementing a data access authorization mechanism in a trusted execution environment, and using access credentials and processing credentials for data encryption and decryption, data security issues during the interaction between user terminals and cloud data are solved, and the security and legality of data during transmission and use are realized.
Patent Information
- Application Number
- CN202411247087.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-05
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2044-09-05
AI Technical Summary
During the data interaction between user terminals and clouds, how to ensure data security and prevent unauthorized data access and leakage, especially security risks in data transmission and use.
By implementing a data access authorization mechanism in a trusted execution environment, data encryption and decryption are used to encrypt and decrypt data, ensuring the security of data during processing, and preventing unauthorized data access through point-to-point data access authorization requests and feedback of authorization information.
It significantly enhances data security, prevents unauthorized access and leakage of data resources, ensures the security of data during transmission and use, and improves the protection level of data resources.
Smart Images

Figure CN119203181B_ABST
Abstract
Description
Technical Field
[0001] Example embodiments of the present disclosure generally relate to the field of computers, and more particularly, to data access methods, apparatuses, devices, and readable storage media. Background Art
[0002] As data security becomes increasingly important, improving it has become a pressing issue. In particular, ensuring the security of data generated by user terminals during data interaction with the cloud is a pressing issue. Summary of the Invention
[0003] In a first aspect of the present disclosure, a data access method is provided. The method can be applied to a user of a data resource and includes: in response to a demand for processing a data resource generated by a target application, sending a data access authorization request for the data resource to multiple clients of the target application, the multiple clients being associated with the data resource; receiving authorization information for the data access authorization request from at least one of the multiple clients; obtaining at least one access credential corresponding to each of the at least one client based on the authorization information; and accessing target data associated with the at least one client in the data resource using the at least one access credential to process the target data.
[0004] In a second aspect of the present disclosure, a data access method is provided. The method is applied to a client of a target application and includes: in response to verification by a credential management service, sending access credentials for data access to the credential management service; processing target data generated by the client in the target application using processing credentials corresponding to the access credentials; storing the processed target data in a data storage side; receiving a data access authorization request from a user of a data resource, the data resource including the target data; generating authorization information for the data access authorization request in response to a positive indication of the data access authorization request; and sending the authorization information to the user of the data resource.
[0005] In a third aspect of the present disclosure, a data access method is provided. The method is applied to a credential management service and includes: sending an attestation report to multiple clients of a target application, the attestation report indicating the trustworthiness of an environment in which access credentials are stored; receiving multiple access credentials corresponding to the multiple clients, the access credentials in the multiple access credentials being used to access data associated with the corresponding clients; and, in response to receiving an access credential request for at least one of the multiple clients from a user of a data resource, sending the access credential corresponding to the at least one client to the user of the data resource.
[0006] In a fourth aspect of the present disclosure, an electronic device is provided. The device includes at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. When executed by the at least one processing unit, the instructions cause the electronic device to perform the method of the first aspect.
[0007] In a fifth aspect of the present disclosure, a computer-readable storage medium is provided, wherein a computer program is stored on the medium, and when the computer program is executed by a processor, the method of the first aspect is implemented.
[0008] It should be understood that the content described in this section is not intended to limit the key features or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. In the accompanying drawings, the same or similar reference numerals represent the same or similar elements, wherein:
[0010] Figure 1 A schematic diagram illustrating an example environment in which embodiments of the present disclosure can be implemented;
[0011] Figure 2 A block diagram illustrating a data access process according to some embodiments of the present disclosure is shown;
[0012] Figure 3 A schematic diagram illustrating a principle of a data access process according to some embodiments of the present disclosure is shown;
[0013] Figure 4 A block diagram illustrating a data access process according to other embodiments of the present disclosure is shown;
[0014] Figure 5 A schematic diagram showing an interactive interface according to some embodiments of the present disclosure is shown;
[0015] Figure 6 A block diagram illustrating a data access process according to other embodiments of the present disclosure is shown;
[0016] Figure 7 A schematic structural block diagram of a data access device according to some embodiments of the present disclosure is shown;
[0017] Figure 8 shows a schematic structural block diagram of a data access device according to some other embodiments of the present disclosure;
[0018] Figure 9A schematic structural block diagram showing a data access device according to some other embodiments of the present disclosure; and
[0019] Figure 10 A block diagram of an electronic device in which one or more embodiments of the present disclosure may be implemented is shown. DETAILED DESCRIPTION
[0020] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0021] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may be included below.
[0022] Herein, unless explicitly stated otherwise, executing a step “in response to A” does not mean executing the step immediately after “A” but may include one or more intermediate steps.
[0023] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0024] It is understandable that before using the technical solutions disclosed in each embodiment of the present disclosure, the type, scope of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to relevant users and authorization should be obtained from relevant users in an appropriate manner in accordance with relevant laws and regulations. The relevant users may include any type of right holders, such as individuals, enterprises, and groups.
[0025] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can independently choose whether to provide information to the software or hardware such as the electronic device, application, server or storage medium that executes the operation of the technical solution of the present disclosure based on the prompt message.
[0026] As an optional but non-limiting implementation, in response to receiving an active request from a relevant user, a prompt message may be sent to the relevant user in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide information to the electronic device.
[0027] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0028] Figure 1 1 shows a schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented. Figure 1 As shown, example environment 100 may include a client 120 of a user 140 and a host device 110 in a cloud environment.
