Data processing method, strategy making method and related equipment
By separating the equipment that formulates the division strategy from the equipment that performs the data division, the risk of information leakage during the data division process is solved and the security division of data is achieved.
Patent Information
- Application Number
- CN202311627140.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-30
AI Technical Summary
During the data division process, the division device can obtain the data to be divided and identify its semantics, resulting in the risk of information leakage.
By separating the device that formulates the division strategy from the device that divides the data, the storage controller only receives the target policy and does not participate in the policy formulation, and does not obtain knowledge related to data identification, thereby avoiding the semantics of the identification of the data.
It effectively prevents the information leakage of data to be divided, reduces the risk of leakage of knowledge related to data identification, and improves the security of data division.
Smart Images

Figure CN120067780A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a data processing method, a policy formulation method, and related devices. Background Art
[0002] At present, the importance of data partitioning has become increasingly prominent. Data partitioning is the basis and prerequisite for data security, and is the starting point and key basis for data security protection throughout the life cycle. Data partitioning includes data classification and / or data grading. Data classification refers to the process of differentiating and classifying organizational data according to its attributes or characteristics, following certain principles and methods, and establishing a certain classification system and arrangement order to better manage and use organizational data. Data grading is to determine the level of data based on the affected objects and the degree of impact caused by the damage to data security, or the importance of the data, etc.
[0003] When partitioning data, a partitioning device formulates a partitioning policy according to the industry standard for data partitioning and relevant knowledge of data identification. Here, the partitioning device is the device for partitioning data. The device obtains the data to be partitioned from a storage device, and then partitions the data according to the partitioning policy. The problem with this data partitioning method is that the partitioning device can not only obtain the data to be partitioned, but also determine the semantics of the data based on relevant knowledge of data identification. Therefore, when the data to be partitioned includes important information such as user information, the partitioning device can master this important information through semantic recognition, which may lead to the leakage of information in the data to be partitioned.
[0004] Therefore, when partitioning data, how to avoid the leakage of information in the data to be partitioned is a technical problem to be solved urgently. Summary of the Invention
[0005] This application provides a data processing method, a policy formulation method, and related devices for preventing the leakage of information in the data to be partitioned.
[0006] In a first aspect of the present application, a data processing method is provided. This method is executed by a storage controller of a storage device. This method can also be executed by the storage device, or by other components (such as a chip or a chip system, etc.) in the storage device, or this method can also be implemented by a logic module or software that can implement all or part of the functions of the storage device. In the first aspect and its possible implementation manners, taking the case where this method is executed by the storage controller of the storage device as an example for description, hereinafter referred to as the storage controller. In this method, the storage controller receives a target policy, and the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data. The first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; the storage controller divides the first data according to the target policy to obtain a first label of the first data, and the first data is stored in the storage device; the storage controller binds and stores the first label and the first data in the storage device or an external storage device; or the storage controller receives a target policy, and the target policy indicates the compositional features and / or structural features of the data with the first label as the category, or the target policy indicates the compositional features and / or structural features of the data with the first label as the level. The storage controller determines the first data that conforms to the first label according to the target policy, and the storage controller binds and stores the first label and the first data in the storage device or an external storage device.
[0007] In the embodiment of the present application, the division of the first data is executed by the storage controller of the storage device. The storage controller only receives the target policy and does not participate in the formulation of the target policy, and does not need to obtain knowledge related to data recognition. Therefore, the storage controller cannot recognize the semantics of the first data. Further, in the embodiment of the present application, the device for formulating the division policy is separated from the device for dividing the data. The storage controller that executes the data division does not need to obtain knowledge related to data recognition necessary for formulating the division. Therefore, although the storage controller stores the first data, that is, the data to be divided, it cannot recognize the semantics of this data, thus preventing the leakage of information of the data to be divided.
[0008] In a possible implementation manner of the first aspect, the target policy comes from a third-party device or a storage management device, and the target policy is formulated by the third-party device.
[0009] Based on the above technical solution, the storage controller does not participate in the formulation of the target policy. Instead, a third-party device formulates the target policy, thus separating the device for formulating the target policy from the device for partitioning the data. Additionally, the target policy can be directly sent by the third-party device to the storage device. In this way, the target policy can be transmitted quickly, avoiding delays in transmission due to excessive intermediate nodes during the transmission process. The target policy can also be sent by the third-party device to the storage management device first, and then the storage management device forwards the target policy to the storage device. This method can be applied to the situation where the third-party device and the storage device cannot communicate with each other.
[0010] Optionally, the storage controller can partition the data through an algorithm, which includes: a data partitioning algorithm based on regular expressions or artificial intelligence.
[0011] Based on the above technical solution, since the data is stored in the storage device, compared with partitioning the data through other devices, directly partitioning the data in the storage device can achieve near-source analysis of the data and reduce the input / output (I / O) overhead of the data.
[0012] Optionally, the compositional features and / or structural features of the above data include: the category of the elements in the data, the arrangement rules of the elements in the data, the relationships between the elements in the data, and one or more of the lengths of the data.
[0013] Optionally, the target policy is a regular expression, which describes the compositional features and / or structural features of the data, as well as the first label corresponding to the data that meets the features.
[0014] Optionally, the target policy further includes: the mapping relationship between the category and level to which the data belongs.
[0015] Optionally, the third-party device formulates the data classification policy in the target policy based on one or more of the following criteria: the criticality of the data, the availability of the data, the sensitivity of the data, the compliance of the data, or the integrity of the data.
[0016] Optionally, the third-party device formulates the data grading policy in the target policy based on one or more of the following criteria: the general standards stipulated by industries or regulations, the sensitivity level of the data, or the impact on enterprises or individuals after the data is damaged.
[0017] Optionally, the external storage device is a database not configured on the storage device.
[0018] In a possible implementation of the first aspect, the storage controller sends the first data to dedicated hardware, which is configured on the storage device or is independent of the storage device; the storage controller sends a target policy to the dedicated hardware and instructs the dedicated hardware to partition the first data according to the target policy; the storage controller receives the first tag sent by the dedicated hardware.
[0019] Based on the above technical solution, the storage controller can rely on dedicated hardware to partition the first data, thereby reducing the pressure on the storage controller to partition the data and saving the computing power of the storage controller.
[0020] Optionally, a fast data reading protocol is established between the dedicated hardware and the storage controller.
[0021] Optionally, the dedicated hardware includes: field programmable gate array (FPGA), graphics processing unit (GPU), data processing unit (DPU), neural processing unit (NPU).
[0022] Optionally, the dedicated hardware can be a chip or a chip system, or can be a device configured with FPGA, GPU, DPU or NPU. The dedicated hardware can also be configured on the storage device in the form of a server or a chip.
[0023] In a possible implementation of the first aspect, the first data includes: second data and third data. The storage controller sends the second data to the dedicated hardware; the storage controller sends the target policy to the dedicated hardware and instructs the dedicated hardware to partition the second data according to the target policy; the storage controller receives the first tag of the second data sent by the dedicated hardware; the storage controller partitions the third data according to the target policy to obtain the first tag of the third data.
