Multi-environment data protection method and device based on security sandbox and storage medium
By introducing a multi-environment data protection method with a secure sandbox in the data processing system, the problem of low data security in a single environmental data isolation method is solved, and the security isolation and access control of data between different environments is realized, which significantly improves the security of data.
Patent Information
- Application Number
- CN202510487536.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, data isolation methods in a single environment lead to low data security and cannot effectively prevent improper flow and leakage of data between different environments.
The multi-environment data protection method based on a secure sandbox is adopted. By receiving data with classification identification, it is stored in multiple operating environment spaces in the sandbox space, and the corresponding operating environment space and access rights of the data operation request are determined based on the role identification of the operation subject, ensuring that only the authorized operation subject can access data in a specific environment.
Through multi-environment isolation and fine-grained access permission management, the improper flow of data between different environments is effectively prevented, the risk of data leakage is reduced, and the security of data is significantly enhanced.
Smart Images

Figure CN120012165A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a multi-environment data protection method, device and storage medium based on a security sandbox. Background Art
[0002] In today's digital age, data has become a core asset for enterprises and organizations. With the continuous expansion and innovation of business, data processing needs are becoming increasingly complex, covering multiple links such as development, testing, and production. In the process of promoting data development and utilization, relevant units, enterprises and other institutions are faced with the challenge of how to achieve efficient sharing and utilization of data while ensuring data security and privacy. For example, in smart city projects, companies hope to open public data such as traffic flow data and air quality data to the outside world so that third-party institutions such as scientific research institutions and enterprises can develop new services or products based on these data, but these data often contain sensitive information, such as personal location data, which requires ensuring data security while sharing data.
[0003] Currently, the data processing and security management fields usually provide data access and processing functions in an isolated environment. Although this method can protect data security to a certain extent, in actual business scenarios, data processing often needs to span multiple environments such as development, testing, and operations. Each environment has different requirements for data security, availability, and access rights. Data processing in a single environment may increase the risk of data leakage due to lack of sufficient isolation, and data security is not high enough.
[0004] The above contents are only used to assist in understanding the technical solution of the present application and do not constitute an admission that the above contents are prior art. Summary of the invention
[0005] The main purpose of this application is to provide an invention title, which aims to solve the technical problem of low data security in the current data isolation method in a single environment.
[0006] To achieve the above objectives, the present application proposes a multi-environment data protection method based on a security sandbox, the method comprising: Receiving data with a classification identifier, wherein the classification identifier is used to determine a sandbox space location where the data is located; Based on the classification identifier, storing the data in a plurality of operating environment spaces in a sandbox space; When receiving a data operation request sent by an operation subject, determining the operation environment space corresponding to the data operation request and the first data access permission of the operation subject according to the role identification of the operation subject; Based on the operation environment space corresponding to the data operation request and the first data access permission, the data in the sandbox space is sent to the operation subject.
[0007] In one embodiment, the classification identifier includes a tenant identifier, a project identifier and an environment identifier, the sandbox space includes at least one tenant space, the tenant space includes at least one project space, and the project space includes at least one operating environment space.
[0008] In one embodiment, the step of storing the data in a plurality of operating environment spaces in a sandbox space based on the classification identifier comprises: Based on the tenant identifier, determine the tenant space location where the data is located; Based on the project identifier, determining the project space location of the data; Based on the environment identifier, determining the operating environment space where the data is located; The data is stored in the operating environment space.
[0009] In one embodiment, the step of storing the data in the operating environment space includes: obtaining the sensitivity level of said data; Obtaining a second data access permission corresponding to the operating environment space, where the second data access permission is used to determine data in the operating environment space that needs to be desensitized; Based on the second data access permission and the sensitivity level of the data, the data is stored in the operating environment space.
[0010] In one embodiment, the step of storing the data in the operating environment space based on the second data access permission and the sensitivity level of the data includes: Based on the second data access permission, determine the desensitized data level corresponding to the operating environment space; If the sensitivity level of the data is greater than or equal to the desensitized data level, the data is desensitized and stored in the operating environment space; If the sensitivity level of the data is lower than the level of the desensitized data, the data is directly stored in the operating environment space.
[0011] In one embodiment, the first data access permission includes an operating environment permission list and / or a data field permission list, and the step of sending the data in the sandbox space to the operating subject based on the operating environment space corresponding to the data operation request and the first data access permission includes: If the operating environment space corresponding to the data operation request is in the operating environment permission list, then sending the data in the corresponding operating environment space in the sandbox space to the operating subject; and / or Obtaining the query field corresponding to the data operation request; If the query field is in the data field permission list, target data is determined in the operating environment space based on the query field, and the target data is sent to the operating subject.