[0029] like Figure 1 As shown, the host device 110 can be deployed with a trusted execution environment 115. In the trusted execution environment 115, a computing engine 112 can be run. Trusted Execution Environment (TEE) is a hardware-based security technology that constructs a secure computing environment isolated from the outside by dividing the secure part and the non-secure part. The secure computing environment can ensure the confidentiality and integrity of the data and code loaded inside the trusted execution environment 115. The trusted execution environment 115 is isolated from the ordinary environment, has a higher security level, and is suitable for processing sensitive data therein. The computing engine can provide confidential cloud computing services (CCC) running in the trusted execution environment 115. The confidential cloud computing services provided by the computing engine are intended to protect the user's data security.
[0030] The credential management service may be executed in the trusted execution environment 115. The credential management service may be executed independently of the host device 110. The credential management service may be a trusted key management service (TKS). The credential management service may be a security service running in the trusted execution environment 115, designed to provide hardware-protected access credential management and proxy services to users.
[0031] Using the credential management service, access credentials obtained from client 120 can be stored in access credential management database 114. Furthermore, host device 110 can store data resources generated in the target application and obtained from client 120 in data storage 116. It will be appreciated that these data resources are data resources generated in the target application and obtained with the permission and authorization of user 140. For example, these data resources may include geographic location data, click behavior data, and so on.
[0032] In some embodiments, the host device 110 communicates with the client 120 to enable data access and analysis. The client 120 can be any type of mobile, fixed, or portable terminal, including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio receiver, an e-book device, a gaming device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, the client 120 can also support any type of interface for the user (such as "wearable" circuitry, etc.).
[0033] The host device 110 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks, and big data and artificial intelligence platforms. The host device 110 can include, for example, a computing system / server such as a mainframe, an edge computing node, a computing device in a cloud environment, etc. The host device 110 can provide backend services for data management for the client 120. An example of the host device 110 is a host machine of a cloud vendor.
[0034] A communication connection may be established between the host device 110 and the client 120. The communication connection may be established in a wired or wireless manner. The communication connection may include, but is not limited to, a Bluetooth connection, a mobile network connection, a Universal Serial Bus connection, a Wi-Fi connection, etc., and the embodiments of the present disclosure are not limited in this respect.
[0035] It should be understood that the structure and function of each element in environment 100 are described for exemplary purposes only and do not imply any limitation on the scope of the present disclosure. In other words, the structure, function, number, and linkage relationship of the elements in environment 100 may be varied according to actual needs. The present disclosure is not limited in this respect.
[0036] Currently, numerous security risks exist in the interaction between client devices and cloud-based host devices. For example, users are unaware of whether data is encrypted during transmission, or how it is used and calculated. This can lead to data being unknowingly accessed, used without authorization, or even shared, posing the risk of personal information leakage.
[0037] In an embodiment of the present disclosure, an improved data access solution is provided. In this solution, a user of a data resource, in response to a demand for processing data resources generated by a target application, sends a data access authorization request for the data resource to multiple clients of the target application, where the multiple clients are associated with the data resource. Authorization information for the data access authorization request is received from at least one of the multiple clients. Based on the authorization information, at least one access credential corresponding to each of the at least one client is obtained. Using the at least one access credential, target data associated with the at least one client in the data resource is accessed to process the target data.
[0038] Through the above process, the data resource user sends data access authorization requests to multiple clients in a point-to-point manner, preventing man-in-the-middle attacks. The data resource user then receives authorization information from at least one client in response to the data access authorization request. The retrieved data includes data resources generated by the target application running on the client, ensuring that user data is retrieved with user authorization. These improvements significantly enhance data security, preventing unauthorized access to data resources and the risk of leakage, thereby resolving data security issues.
[0039] Some example embodiments of the present disclosure will be described in detail below with reference to the examples in the accompanying drawings. It should be understood that the interfaces shown in the accompanying drawings are merely examples, and a variety of interface designs are possible. The various graphical elements in the interface can have different arrangements and different visual representations, one or more elements can be omitted or replaced, and one or more other elements can also be present. The embodiments of the present disclosure are not limited in this respect.
[0040] Figure 2 FIG2 shows a block diagram of a data access process 200 according to some embodiments of the present disclosure. The data access process can be implemented in a host device 110, which can be used as a user of data resources. Figure 1 To describe Figure 2 The task processing process is shown.
[0041] In block 201, host device 110, in response to a demand for a data resource generated by a target application, sends a data access authorization request for the data resource to multiple clients of the target application, where the multiple clients are associated with the data resource. For example, on the host device 110 side, scenarios such as data access tasks and data analysis tasks performed by computing engine 112 can be utilized. The execution of the data access task or data analysis task by computing engine 112 can serve as a trigger instruction for generating and sending the data access authorization request.
[0042] Figure 3 FIG2 shows a schematic diagram of a data access process 300 according to some embodiments of the present disclosure. Figure 3 As shown, for example, the host device 110 executes the POI recommendation task through the computing engine 112 , and may trigger the sending of a data resource access request in step 302 . Figure 3 As shown, although the data storage side 116 and the computing engine 112 are shown on one host device 110, in actual scenarios, the data storage side 116 and the computing engine 112 may be distributed on different host devices 110. In addition, there may be multiple host devices 110.
[0043] For the task of the computing engine 112 , the host device 110 may determine at least one client 120 based on multiple factors such as relevance, quality, and credibility of the data resources. The host device 110 sends the generated data access authorization request to the at least one determined client 120 .
