A data sharing anti-retention method, system, device and storage medium
By leveraging the synergy of the central management platform and application probes, initial and secondary anti-retention checks are performed during the data sharing process. This solves the problem that data providers cannot monitor the caching behavior of data receivers, thereby improving the security of data sharing.
Patent Information
- Application Number
- CN202411453244.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-10-17
AI Technical Summary
In existing technologies, data providers cannot effectively monitor and control the data caching behavior of data receivers, resulting in insufficient security for data sharing.
By establishing a secure sharing strategy through a central management platform and deploying application probes at both the data provider and receiver ends to perform initial and secondary anti-retention verification, the security of the data sharing process is ensured.
It enables real-time monitoring and prevention of abnormal data retention during data sharing without modifying the original business system, thereby improving the security of data sharing.
Smart Images

Figure CN119420765B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of computer, in particular to the technical field of data security, and specifically to a data sharing anti-retention method, system, device and storage medium. BACKGROUND
[0002] In the current society, the division of labor is gradually refined, and it has become a common practice for enterprises to open many different API (Application Programming Interface) interfaces to third-party partners, thereby supporting data processing, resource sharing and other operations.
[0003] At present, the data sharing provider usually uses the open interface API to provide data for the data receiving party, but after receiving the data, the data receiving party has no cache data, and the data provider cannot effectively monitor, control, and block exceptions. SUMMARY
[0004] The present application provides a data sharing anti-retention method, system, device and storage medium to improve the security of data sharing.
[0005] According to an aspect of the present application, a data sharing anti-retention method is provided, which is applied to a data sharing anti-retention system; the system includes a center management platform, a data providing end and a data receiving end; the data providing end is deployed with a first application probe; the data receiving end is deployed with a second application probe; the data providing end and the data receiving end are in communication connection; the center management platform is in communication connection with the data providing end and the data receiving end respectively; the method includes:
[0006] The center management platform formulates a security sharing strategy according to the anti-retention data of the data providing end, and sends the security sharing strategy to the first application probe and the second application probe respectively;
[0007] The first application probe performs a first anti-retention check on the data sharing request based on the security sharing strategy when it identifies that the data providing end receives the data sharing request sent by the data receiving end;
[0008] The data providing end sends target sharing data to the data receiving end when it identifies that the first anti-retention check is passed;
[0009] The second application probe performs a second anti-retention check on the target sharing data based on the security sharing strategy when it identifies that the data receiving end receives the target sharing data sent by the data providing end;
[0010] perform a write operation on the target shared data when it is identified that the secondary anti-preservation check passes.
[0011] According to another aspect of the present application, a data sharing anti-preservation system is provided, which comprises a central management platform, a data providing end and a data receiving end; the data providing end is deployed with a first application probe; the data receiving end is deployed with a second application probe; the data providing end and the data receiving end are in communication connection; the central management platform is in communication connection with the data providing end and the data receiving end respectively:
[0012] The central management platform is configured to formulate a secure sharing strategy according to anti-preservation data of the data providing end, and send the secure sharing strategy to the first application probe and the second application probe respectively.
[0013] The first application probe is configured to, when it is identified that the data providing end receives a data sharing request sent by the data receiving end, perform a first anti-preservation check on the data sharing request based on the secure sharing strategy.
[0014] The data providing end is configured to, when it is identified that the first anti-preservation check passes, send target shared data to the data receiving end.
[0015] The second application probe is configured to, when it is identified that the data receiving end receives the target shared data sent by the data providing end, perform a secondary anti-preservation check on the target shared data based on the secure sharing strategy.
[0016] The data receiving end is configured to, when it is identified that the secondary anti-preservation check passes, perform a write operation on the target shared data.
[0017] According to another aspect of the present application, an electronic device is provided, which comprises:
[0018] one or more processors;
[0019] a memory configured to store one or more programs;
[0020] When the one or more programs are executed by the one or more processors, the one or more processors implement any one of the data sharing anti-preservation methods provided by the embodiments of the present application.
