Data protection method, system, computer device and storage medium

By separating enterprise and terminal ends in a third-party resource pool and utilizing data exchange gateways and operation consoles, the problem of enterprises abusing and improperly processing collected data is solved, user data security is achieved, and data is transmitted and processed within a legal scope is ensured.

CN119848916BActive Publication Date: 2026-02-06CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411629976.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-14
Publication Date
2026-02-06
Estimated Expiration
2044-11-14

AI Technical Summary

Technical Problem

In the current technology, enterprises lack effective means to prevent the misuse, improper processing, unauthorized transmission, and leakage of users' sensitive personal information of collected data. User data is at risk of being improperly processed and lost by enterprises.

Method used

By separating enterprise-side and client-side terminals through a third-party resource pool, terminal data is only allowed to be processed in the third-party resource pool. A data exchange gateway is used to achieve one-way data flow. The console provides a method to make data visible but not accessible, and a data scanning system filters the data to ensure that data is transmitted and processed only within a legal scope.

Benefits of technology

Without affecting business operations and user experience, this aims to prevent companies from improperly handling user data, ensure user data security, prevent data leakage and loss, and protect user personal information and national security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119848916B_ABST
    Figure CN119848916B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, and discloses a data protection method, a data protection system, computer equipment and a storage medium, which comprise the following steps: a terminal collects terminal data and uploads the terminal data to a third-party resource pool with a preset IP address; an enterprise end sends a data processing platform to the third-party resource pool through a data exchange gateway; a desktop picture transmitted by an operation platform is used to access the data processing platform, terminal data is read through the data processing platform, the terminal data is processed, and a target processing result corresponding to the terminal data is obtained; and the third-party resource pool filters the target processing result by using a data scanning system and pushes the filtered target processing result to the terminal. The application technically ensures that an enterprise cannot illegally process collected user information and important data, cannot transmit data and derivatives generated by data processing out of the country, ensures that user data is not lost after the enterprise is closed, and thus ensures the personal information safety of users and national safety.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, in particular to a data protection method and system, a computer device and a storage medium. BACKGROUND

[0002] With the development and popularization of intelligent terminals such as Internet of Things and intelligent vehicles, the demand of intelligent terminals for user data collection, storage, analysis and processing is becoming stronger and stronger, and even forms an intelligent business model driven by data: data collection -> data storage -> data analysis and processing -> terminal deployment -> data re-collection. In this model, the intelligent terminal facing the user collects data and uploads the data to the storage resource pool designated by the terminal provider, and the enterprise is responsible for the storage and management of the data; the data analysis and processing system of the enterprise will analyze and process the data in the storage resource pool, and if necessary, the processing result will be issued to the terminal for deployment and operation. In this scenario, the enterprise has a strong demand for data collection and processing, and its business operation depends on data processing. Since the data is completely stored and managed by the enterprise, the user data faces the risk of being illegally processed and illegally transmitted by the enterprise, and it is difficult for the regulatory agency to find out, and the data faces the risk of loss when the enterprise goes bankrupt.

[0003] In related technologies, most of them focus on protecting data in the process of data collection, data transmission and data access through encryption, identity authentication, permission management and other means to prevent data leakage, but lack effective means to prevent the misuse, illegal processing and illegal transmission of data by the enterprise that collects the data and the leakage of user personal sensitive information. SUMMARY

[0004] Therefore, the present application provides a data protection method, system, computer device and storage medium to solve the problem of lack of effective means to prevent the misuse, illegal processing and illegal transmission of data by the enterprise that collects the data and the leakage of user personal sensitive information.

[0005] In a first aspect, the present application provides a data protection method applied to a third-party resource pool, the method comprising:

[0006] obtaining terminal data collected and uploaded by a terminal and storing the terminal data to a preset IP address;

[0007] in response to a data upload request of an enterprise end, obtaining a data processing platform uploaded by the enterprise end through a data exchange gateway;

[0008] in response to a data processing request of the enterprise end, transmitting a desktop picture to the enterprise end by using an operation console, so that the enterprise end accesses the data processing platform through the desktop picture, reads the terminal data through the data processing platform, processes the terminal data, and obtains a target processing result corresponding to the terminal data.