[0024] Based on the above technical solution, the storage controller and the dedicated hardware can cooperate and divide the first data together. Compared with partitioning the first data only by the storage controller or only by the dedicated hardware, the efficiency of cooperation is higher.
[0025] Optionally, the storage controller divides the first data into second data and third data according to its own data processing ability and the data processing ability of the dedicated hardware. Among them, the storage controller allocates the second data to the dedicated hardware for data partitioning, and the third data is partitioned by the storage controller.
[0026] In a possible implementation of the first aspect, the way of storing the binding includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
[0027] Based on the above technical solution, it is possible to facilitate the storage controller to quickly determine the tag of the first data, and it is also possible to quickly bind and send the first data and the first tag when sharing the first data and the first tag.
[0028] In a possible implementation of the first aspect, the storage controller receives a first message sent by a first device, and the first message indicates to send the first tag; the storage controller responds to the first message and sends the first tag to the first device.
[0029] Based on the above technical solution, the first tag obtained by the storage device can be publicly used externally, and the first device can directly reuse the partitioning result of the storage device.
[0030] Optionally, the storage device includes: a tag reading interface, and the first device sends a first message to the tag reading interface to obtain the first tag.
[0031] Optionally, the first device obtains the first tag from the storage controller through a data security proxy.
[0032] Optionally, the first device may be a device that needs to share the first tag, or a general application, or a sharing application. A general application refers to an application that does not share the data or the tag with other devices after obtaining the first tag of the first data, and a sharing application refers to an application that also shares the data or the tag with other devices after obtaining the first tag of the first data.
[0033] Optionally, the general application reads the first tag of the first data and uses the data securely; the sharing application reads the first data encapsulated with the first tag and shares it.
[0034] Optionally, the general application reads the first tag of the first data in the storage device through a data security proxy; the general application can also directly read the data tag through the tag reading interface of the storage device.
[0035] Optionally, when the application for obtaining the first tag is a sharing application, the sharing application can read the corresponding first data encapsulated with the first tag in the storage device through a data security proxy, and then perform data sharing; or can directly read the first data encapsulated with the first tag through the tag reading interface of the storage device, and then perform data sharing.
[0036] In a possible implementation of the first aspect, when the first tag is stored in the tag file or the metadata of the first data, the storage controller binds the first data with the first tag and sends the bound first data and the first tag to the first device.
[0037] Based on the above technical solution, the storage controller binds and sends the first data with the corresponding first tag, so that the device receiving the bound first data and the first tag can quickly know the corresponding relationship between the first data and the first tag.
[0038] Optionally, when the first device obtains the bound first data and the first tag, the first device verifies the first data and the first tag, and uses the first data and the first tag after the verification passes.
[0039] In a possible implementation of the first aspect, when the first tag is stored in the data content of the first data, the storage controller sends the first data to the first device.
[0040] Based on the above technical solution, since the first tag has been stored in the data content of the first data, only the first data needs to be directly sent, and the recipient of the first data can quickly know that the first data corresponds to the first tag by parsing the data.
[0041] Optionally, after the first device obtains the first data, it parses the first data to obtain the first tag corresponding to the first data.
[0042] In a possible implementation of the first aspect, the storage controller formulates an access control scheme for the first data according to the first tag, and the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access.
[0043] Based on the above technical solution, formulating an access control scheme according to the tag of the data can formulate a differentiated access control scheme based on the category and / or level of the data, so as to realize the differentiated management of the data.
[0044] Optionally, the access control scheme can also be the tag of the data, the mapping relationship between the type of access behavior and the way of controlling data access.
[0045] In a possible implementation of the first aspect, the storage controller divides the fourth data according to the target policy to obtain a second label of the fourth data. The fourth data is stored in the storage device, and the first label is different from the second label. The storage controller binds and stores the second label and the fourth data in the storage device or an external storage device. The space where the first label and the first data are bound and stored is isolated from the space where the second label and the fourth data are bound and stored.
[0046] Based on the above technical solution, isolated storage for different labels, that is, different categories and / or levels of data, can be achieved. Thus, when it is necessary to obtain data of a certain level or a certain category, the corresponding data can be quickly obtained from the corresponding storage space.
[0047] Optionally, the storage controller transparently encrypts the first data according to the first label.
[0048] Optionally, when the first label is the category to which the first data belongs, the storage controller determines whether to transparently encrypt the first data according to the importance level of this category. Data with a higher importance level is preferentially transparently encrypted. When the first label is the level to which the first data belongs, the storage controller determines whether to transparently encrypt the first data according to the level. The storage controller can preferentially transparently encrypt highly sensitive data and data with strong destructiveness.
[0049] Based on the above technical solution, the first data of a specified category and a specified level is transparently encrypted by means of transparent encryption. Among them, the transparent encryption method can forcibly encrypt the data, and the upper-layer application is unaware during the encryption process and does not change the way the application accesses the data.
[0050] Optionally, for the first data with a high level as the first label, retention period management is performed, and the storage controller automatically deletes the high-level data whose retention period has ended.
[0051] Optionally, after the storage device shares the first data with other storage devices, the storage device that receives the shared first data controls the label of the first data and provides a shared service for the label externally.
[0052] The second aspect of the present application provides a data processing method. This method is executed by a storage management device, or by some components (such as a processor, a chip, or a chip system, etc.) in the storage management device, or this method can also be implemented by a logic module or software that can fully or partially implement the functions of the storage management device. In the second aspect and its possible implementation manners, the case where this method is executed by the storage management device is taken as an example for description. In this method, the storage management device receives a target policy, and the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data. The first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; the storage management device divides the first data according to the target policy to obtain a first label of the first data, and the storage management device sends the first label to the storage device, or the storage management device receives a target policy, and the target policy indicates the compositional features and / or structural features of the data with the first label as the category, or the target policy indicates the compositional features and / or structural features of the data with the first label as the level. The storage management device determines the first data that conforms to the first label according to the target policy, and the storage management device sends the first data to the storage device.
[0053] In the embodiments of the present application, the storage management device executes the division of the first data. The storage management device only receives the target policy and does not participate in the formulation of the target policy, and does not need to obtain knowledge related to data identification. Further, in the embodiments of the present application, the device for formulating the division policy is separated from the device for dividing the data. The storage management device that executes the data division does not need to obtain knowledge related to data identification necessary for the division. Therefore, although the storage management device obtains the first data, that is, the data to be divided, it cannot recognize the semantics of this data, thus avoiding the leakage of data information.
[0054] Furthermore, based on the above technical solution, the first data is stored in the storage device, and both the storage management device and the storage device belong to the scope of storage services. The storage management device and the storage device are usually in one network. Therefore, compared with dividing data through other devices, dividing data through the storage management device can quickly obtain the data to be divided and quickly implement the division of the data.
[0055] Optionally, the storage management device receives the target policy sent by a third-party device.