[0021] According to another aspect of the present application, a computer readable storage medium is provided, which stores a computer program, and the program is executed by a processor to implement any one of the data sharing anti-preservation methods provided by the embodiments of the present application.
[0022] The application formulates a security sharing strategy according to the anti-keeping data of the data providing end through the central management platform, and sends the security sharing strategy to the first application probe and the second application probe respectively; when the first application probe identifies that the data providing end receives the data sharing request sent by the data receiving end, the first application probe performs the first anti-keeping verification on the data sharing request based on the security sharing strategy; the data providing end sends the target shared data to the data receiving end when the data providing end identifies that the first anti-keeping verification is passed; the second application probe performs the second anti-keeping verification on the target shared data based on the security sharing strategy when the second application probe identifies that the data receiving end receives the target shared data sent by the data providing end; the data receiving end performs the write operation of the target shared data when the data receiving end identifies that the second anti-keeping verification is passed. The above technical solution, through the central management platform, a unified security sharing strategy is issued, and through the application probe configured in the data receiving end and the data providing end, whether there is an abnormal data keeping behavior in the data sharing process can be monitored in real time, without modifying the original business system of the data sharing parties, the data anti-keeping is realized without sensing, which helps to improve the security of data sharing. BRIEF DESCRIPTION OF DRAWINGS
[0023] Figure 1 is a flowchart of a data sharing anti-keeping method according to an embodiment of the application;
[0024] Figure 2 is a flowchart of a data sharing anti-keeping method according to an embodiment of the application;
[0025] Figure 3 is a structural schematic diagram of a data sharing anti-keeping system according to an embodiment of the application;
[0026] Figure 4 is a structural schematic diagram of an electronic device for implementing the data sharing anti-keeping method according to an embodiment of the application. DETAILED DESCRIPTION
[0027] In order to make the person in the art better understand the application scheme, the technical solutions in the embodiments of the application will be described clearly and completely in conjunction with the drawings in the embodiments of the application. Obviously, the described embodiments are only a part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by the person skilled in the art without creative labor should be within the scope of protection of the application.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and in the above drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] In addition, it should also be noted that in the technical solutions of the present application, the collection, storage, use, processing, transmission, provision and disclosure of the related data such as the anti-retention data and the security sharing strategy all comply with the relevant legal regulations and do not violate public order and good customs.
[0030] Embodiment one
[0031] Figure 1 is a flowchart of a data sharing anti-retention method according to the first embodiment of the present application. The present embodiment can be applicable to the case of preventing abnormal data retention in real time during the data sharing process between the two parties of data sharing, and can be executed by a data sharing anti-retention system, which includes a center management platform, a data providing end and a data receiving end. The data providing end is deployed with a first application probe, and the data receiving end is deployed with a second application probe. The data providing end and the data receiving end are in communication connection. The center management platform is in communication connection with the data providing end and the data receiving end respectively. The system can be realized in the form of hardware and / or software, and the data sharing anti-retention system can be configured in a computer device, such as a server. As shown in the figure, the method comprises: Figure 1
[0032] S110, formulating a security sharing strategy according to the anti-retention data of the data providing end through the center management platform, and sending the security sharing strategy to the first application probe and the second application probe respectively.
[0033] The central management platform refers to a centralized system or tool for managing, monitoring, and coordinating multiple applications and data sources. It can uniformly configure security policies, data sharing rules, and monitoring activities. The non-persistent data refers to sensitive data that is prohibited from being stored or retained in unauthorized circumstances. Examples include user name, user gender, user age, etc. The secure sharing policy refers to a series of regulations and measures to ensure the secure sharing of data between different systems or applications. These policies may include permission control, data encryption, access audit, etc. to protect the confidentiality and integrity of data. The first application probe refers to a component deployed on the application side of the data provider end for monitoring, collecting, or transmitting data. It can obtain real-time behavior data of the application to help analyze and optimize performance or monitor data flow in a security context. The second application probe refers to a component deployed on the application side of the data receiver end for monitoring, collecting, or transmitting data. It can obtain real-time behavior data of the application to help analyze and optimize performance or monitor data flow in a security context.
