A data security access method, apparatus, electronic device, and storage medium
By using a load balancing service and a traffic mirroring module of a pre-defined policy engine in the cloud data center, access requests are mapped and response policies are determined based on security authentication information. This solves the problem of lack of flexibility and compatibility in data security access configuration in the cloud data center, achieving higher security and compatibility.
Patent Information
- Application Number
- CN202411774021.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-04
AI Technical Summary
In existing technologies, cloud data center data security access configurations lack flexibility and compatibility, especially the incompatibility between security access hardware devices and load balancing devices, resulting in insufficient cloud data access security.
The traffic mirroring module between the load balancing service and the preset policy engine maps access requests to the preset policy engine, determines the target response policy based on security authentication information, and responds to access requests according to the policy, including allowing, blocking, and de-identifying responses.
It improves the flexibility and compatibility of data security access configuration in cloud data centers, enhances the security of cloud data access for users, and supports flexible deployment in cloud-native scenarios.
Smart Images

Figure CN119835007B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a data security access method, apparatus, electronic device and storage medium. Background Technology
[0002] Currently, with the continuous development of cloud computing technology, cloud data centers are providing more and more services to customers, such as cloud data storage. Cloud data can be shared and accessed by multiple user terminals. Therefore, how to achieve secure access to cloud data by each user terminal has become a key research topic.
[0003] In related technologies, secure data access control is typically achieved using specialized secure access hardware. However, the deployment of secure access hardware lacks flexibility, and cloud data centers generally provide data services through load balancing equipment, which is currently incompatible with these devices. Therefore, there is an urgent need for a data security access method that can be flexibly configured in cloud data centers, which is of great significance for improving the security of cloud data access. Summary of the Invention
[0004] This application provides a data security access method, apparatus, electronic device, and storage medium to address the shortcomings of related technologies, such as reducing the flexibility and compatibility of data security access configuration in cloud data centers.
[0005] The first aspect of this application provides a method for secure data access, including:
[0006] The load balancing service is used to obtain access requests sent from any user terminal to the cloud data center.
[0007] The access request is mapped to the preset policy engine through the traffic mirroring module between the load balancing service and the preset policy engine;
[0008] Based on the preset strategy engine, the target response strategy for the access request is determined according to the security authentication information represented by the access request.
[0009] The access request is responded to in accordance with the target response strategy.
[0010] In one optional implementation, determining the target response policy for the access request based on the security authentication information represented by the access request, according to the preset policy engine, includes:
[0011] The access request is subjected to authentication feature extraction to obtain the authentication feature extraction result of the access request;
[0012] Based on the preset strategy engine, the security authentication information of the access request is determined according to the authentication feature extraction result of the access request;
[0013] Based on the security authentication information of the access request, determine the target response strategy for the access request.
[0014] In one optional implementation, the step of extracting authentication features from the access request to obtain the authentication feature extraction result of the access request includes:
[0015] User identity features and request action features are extracted from the access request to obtain the authentication feature extraction result of the access request;
[0016] The authentication features include the user identity features and the request action features.
[0017] In one optional implementation, the target response strategy for the access request is at least divided into three types: allow response, block response, and de-identify response.
[0018] In one optional implementation, responding to the access request according to the target response strategy includes:
[0019] Based on the traffic mirroring module, the initial response data obtained from the cloud data center by the load balancing service in response to the access request is read.
[0020] Based on the initial response data, initial tunnel information is encapsulated to obtain an initial response data packet; wherein, the initial response data packet includes the initial response data and the initial tunnel information;
[0021] Map the initial response data packet to the preset strategy engine;
[0022] Based on the preset strategy engine, the initial response data packet is processed for data security in accordance with the target response strategy to obtain the target response data packet; wherein, the target response data packet includes target response data and target tunnel information.