[0012] In one embodiment, the operating environment space includes a computing work model, and the computing work model is used to execute the data operation request in the operating environment space. The method further includes: Based on the code instructions input by the user, the computing working model is created in the target operating environment space; If the operating environment space corresponding to the data operation request is the target operating environment space, executing the data operation request based on the computing work model; If the operating environment space corresponding to the data operation request is not the target operating environment space, synchronizing the computing work model to the operating environment space corresponding to the data operation request; The step of executing the data operation request based on the computing work model is performed.
[0013] In one embodiment, the method further comprises: Obtain the storage period of the data; If the storage time of the data is equal to the storage period and the data is not accessed within the storage period, the data is deleted from the sandbox space.
[0014] In addition, to achieve the above-mentioned objectives, the present application also proposes a multi-environment data protection device based on a security sandbox, the device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the multi-environment data protection method based on a security sandbox as described above.
[0015] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the multi-environment data protection method based on the security sandbox as described above are implemented.
[0016] The present application provides a multi-environment data protection method based on a security sandbox, which first receives data with a classification identifier, and based on the classification identifier, stores the data in a corresponding operating environment space in the sandbox space. When a data operation request sent by an operating subject is received, the operating environment space corresponding to the data operation request and the first data access permission of the operating subject are determined according to the role identifier of the operating subject, and then, based on the operating environment space corresponding to the data operation request and the first data access permission, the data in the sandbox space is sent to the operating subject. The above method effectively prevents the improper flow of data between different environments and reduces the risk of data leakage by storing data in multiple isolated operating environment spaces, and ensures that only authorized operating subjects can access data in a specific environment through fine-grained management of role identifiers and access permissions, further enhancing data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0018] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0019] Figure 1 A flowchart of a first embodiment of a multi-environment data protection method based on a security sandbox of the present application is provided; Figure 2 A schematic diagram of the sandbox space involved in the multi-environment data protection method based on a security sandbox in an embodiment of the present application; Figure 3 A flowchart of the second embodiment of the multi-environment data protection method based on a security sandbox of the present application is provided; Figure 4 A flowchart of the third embodiment of the multi-environment data protection method based on the security sandbox of the present application is provided; Figure 5 A flowchart diagram of Embodiment 4 of the multi-environment data protection method based on a security sandbox of the present application is provided; Figure 6 Schematic diagram of the device structure of the hardware operating environment involved in the multi-environment data protection method based on the security sandbox in the embodiment of the present application.
[0020] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0021] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0022] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0023] In today's digital age, data has become a core asset for enterprises and organizations. With the continuous expansion and innovation of business, data processing needs are becoming increasingly complex, covering multiple links such as development, testing, and production. In the process of promoting data development and utilization, relevant units, enterprises and other institutions are faced with the challenge of how to achieve efficient sharing and utilization of data while ensuring data security and privacy. For example, in smart city projects, companies hope to open public data such as traffic flow data and air quality data to the outside world so that third-party institutions such as scientific research institutions and enterprises can develop new services or products based on these data, but these data often contain sensitive information, such as personal location data, which requires ensuring data security while sharing data.
[0024] Currently, the data processing and security management fields usually provide data access and processing functions in an isolated environment. Although this method can protect data security to a certain extent, in actual business scenarios, data processing often needs to span multiple environments such as development, testing, and operations. Each environment has different requirements for data security, availability, and access rights. Data processing in a single environment may increase the risk of data leakage due to lack of sufficient isolation, and data security is not high enough.
[0025] In view of the above problems, this application proposes a multi-environment data protection method based on a security sandbox, which first receives data with a classification identifier, and based on the classification identifier, stores the data in the corresponding operating environment space in the sandbox space. When a data operation request sent by an operating subject is received, the operating environment space corresponding to the data operation request and the first data access permission of the operating subject are determined according to the role identifier of the operating subject; then, based on the operating environment space corresponding to the data operation request and the first data access permission, the data in the sandbox space is sent to the operating subject. The above method effectively prevents the improper flow of data between different environments and reduces the risk of data leakage by storing data in multiple isolated operating environment spaces, and ensures that only authorized operating subjects can access data in a specific environment through fine-grained management of role identifiers and access permissions, further enhancing data security.
[0026] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, etc., or an electronic device capable of realizing the above functions, a data processing system, etc. The following takes a data processing system based on a security sandbox as an example to illustrate this embodiment and the following embodiments.
[0027] Based on this, the first embodiment proposed in this application provides a multi-environment data protection method based on a security sandbox, referring to Figure 1 In this embodiment, the multi-environment data protection method based on the security sandbox includes steps S10 to S40: Step S10, receiving data with a classification identifier, where the classification identifier is used to determine the sandbox space location of the data.
[0028] Step S20: based on the classification identifier, store the data into a plurality of operating environment spaces in the sandbox space.