[0056] In a possible implementation of the second aspect, the storage management device formulates a security policy based on the security risk analysis of the first data; the storage management device formulates an access control scheme for the first data according to the first label and the security policy, and the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access; the storage management device sends the access control scheme to the storage device.
[0057] Based on the above technical solution, an access control scheme is formulated according to the label and security policy of the data, so that a differentiated access control scheme can be formulated based on the category and / or level of the data and the security status of the data, thereby realizing the differentiated management of the data.
[0058] Optionally, the access control scheme may also be the label of the data, a mapping relationship between the type of access behavior and the way of controlling data access.
[0059] Optionally, the security risk analysis includes: formulating a data map of the first data based on the partition label; performing compliance analysis on the first data or tracing and auditing the first data.
[0060] Optionally, the storage management device can partition the data through an algorithm, and the algorithm includes: a data partitioning algorithm based on regular expressions or artificial intelligence.
[0061] Optionally, the compositional features and / or structural features of the above data include: the category of elements in the data, the arrangement rules of elements in the data, the relationship between elements in the data, one or more of the lengths of the data.
[0062] Optionally, the target policy is a regular expression, which describes the compositional features and / or structural features of the data, and the first label corresponding to the data that meets the features.
[0063] Optionally, the target policy further includes: a mapping relationship between the category and level to which the data belongs.
[0064] Optionally, the third-party device formulates the data classification policy in the target policy based on one or more of the following criteria: the criticality of the data, the availability of the data, the sensitivity of the data, the compliance of the data, or the integrity of the data.
[0065] Optionally, the third-party device formulates the data grading policy in the target policy based on one or more of the following criteria: general standards stipulated by industries or regulations, the sensitivity of the data, or the impact on enterprises or individuals after the data is damaged.
[0066] Optionally, the first data and the first label can be bound and stored in a storage device, or can be bound and stored in a storage management device, or can be both bound and stored in a storage device and bound and stored in a storage management device, or can be bound and stored in an external storage device.
[0067] In a possible implementation of the second aspect, the storage management device sends the first data to dedicated hardware, which is configured on the storage management device or is independent of the storage management device; the storage management device sends the target policy to the dedicated hardware and instructs the dedicated hardware to partition the first data according to the target policy; the storage management device receives the first label sent by the dedicated hardware.
[0068] Based on the above technical solution, the storage management device can partition the first data with the help of dedicated hardware, thereby reducing the pressure on the storage management device to partition data and saving the computing power of the storage management device.
[0069] Optionally, a fast data reading protocol is established between the dedicated hardware and the storage controller.
[0070] Optionally, the dedicated hardware includes: FPGA, GPU, DPU, or NPU.
[0071] Optionally, the dedicated hardware can be a chip or a chip system, or can be a device configured with FPGA, GPU, DPU or NPU, and the dedicated hardware can also be configured on the storage management device in the form of a server or a chip.
[0072] In a possible implementation of the second aspect, the first data includes second data and third data, the storage management device sends the second data to the dedicated hardware; the storage management device sends the target policy to the dedicated hardware and instructs the dedicated hardware to partition the second data according to the target policy; the storage management device receives the first label of the second data sent by the dedicated hardware; the storage management device partitions the third data according to the target policy to obtain the first label of the third data.
[0073] Based on the above technical solution, the storage management device and the dedicated hardware can cooperate in division of labor to jointly partition the first data. Compared with partitioning the first data only by the storage management device or only by the dedicated hardware, the efficiency of the division of labor and cooperation is higher.
[0074] Optionally, the storage management device divides the first data into second data and third data according to its own data processing capabilities and the data processing capabilities of the dedicated hardware, where the second data is allocated to the dedicated hardware for data partitioning, and the third data is partitioned by the storage controller.
[0075] In a possible implementation of the second aspect, the storage management device stores the first data in a first manner, and the first manner includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
[0076] Based on the above technical solution, it is convenient for the storage management device to quickly determine the tag of the first data, and it is also possible to quickly bind and send the first data and the first tag when sharing the first data and the first tag.
[0077] In a possible implementation of the second aspect, the storage management device receives a first message sent by a first device, and the first message indicates to send the first tag; the storage management device responds to the first message and sends the first tag to the first device.
[0078] Based on the above technical solution, the first tag obtained by the storage management device can be publicly used externally, and the first device can directly reuse the partitioning result of the storage management device.
[0079] Optionally, the storage device includes: a tag reading interface, and the first device sends a first message to the tag reading interface to obtain the first tag.
[0080] Optionally, the first device obtains the first tag from the storage management device through a data security proxy.
[0081] Optionally, the first device may be a device that needs to share the first tag, or an upper-layer application, or an application that needs to share the first data.
[0082] Optionally, a general application reads the first tag of the first data and uses the data securely; a sharing application reads the first data encapsulated with the first tag and shares it.
[0083] Optionally, a general application reads the first tag of the first data in the storage device through a data security proxy; the general application can also directly read the data tag through the tag reading interface of the storage device.
[0084] Optionally, when the application for obtaining the first tag is a sharing application, the so-called sharing application means that after obtaining the first tag of the first data, further sharing is required. At this time, the sharing application can read the corresponding first data encapsulated with the first tag in the storage management device through a data security proxy, and then perform data sharing; or it can directly read the first data encapsulated with the first tag through the tag reading interface of the storage management device, and then perform data sharing.
[0085] In a possible implementation of the second aspect, when the first tag is stored in the tag file or the metadata of the first data, the storage management device binds the first data with the corresponding first tag, and sends the bound first data and the corresponding first tag to the first device.
[0086] Based on the above technical solution, the first data is bound and sent with the corresponding first tag, so that the device that receives the bound first data and the first tag can quickly know the correspondence between the first data and the first tag.
[0087] Optionally, when the first device obtains the bound first data and the first tag, the first device verifies the first data and the first tag, and can use the first data and the first tag only after the verification passes.
[0088] In a possible implementation of the second aspect, when the first tag is stored in the data content of the first data, the storage management device sends the first data to the first device.
[0089] Based on the above technical solution, since the first tag has been stored in the data content of the first data, only the first data needs to be directly sent, and the recipient of the first data can quickly know that the first data corresponds to the first tag by parsing the data.
[0090] Optionally, after the first device obtains the first data, it parses the first data to obtain the first tag corresponding to the first data.
[0091] In a possible implementation of the second aspect, the storage management device divides the fourth data according to the target policy to obtain the second tag of the fourth data. The fourth data is stored in the storage device, and the first tag and the second tag are different; the storage management device binds the second tag and the fourth data and stores them in the storage device or an external storage device, and the storage space where the first tag and the first data are bound and stored is isolated from the storage space where the second tag and the fourth data are bound and stored.
[0092] Based on the above technical solution, it is possible to achieve isolated storage of different tags, that is, different categories and / or levels of data, so that when it is necessary to obtain a certain level of data or a certain category of data, the corresponding data can be quickly obtained from the corresponding storage space.
