Data usage control method, apparatus, device, and medium
By monitoring and intercepting application system calls in a trusted execution environment, and controlling data access based on data usage contracts, the problem of data leakage and abuse caused by application failures is solved, fine-grained data usage control is achieved, and the security and reliability of data usage are improved.
Patent Information
- Application Number
- CN202411385319.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing technologies have failed to effectively address data leakage and misuse issues caused by application failures during data usage, lack fine-grained control methods, and pose security risks.
In a trusted execution environment, by monitoring the system calls of applications, access to preset data is intercepted, and based on the data usage contract, it is determined whether the data usage policy is met. A data usage control sandbox is then established to control the application's access to and use of preset data.
It enables fine-grained control over the data usage process, avoiding data leakage and misuse due to application failures, and improving the security and reliability of data use.
Smart Images

Figure CN119357947B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data protection technology, and in particular to a data usage control method, apparatus, device, and medium. Background Technology
[0002] Trusted data space consists of a set of hardware and software components. Its main purpose is to build a confidential computing environment through trust metrics and other methods. By measuring and certifying hardware, firmware, kernel, and applications, the trustworthiness and security of the operating environment can be ensured. However, in order to further enhance the security of data during use, a fine-grained control method for the data usage process is urgently needed.
[0003] Existing technologies typically do not address security issues such as data leaks and misuse caused by application bugs or malfunctions, and therefore cannot achieve fine-grained control over the data usage process, thus leaving certain security vulnerabilities. Summary of the Invention
[0004] This invention provides a data usage control method, apparatus, device, and medium to achieve fine-grained control over the data usage process and further improve the security of the data usage process.
[0005] According to one aspect of the present invention, a data usage control method is provided, the method comprising:
[0006] In the current trusted execution environment, system calls of at least one application are monitored, and when it is determined that a system call accesses preset data, the system call is intercepted; wherein, the preset data includes at least one set of preset data content;
[0007] Based on the data usage contract corresponding to the preset data, it is determined whether the data usage information corresponding to the intercepted system call meets the data usage policy; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation;
[0008] If so, the application is allowed to access the preset data, and a data usage control sandbox corresponding to the application is established; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application;
[0009] Based on the data, a control sandbox is used to control the application's use of the preset data.
[0010] According to another aspect of the present invention, a data usage control device is provided, the device comprising:
[0011] The system call interception module is used to monitor system calls of at least one application in the current trusted execution environment, and to intercept the system call when it is determined that the system call accesses preset data; wherein, the preset data includes at least one set of preset data content;
[0012] The data usage information judgment module is used to determine whether the data usage information corresponding to the intercepted system call meets the data usage policy based on the data usage contract corresponding to the preset data; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation;
[0013] A data usage control sandbox creation module is used to allow the application to access the preset data if the condition is met, and to create a data usage control sandbox corresponding to the application; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application;
[0014] The data usage control module is used to control the application's use of the preset data based on the data usage control sandbox.
[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data usage control method according to any embodiment of the present invention.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the data usage control method described in any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer program product is provided, comprising a computer program / instructions that, when executed by a processor, implement the data usage control method as described in any embodiment of the present invention.
[0021] The technical solution of this invention further establishes independent data storage sandboxes and data usage control sandboxes during data usage within the current trusted execution environment. Data usage contracts negotiated and agreed upon by the data user and data owner are stored in these sandboxes. The system calls of applications within this trusted environment are monitored and intercepted accordingly. This allows for timely interception of data access and usage caused by erroneous system calls due to bugs in the application itself, based on the control of the corresponding data usage control sandbox. This helps avoid data abuse and leakage caused by bugs in the application itself, thereby improving the security and reliability of the data usage process and achieving non-intrusive, fine-grained, and dynamic control over data usage.
[0022] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of a data usage control method provided according to Embodiment 1 of the present invention.
[0025] Figure 2 This is a flowchart of another data usage control method provided according to Embodiment 2 of the present invention.
[0026] Figure 3A This is a flowchart of another data usage control method provided according to Embodiment 3 of the present invention.
[0027] Figure 3B This is an architecture diagram of a trusted execution environment that can be used for data sharing, provided according to Embodiment 3 of the present invention.