[0029] It is understandable that in actual business scenarios, data processing often needs to span multiple environments such as development, testing, and production, and each environment has different requirements for data security, availability, and access rights. For example, in the public data openness and public data authorization operation scenarios, the development team needs to develop data models in the development environment, but should not access production data, while the operation team is responsible for the operation and maintenance of the production environment; in the development environment, developers may need to modify and debug data, while in the test environment, testers may only need to access data for testing and verification. This requires the data processing system to be able to achieve effective isolation and secure access to data in different environments.
[0030] It should be noted that, in this embodiment, the sandbox space is a logically isolated area for storing and processing specific types of data. Each sandbox space can contain multiple operating environment spaces, such as a development environment, a test environment, a production environment, etc. After the data is stored in a designated operating environment space, it can only be accessed and processed in the space, ensuring the isolation and security of the data.
[0031] When data is input into a data processing system, it is accompanied by one or more classification identifiers, which are used to determine the location of the sandbox space where the data is located, that is, in which operating environment space in the sandbox the data should be stored. Classification identifiers can be generated in a variety of ways, such as automatic classification based on data sources, types, sensitivity and other attributes, or manually specified by the data provider.
[0032] In an optional implementation, a correspondence table between classification identifiers and operating environment spaces is established in a data processing system. When the data processing system receives data, it first classifies the data based on its attributes to generate a classification identifier, and then determines the operating environment space corresponding to the data based on the correspondence table between the classification identifier and the operating environment space.
[0033] Optionally, through machine learning or rule engine algorithms, data is automatically classified and classified according to attributes such as source, type, sensitivity, etc., and classification identifiers are generated. Based on a preset correspondence table between classification identifiers and operating environment spaces, the classified data is stored in multiple operating environment spaces.
[0034] Exemplarily, the data processing system collects data from various data sources such as business systems, government databases, and social public data sources through a preset application programming interface (API). Afterwards, the collected data is preprocessed, including cleaning and formatting, to ensure the consistency and processability of the data. Then, key features are extracted from the data using techniques such as machine learning or rule engines, including data sources, data types such as numeric, text, image, etc., and data sensitivity such as "public", "internal", "confidential", etc. Based on the extracted key features, classification algorithms such as decision trees, support vector machines, neural networks, etc. are used to automatically classify the data and generate corresponding classification identifiers. For example, suppose there is a smart city project that needs to collect traffic data from multiple data sources, including traffic flow, vehicle type, vehicle speed, etc. These data come from different sensors and business systems and have different sensitivities and importance. Through the automatic classification system, data can be automatically classified into categories such as "traffic flow data-public", "vehicle type data-internal", etc., and corresponding classification identifiers are generated based on the source of the data, such as which sensor or business system it comes from, the type such as numeric data, and the sensitivity such as public data. After the classification identifier is generated, the data is stored in the corresponding operating environment space according to the preset correspondence table between the classification identifier and the operating environment space, wherein the correspondence table records in which operating environment space each classification identifier should be stored, as well as related storage configuration information.
[0035] Optionally, the data processing system provides a data submission interface, where a data provider uploads data and manually specifies a classification identifier, and then stores the classified data in multiple operating environment spaces based on a preset correspondence table between the classification identifier and the operating environment space.
[0036] In the above implementation, the data processing system achieves accurate classification and storage of data by establishing a correspondence table between classification identifiers and operating environment spaces. When the data processing system receives data, it first automatically classifies the data based on its attributes, such as source, type, sensitivity, etc., using machine learning or rule engine algorithms, and generates classification identifiers. Based on the preset correspondence table between classification identifiers and operating environment spaces, the classified data is stored in multiple operating environment spaces, ensuring that the data can be stored in the most appropriate operating environment space, enhancing the security and isolation of the data, and effectively preventing data leakage and misuse.
[0037] In another possible implementation, if Figure 2 As shown, the classification identifier includes a tenant identifier, a project identifier and an environment identifier, the sandbox space includes at least one tenant space, the tenant space includes at least one project space, and the project space includes at least one operating environment space. Step S20 includes steps S21 to S24: Step S21: determining the tenant space location of the data based on the tenant identifier.
[0038] In a multi-tenant data processing system, each tenant has its own data and configuration, and the tenant identifier is used to distinguish these different tenants. The tenant space is an area allocated to a specific tenant in the sandbox space, which is used to store all the data and configuration of the tenant. When the multi-tenant data processing system receives data, it first parses the tenant identifier in the data, and searches for the corresponding tenant space in the tenant list of the sandbox space according to the tenant identifier. If a matching tenant space is found, proceed to the subsequent steps; if not found, it is processed according to the preset strategy, such as creating a new tenant space or prompting an alarm message.
[0039] Step S22: determining the project space location of the data based on the project identifier.