[0034] It should be noted that the central management platform adopts a B / S (Browser / Server) architecture and can provide a visual operation interface. Its main functions include managing application probes, receiving monitored data behavior data, analyzing data caching risks, managing data sharing policies, post-auditing and tracing, receiving abnormal alarms of the receiving party of shared data and synchronizing them to the application probe of the shared data provider in a timely manner to enable the probe of the data provider to cut off data transmission in a timely manner. The first application probe is deployed on the application side that provides a shared data API interface. Its main functions include monitoring data request behavior, reporting request behavior monitoring data to the central management platform, receiving security policies from the central management platform, and discovering abnormalities and blocking data transmission in a timely manner. The second application probe is deployed on the application side that receives shared data. Its main functions include monitoring data retention behavior after receiving shared data, reporting behavior monitoring data to the central management platform, receiving security policies issued by the central management platform, and blocking data retention behavior in a timely manner.
[0035] Further, the application probe is implemented based on the principle of Hook (Hook Function) technology, and thus does not need to change any code of the original business system, achieving zero modification to realize shared data anti-retention. The operation principle of the application probe of the shared data provider is to monitor the data request behavior based on the interface API Hook (Application Programming Interface Hook) technology, and to execute the security policy issued by the central management platform to timely block abnormal data request behavior. The operation principle of the application probe of the shared data receiver is based on the operating system IO Hook (Input / Output Hook) technology, and the application probe can monitor the IO (Input / Output) behavior of the data receiving application to timely block the IO operation of abnormal data retention.
[0036] Optionally, when the central management platform receives the shared security policy, the central management platform sends the shared security policy to the first application probe and the second application probe respectively.
[0037] It can be understood that the shared security policy at this time is artificially pre-set according to actual situation or experience value.
[0038] S120, when the first application probe identifies that the data providing end receives the data sharing request sent by the data receiving end, the first application probe performs first anti-retention verification on the data sharing request based on the security sharing policy.
[0039] The data providing end refers to a system or application program that sends or shares data, which is responsible for processing data requests and transmitting data to the receiving end. The data receiving end refers to a system or application program that receives data requests from the data providing end, which is usually responsible for processing and using the received data. The data sharing request refers to a request sent by the data receiving end to the data providing end to obtain specific data or information. The first anti-retention verification refers to a check performed before the data sharing request is processed to verify whether the request meets the data retention policy, ensuring that sensitive data is not stored for a long time or misused.
[0040] It should be noted that the data receiving end in the embodiments of the present application can be at least one; and the data providing end corresponding to the data receiving end can also be at least one.
[0041] Optionally, the first anti-retention verification can include at least one of an identifier existence verification and a blocking instruction existence verification.
[0042] The identity existence check refers to checking whether the identities involved in the data sharing request (such as user identity, data type, etc.) exist and are valid. This check aims to ensure that the requester has a legal right and identity to access the requested data. The blocking instruction existence check refers to confirming whether there are instructions or policies that hinder or limit data sharing. This may include laws and regulations, internal policies, or security agreements to ensure that relevant blocking rules are followed when processing data requests.
[0043] For example, in the case of an identity existence check, the first application probe performs an identity existence check on the data sharing request based on the security sharing policy when it identifies that the data providing end has received the data sharing request sent by the data receiving end. If the authentication identity is carried in the data sharing request, it is determined that the identity existence check is passed. If the authentication identity is not carried, it is determined that the identity existence check is not passed, and the data sharing request is blocked, and the subsequent steps are not executed.
[0044] S130, by the data providing end, in the case where it is identified that the first anti-retention check is passed, the target shared data is sent to the data receiving end.
[0045] S140, by the second application probe, in the case where it is identified that the data receiving end has received the target shared data sent by the data providing end, a second anti-retention check is performed on the target shared data based on the security sharing policy.