[0028] Figure 4 This is a schematic diagram of a data usage control device according to Embodiment 4 of the present invention.
[0029] Figure 5 This is a schematic diagram of the structure of an electronic device that implements the data usage control method of the present invention. Detailed Implementation
[0030] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0032] Figure 1 This is a flowchart of a data usage control method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where data usage in a trusted execution environment needs to be controlled. The method can be executed by a data usage device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 The method includes:
[0033] S110. In the current trusted execution environment, system calls of at least one application are monitored, and when it is determined that the system call accesses preset data, the system call is intercepted; wherein, the preset data includes at least one set of preset data content.
[0034] The trusted execution environment (TEA) can be a pre-established secure environment for data sharing, such as a pre-configured virtual machine. This TEA can be used to run at least one application. Data users can use the corresponding preset data through this application. The preset data can be data information provided by at least one data owner for data sharing. Each set of preset data can be used by at least one application. The preset data corresponding to different sets of preset data can overlap or be different. System calls can be calls made by the application to external systems, such as accessing network devices, graphics cards, etc., by calling `socket()` or `ioctl()`, or accessing the file system by calling `open()`. These can be configured as needed and are not specifically limited. Monitoring of the above system calls can be implemented by a pre-configured data sandbox listener, which can be a code module capable of real-time monitoring and interception of the corresponding system calls.
[0035] Specifically, the data sandbox monitor's handler can be written into the system call table by rewriting the system call table, and the handler can be registered as a hook based on the kernel system's preset interface. Correspondingly, when an application initiates various system calls, the interception module in the data sandbox monitor can intercept the corresponding system calls that access preset data.
[0036] S120. Based on the data usage contract corresponding to the preset data, determine whether the data usage information corresponding to the intercepted system call meets the data usage policy; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation.
[0037] The data usage contract may include at least one of the following: data content corresponding to the preset data, data price, and data usage strategy. The method by which the data user and data owner negotiate the data usage contract can be chosen as needed. The data usage strategy can describe the manner and rules of data usage and can be represented in the form of a set. For example, a data usage strategy could be: {Data Owner: {[User1], Readable: Yes, Processable: No, Number of Reads: 3, Data Usage Time (After Destruction): 10 days, The following applications (APPs) can use the data: APP1, APP2, Processed Data Usage Strategy: Inherited}, etc. Data usage information may include at least one of the following information types: data content, usage time, and number of uses.
[0038] Specifically, if the data usage information corresponding to the intercepted system call does not meet the data usage policy, access to and use of the corresponding preset data content by the system call can be denied. Optionally, the data sandbox monitor may also include a usage decision module, which can be used to determine whether the data usage information corresponding to the intercepted system call meets the data usage policy of the preset data content corresponding to the data usage information. Optionally, the data sandbox monitor may also include a data transmission module, whereby the data owner can send the corresponding preset data and the corresponding data usage contract to the data transmission module in the corresponding data sandbox monitor, so that the corresponding preset data and the corresponding data usage contract can be transmitted and saved to the corresponding data storage sandbox based on the data transmission module.
[0039] S130. If so, the application is allowed to access the preset data, and a data usage control sandbox corresponding to the application is established; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application.
[0040] Different applications can correspond to different data usage control sandboxes. For example, APP1's data usage control sandbox can be Sandbox 1, APP2's data usage control sandbox can be Sandbox 2, and so on. That is, if an APP can access multiple sets of preset data content, each accessed preset data content needs to be recorded in the corresponding data usage control sandbox. A single data usage control sandbox can include at least one set of preset data content and at least one data usage policy corresponding to that set of preset data content. A set of preset data content can correspond to at least one data usage policy. The corresponding preset data content and corresponding data usage policy can also be described in the form of a set in the data usage control sandbox, for example, it can be {Application: APP1, Data: [Data1, Data1's corresponding "Data Usage Policy 1"]}, etc.
[0041] Specifically, if it is determined that the data usage information corresponding to the intercepted system call does not meet the data usage policy, the system call's access request to the corresponding preset data can be directly rejected. Consequently, there is no need to make further judgments and controls on the data usage request corresponding to the system call.