[0044] At block 202 , the host device 110 receives authorization information for a data access authorization request from at least one of the plurality of clients. The authorization information may be sent by the client 120 to the host device 110 as feedback to the data access authorization request.
[0045] The client 120 receives the data access authorization request, and the user 140 can authorize the data access authorization request or refuse to authorize the data access authorization request. If the user 140 refuses to authorize the data access authorization request, the entire process ends. Figure 3 As shown, if the user 140 agrees to authorize the data access authorization request, the client 120 generates authorization information and sends it to the host device 110 .
[0046] Generally speaking, the authorization information may include at least an access token of the client 120 (or user 140), which may indicate the identification information of the client. Furthermore, the authorization information may include additional information such as the authorized scope of use of the authorized data resource, the authorized purpose of use, and the authorized use period. For example, the authorized scope of use of the data resource may indicate the category of the data resource generated by the target application. The authorized use period may be one day, one hour, etc. The authorized use purpose may be to authorize only the host device 110 to perform a certain data computing task or a certain data analysis task.
[0047] In block 203, the host device 110 obtains at least one access credential corresponding to at least one client based on the authorization information. Figure 3 As shown, after receiving the authorization information, the host device 110 can use the credential management service to obtain the access credential of the data resource from the access credential management database 114 in step 304-1. In addition, the host device 110 can also obtain the data resource from the data storage side 116 in step 304-2.
[0048] Illustratively, the access credentials for the data resource may be those uploaded by the client 120 to the access credential management database 114 in step 301-1. Furthermore, in step 301-2, the client 120 may process the data resource generated in the target application using the processing credentials and then upload it to the data storage 116. Illustratively, processing the data resource using the processing credentials may include encrypting the data resource using the processing credentials. Corresponding to the processing credentials is the access credential uploaded to the access credential management database 114. Illustratively, the encrypted data resource may be decrypted using the access credentials.
[0049] The host device 110 can obtain the access credentials of the data resource from the access credential management database 114 , and can also obtain the data resource processed by the credential processing from the data storage side 116 .
[0050] At block 204, host device 110 uses the at least one access credential to access target data associated with the at least one client in the data resource to process the target data. Based on the decrypted data resource, computing engine 112 can perform corresponding computing and processing tasks. Accessing the target data associated with the at least one client using the at least one access credential can be performed within trusted execution environment 115, ensuring that the data remains secure during processing and preventing data leakage and misuse.
[0051] Through the above process, the host device 110 ensures the legitimacy of data resource access by feeding back authorization information, preventing unauthorized access to data resources. At the same time, the access credential mechanism ensures the security of data during transmission and use, preventing data leakage and tampering.
[0052] The above is an overview of the overall process for host device 110. Next, obtaining access credentials for data resources and acquiring data resources will be described in detail. First, the process of obtaining access credentials for data resources will be described. In some embodiments, host device 110 determines an access token for at least one client based on authorization information. It then sends an access credential request for the data resource to a credential management service, the access credential request including at least the access token. It then receives from the credential management service at least one access credential corresponding to each of the at least one client.
[0053] Based on the authorization information provided by client 120, host device 110 first determines the access token for client 120. The access token may indicate identification information for client 120. In access credential management database 114, the credential management service configures each access credential entry to consist of unique identification information and a corresponding access credential. The identification information may be the unique identifier of the client. The access credential can then be used to decrypt data resources.
[0054] Host device 110 sends an access credential request for a data resource to a credential management service that manages data resource access credentials. The access credential request includes at least an access token. Based on a structured storage approach, the credential management service can quickly and accurately retrieve the corresponding access credential from the access credential management database 114 based on the identification information. Host device 110 can then receive the access credential from the credential management service. The credential management service can be a secure service running in a trusted execution environment.
[0055] The access credential request may also include a security report indicating the trustworthiness of the trusted execution environment 115 used to process the data resource. The host device 110 sends an access credential request for the data resource to the credential management service. The access credential request may include both an access token and a security report. The security report is used to verify that the trusted execution environment 115 of the computing engine 112 used to process the data resource is secure and trustworthy and meets predetermined security standards.
[0056] For example, the security report may include the operating system version of the host device 110 where the computing engine 112 resides. If the computing engine 112 is running in a virtual machine, the virtual machine software version and configuration are reported. Furthermore, the security report may include the code version of the specific application or software running in the computing engine 112. The operating system version can indicate the security and update status of the system environment. The virtual machine software version can indicate the security of the virtualized environment. The code version of the specific application or software can indicate that the application or software has not been tampered with and is running as expected.
[0057] The credential management service can perform validation on the security report. If the validation is determined to be successful, host device 110 is allowed to receive access credentials for the data resource. By including a security report in the access credential request, the security of computing engine 112 can be verified. For example, by verifying versions and ensuring that system components and software have the latest security patches applied, the risk of malicious or unsafe software being used in the data request process can be reduced.
[0058] The above describes how to obtain access credentials for data resources. Next, we will discuss how to obtain data resources. In some embodiments, host device 110 obtains data resources from data storage 116 , where the data resources are stored by a provider to data storage 116 based on a received attestation report, which indicates the trustworthiness of the environment in which the data resources are stored.
[0059] The data resource is authorized by the client 120 and stored in the data storage side 116. The authorization by the client 120 may include performing a verification on the certification report sent by the host device 110 and obtaining a conclusion that the verification has passed.