[0009] Filtering the target processing result by using the data scanning system, and pushing the filtered target processing result to the terminal.

[0010] In the present application, the terminals of the enterprise end and the client end are separated by the third-party resource pool, and the data of the terminal is only allowed to be processed in the third-party resource pool, so that the enterprise cannot illegally process the collected user information and important data from a technical point of view, cannot transmit the data and the derivatives generated by the data processing out of the country, avoids the abuse, illegal processing, illegal transmission of the collected data by the enterprise itself, and the leakage of user's personal sensitive information, ensures that the user data is not lost after the enterprise goes bankrupt, and thus ensures the safety of the user's personal information and the national security.

[0011] In an optional embodiment, the data exchange gateway comprises a data gateway server and a data gateway client, and the data gateway server is provided with an external network interface and an internal network interface. The data exchange gateway is used to obtain a data processing platform uploaded by the enterprise end, which comprises:

[0012] When it is detected that the enterprise end accesses the data gateway server from the external network interface through the data gateway client, the enterprise end is provided with a function of writing data to the data gateway server;

[0013] When it is detected that the enterprise end accesses the data gateway server from the internal network interface through the data gateway client, the enterprise end is provided with a function of reading data from the data gateway server.

[0014] In this way, when the enterprise end accesses the data exchange gateway server through the data gateway client from the external network interface, it can only write data to the data exchange gateway server, but cannot read data; when the enterprise end accesses through the internal network interface, it can only read data, but cannot write data. Through the data exchange gateway, the enterprise can upload data from the external network interface to the service end of the data exchange gateway, and then download the data from the internal network interface to the data processing platform for use, thereby realizing the one-way inflow ability of data only in and not out.

[0015] In an optional embodiment, the operation platform comprises an operation platform client and an operation platform server, and the operation platform is used to transmit a desktop picture to the enterprise end, which comprises:

[0016] The enterprise end is logged in to the operation platform server through the operation platform client;

[0017] The operation platform server transmits the desktop picture corresponding to the data processing platform and the process of processing the terminal data of the data processing platform back to the operation platform client;

[0018] transmitting the desktop picture from the operation station client to the enterprise end.

[0019] In this way, since only the mouse signal and the desktop picture are allowed to be transmitted between the operation station client and the operation station server, and other data cannot be transmitted, the enterprise end cannot take the terminal data from the data processing platform, thus providing an effective method of data visibility but unavailability, which provides convenience and ensures safety.

[0020] In an optional embodiment, the method further comprises:

[0021] using the operation station server to make the desktop picture into a desktop video file, and storing the desktop video file in the operation station server.

[0022] In this way, by making the desktop picture data into a video file and storing it in the server, all operations of the enterprise end in the desktop of the operation station server are recorded, thus realizing monitoring of the operation behavior of the enterprise end, and the enterprise end has no awareness of this, thus providing an effective method of data visibility but unavailability through the operation station, which provides convenience and ensures safety, and provides an effective monitoring method for the operation behavior of the enterprise end.

[0023] In a second aspect, the present application provides a data protection method, applied to an enterprise end, comprising:

[0024] sending a data upload request to a third-party resource pool, and sending the data processing platform to the third-party resource pool through a data exchange gateway;

[0025] sending a data processing request to the third-party resource pool, accessing the data processing platform by using the desktop picture transmitted by the operation station, reading terminal data through the data processing platform, processing the terminal data, and obtaining a target processing result corresponding to the terminal data.

[0026] In the present application, the enterprise end can only access the data processing platform located in the third-party resource pool through the data exchange gateway, and process the terminal data stored in the third-party resource pool in the third-party resource pool, so that the enterprise end cannot download and obtain the terminal data, and the data collected by the terminal is stored and managed by a trusted third party, and the enterprise can only access and process the data in the resource pool managed by the third party under monitoring. On the one hand, it ensures that the enterprise does not have the ability to obtain personal sensitive information, and fully protects the data security of users; on the other hand, it can meet the processing needs of the enterprise for terminal data and the normal operation needs of the business.