[0093] Optionally, the storage management device transparently encrypts the first data according to the first label. Further, when the first label is the category to which the first data belongs, the storage management device determines whether to transparently encrypt the first data according to the importance level of this category. Data with a higher importance level is preferentially transparently encrypted. When the first label is the category to which the first data belongs, the storage management device determines whether to transparently encrypt the first data according to the level of this category. Highly sensitive data and data with strong destructiveness are preferentially transparently encrypted.
[0094] Based on the above technical solution, certain first data is transparently encrypted in a transparent encryption manner. The first data of the specified category and the specified level is compulsorily encrypted, protecting the security of this part of the data, and the upper-layer application is unaware of the encryption process.
[0095] Optionally, for the first data with a high-level first label, retention period management is performed, and the high-level data whose retention period has ended is automatically deleted.
[0096] Optionally, after the storage management device that performs data partitioning shares the first data with other storage management devices, the storage management device that receives the shared first data controls the label of the first data and provides a shared service for the label externally.
[0097] A third aspect of the present application provides a strategy formulation method, which is executed by a third-party device, or by some components (such as a processor, a chip, or a chip system, etc.) in the third-party device, or the method can also be implemented by a logic module or software that can implement all or part of the functions of the third-party device. In the third aspect and its possible implementation manners, the case where the method is executed by the third-party device is described as an example. In this method, the third-party device obtains a first task, and the first task instructs to identify a target object in the first data and divide the first data; the third-party device formulates a target strategy according to the target object, and the target strategy includes: a first judgment rule for classifying data or a second judgment rule for grading data, where the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; the third-party device sends the target strategy to a storage device or a storage management device, so that the storage device or the storage management device divides the first data according to the target strategy. Or the third-party device obtains a first task, and the first task instructs the first data that conforms to the first label and identifies the target object in the first data; the third-party device formulates a target strategy according to the target object, and the target strategy indicates the compositional features and / or structural features of the data with the category of the first label, or the target strategy indicates the compositional features and / or structural features of the data with the level of the first label, and the third-party device sends the target strategy to a storage device or a storage management device, so that the storage device or the storage management device determines the first data that conforms to the first label according to the target strategy.
[0098] In the embodiments of the present application, the third-party device only formulates a target strategy, that is, formulates a strategy for dividing data, and does not execute the division of data. That is to say, in the embodiments of the present application, the device for formulating the division strategy is separated from the device for dividing the data. Although the third-party device for formulating the target strategy has the ability to recognize the semantics of the data, it does not obtain the first data, thus avoiding the leakage of data information.
[0099] A fourth aspect of the present application provides a communication device, which can implement the method in the first aspect or any possible implementation manner of the first aspect. The communication device includes corresponding units or modules for executing the above method. The units or modules included in the communication device can be implemented in software and / or hardware manners. For example, the device can be a storage controller of a storage device, or the device can be a storage device, or the device can be other components (such as a chip, a chip system, etc.) in the storage device, or the device can also be a logic module or software that can implement all or part of the functions of the storage device.
[0100] Among them, the communication device includes: a transceiver unit and a processing unit; the transceiver unit is configured to receive a target policy, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; the processing unit is configured to divide the first data according to the target policy to obtain a first label of the first data, and the first data is stored in the storage device; the processing unit is further configured to bind and store the first label and the first data in the storage device or an external storage device.
[0101] In a possible implementation manner of the fourth aspect, the sender of the target policy is a third-party device or a storage management device, the target policy is formulated by the third-party device, and the data stored in the storage device is managed by the storage management device.
[0102] In a possible implementation manner of the fourth aspect, the processing unit is specifically configured to: call the transceiver unit to send the first data to a dedicated hardware, where the dedicated hardware is configured on the storage device or the dedicated hardware is independent of the storage device; call the transceiver unit to send the target policy to the dedicated hardware and instruct the dedicated hardware to divide the first data according to the target policy; call the transceiver unit to receive the first label sent by the dedicated hardware.
[0103] In a possible implementation manner of the fourth aspect, the first data includes second data and third data, and the processing unit is specifically configured to: call the transceiver unit to send the second data to the dedicated hardware; call the transceiver unit to send the target policy to the dedicated hardware and instruct the dedicated hardware to divide the second data according to the target policy; call the transceiver unit to receive the first label of the second data sent by the dedicated hardware; divide the third data according to the target policy to obtain the first label of the third data.
[0104] In a possible implementation manner of the fourth aspect, the method of binding and storing includes: storing the first label in the metadata of the first data, storing the first label in a label file, or storing the first label in the data content of the first data.
[0105] In a possible implementation manner of the fourth aspect, the transceiver unit is further configured to: receive a first message sent by a first device, where the first message instructs to send the first label; in response to the first message, send the first label to the first device.
[0106] In a possible implementation of the fourth aspect, the transceiver unit is specifically configured to: when the first tag is stored in the tag file or the metadata of the first data, call the processing unit to bind the first data with the first tag, and send the bound first data and first tag to the first device.
[0107] In a possible implementation of the fourth aspect, the transceiver unit is specifically configured to: when the first tag is stored in the data content of the first data, send the first data to the first device.
[0108] In a possible implementation of the fourth aspect, the processing unit is further configured to: formulate an access control scheme for the first data according to the first tag, where the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access.
[0109] In a possible implementation of the fourth aspect, the processing unit is further configured to: divide the fourth data according to the target policy to obtain a second tag of the fourth data, where the fourth data is stored in the storage device, and the first tag and the second tag are different; bind and store the second tag and the fourth data in the storage device or an external storage device, and the space where the first tag and the first data are bound and stored is isolated from the space where the second tag and the fourth data are bound and stored.
[0110] The fifth aspect of the present application provides a communication device, and the communication device can implement the method in the second aspect or any possible implementation manner of the second aspect. The communication device includes corresponding units or modules for executing the above method. The units or modules included in the communication device can be implemented in software and / or hardware manners. For example, the device can be a storage management device, or the device can be a component in a storage management device (such as a processor, a chip, a chip system, etc.), or the device can also be a logical module or software that can implement all or part of the functions of the storage management device.
[0111] Wherein, the communication device includes: a transceiver unit and a processing unit; the transceiver unit is configured to receive a target policy, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; obtain first data from the storage device; the processing unit is configured to divide the first data according to the target policy to obtain a first tag of the first data; the transceiver unit is further configured to send the first tag to the storage device.
[0112] In a possible implementation of the fifth aspect, the processing unit is further configured to: formulate a security policy based on the security risk analysis of the first data; formulate an access control scheme for the first data according to the first tag and the security policy, where the access control scheme is a mapping relationship between the type of access behavior and the way to control data access; call the transceiver unit to send the access control scheme to the storage device.
[0113] In a possible implementation of the fifth aspect, the processing unit is specifically configured to: call the transceiver unit to send the first data to the dedicated hardware, where the dedicated hardware is configured on the storage management device or the dedicated hardware is independent of the storage management device; call the transceiver unit to send the target policy to the dedicated hardware, and instruct the dedicated hardware to divide the first data according to the target policy; call the transceiver unit to receive the first tag sent by the dedicated hardware.