[0060] The attestation report can indicate the trustworthiness of the environment in which data resources are stored. For example, the attestation report may include information such as hardware Trusted Computing Base (TCB), application measurement values, application custom data, and hardware signatures. Application measurement values generally refer to a set of values obtained after measuring an application or its components in a trusted execution environment. These values are used to verify the integrity and authenticity of the application and ensure that the application has not been tampered with. Application custom data generally refers to data defined by the application according to its own needs and included in the attestation report. This data can be application-specific configurations, identification information, or other content that helps to prove the security and trustworthiness of the application.
[0061] After client 120 successfully verifies the attestation report, it can upload the access credentials to the access credential management database 114, where the credential management service manages the access credentials. Furthermore, client 120 encrypts some data resources using the processing credentials and uploads them to data storage 116 in host device 110. In other words, after client 120 successfully verifies the attestation report, it is authorized to process and upload the data resources generated by the target application on client 120 to data storage 116.
[0062] When the host device 110 sends a data access authorization request to the client 120 based on the task to be executed by the computing engine 112, the client 120 may authorize the access, that is, authorize the host device 110 to obtain all or part of the data resources stored in the data storage side 116.
[0063] Through the above process, the client 120 can securely upload data resources to the data storage side 160 and authorize the computing engine 112 of the host device 10 to access these data resources when needed, ensuring that the access and transmission process of data resources meets security requirements.
[0064] For the at least one client, the target data stored in the data storage side 160 is transmitted to the data storage side 160 after the client processes the data generated in the target application using the processing credentials corresponding to the access credentials of the client.
[0065] On client 120, processing data generated in the target application may include processing the data generated in the target application using the processing credentials and then transmitting it to data storage 116. The processing credentials may correspond to the access credentials uploaded by client 120 to access credential management database 114. For example, the credential management service may decrypt the data resource based on the access credentials. Decryption may be performed within trusted execution environment 115.
[0066] Within the trusted execution environment 115, the host device 110 can also implement data security by processing data resources and data resource access credentials. Specifically, in response to satisfying a preset condition, the target data and the target data access credentials are removed from the trusted execution environment. The preset condition includes the end of access to the target data or the expiration of the authorized usage period of the target data.
[0067] Based on the obtained access credentials, the host device 110 can perform a decryption operation on the data resource in the trusted execution environment 115. The decryption process is completed in the trusted execution environment 115, which can ensure that the decrypted data resource is not exposed to any untrusted environment.
[0068] The decrypted data resources are stored within the trusted execution environment 115. Host device 110 accesses the data resources processed by the access credentials based on data access tasks. These tasks may include data analysis and calculations. Because these accesses are performed within the trusted execution environment 115, the integrity and confidentiality of the data resources are effectively protected.
[0069] Based on predefined preset conditions, when access to a data resource ends or the authorized usage period of the data resource is reached, the host device 110 will remove the data resource and the corresponding access credentials within the trusted execution environment 115. The preset conditions can be set according to different security policies to ensure that the data resource and the access credentials do not remain for a long time. For example, the preset conditions can indicate that the data resource and the corresponding access credentials are removed after the data analysis task or data access task is completed. Alternatively, the preset conditions can indicate that the data resource and the corresponding access credentials are removed after the authorized usage period of the data resource is reached.
[0070] Through the above process, decryption and data access are performed within a trusted execution environment, reducing the risk of exposing data resources (especially those that may contain sensitive information) in untrusted environments. Furthermore, pre-set conditions ensure that data resources and access credentials are securely removed upon the end of access or the expiration of authorized usage, preventing unauthorized use of data resources. Furthermore, transparent security authentication and strict data access procedures enhance data security.
[0071] Access to data resources is performed based on a data access authorization request. This data access authorization request can be directed to a specific provider. The following describes the process for generating a data access authorization request. Based on a pending data processing task, host device 110 determines at least one data resource type corresponding to the data processing task, where the data resource includes data of the at least one data resource type. Based on the at least one data resource type, a data access authorization request is generated.
[0072] Data processing tasks can include various categories. For example, a data processing task may include analyzing the behavioral data of newly registered users of an application to optimize the user experience.
[0073] Based on the data processing task of the computing engine 112, the host device 110 determines the data resource acquisition scope and data resource type corresponding to the data processing task. The data resource acquisition scope can correspond to clients, such as newly registered users (e.g., users registered less than one month ago), users in a certain region, etc.
[0074] Based on the data resource acquisition scope and data resource type, host device 110 may generate a data access authorization request. For example, the data access authorization request may include the purpose of the data access task, the data type, and the usage period. The purpose of the data access task may be content recommendation, improved functionality, etc. The data type may indicate different types of data resources. The usage period may be 1 day, 5 days, etc.
[0075] Through the above process, after receiving a data access authorization request through the client, the user can clearly understand which data resources are being accessed and used. In other words, because the data access authorization request contains detailed information such as the request purpose, data resource acquisition scope, and data resource type, the user has a clearer understanding and control over data usage.
[0076] The process of determining the data resource type involved in the generation of the data access authorization request may include the following steps: determining multiple data resource types corresponding to the data processing task; and determining at least one data resource type based on the degree of association between data of the multiple data resource types and multiple clients.
[0077] A data processing task typically corresponds to multiple data resource types. For data of multiple data resource types, the level can be determined based on the degree of relevance to the client. For example, high-level data resources, mid-level data resources, and low-level data resources. The level classification criteria can be determined based on actual circumstances.