[0042] S140. Based on the data, use a control sandbox to control the application's use of the preset data.
[0043] Specifically, after determining that the corresponding application is allowed to access the preset data and completing the establishment of the data usage control sandbox for the corresponding application, the corresponding application can be controlled to use the preset data content based on the agreement of the corresponding data usage policy.
[0044] For example, if the corresponding preset data content is defined in the data usage policy as only viewable, then during the use of the preset data by the corresponding application, it is possible to control whether any file saving or network transmission is allowed. The corresponding preset data content can only stay in memory, and correspondingly, the preset data content can only be sent to the graphics card for display.
[0045] The technical solution of this invention further establishes independent data storage sandboxes and data usage control sandboxes during data usage within the current trusted execution environment. Data usage contracts negotiated and agreed upon by the data user and data owner are stored in these sandboxes. The system calls of applications within this trusted environment are monitored and intercepted accordingly. This allows for timely interception of data access and usage caused by erroneous system calls due to bugs in the application itself, based on the control of the corresponding data usage control sandbox. This helps avoid data abuse and leakage caused by bugs in the application itself, thereby improving the security and reliability of the data usage process and achieving non-intrusive, fine-grained, and dynamic control over data usage.
[0046] Figure 2 This is a flowchart of a data usage control method provided in Embodiment 2 of the present invention. This embodiment is based on the above embodiments and further optimized. It should be noted that for parts not described in detail in this embodiment, please refer to the relevant descriptions in other embodiments.
[0047] Furthermore, before establishing a data usage control sandbox corresponding to the application, the following addition is made: "By traversing all established data usage control sandboxes, determine whether a data usage control sandbox corresponding to the application exists; if not, establish a data usage control sandbox corresponding to the application and store the data usage policy corresponding to the preset data content currently accessed by the application in the data usage control sandbox; if yes, if it is determined that there is no data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox corresponding to the application, store the data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox," to improve the establishment mechanism of the data usage control sandbox.
[0048] refer to Figure 2 The method specifically includes the following steps:
[0049] S210. In the current trusted execution environment, system calls of at least one application are monitored, and when it is determined that the system call accesses preset data, the system call is intercepted; wherein, the preset data includes at least one set of preset data content.
[0050] S220. Based on the data usage contract corresponding to the preset data, determine whether the data usage information corresponding to the intercepted system call meets the data usage policy; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation.
[0051] S230. If so, the application is allowed to access the preset data, and the existence of a data use control sandbox corresponding to the application is determined by traversing the established data use control sandboxes.
[0052] S241. If so, when it is determined that there is no data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox corresponding to the application, the data usage policy corresponding to the currently accessed preset data content is stored in the data usage control sandbox.
[0053] Specifically, if a data usage policy corresponding to the currently accessed preset data content exists in the data usage control sandbox of the corresponding application, then there is no need to rebuild the corresponding data usage control sandbox, nor is there a need to restore the data usage policy of the currently accessed preset data content. Instead, the existing data usage control sandbox of the application can be used as the current data usage control sandbox of the application.
[0054] S242. If not, then establish a data usage control sandbox corresponding to the application, and store the data usage policy corresponding to the preset data content currently accessed by the application in the data usage control sandbox.
[0055] S250. Based on the data, use a control sandbox to control the application's use of the preset data.
[0056] For example, the preset data content currently accessed by the application can exist in multiple sets; correspondingly, controlling the application's use of the preset data using a control sandbox based on the data can include:
[0057] Based on the data usage control sandbox, the union of data usage policies corresponding to each set of preset data content currently accessed by the application is determined; wherein, the data usage control sandbox includes the data usage policies corresponding to each set of preset data content; the union is used as the new data usage policy corresponding to each set of preset data content, and the application's use of each set of preset data content is controlled according to the new data usage policy.
[0058] In this approach, an application can access multiple sets of preset data content simultaneously, and different preset data content can correspond to different data usage strategies. Specifically, when a corresponding application accesses multiple sets of preset data content simultaneously, the union of the data usage strategies corresponding to each set of preset data content can be used as the new data usage strategy for each set of preset data content.