[0027] In a third aspect, the present application provides a data protection method, applied to a terminal, comprising:

[0028] Collect terminal data, upload the terminal data to a third-party resource pool at a preset IP address based on a preset access control strategy;

[0029] The terminal data is filtered to obtain the target processing result corresponding to the terminal data.

[0030] In the present application, by limiting the terminal, the data collected by the terminal can only be uploaded to the third-party resource pool at the preset IP address, the terminal and the enterprise terminal cannot directly communicate, the data uploaded by the terminal is only allowed to be operated in the third-party resource pool and cannot be downloaded to the enterprise terminal, the filtering of the data filtering system ensures that the personal sensitive information and important data collected by the terminal cannot be obtained by the enterprise, and the enterprise cannot illegally process the collected user information and important data, cannot transmit the data and the derivatives generated by the data processing out of the country, avoids the abuse, illegal processing, illegal transmission of the data by the enterprise itself and the leakage of the user's personal sensitive information, ensures that the user data is not lost after the enterprise goes bankrupt, and thus ensures the safety of the user's personal information and national security.

[0031] In a fourth aspect, the present application provides a data protection system, which comprises a terminal, an enterprise terminal and a third-party resource pool.

[0032] The terminal collects terminal data, and uploads the terminal data to a third-party resource pool at a preset IP address based on a preset access control strategy.

[0033] The enterprise terminal sends a data upload request to the third-party resource pool, sends a data processing platform to the third-party resource pool through a data exchange gateway, sends a data processing request to the third-party resource pool, accesses the data processing platform through a desktop picture transmitted by an operation platform, reads terminal data through the data processing platform, processes the terminal data to obtain a target processing result corresponding to the terminal data.

[0034] The third-party resource pool filters the target processing result by using a data scanning system, and pushes the filtered target processing result to the terminal.

[0035] In the present application, the data collected by the terminal can only be uploaded to the third-party resource pool of the preset IP address, and the data uploaded by the terminal is only allowed to be operated by the enterprise end in the third-party resource pool, so that the terminals of the enterprise end and the client end are separated through the third-party resource pool, and the normal collection and processing of data by the enterprise under the permission of relevant regulations is not affected, the daily operation of the enterprise is not disturbed, and the use experience of domestic users is not affected, so that it is technically ensured that the enterprise cannot illegally process the collected user information and important data, and cannot export the data and derivatives generated by data processing, the abuse, illegal processing, illegal transmission of data by the enterprise collecting data, and the leakage of user personal sensitive information are avoided, the user data is not lost after the enterprise is closed, and the personal information security and national security of the user are ensured.

[0036] In a fifth aspect, the present application provides a computer device, comprising a memory and a processor, the memory and the processor are communicatively connected with each other, the memory stores computer instructions, and the processor executes the data protection method of the first aspect or any of the corresponding embodiments thereof, or executes the data protection method of the second aspect, or executes the data protection method of the third aspect by executing the computer instructions.

[0037] In a sixth aspect, the present application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the data protection method of the first aspect or any of the corresponding embodiments thereof, or execute the data protection method of the second aspect, or execute the data protection method of the third aspect.

[0038] In a seventh aspect, the present application provides a computer program product, which comprises computer instructions, and the computer instructions are used to make a computer execute the data protection method of the first aspect or any of the corresponding embodiments thereof, or execute the data protection method of the second aspect, or execute the data protection method of the third aspect. BRIEF DESCRIPTION OF DRAWINGS

[0039] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the drawings needed in the specific embodiments or prior art description will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0040] Figure 1 It is a structural schematic diagram of the data protection system according to the embodiment of the present application.

[0041] Figure 2 It is an interaction schematic diagram of the data protection system according to the embodiment of the present application.

[0042] Figure 3 is a schematic diagram of an architecture of a data protection system for a smart terminal according to an embodiment of the application.

[0043] Figure 4 is a schematic diagram of terminal data uploading according to an embodiment of the application.

[0044] Figure 5 is a data transmission schematic diagram of a data exchange gateway according to an embodiment of the application.