[0114] In a possible implementation of the fifth aspect, the first data includes second data and third data, and the processing unit is specifically configured to: call the transceiver unit to send the second data to the dedicated hardware; call the transceiver unit to send the target policy to the dedicated hardware, and instruct the dedicated hardware to divide the second data according to the target policy; call the transceiver unit to receive the first tag of the second data sent by the dedicated hardware; divide the third data according to the target policy to obtain the first tag of the third data.
[0115] In a possible implementation of the fifth aspect, the processing unit is further configured to store the first data in a first manner, where the first manner includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
[0116] In a possible implementation of the fifth aspect, the transceiver unit is further configured to: receive a first message sent by a first device, where the first message indicates to send the first tag; in response to the first message, send the first tag to the first device.
[0117] In a possible implementation of the fifth aspect, the transceiver unit is specifically configured to: when the first tag is stored in the tag file or the metadata of the first data, call the processing unit to bind the first data with the first tag, and send the bound first data and first tag to the first device.
[0118] In a possible implementation of the fifth aspect, the transceiver unit is specifically configured to: when the first tag is stored in the data content of the first data, send the first data to the first device.
[0119] In a possible implementation of the fifth aspect, the processing unit is further configured to: divide the fourth data according to the target policy to obtain a second label of the fourth data, where the fourth data is stored in the storage device, and the first label is different from the second label; bind and store the second label and the fourth data in the storage device or an external storage device, and the space where the first label is bound and stored with the first data is isolated from the space where the second label is bound and stored with the fourth data.
[0120] A sixth aspect of the present application provides a communication device, which can implement the method in the third aspect or any possible implementation of the third aspect. The communication device includes corresponding units or modules for executing the above method. The units or modules included in the communication device can be implemented in software and / or hardware. For example, the device can be a third-party device, or the device can be a component in a third-party device (such as a processor, a chip, a chip system, etc.), or the device can also be a logical module or software that can implement all or part of the functions of a third-party device.
[0121] Among them, the communication device includes: a transceiver unit and a processing unit; the transceiver unit is configured to obtain a first task, where the first task instructs to identify a target object in the first data and divide the first data; the processing unit is configured to formulate a target policy according to the target object, and the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, where the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; the transceiver unit is further configured to send the target policy to a storage device or a storage management device, so that the storage device or the storage management device divides the first data according to the target policy.
[0122] A seventh aspect of the present application provides a communication device, including at least one processor and a communication interface, where the processor and the communication interface are configured to execute the method described in the foregoing first aspect or any possible implementation of the first aspect.
[0123] Optionally, the at least one processor is coupled to a memory. For example, the memory is used to store programs or instructions. The at least one processor is configured to execute the programs or instructions to enable the device to implement the method described in the foregoing first aspect or any possible implementation of the first aspect.
[0124] An eighth aspect of the present application provides a communication device, including at least one processor and a communication interface, where the processor and the communication interface are configured to execute the method described in the foregoing second aspect or any possible implementation of the second aspect.
[0125] Optionally, the at least one processor is coupled to a memory. For example, the memory is used to store programs or instructions. The at least one processor is used to execute the programs or instructions so that the device implements the method described in the foregoing second aspect or any possible implementation manner of the second aspect.
[0126] A ninth aspect of this application provides a communication device, including at least one processor and a communication interface. The processor and the communication interface are used to execute the method described in the foregoing third aspect or any possible implementation manner of the third aspect.
[0127] Optionally, the at least one processor is coupled to a memory. For example, the memory is used to store programs or instructions. The at least one processor is used to execute the programs or instructions so that the device implements the method described in the foregoing third aspect or any possible implementation manner of the third aspect.
[0128] A tenth aspect of this application provides a communication device, including at least one logic circuit and an input / output interface; the logic circuit is used to execute the method described in the foregoing first aspect and any possible implementation manner thereof.
[0129] An eleventh aspect of this application provides a communication device, including at least one logic circuit and an input / output interface; the logic circuit is used to execute the method described in the foregoing second aspect and any possible implementation manner thereof.
[0130] A twelfth aspect of this application provides a communication device, including at least one logic circuit and an input / output interface; the logic circuit is used to execute the method described in the foregoing second aspect and any possible implementation manner thereof.
[0131] A thirteenth aspect of this application provides a computer-readable storage medium, which is used to store one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method described in any possible implementation manner of any one of the foregoing first aspect to third aspect.
[0132] A fourteenth aspect of this application provides a computer program product (or computer program). When the computer program product is executed by the processor, the processor executes the method in any possible implementation manner of any one of the foregoing first aspect to third aspect.
[0133] A fifteenth aspect of this application provides a chip system, which includes at least one processor and is used to support a communication device to implement the functions involved in any possible implementation manner of any one of the foregoing first aspect to third aspect.
[0134] In a possible design, the chip system may further include a memory for storing necessary program instructions and data of the communication device. The chip system may be composed of chips or may include chips and other discrete devices. Optionally, the chip system further includes an interface circuit that provides program instructions and / or data for the at least one processor.
[0135] The sixteenth aspect of the present application provides a communication system. The communication system includes the communication device of the fourth aspect above, the call device of the fifth and sixth aspects, or the communication system includes the communication device of the seventh aspect above, the communication devices of the eighth and ninth aspects, or the communication system includes the communication device of the tenth aspect above, the communication devices of the eleventh and twelfth aspects.
[0136] Among them, the technical effects brought by any one of the design methods in the fourth aspect to the sixteenth aspect can be referred to the technical effects brought by the first aspect to the third aspect and their different design methods above, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0137] Figure 1 It is a schematic diagram of the system architecture of a data processing method provided by an embodiment of the present application;
[0138] Figure 2 It is a schematic flow diagram of a data processing method provided by an embodiment of the present application;
[0139] Figure 3 It is a schematic diagram of a storage controller performing hardware acceleration provided by an embodiment of the present application;
[0140] Figure 4 It is a schematic diagram of the main functional modules of the device in Embodiment 1;
[0141] Figure 5 It is a schematic diagram of the cooperation between the devices in Embodiment 1;
[0142] Figure 6 It is a schematic flow diagram in Embodiment 1;
[0143] Figure 7 It is a schematic diagram of the main functional modules of the device in Embodiment 2;
[0144] Figure 8 It is a schematic diagram of the cooperation between the devices in Embodiment 2;
[0145] Figure 9 It is a schematic flow diagram in Embodiment 2;
[0146] Figure 10 It is a schematic structural diagram of a communication device provided by an embodiment of the present application;
[0147] Figure 11 Another structural schematic diagram of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0148] The following is an explanation of some terms related to the embodiments of the present application.
[0149] In the embodiments of the present application, the terms "system" and "network" can be used interchangeably. "At least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" or a similar expression refers to any combination of these items, including any combination of single item(s) or plural item(s). For example, "at least one of A, B, and C" includes A, B, C, AB, AC, BC, or ABC. Also, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, time sequence, priority, or importance of multiple objects.