[0078] By filtering multiple data resource types, data resource types can be determined. For example, only high-level data resources can be retained. In other words, data access authorization requests can be generated only for high-level data resources. Alternatively, both high-level and mid-level data resources can be retained, and data access authorization requests can be generated for both. Through the above process, data resource types are filtered, and access requests are generated only for important data. This avoids frequent data request notifications and reduces user disruption.
[0079] Figure 4 Schematic diagram of a data access process 400 according to some embodiments of the present disclosure is shown. The data access process can be implemented on the client 120 of the target application. Figure 1 To describe Figure 4 The data access process is shown.
[0080] like Figure 4 As shown, in block 401 , in response to the credential management service passing the authentication, access credentials for data access are sent to the credential management service.
[0081] The credential management service can send an attestation report to the client 120. The attestation report can be sent by the credential management service or by the electronic device 110. The attestation report can prove the security of the host device 110. Exemplarily, the attestation report may include hardware trusted computing base (TCB), application measurement values, application custom data, hardware signature and other information. Application measurement values generally refer to a set of values obtained after measuring an application or its components in a trusted execution environment. These values are used to verify the integrity and authenticity of the application and ensure that the application has not been tampered with. Application custom data generally refers to data defined by the application according to its own needs and included in the attestation report. These data can be application-specific configurations, identification information or other content that helps to prove the security and credibility of the application. User 140 confirms the attestation report, which can indicate that the credential management service has passed the verification. Thus, the access credentials for data access can be sent to the credential management service.
[0082] In block 402 , the client 120 processes target data generated by the client in a target application using the processing credentials corresponding to the access credentials.
[0083] The client 120 can upload data resources generated in the target application to the cloud from time to time. The uploaded data resources can be processed using the processing credentials. For example, the access credentials can be used to encrypt the specified data resources to obtain the target data.
[0084] In block 403 , the client 120 may store the processed target data in the data storage side 116 by uploading the target data to the electronic device 110 .
[0085] At block 404, client 120 receives a data access authorization request from a user of a data resource, the data resource including target data. On host device 110, scenarios such as data access tasks and data analysis tasks performed by computing engine 112 can be utilized. The execution of data access tasks or data analysis tasks by computing engine 112 can be sent to client 120 as a trigger for generating and sending a data access authorization request. Client 120 can thus receive a data access authorization request from a user of the data resource.
[0086] At block 405 , the client 120 generates authorization information for the data access authorization request in response to the positive indication of data access authorization. Figure 5A schematic diagram of an interactive interface 500 between client 120 and host device 110 according to some embodiments of the present disclosure is shown. Referring to interface 501, client 120 receives a data access authorization request. In response to a user's "click for details" command, data usage details, as shown in interface 502, may be displayed. For example, the data usage details may include, for example, the scope of data usage, the duration of use, and the purpose of use. In response to a positive indication, authorization information may be generated. For example, the positive indication may be user 140 clicking "Authorize" in interface 502.
[0087] The authorization information may correspond to the data usage details. Specifically, the authorization information may indicate, for example, the scope of application, the duration of use, and the purpose of use of the data. Based on the authorization information, the client 120 may also save an authorization record. Referring to interface 503, the authorization record may correspond to the authorization information. Specifically, the authorization record may include the authorized scope of use, the duration of use, and the purpose of use of the data.
[0088] For example, the scope of authorized use of a data resource may indicate the category of the data resource generated by the target application. The authorized use period may be one day, one hour, etc. The authorized use purpose may be to authorize only the host device 110 to perform a certain data computing task or a certain data analysis task.
[0089] At block 406, client 120 sends the authorization information to the user of the data resource. This information allows the user to access the corresponding data resource. Through this process, the authorization information makes the data access process more transparent. By defining the authorized scope and duration of use, it ensures that the user's data is always under control during use, preventing data misuse or unauthorized access. Users can clearly understand which data is being accessed and the timeframe within which it is being used, thereby enhancing the protection of data resources.
[0090] In some embodiments, the credential management service is authenticated by: receiving an attestation report from the credential management service, the attestation report indicating the trustworthiness of an environment in which the access credentials are stored; and authenticating the credential management service based on the attestation report.
[0091] The attestation report can be sent by the credential management service. The attestation report can include hardware trusted computing basic information, application metrics, application custom data, hardware signatures, etc. The attestation can be verified by the target program in the client 120.
[0092] In some embodiments, the authorization information includes an access token of the client. In addition, the authorization information indicates at least one of the following: the scope of authorized use of the target data, the purpose of authorized use, and the duration of authorized use.
[0093] The authorization information includes the client's access token, which may indicate the identification information of client 120. Based on the identification information, the credential management service configures each access credential entry to consist of unique identification information and a corresponding access credential. Furthermore, the authorization information may also correspond to data usage details, such as the data's scope of application, usage period, and purpose of use.
[0094] Figure 6 A schematic diagram of a data access process 600 according to some embodiments of the present disclosure is shown. The data access process can be implemented in a credential management service. Figure 1 To describe Figure 6 The data access process is shown.
[0095] In block 601 , a credential management service sends an attestation report to a plurality of clients of a target application, the attestation report indicating the trustworthiness of an environment in which access credentials are stored.