[0045] Figure 6 is a data transmission schematic diagram of an operation station according to an embodiment of the application.

[0046] Figure 7 is a schematic diagram of a data protection system in a smart car application scenario according to an embodiment of the application.

[0047] Figure 8 is a hardware structure schematic diagram of a computer device according to an embodiment of the application. DETAILED DESCRIPTION

[0048] To make the objects, technical solutions and advantages of embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the protection scope of the present application.

[0049] In related technologies, most of the focus is on protecting data in the data collection, data transmission and data access process through encryption, identity authentication, permission management and other means to prevent data leakage, but there is a lack of effective means for the misuse of collected data by the enterprise itself, illegal handling, illegal transmission and leakage of user personal sensitive information. For example: existing technical solution 1 “Vehicle data protection method, system, device and storage medium”, which prevents data from being leaked and tampered with in the storage and transmission process through data encryption and blockchain technology. However, the car company has the ability to arbitrarily process personal data on the vehicle end, and has the ability to arbitrarily use and transmit the data processing results, which poses a great data security risk to the user's personal data. Existing technical solution 2 “Data management method, device and storage medium”, which generates permission management information based on identity categories and data security levels, and manages the permission management information by establishing a permission management information library, realizes efficient control of data permissions, and reduces data security protection time cost. Like solution 1, the car company poses a great security threat to the user's personal data and does not fundamentally protect the user's personal data security.

[0050] To solve the above problems, the embodiment of the present application provides a data protection system, which is suitable for smart terminals and protects the data uploaded by the smart terminals. The data collected by the terminal can only be uploaded to a third-party resource pool with a preset IP address, and the data uploaded by the terminal is only allowed to be operated by the enterprise end in the third-party resource pool. The third-party resource pool separates the terminals of the enterprise end and the client end, realizes normal collection and processing of data by the enterprise under the permission of relevant regulations, does not interfere with the daily operation of the enterprise and does not affect the use experience of domestic users, technically ensures that the enterprise cannot illegally process the collected user information and important data, cannot export data and derivatives generated by data processing, avoids the abuse, illegal processing, illegal transmission of data by the enterprise itself and the leakage of user personal sensitive information, ensures that the user data is not lost after the enterprise goes bankrupt, and thus guarantees the safety of personal information and national security.

[0051] In the embodiment, a data protection system is provided, Figure 1 is a structural schematic diagram of the data protection system according to the embodiment of the present application, as Figure 1 shown, the system includes a terminal 1, an enterprise end 2 and a third-party resource pool 3.

[0052] Figure 2 is an interaction schematic diagram of the data protection system according to the embodiment of the present application, as Figure 2 shown, the terminal 1 is used to execute step S101, the enterprise end 2 is used to execute steps S201 to S202, and the third-party resource pool is used to execute step S301.

[0053] Step S101, collecting terminal data, uploading the terminal data to a third-party resource pool with a preset IP address based on a preset access control strategy.

[0054] Step S201, sending a data upload request to the third-party resource pool, and sending a data processing platform to the third-party resource pool through a data exchange gateway.

[0055] Step S202, sending a data processing request to the third-party resource pool, accessing the data processing platform by using a desktop picture transmitted by an operation station, reading the terminal data by using the data processing platform, processing the terminal data, and obtaining a target processing result corresponding to the terminal data.

[0056] Step S301, filtering the target processing result by using a data scanning system, and pushing the filtered target processing result to the terminal.

[0057] In an alternative embodiment, the data exchange gateway comprises a data gateway server and a data gateway client, the data gateway server is provided with an external network interface and an internal network interface, and the data exchange gateway is used to obtain a data processing platform uploaded by an enterprise end, comprising:

[0058] When it is detected that the enterprise end accesses the data gateway server from the external network interface through the data gateway client, the enterprise end is provided with a function of writing data to the data gateway server.

[0059] When it is detected that the enterprise end accesses the data gateway server from the internal network interface through the data gateway client, the enterprise end is provided with a function of reading data from the data gateway server.