[0040] In a multi-tenant environment, the data and applications of different tenants need to be isolated from each other to ensure data security and privacy. By setting up multiple project spaces under the tenant space, the granularity of resource isolation can be further refined so that resources between different types of projects do not interfere with each other, improving the stability and security of the data processing system. Among them, in the tenant space, there is at least one project space, and each project space has its own data and configuration. In each tenant space, a project space is allocated to a specific project to store all data and configurations of the project.
[0041] For example, according to the project identifier, the corresponding project space is searched in the project list in the tenant space. If a matching project space is found, the subsequent steps are entered; if not found, the process is processed according to the preset strategy, such as creating a new project space or prompting an alarm message.
[0042] Step S23: determining the operating environment space where the data is located based on the environment identifier.
[0043] Different environment spaces are set up under the project space to meet the diverse needs during project development and deployment, to ensure that the project can be fully tested and verified at different stages, and ultimately delivered to customers in a stable and secure manner.
[0044] For example, Figure 2 As shown, the sandbox space includes "tenant space 1" and "tenant space 2", and tenant space 1 includes "project space A" and "project space B". Three operating environment spaces are set under each project space, namely "development environment", "test environment" and "production environment". The development environment is the environment used by developers to write, debug and test code. The test environment is used to test the developed product. The production environment is the environment where the developed product actually runs, also known as the online environment, which includes all components and services actually used by users, and processes actual data and business logic. For example, the production environment may contain the personal privacy information of users who are authorized to obtain, and this privacy information needs to be kept confidential during the development stage and cannot be read by developers. Therefore, it is necessary to isolate the data in the project space according to different operating environments. In addition to the above three operating environments, other operating environments can also be created in the project space, such as a demonstration environment for showing software functions to customers or stakeholders. The environment can include the latest version of the software and some key functions, which are used to interact with specific users and only allow specific users to access.
[0045] Alternatively, if Figure 2 As shown, in the physical environment of the sandbox, the same operating environment spaces in different tenant spaces can be aggregated into the same cluster. For example, the data in the development environment of all tenants is stored in the development cluster in the physical environment, the data in the test environment of all tenants is stored in the test cluster in the physical environment, and the data in the production environment of all tenants is stored in the production cluster in the physical environment.
[0046] Exemplarily, the development cluster includes a "development database instance", a "development file storage instance", and a "development computing cluster instance". The "development database instance" includes "data A1-1" of project A and "data B1-1" of project B; the "development file storage instance" includes "data A1-2" of project A and "data B1-2" of project B; the "development computing cluster instance" includes "data A1-3" of project A and "data B1-3" of project B. The test cluster includes a "test database instance", a "test file storage instance", and a "test computing cluster instance". The "test database instance" includes "data A2-1" of project A and "data B2-1" of project B; the "test file storage instance" includes "data A2-2" of project A and "data B2-2" of project B; the "test computing cluster instance" includes "data A2-3" of project A and "data B2-3" of project B.
[0047] Optionally, an exclusive cluster can be created in the sandbox physical environment according to the specific requirements of the tenant to store specific data separately. Figure 2 As shown, the production cluster includes "production database instance", "production file storage instance" and "production computing cluster instance". The "production database instance" includes "data A3-1" of project A; the "production file storage instance" includes "data A3-2" of project A; and the "production computing cluster instance" includes "data A3-3" of project A. The data in the production environment of project B is stored in the exclusive cluster.
[0048] Step S24, storing the data in the operating environment space.
[0049] Optionally, in the physical environment where the sandbox space is actually stored, the same operating environment space in different project spaces of the cluster is stored as an operating environment cluster. The data between different operating environment clusters is stored in physical isolation. Within the operating environment cluster, data from different project spaces is stored in logical isolation. Among them, logical isolation is mainly achieved through software or configuration, and resource isolation is performed using technical means such as virtualization and containerization. For example, virtualization technology can run multiple independent operating system instances or containers on the same physical machine, thereby achieving logical isolation. Physical isolation is achieved through hardware or physical devices, using independent servers, network devices, etc. for resource isolation.
[0050] In the above implementation, the data processing system adopts a hierarchical multi-environment isolation architecture, and subdivides the sandbox space into tenant space, project space, and operating environment space through tenant identification, project identification, and environment identification. After the data processing system receives the data, it first locates the tenant space based on the tenant identification, then determines the project space based on the project identification, and finally finds the corresponding operating environment space based on the environment identification. If no matching space is found in any step, it is processed according to the preset strategy. This hierarchical multi-environment isolation method not only improves the sophistication and efficiency of data management, but also effectively prevents data leakage and misuse, ensures the stable operation of the project at all stages, provides strong support for multi-tenant data processing, and enhances the overall stability and security of the data processing system.