[0023] In one optional implementation, the step of performing data security processing on the initial response data packet according to the target response policy based on the preset policy engine to obtain the target response data packet includes:
[0024] When the target response strategy is a desensitized response, the sensitive data in the initial response data is replaced based on the preset strategy engine to obtain the target impact data.
[0025] Based on the target impact data, the initial tunnel information is modified to obtain the target tunnel information;
[0026] The target impact data and target tunnel information are encapsulated to obtain the target response data packet.
[0027] In an optional implementation, the method further includes:
[0028] Based on the load balancing service, the target response data packet is forwarded to the user terminal.
[0029] A second aspect of this application provides a data security access device, comprising:
[0030] The acquisition module is used to acquire access requests sent by any user terminal to the cloud data center based on the load balancing service;
[0031] The mapping module is used to map the access request to the preset policy engine through the traffic mirroring module between the load balancing service and the preset policy engine;
[0032] The authentication module is used to determine the target response strategy for the access request based on the security authentication information represented by the access request, according to the preset strategy engine.
[0033] The response module is used to respond to the access request in accordance with the target response strategy.
[0034] In one optional implementation, the authentication module is specifically used for:
[0035] The access request is subjected to authentication feature extraction to obtain the authentication feature extraction result of the access request;
[0036] Based on the preset strategy engine, the security authentication information of the access request is determined according to the authentication feature extraction result of the access request;
[0037] Based on the security authentication information of the access request, determine the target response strategy for the access request.
[0038] In one optional implementation, the authentication module is specifically used for:
[0039] User identity features and request action features are extracted from the access request to obtain the authentication feature extraction result of the access request;
[0040] The authentication features include the user identity features and the request action features.
[0041] In one optional implementation, the target response strategy for the access request is at least divided into three types: allow response, block response, and de-identify response.
[0042] In one optional implementation, the response module is specifically used for:
[0043] Based on the traffic mirroring module, the initial response data obtained from the cloud data center by the load balancing service in response to the access request is read.
[0044] Based on the initial response data, initial tunnel information is encapsulated to obtain an initial response data packet; wherein, the initial response data packet includes the initial response data and the initial tunnel information;
[0045] Map the initial response data packet to the preset strategy engine;
[0046] Based on the preset strategy engine, the initial response data packet is processed for data security in accordance with the target response strategy to obtain the target response data packet; wherein, the target response data packet includes target response data and target tunnel information.
[0047] In one optional implementation, the response module is specifically used for:
[0048] When the target response strategy is a desensitized response, the sensitive data in the initial response data is replaced based on the preset strategy engine to obtain the target impact data.
[0049] Based on the target impact data, the initial tunnel information is modified to obtain the target tunnel information;
[0050] The target impact data and target tunnel information are encapsulated to obtain the target response data packet.
[0051] In an optional implementation, the response module is further configured to:
[0052] Based on the load balancing service, the target response data packet is forwarded to the user terminal.
[0053] A third aspect of this application provides an electronic device, comprising: at least one processor and a memory;
[0054] The memory stores computer-executed instructions;
[0055] The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the method described in the first aspect above and various possible designs of the first aspect.
[0056] The fourth aspect of this application provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the method described in the first aspect above and various possible designs of the first aspect.
[0057] The fifth aspect of this application provides a computer program product including computer instructions for causing a computer to perform the methods described in the first aspect above and various possible designs of the first aspect.