[0046] The second anti-retention check refers to a check performed on the application side of the data receiving end to verify whether the application complies with the data retention policy, ensuring that sensitive data is not stored for a long time or misused.
[0047] For example, by the second application probe, in the case where it is identified that the data receiving end has received the target shared data sent by the data providing end, it is determined whether the application side of the data receiving end violates the retention policy based on the security sharing policy. If yes, it is determined that the second anti-retention check is not passed. If no, it is determined that the second anti-retention check is passed.
[0048] S150, by the data receiving end, in the case where it is identified that the second anti-retention check is passed, a write operation of the target shared data is performed.
[0049] In an optional embodiment, by the second application probe, in the case where it is identified that the second anti-retention check is not passed, the write operation of the target shared data is blocked, and a data retention alarm is sent to the central management platform.
[0050] The data retention alarm refers to an alarm sent by the second application probe to the central management platform for the problem of the data receiving end violating the retention of the target shared data.
[0051] Further, the central management platform generates a data blocking instruction when receiving the data retention alarm, and sends the data blocking instruction to the first application probe; the first application probe blocks the data sharing request sent by the data receiving end in the future when receiving the data blocking instruction.
[0052] The data blocking instruction is a command generated by the central management platform, which is used to prevent the processing of a specific data sharing request; the instruction is mainly used to ensure that the relevant data is not shared when there is a risk or compliance problem. The blocking operation refers to the behavior of the first application probe to suspend or reject the processing of a specific data sharing request from the data receiving end according to the data blocking instruction, so as to prevent the erroneous sharing or leakage of data.
[0053] The embodiments of the present application formulate a safe sharing strategy according to the anti-retention data of the data providing end through the central management platform, and send the safe sharing strategy to the first application probe and the second application probe respectively; the first application probe performs a first anti-retention check on the data sharing request based on the safe sharing strategy when identifying that the data providing end receives the data sharing request sent by the data receiving end; the data providing end sends the target shared data to the data receiving end when identifying that the first anti-retention check is passed; the second application probe performs a second anti-retention check on the target shared data based on the safe sharing strategy when identifying that the data receiving end receives the target shared data sent by the data providing end; the data receiving end performs a write operation on the target shared data when identifying that the second anti-retention check is passed. The above technical solution can monitor whether there is an abnormal data retention behavior in the data sharing process in real time through the central management platform issuing a unified safe sharing strategy and the application probe configured in the data receiving end and the data providing end, and realizes data anti-retention without affecting the original business system of the data sharing parties, which helps to improve the security of data sharing.
[0054] Embodiment two
[0055] Figure 2 is a flowchart of a data sharing anti-retention method according to the second embodiment of the present application. Based on the technical solutions of the above embodiments, the first anti-retention check based on the safe sharing strategy is refined into an identification existence check on the authentication identifier of the data sharing request by the first application probe based on the safe sharing strategy; and a blocking instruction existence check on the data sharing request by the first application probe when identifying that the identification existence check is passed. It should be noted that the parts not described in detail in the embodiments of the present application can be referred to the related descriptions of other embodiments.
[0056] As shown in Figure 2 , the method comprises:
[0057] S210, formulating a security sharing strategy according to the anti-preservation data of the data providing end through the central management platform, and sending the security sharing strategy to the first application probe and the second application probe respectively.
[0058] S220, identifying the data sharing request sent by the data receiving end through the first application probe when the data providing end receives the data sharing request, and performing an identity existence check on the authentication identity of the data sharing request based on the security sharing strategy.
[0059] The identity existence check refers to checking whether the identity (such as user identity, data type, etc.) involved in the data sharing request exists and is valid; this check aims to ensure that the requester has a legal right and identity to access the requested data.
[0060] Optionally, before the data receiving end sends the data sharing request to the data providing end, the second application probe is used to add an authentication identity to the data sharing request based on the security sharing strategy.