[0051] Step S30: When a data operation request sent by an operation subject is received, the operation environment space corresponding to the data operation request and the first data access permission of the operation subject are determined according to the role identification of the operation subject.
[0052] It should be noted that the operating subject refers to the entity that initiates the data operation request, including users, applications, services or other system components. Data operation requests include data access, modification, deletion and other operation requests. The first data access right is the data access right authorized by the operating subject in the operating environment space, including read, write, delete, etc.
[0053] Exemplarily, the role identification of the operating subject is used to identify the identity and authority of the operating subject, and can be determined based on the attribute information of the operating subject, such as user type (such as internal employee, external partner), department (such as finance department, marketing department), position (such as data analyst, product manager), user account, etc. When the data processing system receives a data operation request from the operating subject, it will load the predefined access control rules or permission configuration from the configuration file, database or memory cache, and search for the permission entry that matches the role identification of the operating subject in the predefined rules or configuration to find the corresponding permission set. The permission set includes read permission, write permission, execute permission, etc. According to the matching results, the first data access permission of the operating subject in different operating environment spaces is determined, and the data access permission includes the reading range of the data, write permission, delete permission, permission to perform specific operations, etc.
[0054] Step S40: sending the data in the sandbox space to the operation subject based on the operation environment space corresponding to the data operation request and the first data access permission.
[0055] Optionally, the first data access permission includes an operating environment permission list. If the operating environment space corresponding to the data operation request is in the operating environment permission list, the data in the corresponding operating environment space in the sandbox space is sent to the operating subject. Specifically, the operating environment permission list, as a component of the first data access permission, lists all operating environment spaces that the operating subject has the right to access. After receiving the data operation request, the data processing system parses the operating environment space information in the request, compares the parsed operating environment space with the operating environment permission list in the first data access permission, and when the operating environment space corresponding to the data operation request is in the operating environment permission list, the corresponding data is extracted from the sandbox space and sent to the operating subject so that it can perform further data operations or analysis.
[0056] Optionally, the first data access permission includes a data field permission list. After receiving the data operation request sent by the operation subject, the data processing system obtains the query field corresponding to the data operation request. If the query field is in the data field permission list, the target data is determined in the operation environment space based on the query field, and the target data is sent to the operation subject.
[0057] Exemplarily, a query statement corresponding to a data operation request is obtained, and the query statement contains fields corresponding to the query request, such as "SELECT phone number FROM user table". After receiving the above query field, the data processing system will make a judgment based on the query field "phone number" and the data field permission list corresponding to the operating subject to confirm whether the operating subject can obtain the queried data. For example, the operating subject is first authenticated, and the true identity and legal authorization of the operating subject are ensured by checking the user name and password, digital certificate, two-factor authentication, etc., to prevent unauthorized users from impersonating their identities. After the authentication is passed, the data processing system checks whether the "phone number" field is within its readable permission range based on the data field permission list corresponding to the operating subject. For example, the data field permission list of the developer does not include the read permission of the real phone number, while the operator can obtain the read permission of the real phone number in the data field permission list if the user is authorized.
[0058] Optionally, the first data access permission includes an operating environment permission list and a data field permission list. After receiving the data operation request sent by the operating subject, the data processing system first parses the operating environment space information in the request, determines that the operating environment space is within the operating environment permission list in the first data access permission, and then determines whether the query field corresponding to the data operation request is within the data field permission list in the first data access permission. If so, the target data is determined according to the query field and the target data is sent to the operating subject.
[0059] It should be noted that in this embodiment, the data in the sandbox space sent to the operating entity are read and stored after the user's explicit authorization and in compliance with the user agreement through a compliant process.
[0060] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can refer to the above introduction, and will not be repeated later. Figure 3 , step S24 includes steps S241 to S243: Step S241, obtaining the sensitivity level of the data.
[0061] Sensitivity level is a grade label assigned to data based on factors such as the importance, confidentiality, and privacy of the data, which is used to identify the sensitivity of the data. The sensitivity level of data is usually divided into multiple levels, such as public level, internal level, confidential level, top secret level, etc. Different levels of data require different protection measures. For example, a customer's personal information may be classified as confidential data, while a company's public report may be classified as public data. Exemplarily, a hierarchical model is created to classify data into different sensitivity levels and set labels through rule pattern matching.
[0062] Step S242: Obtain a second data access permission corresponding to the operating environment space, where the second data access permission is used to determine the data in the operating environment space that needs to be desensitized.
[0063] The second access right is the data access rule defined in the operating environment space. For example, the second data access right of operating environment space A indicates that all data in operating environment space A can be directly read. The second data access right of operating environment B indicates that among the data in operating environment space B, the "confidential level" and "top secret level" data need to be desensitized, and the data of other levels can be directly read.
