Safety data sharing and processing method and device based on Ukey, storage medium and electronic equipment
Through the secure data sharing and processing method based on Ukey, the problems of key management and access rights control during data sharing are solved, data security and user privacy are guaranteed, and flexible access control and efficient key management are provided.
Patent Information
- Application Number
- CN202510188429.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art is difficult to efficiently and securely manage keys and access rights during data sharing, resulting in difficult protection of data security and user privacy.
Using a secure data sharing and processing method based on Ukey, the data owner uses the first Ukey for data storage encryption, and the data user carries the public key of the second Ukey to apply for access data. After the access approval, a virtual machine is created in combination with the private key of the second Ukey and half of the key of the first Ukey to decrypt and obtain data.
Ensure the security of data during sharing and processing, protect user privacy, achieve flexible access control and efficient key management, and reduce data breaches and compliance risks.
Smart Images

Figure CN120046171A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data security processing. Specifically, it relates to a method, device, storage medium, and electronic device for secure data sharing and processing based on a Ukey. Background Art
[0002] With the development of artificial intelligence technology, a variety of different models have been developed to solve various problems. However, the model needs to be trained to ensure the accuracy of the results, so the security and privacy protection of data have received increasing attention. In the process of data sharing and processing, how to ensure the security of data and user privacy has become an important issue. In the existing technology, encryption means are usually used to protect data security, but in the process of data sharing, how to efficiently and securely manage keys and access permissions is still a challenge. Summary of the Invention
[0003] Embodiments of the present application provide a method, device, storage medium, and electronic device for secure data sharing and processing based on a Ukey to solve the technical problems existing in the prior art.
[0004] Other features and advantages of the present application will become apparent through the following detailed description, or will be partially learned through the practice of the present application.
[0005] According to the first aspect of the embodiments of the present application, a method for secure data sharing and processing based on a Ukey is provided, including:
[0006] The data owner uploads data through the first Ukey and performs storage encryption;
[0007] The data user applies for access to the data by carrying the public key of the second Ukey;
[0008] When the access request is approved, the data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey, and decrypts the data based on the virtual machine to obtain the data.
[0009] In some embodiments of the present application, based on the foregoing solution, the data owner uploads data through the first Ukey and performs storage encryption, including:
[0010] The data owner logs in to the system through the first Ukey and uploads the data to the NFS storage server;
[0011] The data owner encrypts the data using the public key of the first Ukey.
[0012] In some embodiments of the present application, based on the foregoing solution, when the access request is approved, the data user creates a virtual machine by combining the second Ukey and the first Ukey, including
[0013] The data owner approves the access request and, after approval, issues half of the key of the first Ukey to the data user;
[0014] The data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey.
[0015] In some embodiments of the present application, based on the foregoing solution, decrypting the data based on the virtual machine to obtain the data includes:
[0016] The NFS storage server mounts the encrypted data to the virtual machine;
[0017] The virtual machine decrypts the encrypted data by combining the private key of the second Ukey and half of the key of the first Ukey to obtain the data.
[0018] According to the second aspect of the embodiments of the present application, a secure data sharing and processing device based on Ukey is provided, including:
[0019] A first processing unit for the data owner to upload data through the first Ukey and perform storage encryption;
[0020] An access application unit for the data user to apply for accessing data with the public key of the second Ukey;
[0021] A creation unit for the data user to create a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey when the access request is approved;
[0022] A decryption unit for decrypting the data based on the virtual machine to obtain the data.
[0023] According to the third aspect of the embodiments of the present application, a computer-readable storage medium is provided. Computer instructions are stored in the storage medium, and when the computer instructions run on a computer, the computer is caused to execute the method as described in the first aspect.
[0024] According to the fourth aspect of the embodiments of the present application, an electronic device is provided, including: a memory and a processor;
[0025] The memory is used for storing computer instructions;
[0026] The processor is used for calling the computer instructions stored in the memory, so that the electronic device executes the method as described in the first aspect.
[0027] The technical solution of this application can ensure the security of data during sharing and processing, while protecting user privacy.