[0058] The technical solution of this application has the following advantages:
[0059] This application provides a data security access method, apparatus, electronic device, and storage medium. The method includes: obtaining an access request sent by any user terminal to a cloud data center based on a load balancing service; mapping the access request to the preset policy engine through a traffic mirroring module between the load balancing service and the preset policy engine; determining a target response policy for the access request based on the security authentication information represented by the access request, according to the preset policy engine; and responding to the access request according to the target response policy. The method provided above improves the flexibility and compatibility of data security access configuration in the cloud data center by mapping the access request obtained from the load balancing service to the preset policy engine, thereby enabling a data security access controller for the cloud data center based on the preset policy engine. This lays the foundation for improving the security of user terminal access to cloud data. Attached Figure Description
[0060] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0061] Figure 1 This is a schematic diagram of the data security access system on which the embodiments of this application are based;
[0062] Figure 2 A flowchart illustrating the data security access method provided in this application embodiment;
[0063] Figure 3 A schematic diagram of the structure of an exemplary data security access system provided in the embodiments of this application;
[0064] Figure 4 This is a schematic diagram of the structure of the preset strategy engine provided in the embodiments of this application;
[0065] Figure 5 This is a schematic diagram of the connection establishment process provided in an embodiment of this application;
[0066] Figure 6 This is a schematic diagram of the response data transmission process provided in an embodiment of this application;
[0067] Figure 7 This is a schematic diagram of the structure of the data security access device provided in the embodiments of this application;
[0068] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0069] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the present disclosure in any way, but rather to illustrate the concepts of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0070] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0071] Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. In the following descriptions of embodiments, "a plurality of" means two or more, unless otherwise explicitly defined.
[0072] In related technologies, data access control is a crucial aspect of data security, and can be understood as a fundamental security mechanism. Access control authorizes legitimate users to access resources based on prescribed security policies and models, and prevents unauthorized access by both authorized and unauthorized users. The objects involved typically include components such as the access subject, the resource object, access policies, and policy enforcement.
[0073] With the development of digital transformation, enterprise services are increasingly migrating to cloud-native and cloud-based architectures. Current technical solutions typically rely on specialized equipment for data security access control, lacking security controls for cloud-native scenarios and cloud-based business data access, and lacking flexible deployment mechanisms. They cannot be flexibly deployed in cloud-native and cloud-based data access scenarios and lack ABAC (attribute-based access control) based security access control mechanisms. Furthermore, many users' existing data services rely on general-purpose Nginx for load balancing; switching to traditional security access control equipment would increase unnecessary hardware costs and necessitate adjustments to the service architecture.
[0074] To address the aforementioned issues, this application provides a data security access method, apparatus, electronic device, and storage medium. The method includes: obtaining an access request sent by any user terminal to a cloud data center based on a load balancing service; mapping the access request to the preset policy engine through a traffic mirroring module between the load balancing service and the preset policy engine; determining a target response policy for the access request based on the security authentication information represented by the access request, according to the preset policy engine; and responding to the access request according to the target response policy. The method provided by the above solution improves the flexibility and compatibility of data security access configuration in the cloud data center by mapping the access request obtained from the load balancing service to the preset policy engine, thereby enabling a data security access controller for the cloud data center based on the preset policy engine. This lays the foundation for improving the security of user terminal access to cloud data.
[0075] The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present invention will now be described with reference to the accompanying drawings.
[0076] First, the structure of the data security access system on which this application is based will be described:
[0077] The data security access method, apparatus, electronic device, and storage medium provided in this application are suitable for providing secure responses to cloud data center access requests sent by user terminals. For example... Figure 1 The diagram shown illustrates the structure of the data security access system upon which this application's embodiment is based. It mainly includes a user terminal, a cloud data center, and a data security access device. The user terminal first sends an access request to the data security access device, which then determines the target response strategy for the access request and finally responds to the access request according to the target response strategy.
[0078] This application provides a data security access method for securely responding to cloud data center access requests sent by a user terminal. The execution subject of this application embodiment is an electronic device, such as a server, desktop computer, laptop computer, tablet computer, or other electronic devices that can be used to securely respond to cloud data center access requests sent by a user terminal.
[0079] like Figure 2 The diagram shown is a flowchart illustrating a data security access method provided in an embodiment of this application. The method includes:
[0080] Step 201: Obtain the access request sent by any user terminal to the cloud data center based on the load balancing service.
[0081] Specifically, the load balancing service can refer to nginx, a high-performance HTTP and reverse proxy server commonly used in network services to provide load balancing services.