[0096] The attestation report can indicate the trustworthiness of the environment in which the credential management service stores data resources. For example, the attestation report can include hardware trusted computing infrastructure information, application metrics, application custom data, and hardware signatures. The credential management service can send the attestation report to multiple clients 120 of the target application to verify its trustworthiness.
[0097] In block 602 , the credential management service receives a plurality of access credentials respectively corresponding to the plurality of clients 120 from the plurality of clients 120 , where the access credentials in the plurality of access credentials are used to access data associated with the corresponding clients 120 .
[0098] After client 120 verifies the attestation report, it can upload the access credentials to the access credential management database 114, which is managed by the credential management service. The credential management service configures each access credential entry to consist of unique identification information and a corresponding access credential. The identification information can be a unique identifier for client 120, which can correspond to the access token of client 120. The access credential can then be used to access data associated with the corresponding client 120.
[0099] In block 603 , in response to receiving an access credential request for at least one of the plurality of clients from a user of the data resource, the credential management service sends an access credential corresponding to the at least one client to the user of the data resource.
[0100] Host device 110, as a user of data resources, responds to data resource requirements generated by a target application by sending data access authorization requests to multiple clients 120 of the target application. After obtaining authorization information from at least one of the multiple clients regarding the data access authorization request, host device 110 can determine an access token for the at least one client based on the authorization information. Based on the access token of the at least one client, host device 110 can send a credential access request for the data resource to a credential management service.
[0101] The credential management service sends the access credential corresponding to the at least one client to the user of the data resource in response to the access credential request.
[0102] The access credential request may include at least an access token. In response to the access credential request including at least one client's access token, the credential management service verifies the access credential request based on the at least one client's access token. In response to the access credential request passing verification, the credential management service sends the at least one client's access credential to the user of the data resource.
[0103] As previously mentioned, the credential management service configures each access credential entry to consist of unique identification information and a corresponding access credential. The access token can indicate the client's identification information. Based on this, the credential management service, using a structured storage method, can quickly and accurately retrieve the corresponding access credential from the access credential management database 114 based on the identification information. The access credential of at least one client is then sent to the user of the data resource.
[0104] The access credential request may also include a security report indicating the trustworthiness of the trusted execution environment 115 used to process the data resource. In response to verification of the security report in the access credential request, the credential management service sends the access credential of at least one client to the user of the data resource, wherein the security report indicates the trustworthiness of the environment used to process the data resource.
[0105] Each access credential corresponds to a processing credential. That is, a processing credential and an access credential constitute a credential pair. On client 120 , target data generated in the target application can be processed based on the processing credential. Exemplarily, this processing can include encryption. The processed target data is stored in data storage 116 .
[0106] Host device 110 sends a credential request for access to a data resource to the credential management service. The credential request may include both an access token and a security report. Based on the access token, the credential management service identifies the corresponding client 120 and retrieves the corresponding access credential. The security report verifies that the trusted execution environment 115 of the computing engine 112 used to process the data resource is secure and trustworthy and meets predetermined security standards. The credential management service verifies the security report and, if verification is successful, sends the access credential for the data resource to the host device 110.
[0107] Figure 7 : A schematic structural block diagram of a data access apparatus 700 according to some embodiments of the present disclosure is shown. The apparatus 700 may be implemented in or included in the host device 110. Each module / component in the apparatus 700 may be implemented by hardware, software, firmware, or any combination thereof.
[0108] As shown, apparatus 700 includes a data access authorization request sending module 701, configured to send a data access authorization request for a data resource to multiple clients of a target application in response to a request for processing a data resource generated in the target application, wherein the multiple clients are associated with the data resource. A data acquisition module 702 is configured to receive authorization information for the data access authorization request from at least one of the multiple clients. An access credential acquisition module 703 is configured to acquire at least one access credential corresponding to each of the at least one client based on the authorization information. A data access module 704 is configured to access target data associated with the at least one client in the data resource to process the target data.
[0109] In some embodiments, the data acquisition module 702 may be specifically configured to: determine an access token for at least one client based on the authorization information; send an access credential request for a data resource to a credential management service, the access credential request including at least the access token; and receive at least one access credential corresponding to each of the at least one client from the credential management service.
[0110] In some implementations, the access credential request also includes a security report indicating the trustworthiness of the environment used to process the data resource.
[0111] In some embodiments, the data acquisition module 702 can also be configured to acquire target data from the data storage side, where the target data is stored in the data storage side by at least one client based on a received certification report, and the certification report indicates the credibility of the environment of the storage data resource.
[0112] In some embodiments, for at least one client, the target data stored in the data storage side is the data generated in the target application processed by the client using processing credentials corresponding to the access credentials of the client and then transmitted to the data storage side.
[0113] In some embodiments, accessing data resources using access credentials is performed within a trusted execution environment, and based on this, a data removal module is also included. The data removal module is configured to remove target data and the access credentials to the target data from the trusted execution environment in response to satisfying a preset condition, wherein the preset condition includes that access to the target data ends or the authorized usage period of the target data expires.
[0114] In some embodiments, the data access authorization request sending module 701 may be specifically configured to: determine, based on the data processing task to be executed, at least one data resource type corresponding to the data processing task, where the data resource includes data of the at least one data resource type; and generate a data access authorization request based on the at least one data resource type.
[0115] In some embodiments, the data access authorization request sending module 701 may be specifically configured to: determine multiple data resource types corresponding to the data processing task, and determine at least one data resource type based on the degree of association between data of the multiple data resource types and multiple clients.