[0059] It is understandable that by combining the data usage policies corresponding to each set of preset data content in a union manner when the application accesses multiple sets of preset data content simultaneously, a more stringent data usage policy can be obtained. This helps to avoid data abuse or leakage caused by inconsistent stringency of data usage policies in the overlapping parts when multiple sets of preset data content have overlapping parts. It also helps to avoid resource consumption and inconsistent stringency caused by setting independent data usage policies for each set of preset data content separately, thereby helping to improve the security of the corresponding data usage process.
[0060] In an alternative embodiment, prior to monitoring system calls of at least one application, the following may also be included:
[0061] In response to an application download command sent by a data user, at least one application corresponding to the application download command is downloaded; the downloaded application is verified to determine the integrity of the application.
[0062] At least one application can be an application selected by the user when they have a data usage need, allowing them to access and use preset data content corresponding to that data usage need. The corresponding application download command can be generated based on the application selection information entered by the user.
[0063] Specifically, when a data user selects to use at least one application, a download command for that application can be sent to the data sandbox monitor. The data sandbox monitor can then respond to the download command, download the application, and, upon completion, measure the application to verify its integrity.
[0064] It is understandable that by downloading at least one application corresponding to the application download command in response to the application download command sent by the data user in the corresponding trusted execution environment, and performing integrity verification on the downloaded application, it helps to avoid the situation where the application is downloaded in an untrusted environment and / or the integrity of the downloaded application is not further verified, thereby helping to further ensure the integrity of the application itself.
[0065] In this embodiment of the invention, by traversing all established data usage control sandboxes, it is determined whether a data usage control sandbox corresponding to the corresponding application exists. If a data usage control sandbox corresponding to the application already exists, it is further determined that the sandbox does not contain a usage control policy corresponding to the currently accessed preset data content. If the sandbox corresponding to the application does not contain a data usage policy corresponding to the currently accessed preset data content, the data usage policy is further stored. This avoids the situation where a data usage control sandbox corresponding to the application already exists and that sandbox already stores a corresponding data usage policy, requiring the re-establishment of the sandbox corresponding to the application. This helps reduce the waste of computing and storage resources and also helps improve the execution efficiency of the corresponding data usage process.
[0066] Figure 3A This is a flowchart of a data usage control method provided in Embodiment 3 of the present invention. This embodiment is based on the above embodiments and further optimized. It should be noted that for parts not described in detail in this embodiment, please refer to the relevant descriptions in other embodiments.
[0067] Furthermore, the phrase "controlling the application's use of the preset data based on the data usage control sandbox" is refined to "determining the preset data content currently accessed by the application, and determining the data usage strategy corresponding to the preset data content in the data usage control sandbox based on the preset data content; judging whether the application's use of the preset data content conforms to the agreement of the corresponding data usage strategy; if not, then rejecting the application's use of the preset data content," thereby improving the data usage control mechanism.
[0068] refer to Figure 3A The method specifically includes the following steps:
[0069] S310. In the current trusted execution environment, system calls of at least one application are monitored, and when it is determined that the system call accesses preset data, the system call is intercepted; wherein, the preset data includes at least one set of preset data content.
[0070] S320. Based on the data usage contract corresponding to the preset data, determine whether the data usage information corresponding to the intercepted system call meets the data usage policy; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation.
[0071] S330. If so, the application is allowed to access the preset data, and a data usage control sandbox corresponding to the application is established; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application.
[0072] S340. Determine the preset data content currently accessed by the application, and based on the preset data content, determine the data usage strategy in the data usage control sandbox corresponding to the preset data content.
[0073] S350. Determine whether the application's use of the preset data content conforms to the agreement of the corresponding data usage strategy.
[0074] S360. If not, then the application's use of the preset data content is rejected.
[0075] Specifically, if the application's use of the corresponding preset data content conforms to the agreement of the corresponding data usage policy, it can be allowed, and the preset data content can be loaded into memory so that the application can use the preset data content normally based on the agreement of the corresponding data usage policy. The process of determining whether the application's use of the preset data content conforms to the agreement of the corresponding data usage policy can be executed by the corresponding usage decision module.