[0064] Step S243: based on the second data access permission and the sensitivity level of the data, storing the data into the operating environment space.
[0065] Optionally, step S243 also includes steps S2431 and S2432: Step S2431: Determine the desensitized data level corresponding to the operating environment space based on the second data access permission.
[0066] Step S2432: If the sensitivity level of the data is greater than or equal to the desensitized data level, the data is desensitized and stored in the operating environment space.
[0067] Step S2433: if the sensitivity level of the data is lower than the level of the desensitized data, the data is directly stored in the operating environment space.
[0068] Before storing data, the data processing system will perform security checks and preprocessing based on the sensitivity level of the data and the second data access permission of the operating environment space. If the sensitivity level of the data exceeds the maximum sensitivity level allowed by the operating environment space, the data processing system will reject the storage request or perform desensitization processing. If the sensitivity level of the data matches the second data access permission of the operating environment space, it will be securely stored in the specified operating environment space.
[0069] Optionally, data can be desensitized by mask replacement. For example, when displaying a credit card number, the first six digits and the last four digits are retained, and the middle part is replaced with asterisks or other characters. Alternatively, sensitive data can be encoded using complex mathematical algorithms, such as symmetric encryption, asymmetric encryption, and hash functions to encrypt data. Specific data desensitization methods can be specified in the second data access rights of different operating environment spaces. It should be noted that the credit card number cited in this example is also read and stored by the data processing system after the user's explicit authorization and in compliance with the user agreement.
[0070] Exemplarily, it is assumed that there is a tenant space in the sandbox space of the data processing system, and there is a project space in the tenant space. There are three operating environment spaces in the project space, namely, "development environment", "test environment" and "production environment". When the data processing system receives a batch of historical operating data, it is necessary to store the above operating data in the sandbox space. If the production environment is set to be directly readable, the operating data is directly stored in the production environment; if the test environment is set to be directly readable, the operating data can be sampled and directly stored in the test environment; if the development environment is set to be not directly readable, the sampled data in the test environment can be desensitized and then stored in the development environment according to the second data access permission of the development environment. When the operating subject sends a data operation request to the data processing system, the data in a specific operating environment space is accessed according to the first data access permission of the operating subject. For example, developers can only access data in the development environment, testers can only access data in the test environment, and operators can only access data in the production environment.
[0071] In this embodiment, the data processing system will first classify the data into different sensitivity levels and set labels through the hierarchical model and rule pattern matching. Then, according to the second data access permission of the operating environment space, the data level that needs to be desensitized in the space is determined. If the sensitivity level of the data is greater than or equal to the desensitized data level, the system will desensitize the data, thereby ensuring data security and privacy while meeting data usage requirements in different operating environments. At the same time, by limiting the access rights of the operating subject, the security and isolation of the data are further enhanced, effectively preventing data leakage and misuse, and providing a more sophisticated and effective security management mechanism for multi-environment data processing.
[0072] Based on the above embodiments of the present application, in the third embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above description, and no further description will be given later. On this basis, the operating environment space includes a computing work model, and the computing work model is used to execute the data operation request in the operating environment space. Please refer to Figure 4 The multi-environment data protection method based on the security sandbox further includes steps S50 to S80: Step S50: creating the computing work model in the target operating environment space based on the code instructions input by the user.
[0073] In this embodiment, the data processing system can adopt the underlying technology of the big data ecosystem and provide an offline computing framework in the sandbox space through an open architecture such as Apache Hadoop. Users can write scripts by entering code instructions through the editing interface or command line, specifying the creation process and parameters of the computing work model, and the data processing system executes the script to complete the creation of the computing work model. Third-party users can perform data analysis and processing through computing tool models in a specific sandbox without moving the data out of the sandbox to ensure data security. However, third parties need to operate through the specific application programming interface provided by the sandbox to ensure that the data is not illegally copied or exported.
[0074] Step S60: If the operating environment space corresponding to the data operation request is the target operating environment space, the data operation request is executed based on the computing work model.
[0075] Exemplarily, if the data processing system receives a data operation request, it reads the operating environment space corresponding to the data operation request. If there is already a computing work model in the operating environment space, it directly uses the computing work model to execute the data operation request.
[0076] Step S70: If the operating environment space corresponding to the data operation request is not the target operating environment space, the computing work model is synchronized to the operating environment space corresponding to the data operation request.
[0077] Step S80, executing the step of executing the data operation request based on the computing work model.
[0078] If there is no computing work model in the operating environment space corresponding to the data operation request, and there is an available working computing model in other operating environment spaces, the working computing model is synchronized to the operating environment space corresponding to the data operation request. In the synchronization process, only the working computing model is synchronized, that is, the operation logic of the working computing model is migrated. The same working computing model processes different data in different operating environment spaces.