[0150] The following is an example of the system architecture of the embodiments of the present application.
[0151] The present application can be applied to the following system: The system consists of a third-party device, a storage device, and a storage management device. The storage device includes: a storage controller, and the storage management device is used to manage the data stored in the storage device.
[0152] Please refer to Figure 1 , Figure 1 a schematic diagram of a possible and non-limiting application scenario provided by the present application. The solution provided by the present application can be applied to Figure 1 the communication system shown in Figure 1 As shown in
[0153] Method ①: The third-party device 101 formulates a partitioning strategy and directly sends the strategy to the storage device 103, so that the storage controller of the storage device 103 executes the partitioning of the data.
[0154] Method ②: The third-party device 101 formulates a partitioning strategy and sends the strategy to the storage management device 102, and then the storage management device 102 forwards it to the storage device 103, so that the storage controller of the storage device 103 executes the partitioning of the data.
[0155] Method ③: The third-party device 101 formulates a partitioning strategy and sends the strategy to the storage management device 102, so that the storage management device 102 executes the partitioning of the data.
[0156] The method flow of the embodiments of the present application will be illustrated by way of example below.
[0157] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the data processing method provided by the present application. It should be noted that Figure 2 takes the storage controller as the execution subject as an example to illustrate the method, but the present application does not limit the execution subject of the method. Specifically, on the one hand, Figure 2 and the execution subject in steps S201-S203 in the corresponding embodiments can be Figure 2 the storage controller mentioned in Figure 2 . The storage controller can be a storage server, etc., the execution subject can also be a storage device, or other components in the storage device (such as a chip or a chip system, etc.) to execute, and the execution subject can also be a logical module or software implementation that can implement all or part of the functions of the storage device. On the other hand,
[0158] The method includes the following steps:
[0159] Step S201: The storage controller receives the target policy.
[0160] Among them, the target policy is a judgment rule for indicating the category to which the data belongs. The judgment rule is a mapping relationship between the compositional characteristics and / or structural characteristics of the data and the category of the data, or the target policy is a judgment rule for indicating the level to which the data belongs. The judgment rule is a mapping relationship between the compositional characteristics and / or structural characteristics of the data and the level of the data.
[0161] It should be noted that the target policy is a rule for determining the category and / or level to which the data belongs. The target policy can also be referred to as a rule, or a partitioning rule, a data partitioning rule, etc. The target policy can also be referred to as a standard, or a partitioning standard, a data partitioning standard, etc. The target policy can also be referred to as a method, or a partitioning method, a data processing method, etc.
[0162] It is understandable that the target policy is a policy for partitioning data, and the scope of the target policy encompasses the partitioning policies in the foregoing text.
[0163] The target policy may include: the mapping relationship between the compositional features of the data and the category of the data, the mapping relationship between the compositional features of the data and the level of the data, the mapping relationship between the compositional features of the data and the category and level of the data, the mapping relationship between the structural features of the data and the category of the data, the mapping relationship between the structural features of the data and the level of the data, the mapping relationship between the structural features of the data and the category and level of the data, the mapping relationship between the compositional features and structural features of the data and the category of the data, the mapping relationship between the compositional features and structural features of the data and the level of the data, or the mapping relationship between the compositional features and structural features of the data and the category and level of the data. In addition, the target policy may further include: the mapping relationship between the category to which the data belongs and the level. For example, the target policy is: when the category of the data is complete data, its level is level one.
[0164] Optionally, the foregoing compositional features and / or structural features of the data include: the category of the elements in the data, the arrangement rule of the elements in the data, the relationship between the elements in the data, the length of the data, or one or more of them. Correspondingly, the target policy describes these compositional features and / or structural features of the data and the corresponding category or level of the data. For example, the target policy may be: {regular expression / ^1[3456789]\d{9}$ / , level one}, and the meaning of this regular expression is: if the digital characters in the first data satisfy "the first digit starts with 1, and the second digit is one of 3456789 and the last nine digits are numbers", then its corresponding level is 1. Another example is that the target policy may be: if the first data is logically expressed and implemented by a two-dimensional table structure, then the category of the first data is structured data and the level of the first data is 1.
[0165] The foregoing has described the content and manifestation forms included in the target policy, etc. Next, introduce how the target policy is formulated:
[0166] As described above, the device for formulating the target policy is not a storage device. The device for formulating the target policy may be a third-party device, may also be a third-party application, or may also be a third-party server, etc. The so-called third party means that it exists independently from the storage device and the storage management device. Hereinafter, examples will be given with the device for formulating the target policy being a third-party device. In addition, the storage management device and the storage device are also independent of each other.
[0167] To formulate target strategies, knowledge related to data partitioning needs to be configured in the third-party device. Such knowledge includes: regulations related to partitioning, industry-wide standards, or partitioning rules customized by the manufacturer of the third-party device, as well as knowledge and methods related to data identification. More specifically, the criteria for data classification can include: the criticality of the data, the availability of the data, the sensitivity of the data, the compliance of the data, or the integrity of the data. The criteria for data grading can include: general standards stipulated by the industry or regulations, the sensitivity level of the data, or the impact on the enterprise or individual after the data is damaged.
[0168] After configuring the relevant knowledge of partitioning, the third-party device can actively trigger the data partitioning process, or another device can send a certain instruction to trigger the third-party device to start the data partitioning process. Taking the example of triggering the data partitioning process by another device: The third-party device receives an instruction for indicating data partitioning, and this instruction indicates to identify a certain type of object in the data and determine the level of the data. For example, this instruction can indicate that the third-party device identifies the IP addresses of the devices included in the data and determines the levels of the IP addresses.
[0169] After receiving this instruction, the third-party device can formulate a target strategy based on the identified object. At this time, the third-party device can formulate the target strategy by combining the previously configured relevant knowledge of partitioning. For example, this instruction indicates that the third-party device identifies the mobile phone numbers included in the data. The third-party device obtains the identification rule of the mobile phone number according to the configured relevant knowledge of partitioning: The data with the composition of "the first digit starts with 1, the second digit is one of 3, 4, 5, 6, 7, 8, 9, and the last nine digits are numbers" is a mobile phone number. And the third-party device obtains according to the configured relevant knowledge of partitioning that the mobile phone number is highly sensitive data and its level is level 1. Therefore, the third-party device can formulate the target strategy as: {regular expression / ^1[3456789]\d{9}$ / , first level}.
[0170] After the third-party device formulates the target strategy, the third-party device does not perform the data partitioning. Instead, the storage controller performs the data partitioning. Therefore, the third-party device needs to send the target strategy to the storage controller. The third-party device can directly send the target strategy to the storage controller, or can send the target strategy to the storage controller via another device. From the perspective of the storage controller, the target strategy can be received through the following implementation methods:
[0171] In a possible implementation method, the target strategy comes from the third-party device or the storage management device. The target strategy is formulated by the third-party device, and the data stored in the storage device is managed by the storage management device.