[0082] Step 202: Map access requests to the preset policy engine through the traffic mirroring module between the load balancing service and the preset policy engine.
[0083] The traffic mirroring module can be called the tcp / http_stream_mirror module. The traffic mirroring module is developed through the flexible third-party module extension mechanism provided by nginx.
[0084] Step 203: Based on the preset policy engine, determine the target response policy for the access request according to the security authentication information represented by the access request.
[0085] Specifically, based on a preset policy engine, the security authentication information represented by the access request can be analyzed and matched to determine the target response policy for the access request.
[0086] The target response strategy for access requests can be divided into at least three types: allow response, block response, and de-identify response.
[0087] Step 204: Respond to the access request according to the target response strategy.
[0088] Specifically, when the target impact policy is to allow the response, nginx directly forwards the response data returned by the preset policy engine without performing any operations. When the target impact policy is to block the response, nginx disconnects the current connection and discards the data. When the target impact policy is to anonymize the response, nginx forwards the anonymized data to the client. Modifications may be made to the returned content, such as adding more restrictions or removing invisible parts of the returned content.
[0089] Specifically, such as Figure 3The diagram illustrates the structure of an exemplary data security access system provided in this application embodiment. The user client sends access requests to the database service in the cloud data center through an application container engine. The application container engine includes a load balancing service (nginx), a traffic mirroring module (tcp / http_stream_mirror), and a preset policy engine. The load balancing service Nginx and the preset policy engine can be independently and flexibly scaled elastically, allowing for lossless elastic scaling based on the cloud data center's business and load, ensuring service availability. Modules developed based on the nginx module can be directly loaded as module components into the existing nginx cluster of the user-side service, providing lossless online service expansion.
[0090] Based on the above embodiments, as an implementable approach, in one embodiment, a target response strategy for an access request is determined based on a preset policy engine and the security authentication information represented by the access request, including:
[0091] Step 2031: Extract authentication features from the access request to obtain the authentication feature extraction results of the access request;
[0092] Step 2032: Based on the preset policy engine, determine the security authentication information of the access request according to the authentication feature extraction results of the access request;
[0093] Step 2033: Determine the target response strategy for the access request based on the security authentication information of the access request.
[0094] Specifically, in one embodiment, user identity features and request action features can be extracted from the access request to obtain the authentication feature extraction result of the access request.
[0095] The authentication features include user identity features and request action features.
[0096] Specifically, the preset strategy engine can extract the authentication features of the access request to identify the user's identity and role, as well as the access action of the access request. It can analyze the content of the data traffic, combine the extracted features and the identified content with the extracted keywords to perform ABAC strategy analysis, determine the target response strategy for the access request based on the analysis results (security authentication information), and then perform the corresponding operations, data processing, and real-time control of the rationality of the access data.
[0097] Specifically, such as Figure 4The diagram shown illustrates the structure of the preset policy engine provided in this embodiment. Internally, the PolicyEngine retrieves information from a third-party or user-internal Identity and Access Management System (IPAM) via the OPA PolicyAgent (policy execution component). After internal data processing, this information is converted into a general PolicyEngine data interface and compiled into a high-performance matching engine (OPA Engine) using the Compile method. This matching engine then performs security authentication on the authentication feature extraction results of the access request (SQL statement) to determine the security authentication information of the access request and further determine the target response policy.
[0098] When the access request is an SQL statement, Nginx, based on the mirror module, forwards traffic to the PolicyEngine in real time via stream. The PolicyEngine identifies the SQL type based on traffic characteristics, parses the SQL statement, extracts user tokens, IP addresses, and other information for ABAC user identification, extracts the SQL statement actions, select clauses, where clauses, etc., and converts them into internal ABAC data interfaces, calling the OPA Engine for matching processing. Based on the matching results (target response policy), actions are executed: allowing, de-identifying, blocking, etc. The matching results can be further returned to the traffic mirroring module, which then performs corresponding processing based on the returned results.