[0060] In this way, when the enterprise end accesses the data exchange gateway server through the data gateway client from the external network interface, it can only write data to the data exchange gateway server, but cannot read data; when the enterprise end accesses through the internal network interface, it can only read data, but cannot write data. Through the data exchange gateway, the enterprise can upload data from the external network interface to the service end of the data exchange gateway, and then download the data from the internal network interface to the data processing platform for use, thereby realizing the one-way inflow capability of data only in.

[0061] In an alternative embodiment, the operating platform comprises an operating platform client and an operating platform server, and the operating platform is used to transmit a desktop picture to an enterprise end, comprising:

[0062] The enterprise end is logged in to the operating platform server through the operating platform client.

[0063] The operating platform server transmits a desktop picture corresponding to the data processing platform and the process of processing terminal data by the data processing platform back to the operating platform client.

[0064] The operating platform client transmits the desktop picture to the enterprise end.

[0065] In this way, since only mouse signals and desktop pictures can be transmitted between the operating platform client and the operating platform server, and other data cannot be transmitted, the enterprise end cannot take terminal data from the data processing platform, thereby providing an effective method of data visibility but inaccessibility, which provides convenience and ensures security.

[0066] In an alternative embodiment, the method further comprises: using the operating platform server to make the desktop picture into a desktop video file, and storing the desktop video file in the operating platform server.

[0067] In this mode, by making the desktop picture data into a video file stored in the server, all operations of the enterprise end in the desktop of the operating platform server are recorded, and the monitoring of the operation behavior of the enterprise end is realized, and the enterprise end has no perception of this. An effective method of data visibility but unavailability is provided by the operating platform, which provides convenience and ensures safety while providing an effective monitoring method for the operation behavior of the enterprise end.

[0068] In an example, Figure 3 is a schematic diagram of a data protection system for a smart terminal according to an embodiment of the application, as shown in Figure 3 The data protection system for a smart terminal includes six parts: a terminal, a data processing platform, a resource pool, a data exchange gateway, an operating platform, and a data scanning system.

[0069] I. Terminal: The terminal is sold to the customer with a traffic card, and the traffic card is strictly limited to the IP addresses or domain names that can be accessed, Figure 4 is a schematic diagram of terminal data upload according to an embodiment of the application, as shown in Figure 4 The data collected by the terminal can only be uploaded to the resource pool at the specified IP address, and the terminal cannot directly communicate with the enterprise.

[0070] II. Data processing platform: The data processing platform is a system composed of software and hardware, generally provided by the enterprise, and completes the access, processing, management, and other needs of the enterprise to the data. It is deployed in the resource pool provided by the neutral operator.

[0071] III. Resource pool: The resource pool is a dedicated cloud provided by the neutral operator, which provides storage capacity and computing capacity. It uses 3AZ high-availability technology to ensure that the service availability is not less than 99.95%, the data reliability is not less than 99.99999999999% (13 nines), and the data is encrypted by hardware to ensure the security of the data.

[0072] IV. Data exchange gateway: The data exchange gateway is a system for facilitating the enterprise to transfer data from the outside to the resource pool. The data exchange gateway is composed of a data exchange gateway client and a data exchange gateway server. Figure 5 is a data transmission schematic diagram of a data exchange gateway according to an embodiment of the application, as shown in Figure 5As shown, the enterprise end uploads and downloads data through the data exchange gateway client. The data exchange gateway server has two types of network interfaces, one is an external network interface, and the other is an internal network interface. When the enterprise end accesses the data exchange gateway server through the data exchange gateway client from the external network interface, it can only write data to the data exchange gateway server, but cannot read data; when the enterprise end accesses the data exchange gateway server through the internal network interface, it can only read data, but cannot write data. Through the data exchange gateway, the enterprise can upload data (including programs) from the external network interface to the data exchange gateway server, and then download data (including programs) from the internal network interface to the data processing platform for use, thereby realizing the one-way inflow capability of "data only in and not out".