[0172] It can be understood that in the above implementation, the ways for the storage device to receive the target policy include: receiving the target policy sent by a third-party device; receiving the target policy sent by a storage management device. Correspondingly, from the perspective of the third-party device, the target policy can be sent to the storage device in the following ways: after formulating the target policy, the third-party device directly sends the target policy to the storage device without forwarding through other devices; the third-party device sends the target policy to the storage device via the storage management device.
[0173] It should be noted that the third-party device can also forward the target policy to the storage management device with the help of other devices, such as laptops, switches, etc., and this application does not limit this.
[0174] More specifically, the first interface is the interface for the storage controller to connect to the third-party device, and the third-party device can send the target policy to the storage controller through the first interface; the second interface is the interface for the storage management device to connect to the third-party device, and the third interface is the interface for the storage management device to connect to the storage device. The third-party device can first send the target policy to the storage management device through the second interface, and then the storage management device sends the target policy to the storage device through the third interface.
[0175] It should be noted that the target policy formulated by the third-party device does not include the relevant rules for semantic recognition. More specifically, the target policy does not cover the relationship between the compositional features and / or structural features of the data and the semantics of the data. For example, the policy is {regular expression / ^1[3456789]\d{9}$ / , first level}, but this target policy does not include {regular expression / ^1[3456789]\d{9}$ / , mobile phone number}, that is to say, this target policy does not indicate that the data whose composition conforms to this regular expression is a mobile phone number.
[0176] It should be further noted that the third-party device does not send the knowledge related to partitioning to the storage controller. Furthermore, the storage controller does not receive and will not be configured with the knowledge related to partitioning, especially the knowledge related to data recognition. This is because the storage controller only performs data partitioning and does not participate in the formulation of partitioning policies, and it does not need to obtain the knowledge related to partitioning.
[0177] Step S202: The storage controller partitions the first data according to the target policy to obtain the first label of the first data.
[0178] Among them, the first data is stored in the storage device.
[0179] In step S202, data is divided by the storage controller in the storage device. Since the data is stored in the storage device, compared with data division through other devices, dividing the data directly in the storage device can realize near-source analysis of the data and reduce the I / O overhead of the data.
[0180] It can be understood that the first label is a label of the category or level of the data. For example, the first label can be the first level, indicating that the data is first level data. The first label can also be "complete data", indicating that the category of the data is: complete data.
[0181] The first data generally refers to all the data stored in the storage device, but the first data may also be a designated portion of data, for example, the third-party device receives a data partitioning instruction, which instructs the data in a certain range to be partitioned. Subsequently, the third-party device instructs the storage device to partition the data in the range.
[0182] As hardware, the storage controller can complete data partitioning independently, but there may be some hardware that is more efficient in data partitioning than the storage controller. Therefore, in order to partition data more quickly, the storage controller can partition data through hardware acceleration, in other words, with the help of other dedicated hardware to assist in data partitioning. Specifically, the storage controller can partition data in one or more of the following ways:
[0183] First, the storage controller independently divides the first data. At this time, the storage controller can divide the data through an algorithm, and the algorithm includes: a data division algorithm based on regularization or artificial intelligence.
[0184] Second, use dedicated hardware to complete the division of all first data. Since there may be other hardware with stronger computing power than the storage controller, or more suitable for the division of the first data type than the storage controller, the storage controller can use this type of hardware to divide the data. Specifically, it can be implemented in the following ways:
[0185] In one possible implementation, the storage controller sends the first data to dedicated hardware, which is configured on the storage device or is independent of the storage device; the storage controller sends a target policy to the dedicated hardware and instructs the dedicated hardware to divide the first data according to the target policy; the storage controller receives the first label sent by the dedicated hardware.
[0186] Optionally, a fast data reading protocol is established between the dedicated hardware and the storage controller. The fast data reading protocol includes: a publicly disclosed standard transmission protocol or a proprietary data reading protocol. For example, it can be a UDP-based data transfer protocol (UDT).
[0187] Combined with Figure 3 to explain this implementation method in more detail. In Figure 3 , the storage controller divides data through hardware acceleration. Specifically, the storage controller and the dedicated hardware are connected through a peripheral component interconnect express (PCI-E) interface. The storage controller sends the first data and the target policy to the dedicated hardware through the PCI-E interface. Compared with data transmission between devices through wireless fidelity (WIFI) or Bluetooth, etc., the PCI-E interface enables the storage controller to quickly send the first data to the dedicated hardware. After that, the dedicated hardware can divide the data based on the target policy.
[0188] More specifically, the above-mentioned dedicated hardware includes: FPGA, GPU, DPU, NPU. The dedicated hardware can be a chip or a chip system, or a device configured with FPGA, GPU, DPU or NPU. The dedicated hardware can also be configured on the storage device in the form of a server or a chip.
[0189] Third, the division of the first data is completed through the division of labor and cooperation between the storage controller and the dedicated hardware. Compared with simply relying on the storage controller or the dedicated hardware to complete data division, the division of labor and cooperation between the storage controller and the dedicated hardware to complete data division has higher efficiency. Specifically, it can be achieved through the following implementation methods:
[0190] In a possible implementation method, the first data includes: second data and third data. The storage controller sends the second data to the dedicated hardware; the storage controller sends the target policy to the dedicated hardware and instructs the dedicated hardware to divide the second data according to the target policy; the storage controller receives the first label of the second data sent by the dedicated hardware; the storage controller divides the third data according to the target policy to obtain the first label of the third data.
[0191] In the above implementation manner, it is not specified that the first data has been divided into the second data and the third data. In fact, when the first data may not have been divided into the second data and the third data yet, if there are multiple data with significantly different compositions and structures in the first data, and the data processing methods required for these data are different, the first data can be divided. Specifically, the storage controller can divide the first data into the second data and the third data according to its own data processing capabilities and the data processing capabilities of the dedicated hardware. Among them, the storage controller allocates the second data to the dedicated hardware for data division, and the third data is divided by the storage controller. To help understand, for example: if the dedicated hardware is a GPU and the storage controller is based on a central processor unit (CPU), the dedicated hardware is more suitable for dividing image data. Therefore, the first data is divided into image data and non-image data. The dedicated hardware divides the image data, and the storage controller divides the non-graphic data.
[0192] The above all list the cases where the device for data division is the storage controller. When the device for data division is the storage management device, the way for the storage management device to divide data is the same as the aforementioned step S202. However, since the first data is stored in the storage device, the storage management device needs to first obtain the first data from the storage device. And both the storage management device and the storage device belong to the scope of storage operations. Generally, a data fast reading protocol is established between the storage management device and the storage device, and they are usually in the same network. Therefore, compared with dividing data through other devices, dividing data through the storage management device can quickly obtain the data to be divided and quickly achieve data division. After obtaining the first data, the storage management device divides the first data to obtain the first label of the first data. At this time, the storage management device will send the first label to the storage controller, so that the storage controller can manage the first data based on the first label and maintain the security of the first data.