[0099] Based on the above embodiments, as one implementable approach, in one embodiment, responding to an access request according to a target response strategy includes:
[0100] Step 2041: Based on the traffic mirroring module, read the initial response data obtained from the cloud data center in response to the access request from the load balancing service;
[0101] Step 2042: Based on the initial response data, encapsulate the initial tunnel information to obtain the initial response data packet;
[0102] Step 2043: Map the initial response data packet to the preset policy engine;
[0103] Step 2044: Based on the preset strategy engine, perform data security processing on the initial response data packet according to the target response strategy to obtain the target response data packet.
[0104] The initial response data packet includes initial response data and initial tunnel information; the target response data packet includes target response data and target tunnel information. The initial response data is data directly read from the backend database service according to the access request, and the tunnel information includes at least the data transmission length and data offset.
[0105] It should be noted that this application embodiment, in conjunction with the third-party module extension interface provided by nginx, developed the tcp / http_stream_mirror module (traffic mirroring module). This module is developed based on the nginx third-party extension structure, adding configuration items and processing modules. When users access the database through nginx, Tcp / http_stream_mirror reuses the nginx upstream mechanism (load balancing service upper-level mechanism), and based on the processing module, flexibly extends and configures the PolicyEngine (preset policy engine) according to the configuration items.
[0106] Among them, such as Figure 5 The diagram illustrates the connection establishment process provided in this embodiment. When a client accesses a backend database service through nginx, nginx establishes a TCP connection with the client. After the connection is established (1)(2), nginx enters the proxy / upstream module and establishes a TCP connection with the backend database service (3)(4). After the connection is established, the client sends a normal data access request. After nginx establishes a connection with the backend database, when there is data exchange in the current connection, it will simultaneously establish a connection with the Policy Engine (5)(6). The connection supports both Unix and TCP methods.
[0107] Specifically, in one embodiment, when the target response strategy is a desensitized response, sensitive data in the initial response data is replaced based on a preset strategy engine to obtain target impact data; the initial tunnel information is modified according to the target impact data to obtain target tunnel information; and the target impact data and target tunnel information are encapsulated to obtain a target response data packet.
[0108] Furthermore, in one embodiment, the target response data packet can be forwarded to the user terminal based on a load balancing service.
[0109] Specifically, such as Figure 6As shown, this is a schematic diagram of the response data transmission process provided in this application embodiment. When there is data transmission in the connection (1)(5), the tcp / http_stream_mirror (traffic mirroring module) will cache the data (initial response data) read from the cache socket of the load balancing service and encapsulate the private tunnel information (initial tunnel information). The data (initial data packet) is mapped to the Policy Engine (2, 6). After the Policy Engine finishes processing, it encapsulates the processed data (target response data) and the action to be executed with the private tunnel information (target tunnel information) to obtain the target response data packet. The target response data packet is sent back to the traffic mirroring module (3, 7). The traffic mirroring module performs data processing based on the returned result. If the data does not need to be replaced, the corresponding cached data is forwarded directly, that is, the initial response data is returned to the user. If the original data needs to be modified, the cached data is released and the data processed by the PolicyEngine (target response data) is forwarded to realize the asynchronous processing of the entire security service (4)(8).
[0110] The data security access method provided in this application obtains access requests sent by any user terminal to the cloud data center based on a load balancing service; maps the access requests to the preset policy engine through a traffic mirroring module between the load balancing service and the preset policy engine; determines the target response policy for the access request based on the security authentication information represented by the access request, according to the preset policy engine; and responds to the access request according to the target response policy. The method provided by the above solution improves the flexibility and compatibility of data security access configuration in the cloud data center by mapping access requests obtained from the load balancing service to the preset policy engine, thereby establishing a data security access controller for the cloud data center based on the preset policy engine. This lays the foundation for improving the security of user terminal access to cloud data. Furthermore, the entire architecture supports flexible deployment. It can be deployed in cloud-native scenarios, combining Kubernetes' ABAC, ingress controller, CRD, and other mechanisms to achieve non-intrusive deployment of microservices. It can also be deployed as a standalone service in a cloud VPC to achieve secure control over data access on the VPC.