[0028] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application. Obviously, the drawings in the following description are only some embodiments of this application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts. In the drawings:
[0030] Figure 1 A schematic flowchart of a method for secure data sharing and processing based on a Ukey according to an embodiment of this application is shown;
[0031] Figure 2 A block diagram of a device for secure data sharing and processing based on a Ukey according to an embodiment of this application is shown;
[0032] Figure 3 A block diagram of an electronic device according to an embodiment of this application is shown;
[0033] Figure 4 A schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of this application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0035] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of this application. However, those skilled in the art will realize that this application can be practiced without one or more of the specific details, or can be implemented using other methods, components, devices, steps, etc. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of this application.
[0036] The block diagrams shown in the accompanying drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0037] The flowcharts shown in the accompanying drawings are only illustrative and not necessarily include all the content and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0038] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the objects used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described.
[0039] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0040] The following will describe in detail some embodiments of the present application in conjunction with the accompanying drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0041] See Figure 1 , which shows a schematic flowchart of a method for secure data sharing and processing based on a Ukey according to an embodiment of the present application.
[0042] As Figure 1 shown, a method for secure data sharing and processing based on a Ukey is shown, which specifically includes steps S100 to S400.
[0043] Refer to Figure 1 , step S100, the data owner uploads data through the first Ukey and performs storage encryption.
[0044] In some feasible embodiments, based on the foregoing solution, the data owner uploading data through the first Ukey and performing storage encryption includes:
[0045] The data owner logs in to the system through the first Ukey and uploads the data to the NFS storage server;
[0046] The data owner uses the public key of the first Ukey to encrypt the data.
[0047] It can be understood that encrypting the data can ensure the security of the data.
[0048] Continue to refer to Figure 1 , step S200, the data user applies for access to the data by carrying the public key of the second Ukey.
[0049] Exemplarily, the data user logs in to the system using the second Ukey and applies for access to the encrypted data by carrying the public key of the second Ukey.
[0050] Continue to refer to Figure 1 , step S300, when the access request is approved, the data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey.
[0051] In some feasible embodiments, based on the foregoing solution, when the access request is approved, the data user creates a virtual machine by combining the second Ukey and the first Ukey, including
[0052] The data owner approves the access request and, after approval, issues half of the key of the first Ukey to the data user;
[0053] The data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey.
[0054] Continue to refer to Figure 1 , step S400, decrypt the data based on the virtual machine to obtain the data.
[0055] In some feasible embodiments, based on the foregoing solution, the decrypting the data based on the virtual machine to obtain the data includes:
[0056] The NFS storage server mounts the encrypted data to the virtual machine;
[0057] The virtual machine decrypts the encrypted data by combining the private key of the second Ukey and half of the key of the first Ukey to obtain the data.
[0058] It can be understood that by using the virtual machine decryption method, the data user obtains the data, ensuring that the data user can use the data securely.
[0059] The method provided by the embodiments of the present application has the following advantages:
[0060] 1. Enhanced security: By using Ukeys for authentication and data encryption, this method provides stronger security for data sharing and processing. As a security token, the Ukey can effectively prevent unauthorized access and ensure that only legitimate users can access the data.
[0061] 2. Privacy protection: The encryption server encrypts the data, protecting the privacy of the data owners. Even if the data is stored on the NFS server, unauthorized users cannot read the original data, thus reducing the risk of data leakage.
[0062] 3. Flexible access control: The data owner can approve the access requests of data users. This fine-grained access control mechanism allows the data owner to precisely control who can access their data and when.
[0063] 4. Efficient key management: By distributing half of the key and combining it with the private key of the user's Ukey, this method achieves efficient key management. This approach not only simplifies the key distribution process but also ensures data security even in the event of key leakage.
[0064] 5. Compliance: With the increasing strictness of data protection regulations such as GDPR, this method helps organizations comply with relevant data protection regulations and reduce compliance risks.
[0065] In summary, this application provides a secure and flexible data sharing and processing method, which is particularly suitable for application scenarios that require high security and privacy protection, such as the management of military, medical, financial, and scientific research data.
[0066] The following introduces the device embodiments of this application, which can be used to execute a Ukey-based secure data sharing and processing method in the above embodiments of this application. For details not disclosed in the device embodiments of this application, please refer to the method embodiments of this application above.