[0076] In an optional embodiment, the corresponding method may further include:
[0077] If a data processor processes preset data provided by at least one data owner, the union of at least one data usage strategy corresponding to the preset data and the data usage strategy added by the data processor is taken as the new data usage strategy corresponding to the processed preset data. The new data usage strategy and the processed preset data are stored in the data storage sandbox, and the owner of the processed preset data is recorded. The owner of the processed preset data includes the at least one data owner and the data processor.
[0078] The data processor can be an operator with permissions to process pre-defined data shared by all data owners. This data processor can add new data usage strategies to the processed pre-defined data.
[0079] For example, in scenarios involving data processing, the processed preset data can integrate and retain the data usage strategy of its original data. Furthermore, if there are multiple original data sets, the data usage strategies corresponding to these multiple original data sets can be merged. For the original data corresponding to the relevant preset data, the characteristic information and data usage strategy of the original data can be sent to the blockchain for traceability and ownership confirmation. For example, it can determine who holds the original data, who processes it, and if the usage period of the original data is only authorized for one year, then the expiration period of all processed data derived from this original data can also be only one year.
[0080] It is understandable that when the data processing party completes the processing of the corresponding preset data and adds a data usage strategy for the processed preset data, the newly added data usage strategy can be merged with the original data usage strategy corresponding to the preset data itself, and the data usage strategy for the processed preset data can be obtained in the form of a union. This allows the data usage strategy for the processed preset data to be combined with the usage control strategies of all parties, thereby ensuring that the strictness of the corresponding data usage strategy can meet the needs of all parties at the same time, and avoiding data abuse and leakage.
[0081] In an optional embodiment, if the validity period of the data included in the data usage strategy corresponding to the preset data expires, the data processor may renegotiate the corresponding data usage strategy with the original data owner corresponding to the preset data, and use the negotiated data usage strategy as the data usage strategy corresponding to the processed preset data.
[0082] In one optional embodiment, the negotiation and agreement process for the data usage contract corresponding to the preset data may include:
[0083] The description information of preset data is published on the blockchain so that the data user can create a candidate data usage smart contract corresponding to the preset data based on the description information of the preset data; wherein, the data usage smart contract includes at least the description information of the preset data and the candidate data usage strategy; the status of the candidate data usage smart contract is obtained, and when the status is signed, the candidate data usage smart contract in the signed state is used as the target data usage smart contract; wherein, the target data usage smart contract is the data usage contract corresponding to the preset data, and the target data usage smart contract is obtained through negotiation, modification and unanimous confirmation by the data owner and the data user.
[0084] The description information of the preset data can be uploaded by the data owner. This description information may include at least one of the following data types: data fields, number of data entries, and data format. This description information can be equivalent to the data content of the corresponding preset data. The data usage smart contract may include the corresponding data usage contract. The status of the candidate data usage smart contract may include a negotiation status and a signing status. The negotiation status may be triggered when the data owner negotiates and modifies the data usage strategy corresponding to the candidate data usage smart contract. The signing status can be used to indicate that both the data owner and the data user agree to the data usage strategy in the current data usage smart contract. The current data usage smart contract may be the original candidate data usage smart contract or the candidate data usage smart contract modified by the data owner. The negotiation method between the data owner and the data user may be based on uploading whether they agree to the data usage strategy in the current data usage smart contract through the blockchain, or it may be other negotiation methods determined as needed, without specific restrictions here.
[0085] Understandably, the negotiation and confirmation of data usage contracts between data owners and users through blockchain can ensure the reliability of the final data usage contracts. This facilitates the rapid and accurate tracing and confirmation of rights for relevant information on the data, thereby improving the security and reliability of the data usage process.
[0086] In one optional embodiment, the usage records of preset data can be uploaded to the blockchain, allowing the data owner to view the usage records of the corresponding preset data in real time. Upon discovering any unauthorized usage, a data access cutoff command can be sent to the blockchain in real time. This command is then transmitted via the blockchain to the sandbox control structure to cut off access to the data corresponding to the unauthorized usage record. Furthermore, the usage records of the preset data can also be used for auditing and monitoring.
[0087] In this embodiment of the invention, after determining that access to the corresponding preset data is permitted, the use of the preset data is controlled based on the data usage policy in the control sandbox. This further ensures that the use of the corresponding preset data does not violate the agreement of the corresponding data usage policy, thereby helping to avoid data abuse and leakage caused by bugs in the application itself, and improving the security and reliability of the corresponding data usage process.