[0111] This application provides a data security access device for executing the data security access method provided in the above embodiments.
[0112] like Figure 7 The diagram shown is a structural schematic of a data security access device provided in an embodiment of this application. The data security access device 70 includes: an acquisition module 701, a mapping module 702, an authentication module 703, and a response module 704.
[0113] The system includes: an acquisition module for acquiring access requests sent from any user terminal to the cloud data center based on the load balancing service; a mapping module for mapping access requests to the preset policy engine through a traffic mirroring module between the load balancing service and the preset policy engine; an authentication module for determining the target response policy for the access request based on the security authentication information represented by the access request and the preset policy engine; and a response module for responding to the access request according to the target response policy.
[0114] Specifically, in one embodiment, the authentication module is specifically used for:
[0115] Authentication features are extracted from the access request to obtain the authentication feature extraction results of the access request;
[0116] Based on the preset strategy engine, the security authentication information of the access request is determined according to the authentication feature extraction results of the access request;
[0117] Based on the security authentication information of the access request, determine the target response strategy for the access request.
[0118] Specifically, in one embodiment, the authentication module is specifically used for:
[0119] User identity features and request action features are extracted from the access request to obtain the authentication feature extraction results of the access request;
[0120] The authentication features include user identity features and request action features.
[0121] Specifically, in one embodiment, the target response strategy for access requests is divided into at least three types: allow response, block response, and de-identify response.
[0122] Specifically, in one embodiment, the response module is specifically used for:
[0123] Based on the traffic mirroring module, the initial response data obtained from the cloud data center is read from the load balancing service in response to the access request.
[0124] Based on the initial response data, the initial tunnel information is encapsulated to obtain the initial response data packet; wherein, the initial response data packet includes the initial response data and the initial tunnel information;
[0125] Map the initial response data packet to the preset policy engine;
[0126] Based on the preset strategy engine, the initial response data packet is processed for data security in accordance with the target response strategy to obtain the target response data packet; the target response data packet includes target response data and target tunnel information.
[0127] Specifically, in one embodiment, the response module is specifically used for:
[0128] When the target response strategy is a desensitized response, the sensitive data in the initial response data is replaced based on the preset strategy engine to obtain the target impact data;
[0129] Based on the target impact data, modify the initial tunnel information to obtain the target tunnel information;
[0130] Encapsulate the target impact data and target tunnel information to obtain the target response data packet.
[0131] Specifically, in one embodiment, the response module is further configured to:
[0132] Based on the load balancing service, the target response data packet is forwarded to the user terminal.
[0133] Regarding the data security access device in this embodiment, the specific methods by which each module performs its operations have been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0134] The data security access device provided in this application embodiment is used to execute the data security access method provided in the above embodiment. Its implementation method and principle are the same, and will not be described again.
[0135] This application provides an electronic device for executing the data security access method provided in the above embodiments.
[0136] like Figure 8 The diagram shown is a structural schematic of an electronic device provided in an embodiment of this application. The electronic device 80 includes at least one processor 81 and a memory 82.
[0137] The memory stores computer-executable instructions; at least one processor executes the computer-executable instructions stored in the memory, causing the at least one processor to perform the data security access method provided in the above embodiments.
[0138] The electronic device provided in this application embodiment is used to execute the data security access method provided in the above embodiment. Its implementation method and principle are the same, and will not be described again.
[0139] This application provides a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the data security access method provided in any of the above embodiments.
[0140] The storage medium containing computer-executable instructions provided in this application embodiment can be used to store computer-executable instructions for the data security access method provided in the foregoing embodiments. Its implementation method and principle are the same, and will not be described again.