[0073] Five, operation platform. The operation platform is a system that facilitates the enterprise to remotely operate the data processing platform. The system is composed of a client and a server. Figure 6 A data transmission schematic diagram of an operation platform according to an embodiment of the application is shown in FIG. 5. Figure 6 As shown, the operation platform client is a software that can run on various mainstream operating systems, such as Windows, Mac, Linux, Android, etc. The operation platform server runs many desktop operating systems (referred to as desktops), such as Windows, Linux, etc. When the enterprise end needs to remotely operate the data processing platform in the resource pool, it needs to log in to the desktop of the operation platform server using the operation platform client, and then access the data processing platform in the resource pool through the desktop of the operation platform server. Since only mouse and keyboard signals and desktop pictures are transmitted between the operation platform client and the operation platform server, and no other data is transmitted, the enterprise end cannot download data from the data processing platform. In addition, the operation platform server stores the desktop picture data as a video file in the server while transmitting the desktop picture back to the operation platform client. Thus, all operations of the enterprise end in the desktop of the server are recorded, and the monitoring of the operation behavior of the enterprise end is realized, which is imperceptible to the enterprise end. In summary, the operation platform provides an effective method of "data visible but not available", which provides convenience, ensures safety, and provides a monitoring method.

[0074] Six, data scanning system. For parsing and scanning data traffic between terminal and data processing platform to determine the legitimacy of the data, strictly limit the data out of data processing platform, only allow the terminal software to run the legal data out of data processing platform. In order to let the data scanning system can "understand" the data, the enterprise side needs to provide data communication protocol to the operator of data scanning system, the resource pool first checks whether the protocol is legal, and then designs the scanning rule according to the protocol. In the normal operation process, when the data scanning system finds that there is data flow out of the rule, it will be blocked to prevent illegal data from flowing out. In this way, the normal operation of enterprise business is ensured, and the leakage of illegal data is prevented.

[0075] Specifically, the collection, storage and processing of data are as follows: first, the intelligent terminal collects data and uploads it to the resource pool operated by the neutral operator through the built-in flow card for storage; second, the enterprise uploads its own data processing platform to the resource pool through the data exchange gateway, and logs in to the resource pool remotely through the operation platform to complete the deployment, operation and maintenance of the data processing platform in the resource pool; finally, the data processing platform reads the terminal data stored in the resource pool for processing.

[0076] The interaction process between the intelligent terminal and the enterprise is as follows: first, the intelligent terminal cannot directly communicate with the enterprise and cannot directly transmit data; second, there are two scenarios for transmitting data between the intelligent terminal and the enterprise: one is when the software of the intelligent terminal needs to be updated; the second is that the result generated by the data processing platform needs to be pushed to the intelligent terminal. For the first scenario, the enterprise first needs to upload the software update package to the resource pool through the data exchange gateway, and copy the software update package to the data processing platform through the operation platform. Next, the processing methods of the two scenarios are consistent, and the data or software package is pushed to the intelligent terminal by the data processing platform after being scanned by the data scanning system. The scanning rule of the data scanning system is designed by the data communication protocol provided by the enterprise, and only the data or software package that meets the scanning rule can be transmitted out of the resource pool.

[0077] In an implementation scenario, Figure 7 The structure diagram of a data protection system in an intelligent automobile application scenario according to an embodiment of the present application is shown in Figure 7 In the present embodiment, the terminal is an intelligent automobile; the resource pool is a 3AZ dedicated cloud resource pool constructed across three data centers, which provides object storage supporting S3 protocol and elastic and scalable computing capacity; the data exchange gateway is an FTP server, which provides data upload service; and the operation platform is a cloud computer, through which the enterprise side operates the data processing platform in the dedicated cloud resource pool, as shown in Figure 5

[0078] ​The automobile terminal collects user data in the cabin, vehicle driving state data, external environment data, and the like, and uploads the data to a dedicated cloud operated by a neutral operator according to a certain strategy through a built-in traffic card calling an S3 protocol interface. Each automobile is built-in with a traffic card at the time of factory shipment, and the traffic card is configured with an access control strategy by the neutral operator through its core network capability, and is limited to only accessing the dedicated cloud and other specified preset IP addresses or domain names. That is, the data collected by the automobile terminal can only be uploaded to the dedicated cloud resource pool storage system, and cannot be uploaded to the vehicle enterprise, and the automobile terminal is limited to not being able to directly communicate with the vehicle enterprise.