[0088] For ease of understanding, please refer to Figure 3B This provides a concrete example of a trusted execution environment that can be used for data sharing. It should be noted that... Figure 3BThe applications, data types, and usage control policies mentioned herein are for illustrative purposes only and should not be construed as specific limitations of the present invention.
[0089] Figure 3B An architecture diagram of a trusted execution environment that can be used for data sharing, for example... Figure 3B As shown, the data owner can provide corresponding data to the trusted execution environment, and the data user can use the data based on this trusted execution environment. The trusted execution environment can be a virtual machine (VM), specifically including a security processor, a hypervisor, a Basic Input Output System (BIOS), a bootloader, a kernel, a data sandbox monitor, and virtualized usage control sandboxes and data storage sandboxes. The data sandbox monitor can include a usage control sandbox structure, a data storage sandbox monitoring module, a data transmission module, a usage decision module, and a usage interception module. The usage control sandbox can be the aforementioned data usage control sandbox. The usage control sandbox structure can include usage control sandbox structure 1, usage control sandbox structure 2, etc., which can correspond to the established usage control sandbox and can be used to control the use of preset data. The data storage sandbox monitoring module can be used to determine whether the data usage information corresponding to the intercepted system call meets the data usage policy. The corresponding applications can be application 1 and application 2, etc. The preset data accessed by application 1 can be data 1, and the data usage policy corresponding to data 1 can be usage control policy 1. The preset data accessed by application 2 can be data 2, and the data usage policy corresponding to data 2 can be usage control policy 2. The preset data stored in the data storage sandbox can include corresponding data 1 and data 2, etc., and correspondingly, the stored data usage policies can include usage control policy 1 and usage control policy 2. The data content in the usage control sandbox corresponds to the data content stored in the data storage sandbox.
[0090] Figure 4 This is a schematic diagram of a data usage control device provided in Embodiment 4 of the present invention. This embodiment is applicable to situations where data usage in a trusted execution environment is controlled. The device can be implemented in hardware and / or software and can be configured in an electronic device. Figure 4 The device includes:
[0091] The system call interception module 410 is used to monitor system calls of at least one application in the current trusted execution environment, and to intercept the system call when it is determined that the system call accesses preset data; wherein, the preset data includes at least one set of preset data content.
[0092] The data usage information judgment module 420 is used to determine whether the data usage information corresponding to the intercepted system call meets the data usage policy based on the data usage contract corresponding to the preset data; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation.
[0093] The data usage control sandbox establishment module 430 is used to allow the application to access the preset data if the condition is met, and to establish a data usage control sandbox corresponding to the application; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application.
[0094] The data usage control module 440 is used to control the application's use of the preset data based on the data usage control sandbox.
[0095] The technical solution of this invention further establishes independent data storage sandboxes and data usage control sandboxes during data usage within the current trusted execution environment. Data usage contracts negotiated and agreed upon by the data user and data owner are stored in these sandboxes. The system calls of applications within this trusted environment are monitored and intercepted accordingly. This allows for timely interception of data access and usage caused by erroneous system calls due to bugs in the application itself, based on the control of the corresponding data usage control sandbox. This helps avoid data abuse and leakage caused by bugs in the application itself, thereby improving the security and reliability of the data usage process and achieving non-intrusive, fine-grained, and dynamic control over data usage.
[0096] Optionally, the corresponding device may also include:
[0097] The use of a control sandbox existence determination module is used to determine whether a data use control sandbox corresponding to the application exists by traversing the existing data use control sandboxes before establishing a data use control sandbox corresponding to the application.
[0098] A data usage policy existence determination module is used to, if it is determined that there is no data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox corresponding to the application, store the data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox.
[0099] A control sandbox is used to establish a trigger module, which, if not, establishes a data usage control sandbox corresponding to the application and stores the data usage policy corresponding to the preset data content currently accessed by the application in the data usage control sandbox.