[0141] This application provides a computer program product, including computer instructions, which are used to cause a computer to execute the data security access method provided in the foregoing embodiments.
[0142] The computer program product provided in this application embodiment can be used to execute computer instructions for the data security access method provided in the foregoing embodiments. Its implementation method and principle are the same, and will not be described again.
[0143] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0145] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units.
[0146] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0147] A portion of this application can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the present invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0148] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is merely an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0149] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for secure data access, characterized in that, include: The load balancing service is used to obtain access requests sent from any user terminal to the cloud data center. The access request is mapped to the preset policy engine through the traffic mirroring module between the load balancing service and the preset policy engine; Based on the preset strategy engine, the target response strategy for the access request is determined according to the security authentication information represented by the access request. Respond to the access request in accordance with the target response strategy; Responding to the access request according to the target response strategy includes: Based on the traffic mirroring module, the initial response data obtained from the cloud data center by the load balancing service in response to the access request is read. Based on the initial response data, initial tunnel information is encapsulated to obtain an initial response data packet; wherein, the initial response data packet includes the initial response data and the initial tunnel information; Map the initial response data packet to the preset strategy engine; Based on the preset strategy engine, the initial response data packet is processed for data security in accordance with the target response strategy to obtain the target response data packet; wherein, the target response data packet includes target response data and target tunnel information.
2. The method according to claim 1, characterized in that, The step of determining the target response strategy for the access request based on the security authentication information represented by the access request, using the preset strategy engine, includes: The access request is subjected to authentication feature extraction to obtain the authentication feature extraction result of the access request; Based on the preset strategy engine, the security authentication information of the access request is determined according to the authentication feature extraction result of the access request; Based on the security authentication information of the access request, determine the target response strategy for the access request.
3. The method according to claim 2, characterized in that, The step of extracting authentication features from the access request to obtain the authentication feature extraction result of the access request includes: User identity features and request action features are extracted from the access request to obtain the authentication feature extraction result of the access request; The authentication features include the user identity features and the request action features.
4. The method according to claim 2, characterized in that, The target response strategy for the access request is divided into at least three types: allow response, block response, and de-identify response.
5. The method according to claim 4, characterized in that, The step of performing data security processing on the initial response data packet based on the preset strategy engine and according to the target response strategy to obtain the target response data packet includes: When the target response strategy is a desensitized response, the sensitive data in the initial response data is replaced based on the preset strategy engine to obtain the target response data; Based on the target response data, modify the initial tunnel information to obtain the target tunnel information; The target response data and target tunnel information are encapsulated to obtain the target response data packet.
6. The method according to claim 1, characterized in that, The method further includes: Based on the load balancing service, the target response data packet is forwarded to the user terminal.
7. A data security access device, characterized in that, include: The acquisition module is used to acquire access requests sent by any user terminal to the cloud data center based on the load balancing service; The mapping module is used to map the access request to the preset policy engine through the traffic mirroring module between the load balancing service and the preset policy engine; The authentication module is used to determine the target response strategy for the access request based on the security authentication information represented by the access request, according to the preset strategy engine. A response module is used to respond to the access request in accordance with the target response strategy; The response module is specifically used for: Based on the traffic mirroring module, the initial response data obtained from the cloud data center by the load balancing service in response to the access request is read. Based on the initial response data, initial tunnel information is encapsulated to obtain an initial response data packet; wherein, the initial response data packet includes the initial response data and the initial tunnel information; Map the initial response data packet to the preset strategy engine; Based on the preset strategy engine, the initial response data packet is processed for data security in accordance with the target response strategy to obtain the target response data packet; wherein, the target response data packet includes target response data and target tunnel information.
8. An electronic device, characterized in that, include: At least one processor and memory; The memory stores computer-executed instructions; The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Access control determination engine optimization system and method based on big data
CN103902742A
Service access method and device, equipment and storage medium
CN118827166A