[0116] Figure 8 Schematic block diagram of a data access device 800 according to some embodiments of the present disclosure is shown. The device 800 may be implemented in or included in the client 120. Each module / component in the device 800 may be implemented by hardware, software, firmware, or any combination thereof.
[0117] As shown in the figure, the device 800 includes an access credential sending module 801, which is configured to send the access credential for data access to the credential management service in response to the credential management service passing the verification. The data processing module 802 is configured to use the processing credential corresponding to the access credential to process the target data generated by the client in the target application. The data storage module 803 is configured to store the processed target data to the data storage side. The access request receiving module 804 is configured to receive a data access authorization request from the user end of the data resource, and the data resource includes the target data. The authorization information generating module 805 is configured to generate authorization information for the data access authorization request in response to an affirmative indication of the data access authorization request. The authorization information sending module 806 is configured to send the authorization information to the user end of the data resource.
[0118] In some embodiments, the credential sending module 801 may be further configured to receive an attestation report from the credential management service, the attestation report indicating the trustworthiness of the environment in which the access credential is stored, and to verify the credential management service based on the attestation report.
[0119] In some implementations, the authorization information includes an access token for the client.
[0120] In some embodiments, the authorization information indicates at least one of an authorized use scope, an authorized use purpose, or an authorized use period of the data resource.
[0121] Figure 9 1 shows a schematic structural block diagram of a data access device 900 according to some embodiments of the present disclosure. The device 900 can be implemented in or included in a credential management service, for example. The various modules / components in the device 900 can be implemented by hardware, software, firmware, or any combination thereof.
[0122] As shown, apparatus 900 includes an attestation report sending module 901 configured to send an attestation report to multiple clients of a target application, the attestation report indicating the credibility of the environment in which access credentials are stored. An access credential receiving module 902 is configured to receive, from multiple clients, multiple access credentials corresponding to the multiple clients, each of which is used to access data associated with the corresponding client. An access credential sending module 903 is configured to, in response to receiving an access credential request for at least one of the multiple clients from a user of a data resource, send the access credential corresponding to the at least one client to the user of the data resource.
[0123] In some embodiments, the access credentials corresponding to a client among the multiple clients have corresponding processing credentials, and the corresponding processing credentials are used by the client to process target data generated in the target application, and the processed target data is stored in the data storage side.
[0124] In some embodiments, the access credential sending module 903 may be specifically configured to: in response to an access credential request including at least one client's access token, verify the access credential request based on the at least one client's access token, and in response to the access credential request passing verification, send the at least one client's access credential to a user of the data resource.
[0125] In some embodiments, the access credential sending module 903 can be specifically configured to: in response to the security report in the access credential request being verified, send the access credential of at least one client to the user end of the data resource, and the security report indicates the credibility of the environment used to process the data resource.
[0126] Figure 101 is a block diagram of an electronic device 1000 in which one or more embodiments of the present disclosure may be implemented. Figure 10 The illustrated electronic device 1000 is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 10 The electronic device 1000 shown may include or be implemented as Figure 1 The host device 110, the client 120, the credential management service, Figure 7 Device 700, Figure 8 Device 800 or Figure 9 device 900.
[0127] like Figure 10 As shown, electronic device 1000 is in the form of a general electronic device. Components of electronic device 1000 may include, but are not limited to, one or more processors or processing units 1010, memory 1020, storage device 1030, one or more communication units 1040, one or more input devices 1050, and one or more output devices 1060. Processing unit 1010 may be a real or virtual processor and is capable of performing various processes according to a program stored in memory 1020. In a multi-processor system, multiple processing units execute computer-executable instructions in parallel to increase the parallel processing capabilities of electronic device 1000.
[0128] The electronic device 1000 typically includes a plurality of computer storage media. Such media can be any accessible media that is accessible to the electronic device 1000, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 1020 can be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 1030 can be a removable or non-removable medium and can include a machine-readable medium, such as a flash drive, a disk, or any other medium that can be used to store information and / or data and can be accessed within the electronic device 1000.
[0129] The electronic device 1000 may further include additional removable / non-removable, volatile / non-volatile storage media. Figure 8As shown in FIG, a magnetic disk drive for reading from or writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk") and an optical disk drive for reading from or writing to a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data media interfaces. Memory 1020 may include a computer program product 1025 having one or more program modules configured to perform various methods or actions of various embodiments of the present disclosure.
[0130] The communication unit 1040 enables communication with other electronic devices via a communication medium. Additionally, the functions of the components of the electronic device 1000 can be implemented as a single computing cluster or multiple computing machines that can communicate via a communication connection. Thus, the electronic device 1000 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or other network nodes.
[0131] Input device 1050 may be one or more input devices, such as a mouse, keyboard, or trackball. Output device 1060 may be one or more output devices, such as a display, a speaker, or a printer. Electronic device 1000 may also communicate with one or more external devices (not shown) via communication unit 1040 as needed, such as storage devices, display devices, or the like, with one or more devices that allow a user to interact with electronic device 1000, or with any device that allows electronic device 1000 to communicate with one or more other electronic devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).
[0132] According to an exemplary implementation of the present disclosure, a computer-readable storage medium is provided, on which computer-executable instructions are stored, wherein the computer-executable instructions are executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the method described above.
[0133] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0134] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, such that when these instructions are executed by the processing unit of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.