[0100] Optionally, the preset data content currently accessed by the application can exist in multiple sets; correspondingly, the data usage control module 440 may include:
[0101] The union determination unit is used to determine the union of data usage policies corresponding to each set of preset data content currently accessed by the application, based on the data usage control sandbox; wherein, the data usage control sandbox includes the data usage policies corresponding to each set of preset data.
[0102] The data usage control unit is used to take the union as a new data usage strategy corresponding to each set of preset data content, and control the application's use of each set of preset data content according to the new data usage strategy.
[0103] Optionally, the data use control module 440 may also include:
[0104] A data usage strategy determination unit is used to determine the preset data content currently accessed by the application, and to determine the data usage strategy corresponding to the preset data content in the data usage control sandbox based on the preset data content.
[0105] The agreement compliance determination unit is used to determine whether the application's use of the preset data content complies with the agreement of the corresponding data usage strategy;
[0106] The data use rejection unit is used to reject the application's use of the preset data content if no.
[0107] Optionally, the corresponding device may also include:
[0108] The new data usage strategy determination module is used to determine the new data usage strategy corresponding to the pre-defined data if a data processor processes pre-defined data provided by at least one data owner. The union of the pre-defined data usage strategy corresponding to the pre-defined data and the data processing strategy added by the data processor is used as the new data usage strategy corresponding to the pre-defined data after processing.
[0109] The data owner recording module is used to store the new data usage strategy and the processed preset data in the data storage sandbox, and record the owner of the processed preset data; wherein, the owner of the processed preset data includes the at least one data owner and the data processor.
[0110] Optionally, the negotiation and agreement process for the data usage contract corresponding to the preset data may include:
[0111] The description information of the preset data is published on the blockchain so that the data user can create a candidate data usage smart contract corresponding to the preset data based on the description information of the preset data; wherein, the data usage smart contract includes at least the description information of the preset data and the candidate data usage strategy;
[0112] The status of the candidate data using smart contract is obtained, and when the status is signed, the candidate data using smart contract in the signed state is used as the target data using smart contract; wherein, the target data using smart contract is the data using contract corresponding to the preset data, and the target data using smart contract is obtained after negotiation, modification and unanimous confirmation by the data owner and the data user.
[0113] Optionally, the corresponding device may also include:
[0114] The application download module is used to download at least one application corresponding to the application download command sent by the data user in response to the system call of at least one application before monitoring the system call of at least one application.
[0115] The integrity verification module is used to verify the downloaded application to determine its integrity.
[0116] The data usage control device provided in this embodiment of the invention can execute any of the data usage control methods provided in this embodiment of the invention, and has the corresponding functional modules and beneficial effects for executing each data usage control method. Content not described in detail in this embodiment of the invention can be referred to the description in any of the data usage control method embodiments of this invention.
[0117] According to embodiments of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0118] Figure 5A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0119] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0120] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0121] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as data usage control methods.
[0122] In some embodiments, the data usage control method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the data usage control method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the data usage control method by any other suitable means (e.g., by means of firmware).
[0123] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0124] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0125] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0126] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0127] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0128] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0129] Artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies mainly include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0130] Cloud computing refers to a technology system that enables access to a shared pool of physical or virtual resources via a network. These resources can include servers, operating systems, networks, software, applications, and storage devices, and can be deployed and managed on demand and in a self-service manner. Cloud computing technology can provide efficient and powerful data processing capabilities for applications such as artificial intelligence and blockchain, as well as for model training.
[0131] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution provided in this disclosure can be achieved, and this is not limited herein.
[0132] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A data usage control method, characterized in that, include: In the current trusted execution environment, system calls of at least one application are monitored, and when it is determined that a system call accesses preset data, the system call is intercepted; wherein, the preset data includes at least one set of preset data content; Based on the data usage contract corresponding to the preset data, it is determined whether the data usage information corresponding to the intercepted system call meets the data usage policy; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation; If so, the application is allowed to access the preset data, and a data usage control sandbox corresponding to the application is established; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application; Based on the data, a control sandbox is used to control the application's use of the preset data; The application currently accesses multiple sets of preset data content; correspondingly, a control sandbox is used to control the application's use of the preset data, including: Based on the data usage control sandbox, the union of data usage policies corresponding to each set of preset data content currently accessed by the application is determined; wherein, the data usage control sandbox includes the data usage policies corresponding to each set of preset data content; The union is used as a new data usage strategy corresponding to each set of preset data content, and the application's use of each set of preset data content is controlled according to the new data usage strategy.