[0079] The dedicated cloud resource pool operated by the neutral operator provides both storage capability and computing capability, adopts 3AZ high availability technology to ensure that the service availability is not less than 99.95%, the data reliability is not less than 99.99999999999% (13 nines), and the data is encrypted by hardware to ensure the security of the data.

[0080] The enterprise end first uploads its own data processing platform to the dedicated cloud resource pool through the FTP server, and then logs in to the resource pool through the cloud computer to deploy the data processing platform to the dedicated computing hardware in the resource pool. The data processing platform reads the terminal data stored in the resource pool to complete the analysis and processing.

[0081] All operation behaviors of the enterprise end in the resource pool through the local terminal of the cloud computer are recorded, and the enterprise end has no awareness of this, so that the behavior of the enterprise end can be standardized, and the occurrence of data leakage and other illegal behaviors can be prevented, and the operation record can also be used as a basis for subsequent review, and traceability can be achieved.

[0082] The processing result of the data processing platform in processing the vehicle end data is pushed to the vehicle end after being scanned and filtered by the data filtering system, and the vehicle end software is upgraded. The filtering rule of the data filtering system is set according to the data communication protocol between the vehicle end and the data processing platform provided by the vehicle enterprise, and only the data meeting the rule can flow out of the resource pool, otherwise it will be intercepted to prevent user sensitive information and other important information from being leaked. Similarly, since direct communication between the vehicle end and the vehicle enterprise is prohibited, when the vehicle enterprise needs to upgrade the vehicle end software, it first needs to upload the software upgrade package to the data processing platform through the data exchange gateway, and then push it to the vehicle end after being filtered by the data filtering system.

[0083] The data protection system provided in this embodiment allows data collected by terminals to be uploaded only to a third-party resource pool with a specified IP address. Data uploaded by terminals can only be processed by the enterprise side within this third-party resource pool. By separating the enterprise side and the client side through the third-party resource pool, the system ensures that enterprises can collect and process data normally within the limits of relevant regulations, without interfering with their daily operations or affecting the user experience of domestic users. Technically, this prevents enterprises from illegally processing collected user information and important data, and from transmitting data and its derivatives abroad. This avoids the misuse, illegal processing, and illegal transmission of data by the data-collecting enterprise itself, as well as the leakage of users' sensitive personal information. It also ensures that user data is not lost even after the enterprise goes bankrupt, thereby protecting users' personal information security and national security.

[0084] This invention also provides a computer device; please refer to [link / reference]. Figure 8 , Figure 8 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 8 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 8 Take a processor 10 as an example.

[0085] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GPA), or any combination thereof.

[0086] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.

[0087] The memory 20 can include a program storage area and a data storage area, where the program storage area can store an operating system, application programs required by at least one function, and the data storage area can store data created according to the use of the computer device, etc. In addition, the memory 20 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some optional embodiments, the memory 20 can optionally include a memory disposed remotely with respect to the processor 10, which can be connected to the computer device through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0088] The memory 20 can include a volatile memory, such as a random access memory; the memory can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid-state disk; and the memory 20 can also include a combination of the above-mentioned kinds of memories.

[0089] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30, and the output device 40 can be connected through a bus or other means, Figure 8 For example, by way of example, through a bus connection.

[0090] The input device 30 can receive inputted digital or character information, and generate key signal inputs related to the user settings and function controls of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes, but is not limited to, a liquid crystal display, a light-emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0091] The embodiments of the present application further provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium through network, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.

[0092] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, through the operation of the computer, the method and / or technical solutions according to the present application can be called or provided. Those skilled in the art should understand that the form of computer program instructions in a computer readable medium includes but is not limited to source files, executable files, installation package files, etc. Correspondingly, the way of executing computer program instructions by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.

[0093] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.