[0061] The authentication identity is an identity information used to verify the legality and source of the request. It can include user identity, access rights, timestamp, etc., to ensure that only authorized requests can obtain approval for data sharing
[0062] Further, the first application probe is used to perform an identity existence check on the authentication identity in the data sharing request based on the security sharing strategy when the data providing end receives the data sharing request sent by the data receiving end; if the authentication identity is identified in the data sharing request, the identity existence check is passed; if the authentication identity is not identified in the data sharing request, the identity existence check is not passed.
[0063] S230, performing a blocking instruction existence check on the data sharing request through the first application probe when the identity existence check is passed.
[0064] The blocking instruction existence check refers to confirming whether there is an instruction or strategy that hinders or restricts data sharing; this can include laws and regulations, internal policies or security agreements, to ensure that relevant blocking rules are followed when processing data requests.
[0065] Illustratively, the first application probe is used to perform a blocking instruction existence check on whether the data sharing request contains a data blocking instruction based on the security sharing strategy when the data providing end receives the data sharing request sent by the data receiving end; if the data sharing request contains a data blocking instruction, the blocking instruction existence check is not passed; if the data sharing request does not contain a data blocking instruction, the blocking instruction existence check is passed.
[0066] S240, sending the target shared data to the data receiving end by the data providing end in the case that the identification existence check and the blocking instruction existence check pass.
[0067] Optionally, in the case that the identification existence check and the blocking instruction existence check pass, the target shared data is encrypted by the data providing end, and the encrypted target shared data is sent to the data receiving end.
[0068] In an optional embodiment, the data sharing request is blocked by the first application probe in the case that the identification existence check or the blocking instruction existence check fails.
[0069] S250, performing secondary anti-preservation check on the target shared data based on the secure sharing policy by the second application probe in the case that the data receiving end receives the target shared data sent by the data providing end.
[0070] Optionally, the target shared data is decrypted by the data receiving end in the case that the target shared data sent by the data providing end is received, and the second application probe performs secondary anti-preservation check on the write operation of the target shared data based on the secure sharing policy.
[0071] S260, performing the write operation of the target shared data by the data receiving end in the case that the secondary anti-preservation check passes.
[0072] In an optional embodiment, in the technical scenario that a certain operator needs to provide specific user data to a customer service operation service provider, when the customer service receives a user service hotline, the service provider only needs to query more detailed information of the user in the operator according to the personal information provided by the user, the execution steps of the embodiment of the application are as follows:
[0073] 1) Deployment. Deploy a central management platform P on the side of a certain operator, deploy an application probe S on the side of a user information query application system of a certain operator, and deploy an application probe A on the side of a customer service application system of a customer service provider.
[0074] 2) Formulate a secure sharing policy for anti-preservation. For example, the user information query API of the operator only allows the customer service system IP (Internet Protocol) to query, and does not allow sensitive information such as user ID number, mobile phone number, name, home address, etc. to be preserved, and if the preservation is found, an alarm is given and the preservation is blocked; and the policy is synchronized and sent to the application probe S and the application probe A.
[0075] 3) Application probe loads retention prevention security policy and takes effect. When the customer service application system queries the user information of the operator, an API request is initiated to the application system of the operator, and the application probe A located in the customer service system automatically adds an authentication Token (token / identifier) to the original request; after receiving the request, the application probe S of the operator's application system verifies whether the request is written to the Token and whether the Token is legal, and if not, the request is rejected, and if so, the application probe S accepts and returns the encrypted user information; the Token is exclusive to the application probe A, and the encrypted information returned by the application probe S can only be decrypted by the application probe A, which achieves the purpose of preventing the customer service provider from forging query requests; after receiving the encrypted user information returned by the application API of the operator, the application probe A of the customer service application system parses the ciphertext into plaintext and hands it over to the customer service system for further processing; the application probe A of the customer service application system monitors whether the customer service system caches user personal information in real time.