[0079] Optionally, the computing work model and its dependent environment are packaged into a container image, and the packaged container image is transferred to the target operating environment space through a container image repository or direct file transfer. In the target operating environment space, the container image is deployed using a container orchestration tool or manually, thereby instantiating the computing work model and achieving synchronization of the computing work model.
[0080] Optionally, virtualization software and virtual machines are configured in the source operating environment space and the target operating environment space, respectively. The virtual machine provides an isolated computing environment to ensure the independence of the model in different spaces. In the source operating environment space, the computing work model and its dependencies are exported as an importable format file. Then, in the target operating environment space, the virtualization software is used to import the above file, thereby instantiating the computing work model and realizing the synchronization of the computing work model.
[0081] For example, refer to Figure 2 In project space A, developers can develop computing work models in the "development environment" and synchronize the computing work models to the "test environment" when testing is needed. When the computing work models are put into formal use, they will be synchronized to the "production environment".
[0082] In this embodiment, the data processing system introduces a computing work model in the operating environment space for executing data operation requests. Users can create a computing work model in the target operating environment space by inputting code instructions. When a data operation request is received, the data processing system will check whether a computing work model already exists in the operating environment space corresponding to the request. If it exists, the model is used directly to execute the request; if it does not exist, the computing work model is synchronized to the corresponding operating environment space, and only the operation logic of the model is migrated to ensure that the same model processes different data in different environments. This realizes the flexible synchronization and deployment of computing work models between different operating environment spaces, and improves the efficiency and flexibility of data processing.
[0083] Based on the above embodiments of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction, and will not be described in detail later. Figure 5 The multi-environment data protection method based on the security sandbox also includes steps S90 to S100: Step S90, obtaining the storage period of the data.
[0084] The storage period may be a predefined fixed time or a fixed time set according to different types of data. For example, a corresponding storage period correspondence table is set based on the classification identification or sensitivity level of the data, and the storage period correspondence table is saved in the data processing system. The data processing system can determine the storage period of the data by reading the storage period correspondence table.
[0085] Step S100: If the storage time of the data is equal to the storage period, and the data has not been accessed within the storage period, the data is deleted from the sandbox space.
[0086] For example, the data processing system can check the storage time and access record of each data periodically or in real time. If the storage time of a certain data is equal to its storage period and it has not been accessed within the period, the deletion operation is triggered. The deletion operation can be physical deletion, that is, completely deleting from the storage medium, or logical deletion, that is, marking the data as deleted, but actually still retaining it on the storage medium, but no longer visible to the outside.
[0087] An audit module can also be set up in the data processing system. During the access process, the audit module records the operating behavior of the operator, regularly reviews whether the user's operations are compliant, whether the data is secretly operated, and records them. In addition, the lifecycle management module regularly cleans and destroys expired data and cold data that has not been used for a set period to avoid excessive retention of data, reduce storage costs and potential security risks.
[0088] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the multi-environment data protection method based on the security sandbox of the present application. More simple transformations based on this technical concept are all within the protection scope of the present application.
[0089] The present application provides a multi-environment data protection device based on a security sandbox, and the multi-environment data protection device based on a security sandbox includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the multi-environment data protection method based on the security sandbox in the above-mentioned embodiment one.
[0090] Reference below Figure 6 , which shows a schematic diagram of the structure of a multi-environment data protection device based on a security sandbox suitable for implementing the embodiment of the present application. The multi-environment data protection device based on a security sandbox in the embodiment of the present application may include but is not limited to a mobile terminal such as a laptop computer and a fixed terminal such as a desktop computer. Figure 6 The multi-environment data protection device based on the security sandbox shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0091] like Figure 6 As shown, the multi-environment data protection device based on the security sandbox may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage device 1003 to the random access memory (RAM) 1004. In the random access memory 1004, various programs and data required for the operation of the multi-environment data protection device based on the security sandbox are also stored. The processing device 1001, the read-only memory 1002 and the random access memory 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 1003 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1009. The communication device 1009 can allow the multi-environment data protection device based on a security sandbox to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a multi-environment data protection device based on a security sandbox with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or have alternatively.
[0092] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0093] The multi-environment data protection device based on a security sandbox provided by the present application adopts the multi-environment data protection method based on a security sandbox in the above-mentioned embodiment, which can solve the technical problem of low data security in the current single-environment data isolation method. Compared with the prior art, the beneficial effects of the multi-environment data protection device based on a security sandbox provided by the present application are the same as the beneficial effects of the multi-environment data protection method based on a security sandbox provided by the above-mentioned embodiment, and the other technical features of the multi-environment data protection device based on a security sandbox are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0094] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0095] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0096] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the multi-environment data protection method based on the security sandbox in the above-mentioned embodiment.