Claims

1. A data protection method, characterized by, The method is applied to a third-party resource pool, and the method comprises: Acquiring terminal data collected and uploaded by a terminal and storing the terminal data to a preset IP address; In response to a data uploading request of an enterprise end, acquiring a data processing platform uploaded by the enterprise end through a data exchange gateway, wherein the data exchange gateway comprises a data gateway server and a data gateway client; In response to a data processing request of the enterprise end, transmitting a desktop picture to the enterprise end by using a console to enable the enterprise end to access the data processing platform through the desktop picture, read the terminal data through the data processing platform, process the terminal data, and obtain a target processing result corresponding to the terminal data; the console comprises a console client and a console server, and the transmitting of the desktop picture to the enterprise end by using the console comprises: Logging in the enterprise end to the console server through the console client; Transmitting the data processing platform and a desktop picture corresponding to a process of processing the terminal data by the data processing platform back to the console client by using the console server; Transmitting the desktop picture to the enterprise end through the console client; Making the desktop picture into a desktop video file and storing the desktop video file to the console server by using the console server; Filtering the target processing result by using a data scanning system and pushing the filtered target processing result to the terminal.

2. The method of claim 1, wherein, The data gateway server is provided with an external network interface and an internal network interface, and the acquiring of the data processing platform uploaded by the enterprise end through the data exchange gateway comprises: When detecting that the enterprise end accesses the data gateway server from the external network interface through the data gateway client, providing a function of writing data to the data gateway server for the enterprise end; When detecting that the enterprise end accesses the data gateway server from the internal network interface through the data gateway client, providing a function of reading data from the data gateway server for the enterprise end.

3. A data protection method, characterized by, The method is applied to an enterprise end, and the method comprises: Sending a data uploading request to a third-party resource pool and sending a data processing platform to the third-party resource pool through a data exchange gateway, wherein the data exchange gateway comprises a data gateway server and a data gateway client; Sending a data processing request to the third-party resource pool, accessing the data processing platform by using a desktop picture transmitted by a console, reading terminal data through the data processing platform, processing the terminal data, obtaining a target processing result corresponding to the terminal data, and filtering the target processing result by using a data scanning system of the third-party resource pool and pushing the filtered target processing result to a terminal; the console comprises a console client and a console server, and the accessing of the data processing platform by using the desktop picture transmitted by the console comprises: logging in the enterprise end to the console server through the console client; The operation station server transmits the desktop picture corresponding to the data processing platform and the process of processing the terminal data to the operation station client; The operation station client transmits the desktop picture to the enterprise end; The operation station server stores the desktop picture as a desktop video file and stores the desktop video file in the operation station server.

4. A data protection method, characterized by, The method applied to a terminal comprises: Collecting terminal data and uploading the terminal data to a third-party resource pool at a preset IP address based on a preset access control strategy; Receiving a filtered target processing result corresponding to the terminal data, wherein the filtered target processing result is obtained by a data exchange gateway in response to a data upload request of an enterprise end, the data exchange gateway comprising a data gateway server and a data gateway client; in response to a data processing request of the enterprise end, a desktop picture is transmitted to the enterprise end by an operation station, the operation station comprising an operation station client and an operation station server, the enterprise end logs in the server through the client, the server transmits a data processing platform and a desktop picture of a processing process to the client, and then the client transmits the desktop picture to the enterprise end, and the server stores the desktop picture as a desktop video file; the terminal data is read by the data processing platform, the terminal data is processed to obtain a target processing result corresponding to the terminal data, and the target processing result is filtered by a data scanning system of the third-party resource pool and pushed to the terminal as a filtered target processing result.

5. A data protection system, characterized by The system comprises a terminal, an enterprise end and a third-party resource pool, and is used to execute the data protection method in any one of claims 1 to 4.

6. A computer device, comprising: The system comprises: A memory and a processor, which are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to execute the data protection method in any one of claims 1 to 4.

7. A computer readable storage medium characterized by The computer readable storage medium stores computer instructions for making a computer execute the data protection method in any one of claims 1 to 4.

8. A computer program product, characterised in that, The computer instructions are used to make a computer execute the data protection method in any one of claims 1 to 4.

Citation Information

Patent Citations

  • System and method for security management

    CN104618313A

  • Data processing method, resource pool platform, system, equipment, medium and product

    CN117742828A