[0076] Specifically, the application probe A of the customer service application system can monitor whether the customer service system caches user personal information in real time by intercepting the IO write request of the customer service system, identifying whether it contains personal sensitive information such as ID number and mobile phone number, and determining whether the SQL request for connecting data to write to the database contains personal sensitive information; if the IO write request contains personal sensitive information, the application probe A will intercept this IO write request, such as a SQL write request containing sensitive information that cannot be executed; after the application probe A discovers abnormal retention actions, it will also send an alarm message to the central management platform and send a blocking instruction to the application probe S of the operator, and the application probe S will reject all query requests from the customer service system after receiving the blocking instruction.
[0077] The embodiment of the application formulates a security sharing strategy according to the anti-keeping data of the data providing end through the central management platform, and sends the security sharing strategy to the first application probe and the second application probe respectively; the first application probe performs an identification existence check on the authentication identifier of the data sharing request based on the security sharing strategy when it identifies that the data providing end receives the data sharing request sent by the data receiving end; the first application probe performs a blocking instruction existence check on the data sharing request when it identifies that the identification existence check is passed; the data providing end sends the target shared data to the data receiving end when it identifies that the identification existence check and the blocking instruction existence check are passed; the second application probe performs a secondary anti-keeping check on the target shared data based on the security sharing strategy when it identifies that the data receiving end receives the target shared data sent by the data providing end; the data receiving end performs a write operation of the target shared data when it identifies that the secondary anti-keeping check is passed. The above technical solution can realize real-time monitoring of whether there is an abnormal data keeping behavior in the data sharing process through the central management platform issuing a unified security sharing strategy and the application probe configured in the data receiving end and the data providing end, and realizes data anti-keeping without modifying the original business system of the data sharing parties, which helps to improve the security of data sharing.
[0078] Embodiment three
[0079] Figure 3 It is a structure schematic diagram of a data sharing anti-keeping system provided by the embodiment three of the application, which can be applicable to the case of preventing abnormal data keeping in real time in the data sharing process of the data sharing parties. The data sharing anti-keeping system can be realized in the form of hardware and / or software. As shown in the figure, the data sharing anti-keeping system includes a central management platform 310, a data providing end 320 and a data receiving end 330; the data providing end 320 is deployed with a first application probe 321; the data receiving end 330 is deployed with a second application probe 331; the data providing end 320 and the data receiving end 330 are in communication connection; the central management platform 310 is in communication connection with the data providing end 320 and the data receiving end 330 respectively; the system can be configured in a computer device, such as a server. Figure 3
[0080] The central management platform 310 is configured to formulate a security sharing strategy according to the anti-keeping data of the data providing end 320, and send the security sharing strategy to the first application probe 321 and the second application probe 331 respectively;
[0081] The first application probe 321 is configured to perform a first anti-keeping check on the data sharing request based on the security sharing strategy when it identifies that the data providing end 320 receives the data sharing request sent by the data receiving end 330;
[0082] The data providing end 320 is configured to send the target shared data to the data receiving end 330 in a case where it is identified that the first anti-retention check is passed.
[0083] The second application probe 331 is configured to perform a second anti-retention check on the target shared data based on the security sharing policy in a case where it is identified that the data receiving end 330 receives the target shared data sent by the data providing end 320.
[0084] The data receiving end 330 is configured to perform a write operation on the target shared data in a case where it is identified that the second anti-retention check is passed.
[0085] The embodiments of the present application can formulate a security sharing policy according to the anti-retention data of the data providing end by the central management platform, and send the security sharing policy to the first application probe and the second application probe respectively. The first application probe can perform a first anti-retention check on the data sharing request based on the security sharing policy in a case where it is identified that the data providing end receives the data sharing request sent by the data receiving end. The data providing end can send the target shared data to the data receiving end in a case where it is identified that the first anti-retention check is passed. The second application probe can perform a second anti-retention check on the target shared data based on the security sharing policy in a case where it is identified that the data receiving end receives the target shared data sent by the data providing end. The data receiving end can perform a write operation on the target shared data in a case where it is identified that the second anti-retention check is passed. The above technical solution can monitor whether there is an abnormal data retention behavior in the data sharing process in real time by the central management platform issuing a unified security sharing policy and the application probes configured in the data receiving end and the data providing end, and achieve data anti-retention without changing the original business system of the data sharing parties, which helps to improve the security of data sharing.