[0067] Refer to Figure 2 As shown, a Ukey-based secure data sharing and processing device 200 according to an embodiment of this application includes:
[0068] A first processing unit 201 for the data owner to upload data through the first Ukey and perform storage encryption;
[0069] An access application unit 202 for the data user to apply for access to the data with the public key of the second Ukey;
[0070] A creation unit 203 for the data user to create a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey when the access request is approved;
[0071] The decryption unit 204 is configured to decrypt the data based on the virtual machine to obtain the data.
[0072] As Figure 3 shown, an embodiment of the present application further provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor. When the processor 320 executes the computer program 311, the steps of the above-mentioned method for secure data sharing and processing based on a Ukey are implemented.
[0073] Since the electronic device introduced in this embodiment is the device adopted for implementing a secure data sharing and processing device based on a Ukey in an embodiment of the present application, based on the method introduced in the embodiment of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiment of the present application will not be described in detail here. As long as the device adopted by those skilled in the art to implement the method in the embodiment of the present application belongs to the scope protected by the present application.
[0074] In the specific implementation process, when the computer program 311 is executed by the processor, any implementation manner in the corresponding embodiment of the first aspect can be implemented.
[0075] Figure 4 shows a schematic structural diagram of a computer system of an electronic device suitable for implementing an embodiment of the present application.
[0076] It should be noted that Figure 4 the computer system 400 of the electronic device shown is only an example and should not bring any limitation to the functions and usage scopes of the embodiments of the present application.
[0077] As Figure 4 shown, the computer system 400 includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 402 or the program loaded from the storage section 408 into the random access memory (RAM) 403, such as executing the method described in the above embodiment. In the RAM 403, various programs and data required for system operation are also stored. The CPU 401, ROM 402, and RAM 403 are connected to each other through a bus 404. The input / output (I / O) interface 405 is also connected to the bus 404.
[0078] The following components are connected to the I / O interface 405: an input section 406 including a keyboard, a mouse, etc.; an output section 407 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the I / O interface 405 as needed. A removable medium 411 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is installed on the drive 410 as needed so that a computer program read therefrom is installed into the storage section 408 as needed.
[0079] Specifically, according to an embodiment of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 409, and / or installed from the removable medium 411. When the computer program is executed by a central processing unit (CPU) 401, various functions defined in the system of the present application are executed.
[0080] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0081] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0082] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. In some cases, the names of these units do not constitute a limitation on the units themselves.
[0083] As another aspect, the present application also provides a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes a method for secure data sharing and processing based on a Ukey described in the above embodiments.
[0084] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements a method for secure data sharing and processing based on a Ukey described in the above embodiments.
[0085] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0086] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0087] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the embodiments disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application. It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A secure data sharing and processing method based on Ukey, characterized in that: include: The data owner uploads the data through First Ukey and encrypts the storage; The data user applies to access the data with the public key of the second Ukey; When the access request is approved, the data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey, and decrypts the data based on the virtual machine to obtain the data.
2. The method according to claim 1, characterized in that The data owner uploads the data through the first Ukey and performs storage encryption, including: The data owner logs into the system through the First Ukey and uploads the data to the NFS storage server; The data owner uses the public key of the first Ukey to encrypt the data.
3. The method according to claim 2, characterized in that When the access request is approved, the data user creates a virtual machine by combining the second Ukey and the first Ukey, including The data owner approves the access request and, after approval, issues half of the first Ukey key to the data user; The data user creates a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey.
4. The method according to claim 3, characterized in that Decrypting the data based on the virtual machine to obtain the data includes: The NFS storage server mounts the encrypted data to the virtual machine; The virtual machine decrypts the encrypted data by combining the private key of the second Ukey and half of the key of the first Ukey to obtain the data.
5. A secure data sharing and processing device based on Ukey, characterized in that: include: The first processing unit is used for the data owner to upload data through the first Ukey and store and encrypt the data; The access application unit is used by the data user to apply for access to data with the public key of the second Ukey; A creation unit, configured to, when the access request is approved, enable the data user to create a virtual machine by combining the private key of the second Ukey and half of the key of the first Ukey; A decryption unit is used to decrypt data based on the virtual machine to obtain data.
6. A computer-readable storage medium, characterized in that: The storage medium stores computer instructions, and when the computer instructions are executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 5.
7. An electronic device, characterized in that: include: Memory and processor; The memory is used to store computer instructions; The processor is used to call the computer instructions stored in the memory so that the electronic device executes the method as described in any one of claims 1-5.