[0097] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory (EPROM, Erasable Programmable ReadOnly Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM, CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, radio frequencies (RF, Radio Frequency), etc., or any suitable combination of the above.
[0098] The above-mentioned computer-readable storage medium may be included in a multi-environment data protection device based on a security sandbox; or may exist independently without being assembled into a multi-environment data protection device based on a security sandbox.
[0099] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by a multi-environment data protection device based on a security sandbox, the multi-environment data protection device based on a security sandbox can be written in one or more programming languages or a combination thereof to write computer program codes for performing the operations of the present application. The programming languages include object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, or as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0100] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0101] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0102] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned multi-environment data protection method based on a security sandbox, and can solve the technical problem of low data security in the current data isolation method for a single environment. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the multi-environment data protection method based on a security sandbox provided by the above-mentioned embodiment, and will not be repeated here.
[0103] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A multi-environment data protection method based on a security sandbox, characterized in that: The method comprises: Receiving data with a classification identifier, wherein the classification identifier is used to determine a sandbox space location where the data is located; Based on the classification identifier, storing the data in a plurality of operating environment spaces in a sandbox space; When receiving a data operation request sent by an operation subject, determining the operation environment space corresponding to the data operation request and the first data access permission of the operation subject according to the role identification of the operation subject; Based on the operation environment space corresponding to the data operation request and the first data access permission, the data in the sandbox space is sent to the operation subject.
2. The multi-environment data protection method based on security sandbox according to claim 1, characterized in that: The classification identifier includes a tenant identifier, a project identifier and an environment identifier. The sandbox space includes at least one tenant space, the tenant space includes at least one project space, and the project space includes at least one operating environment space.
3. The multi-environment data protection method based on security sandbox as claimed in claim 2, characterized in that: The step of storing the data in a plurality of operating environment spaces in the sandbox space based on the classification identifier comprises: Based on the tenant identifier, determine the tenant space location where the data is located; Based on the project identifier, determining the project spatial location of the data; Based on the environment identifier, determining the operating environment space where the data is located; The data is stored in the operating environment space.
4. The multi-environment data protection method based on security sandbox as claimed in claim 3, characterized in that: The step of storing the data in the operating environment space comprises: obtaining the sensitivity level of said data; Obtaining a second data access permission corresponding to the operating environment space, where the second data access permission is used to determine data in the operating environment space that needs to be desensitized; Based on the second data access permission and the sensitivity level of the data, the data is stored in the operating environment space.
5. The multi-environment data protection method based on security sandbox according to claim 4, characterized in that: The step of storing the data in the operating environment space based on the second data access permission and the sensitivity level of the data includes: Based on the second data access permission, determine the desensitized data level corresponding to the operating environment space; If the sensitivity level of the data is greater than or equal to the desensitized data level, the data is desensitized and stored in the operating environment space; If the sensitivity level of the data is lower than the level of the desensitized data, the data is directly stored in the operating environment space.
6. The multi-environment data protection method based on security sandbox according to claim 1, characterized in that: The first data access permission includes an operating environment permission list and / or a data field permission list, and the step of sending the data in the sandbox space to the operating subject based on the operating environment space corresponding to the data operation request and the first data access permission includes: If the operating environment space corresponding to the data operation request is in the operating environment permission list, then sending the data in the corresponding operating environment space in the sandbox space to the operating subject; and / or Obtaining the query field corresponding to the data operation request; If the query field is in the data field permission list, target data is determined in the operating environment space based on the query field, and the target data is sent to the operating subject.
7. The multi-environment data protection method based on a security sandbox according to any one of claims 1 to 6, characterized in that: The operating environment space includes a computing work model, and the computing work model is used to execute the data operation request in the operating environment space. The method further includes: Based on the code instructions input by the user, the computing working model is created in the target operating environment space; If the operating environment space corresponding to the data operation request is the target operating environment space, executing the data operation request based on the computing work model; If the operating environment space corresponding to the data operation request is not the target operating environment space, synchronizing the computing work model to the operating environment space corresponding to the data operation request; The step of executing the data operation request based on the computing work model is performed.
8. The multi-environment data protection method based on security sandbox according to claim 1, characterized in that: The method further comprises: Obtain the storage period of the data; If the storage time of the data is equal to the storage period and the data is not accessed within the storage period, the data is deleted from the sandbox space.
9. A multi-environment data protection device based on a security sandbox, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the multi-environment data protection method based on a security sandbox as described in any one of claims 1 to 8.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the multi-environment data protection method based on a security sandbox as described in any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Data access method and device
CN112163214A
Data model development platform
CN113468149A
Big data application development method and device, computer equipment and storage medium
CN114253514A
Data stream processing method and device, electronic equipment and readable storage medium
CN117240872A
Data processing method and device based on data sandbox, equipment and storage medium
CN117494106A