[0086] Optionally, the first anti-retention check includes an identifier existence check and a blocking instruction existence check. Correspondingly, the first application probe 321 is specifically configured to:
[0087] perform the identifier existence check on the authentication identifier of the data sharing request based on the security sharing policy;
[0088] perform the blocking instruction existence check on the data sharing request in a case where it is identified that the identifier existence check is passed.
[0089] Optionally, the first application probe 321 is further configured to:
[0090] block the data sharing request in a case where it is identified that the identifier existence check or the blocking instruction existence check is not passed.
[0091] Optionally, the second application probe 331 is specifically configured to:
[0092] In the case of identifying that the secondary anti-retention check fails, the write operation of the target shared data is blocked, and a data retention alarm is sent to the central management platform 310.
[0093] Optionally, the central management platform 310 is further configured to:
[0094] When the data retention alarm is received, a data blocking instruction is generated, and the data blocking instruction is sent to the first application probe 321.
[0095] Correspondingly, the first application probe 321 is further configured to:
[0096] When the data blocking instruction is received, the data sharing request sent by the data receiving end 330 in the future is blocked.
[0097] The data sharing anti-retention system provided in the embodiments of the present application can execute the data sharing anti-retention method provided in any embodiment of the present application, and has the corresponding function modules and beneficial effects of executing each data sharing anti-retention method.
[0098] Embodiment four
[0099] Figure 4 FIG. 4 is a structural schematic diagram of an electronic device 410 for implementing the data sharing anti-retention method according to the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are merely examples and are not intended to limit the implementations described and / or claimed in this document.
[0100] As Figure 4As shown, the electronic device 410 includes at least one processor 411, and a memory, such as a read-only memory (ROM) 412, a random access memory (RAM) 413, and the like, connected to the at least one processor 411 in communication. The memory stores a computer program executable by the at least one processor 411, and the processor 411 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 412 or loaded into the random access memory (RAM) 413 from the storage unit 418. In the RAM 413, various programs and data required for the operation of the electronic device 410 can also be stored. The processor 411, the ROM 412, and the RAM 413 are connected to each other through a bus 414. An input / output (I / O) interface 415 is also connected to the bus 414.
[0101] Various components in the electronic device 410 are connected to the I / O interface 415, including an input unit 416, such as a keyboard, a mouse, and the like, an output unit 417, such as various types of displays, a speaker, and the like, a storage unit 418, such as a magnetic disk, an optical disk, and the like, and a communication unit 419, such as a network card, a modem, a wireless communication transceiver, and the like. The communication unit 419 allows the electronic device 410 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0102] The processor 411 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 411 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, and the like. The processor 411 performs various methods and processes described above, such as the data sharing anti-retention method.
[0103] In some embodiments, the data sharing anti-retention method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 418. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 410 via the ROM 412 and / or the communication unit 419. When the computer program is loaded into the RAM 413 and executed by the processor 411, one or more steps of the data sharing anti-retention method described above can be performed. Alternatively, in other embodiments, the processor 411 can be configured as the data sharing anti-retention method by any other appropriate means, such as by means of firmware.
[0104] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0105] Computer programs used to implement the processes of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program
[0106] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0107] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0108] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0109] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0110] It should be understood that various forms of flow shown above can be used with orders of steps reordered, added to, or removed. For example, the steps recited in the present application can be executed in parallel, in series, or in a different order, as long as the desired results of the present application are achieved, and the present application is not limited herein.
[0111] The specific embodiments described above are not intended to be limiting, and persons skilled in the art will appreciate that various modifications, combinations, sub-combinations and alternatives can be made to the specific embodiments without departing from the spirit and scope of the disclosure. Any further modifications, equivalents, and / or alternatives come within the scope of the present disclosure as described in the following claims.