[0135] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0136] The flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to multiple implementations of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a part for a module, program segment or instruction, and a part for a module, program segment or instruction comprises one or more executable instructions for realizing the logical function of the specification. In some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be realized by a special hardware-based system that performs the function or action of the specification, or can be realized by a combination of special hardware and computer instructions.
[0137] While various implementations of the present disclosure have been described above, the foregoing description is intended to be illustrative, not exhaustive, and not limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is selected to best explain the principles of the implementations, their practical applications, or improvements to existing technologies, or to enable others skilled in the art to understand the various implementations disclosed herein.
Claims
1. A data access method, applied to a user end of a data resource, comprising: In response to a demand for a data resource generated in a processing target application, sending a data access authorization request for the data resource to a plurality of clients of the target application, the plurality of clients being associated with the data resource; receiving authorization information for the data access authorization request from at least one client among the plurality of clients; Based on the authorization information, obtaining at least one access credential corresponding to the at least one client; as well as Utilizing the at least one access credential, access the target data associated with the at least one client in the data resource to process the target data, wherein the target data is stored by the at least one client to the data storage side based on a received attestation report, and the attestation report indicates the credibility of the environment storing the data resource.
2. The method according to claim 1, wherein obtaining at least one access credential corresponding to each of the at least one client comprises: determining an access token for the at least one client based on the authorization information; Sending an access credential request for the data resource to a credential management service, the access credential request including at least the access token; as well as At least one access credential respectively corresponding to the at least one client is received from the credential management service.
3. The method of claim 2, wherein the access credential request further comprises: A security report indicating the trustworthiness of an environment for processing the data resource.
4. The method according to claim 1, wherein, for a client among the at least one client, the target data stored in the data storage side is the data generated in the target application processed by the client using processing credentials corresponding to the access credentials of the client and then transmitted to the data storage side.
5. The method according to claim 1 , wherein accessing target data associated with the at least one client in the data resource is performed within a trusted execution environment, and the method further comprises: In response to a preset condition being met, the target data and the access credential to the target data are removed from the trusted execution environment. The preset condition includes that access to the target data ends or an authorized usage period of the target data has expired.
6. The method according to claim 1, wherein the data access authorization request is determined by: determining, based on a data processing task to be executed, at least one data resource type corresponding to the data processing task, the data resource including data of the at least one data resource type; and The data access authorization request is generated based on the at least one data resource type.
7. The method according to claim 6, wherein determining at least one data resource type corresponding to the data processing task comprises: determining a plurality of data resource types corresponding to the data processing task; as well as The at least one data resource type is determined based on the association levels between the data of the multiple data resource types and the multiple clients.
8. A data access method, applied to a client of a target application, comprising: In response to the credential management service passing the authentication, sending access credentials for data access to the credential management service; Processing target data generated by the client in the target application using a processing credential corresponding to the access credential; storing the processed target data in a data storage side based on a received first attestation report, the first attestation report indicating the trustworthiness of an environment storing a data resource; receiving a data access authorization request from a user of the data resource, wherein the data resource includes the target data; generating authorization information for the data access authorization request in response to a positive indication of the data access authorization request; as well as The authorization information is sent to the user of the data resource.
9. The method of claim 8, wherein the credential management service is authenticated by: receiving a second attestation report from the credential management service, the second attestation report indicating the trustworthiness of an environment in which access credentials are stored; and The credential management service is authenticated based on the second attestation report.
10. The method of claim 8, wherein the authorization information comprises an access token of the client.
11. The method according to claim 8, wherein the authorization information indicates at least one of the following: The scope of authorized use of the target data, Authorized use purpose, Authorized use period.
12. A data access method, applied to a credential management service, comprising: sending an attestation report to a plurality of clients of the target application, the attestation report indicating the trustworthiness of an environment storing access credentials; receiving, from the plurality of clients, a plurality of access credentials respectively corresponding to the plurality of clients, wherein the access credentials in the plurality of access credentials are used to access data associated with the corresponding clients; as well as In response to receiving an access credential request for at least one of the plurality of clients from a user of the data resource, an access credential corresponding to the at least one client is sent to the user of the data resource.
13. The method according to claim 12, wherein the access credentials corresponding to the client among the multiple clients have corresponding processing credentials, and the corresponding processing credentials are used by the client to process the target data generated in the target application, and the processed target data is stored in the data storage side.
14. The method according to claim 12, wherein sending the access credentials corresponding to the at least one client to the user of the data resource comprises: In response to the access credential request including at least an access token of the at least one client, verifying the access credential request based on the access token of the at least one client; as well as In response to the access credential request being verified, the access credential of the at least one client is sent to a user of the data resource.
15. The method according to claim 12, wherein sending the access credentials corresponding to the at least one client to the user of the data resource comprises: In response to a security report in the access credential request being verified, the access credential of the at least one client is sent to a user of the data resource, the security report indicating the trustworthiness of an environment for processing the data resource.
16. An electronic device comprising: at least one processing unit; as well as At least one memory, the at least one memory being coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions causing the electronic device to perform the method according to any one of claims 1 to 15 when executed by the at least one processing unit.
17. A computer-readable storage medium having a computer program stored thereon, the computer program being executable by a processor to implement the method according to any one of claims 1 to 15.
Citation Information
Patent Citations
Data processing method and device and readable storage medium
CN110798501A
Data processing method based on block chain and related equipment thereof
CN114077749A
Cited By
Time based file access
US20260010593A1