2. The method according to claim 1, characterized in that, Before establishing a data usage control sandbox corresponding to the application, the following should be included: By traversing through the established data usage control sandboxes, it can be determined whether there exists a data usage control sandbox corresponding to the application. If so, when it is determined that there is no data usage policy corresponding to the currently accessed preset data content in the data usage control sandbox corresponding to the application, the data usage policy corresponding to the currently accessed preset data content is stored in the data usage control sandbox. If not, a data usage control sandbox corresponding to the application is established, and the data usage policy corresponding to the preset data content currently accessed by the application is stored in the data usage control sandbox.
3. The method according to claim 1, characterized in that, Based on the data, a control sandbox is used to control the application's use of the preset data, including: Determine the preset data content currently accessed by the application, and based on the preset data content, determine the data usage strategy in the data usage control sandbox corresponding to the preset data content; Determine whether the application's use of the preset data content conforms to the agreement of the corresponding data usage strategy; If not, then the application's use of the preset data content is rejected.
4. The method according to claim 1, characterized in that, The method further includes: If a data processor processes preset data provided by at least one data owner, the union of at least one data usage strategy corresponding to the preset data and the data usage strategy added by the data processor shall be taken as the new data usage strategy corresponding to the processed preset data. The new data is used with a strategy and the processed preset data is stored in the data storage sandbox, and the owner of the processed preset data is recorded; wherein, the owner of the processed preset data includes the at least one data owner and the data processor.
5. The method according to claim 1, characterized in that, The negotiation and agreement process for the data usage contract corresponding to the preset data includes: The description information of the preset data is published on the blockchain so that the data user can create a candidate data usage smart contract corresponding to the preset data based on the description information of the preset data; wherein, the data usage smart contract includes at least the description information of the preset data and the candidate data usage strategy; The status of the candidate data using smart contract is obtained, and when the status is signed, the candidate data using smart contract in the signed state is used as the target data using smart contract; wherein, the target data using smart contract is the data using contract corresponding to the preset data, and the target data using smart contract is obtained after negotiation, modification and unanimous confirmation by the data owner and the data user.
6. The method according to claim 1, characterized in that, Before monitoring system calls of at least one application, the following is also included: In response to an application download command sent by a data user, at least one application corresponding to the application download command is downloaded; The downloaded application is verified to determine its integrity.
7. A data usage control device, characterized in that, include: The system call interception module is used to monitor system calls of at least one application in the current trusted execution environment, and to intercept the system call when it is determined that the system call accesses preset data; wherein, the preset data includes at least one set of preset data content; The data usage information judgment module is used to determine whether the data usage information corresponding to the intercepted system call meets the data usage policy based on the data usage contract corresponding to the preset data; wherein, the preset data and the corresponding data usage contract are stored in a preset data storage sandbox, and the data usage contract is agreed upon by the data owner and the data user through negotiation; A data usage control sandbox creation module is used to allow the application to access the preset data if the condition is met, and to create a data usage control sandbox corresponding to the application; wherein, the data usage control sandbox is used to store the data usage policy corresponding to the preset data content accessed by the application; The data usage control module is used to control the application's use of the preset data based on the data usage control sandbox; The application currently accesses multiple sets of preset data content; correspondingly, the data usage control module includes: The union determination unit is used to determine the union of data usage policies corresponding to each set of preset data content currently accessed by the application, based on the data usage control sandbox; wherein, the data usage control sandbox includes the data usage policies corresponding to each set of preset data content; The data usage control unit is used to take the union as a new data usage strategy corresponding to each set of preset data content, and to control the application's use of each set of preset data content according to the new data usage strategy.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the data use control method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the data use control method of any one of claims 1-6.
Citation Information
Patent Citations
Data sharing method and device, equipment and storage medium
CN113901498A
Data use control method and system, electronic equipment and storage medium
CN114444109A
Smart contract protection method and device based on sandbox and electronic equipment
CN118153035A