Claims
1. A data sharing and non-preservation method, characterized in that, The application is applied to a data sharing and retention prevention system; the system comprises a central management platform, a data providing end and a data receiving end; the data providing end is deployed with a first application probe; the data receiving end is deployed with a second application probe; the data providing end and the data receiving end are in communication connection; The central management platform is in communication connection with the data providing end and the data receiving end respectively; the method comprises: The central management platform formulates a security sharing strategy according to the anti-retention data of the data providing end, and sends the security sharing strategy to the first application probe and the second application probe respectively; The first application probe performs a first anti-retention check on the data sharing request based on the security sharing strategy when it identifies that the data providing end receives the data sharing request sent by the data receiving end; The data providing end sends target sharing data to the data receiving end when it identifies that the first anti-retention check is passed; The second application probe performs a second anti-retention check on the target sharing data based on the security sharing strategy when it identifies that the data receiving end receives the target sharing data sent by the data providing end; The data receiving end performs a write operation of the target sharing data when it identifies that the second anti-retention check is passed.
2. The method of claim 1, wherein, The first anti-retention check comprises an identification existence check and a blocking instruction existence check; accordingly, performing a first anti-retention check on the data sharing request based on the security sharing strategy comprises: The first application probe performs an identification existence check on the authentication identification of the data sharing request based on the security sharing strategy; The first application probe performs a blocking instruction existence check on the data sharing request when it identifies that the identification existence check is passed.
3. The method of claim 2, wherein, The method further comprises: The first application probe blocks the data sharing request when it identifies that the identification existence check or the blocking instruction existence check is not passed.
4. The method of claim 1, wherein, The method further comprises: The second application probe blocks the write operation of the target sharing data and sends a data retention alarm to the central management platform when it identifies that the second anti-retention check is not passed.
5. The method of claim 4, wherein, The method further comprises: The central management platform generates a data blocking instruction and sends the data blocking instruction to the first application probe when it receives the data retention alarm; The first application probe performs a blocking operation on the data sharing request sent by the data receiving end in the future when it receives the data blocking instruction.
6. A data sharing non-preservation system, characterized by, The system comprises a central management platform, a data providing end and a data receiving end; the data providing end is deployed with a first application probe; the data receiving end is deployed with a second application probe; the data providing end and the data receiving end are in communication connection; the central management platform is in communication connection with the data providing end and the data receiving end respectively; The central management platform is configured to formulate a security sharing strategy according to the anti-leave data of the data providing end, and send the security sharing strategy to the first application probe and the second application probe respectively. The first application probe is configured to, when it is identified that the data providing end receives a data sharing request sent by the data receiving end, perform a first anti-leave check on the data sharing request based on the security sharing strategy. The data providing end is configured to, when it is identified that the first anti-leave check is passed, send target shared data to the data receiving end. The second application probe is configured to, when it is identified that the data receiving end receives the target shared data sent by the data providing end, perform a second anti-leave check on the target shared data based on the security sharing strategy. The data receiving end is configured to, when it is identified that the second anti-leave check is passed, perform a write operation on the target shared data.
7. The system of claim 6, wherein, The first anti-leave check includes an identifier existence check and a blocking instruction existence check. Correspondingly, the first application probe is specifically configured to: perform an identifier existence check on an authentication identifier of the data sharing request based on the security sharing strategy; and when it is identified that the identifier existence check is passed, perform a blocking instruction existence check on the data sharing request.
8. An electronic device, comprising: The apparatus comprises: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the data sharing anti-leave method according to any one of claims 1-5.
9. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the data sharing anti-leave method according to any one of claims 1-5.
10. A computer program product comprising a computer program which, when executed by a processor, implements the data sharing anti-leave method according to any one of claims 1-5.
Citation Information
Patent Citations
Double file anti-divulging method and system based on HOOK and filtering driving
CN103605930A
Method and device for preventing website data from leaking
CN106033511A