[0193] Step S203: The storage controller binds and stores the first label and the first data in the storage device or an external storage device.
[0194] It can be understood that in order for the storage controller to quickly find the label corresponding to the first data, or to quickly determine the correspondence between the data and the label when sharing the first data and the first label. The storage device needs to bind and store the first data and the first label. Specifically, the first data and the first label can be bound and stored in the following way:
[0195] In a possible implementation, the way of binding and storing includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
[0196] In addition to partitioning data to obtain tags for the data, the technical solution provided by this application also supports sharing tags externally and maintaining data security based on tags. Specifically:
[0197] First, sharing of tags. After the storage controller binds and stores the first data and the first tag, if it receives a request from another device to send a message of the first tag, the storage controller can share the first tag, thus facilitating other devices to borrow the result of data partitioning without having to perform data partitioning themselves. Specifically, it can be implemented in the following ways:
[0198] In a possible implementation, the storage controller receives a first message sent by a first device, and the first message indicates to send the first tag; the storage controller responds to the first message and sends the first tag to the first device.
[0199] To enable the first device to receive the first tag, the storage controller sends the first tag to the first device through a tag reading interface. Here, the first device can be a device that needs to share the first tag, or a general application, or a sharing application. A general application refers to an application that does not share the data or the tag with other devices after obtaining the first tag of the first data, and a sharing application refers to an application that also shares the data or the tag with other devices after obtaining the first tag of the first data. In addition, the first device can also obtain the first tag of the first device through a data proxy, and the data proxy can be located in the first device.
[0200] If only the first tag is sent to the first device, the first device cannot determine which data the first tag is the partitioning result of, nor can it know which level or category the first tag belongs to for the data. Therefore, attention needs to be paid to the form of the tags sent externally. Specifically, it can be implemented in the following ways:
[0201] In a possible implementation, when the first tag is stored in the tag file or the metadata of the first data, the storage controller binds the first data and the first tag and sends the bound first data and the first tag to the first device.
[0202] In a possible implementation, when the first tag is stored in the data content of the first data, the storage controller sends the first data to the first device.
[0203] After the first tag and the first data are bound, especially when the first tag is included in the data content, the device that receives the first tag cannot directly obtain the first tag and needs to obtain the first tag through a certain method. Specifically: when the storage controller sends the first tag and the first data to the first device for binding, the first device obtains the first tag and the first data according to the binding relationship, and verifies the first tag and the first data. Only after the verification passes can the data be correctly used; when the storage controller directly sends the first data to the first device and the first tag is carried in the data content of the first data, the first device needs to parse the first data to obtain the first tag carried therein, or parse the first data through a data proxy, and then the data proxy sends the obtained first tag to the first device.
[0204] In addition, in addition to the storage controller that divides the data can manage the tags and share the tags, the device that receives the first data shared by the storage controller can also manage the tags of the first data and provide a tag sharing service externally.
[0205] Second, the maintenance of data security based on tags. Since the importance of data at different levels or of different categories may be different, and the impacts caused by their being damaged may also be different, it is necessary to formulate different ways to maintain data security for data with different tags. Specifically, it includes one or more of the following ways: controlling data access based on tags, storing data with different tags in isolation, transparently encrypting some categories or levels of data, or managing the retention period of high-level data. The following specifically introduces these four ways to maintain data security:
[0206] First, controlling data access based on tags. This protection method is divided into two cases. Case 1: The execution subject of steps S201 - S203 is the storage controller. At this time, the storage controller formulates an access control scheme for the first data according to the first tag. Case 2: The execution subject of steps S201 - S203 is the storage management device. The storage management device can perform a security risk analysis on the stored data and formulate an access control scheme according to the results of the security risk analysis and the tags.
[0207] When the execution subject of steps S201 to S203 is the storage controller. At this time, the access control scheme can be formulated through the following implementation methods:
[0208] In a possible implementation method, the storage controller formulates an access control scheme for the first data according to the first tag, and the access control scheme is a mapping relationship between the type of access behavior and the way to control data access.
[0209] To help understand the above implementation method, here is an example: When the first tag is at the first level, since the level of the data is very high, a more stringent access control scheme needs to be formulated. At this time, the access control scheme that can be specified is: When a user accesses the data at the same time for more than ten days, it is considered that there is a security risk for the data, and the user is prohibited from accessing the data.
[0210] In addition, the access control scheme can also be a mapping relationship between the label of the data, the type of access behavior, and the way to control the data access. For example, the access control scheme is: When the first tag is at the first level, if a user accesses the data at the same time for more than ten days, it is considered that there is a security risk for the data, and the user is prohibited from accessing the data. When the first tag is at the second level, if a user accesses the data at the same time for more than ten days, it is considered that there is a security risk for the data, and the number of times the user accesses the data in the same time period is restricted to no more than 3 times.
[0211] When the execution subjects of steps S201 - S203 are storage management devices. At this time, the access control scheme can be formulated through the following implementation method:
[0212] In a possible implementation method, the storage management device formulates a security policy based on the security risk analysis of the first data; the storage management device formulates the access control scheme of the first data according to the first tag and the security policy, and the access control scheme is a mapping relationship between the type of access behavior and the way to control the data access; the storage management device sends the access control scheme to the storage device.
[0213] To help understand the above implementation method, here is an example: According to the security risk analysis, it is found that there is a security risk for Data 1, and the access behavior of Data 1 needs to be controlled. And Data 1 belongs to the data at the first level, so more stringent control needs to be imposed on the access behavior of Data 1. At this time, any user can be directly prohibited from accessing Data 1, or the user can be prohibited from accessing Data 1 more than 5 times within 5 minutes.
[0214] Among them, the security risk analysis includes: formulating a data map of the first data based on the divided tags; performing compliance analysis on the first data or tracing and auditing the first data. The so-called "formulating a data map of the first data based on the divided tags" means constructing a label reading interface according to the location where the data access behavior occurs and the level of the data. For example, the data map can depict in which areas of the devices the data at the first level is often accessed.
[0215] Second, isolate and store data with different tags. When the storage device needs to obtain data at a certain level or of a certain category, in order to ensure that the storage can quickly obtain the data from the corresponding storage space, a good way to handle this is to store the data according to the data tags when storing the data. Specifically, it can be implemented in the following ways:
[0216] In a possible implementation, the storage controller divides the fourth data according to the target policy to obtain the second tag of the fourth data. The fourth data is stored in the storage device, and the first tag and the second tag are different; the storage controller binds and stores the second tag and the fourth data in the storage device or an external storage device, and the space where the first tag is bound and stored with the first data is isolated from the space where the second tag is bound and stored with the fourth data.
[0217] Third, perform transparent encryption on data of some categories or levels. For data of certain high levels or of relatively high importance, more effective encryption methods are needed to encrypt this data, and the process of data encryption should preferably be imperceptible to the upper-layer applications. Therefore, transparent encryption can be used. Specifically, the storage controller performs transparent encryption on the first data according to the first tag. Further, when the first tag is the category to which the first data belongs, the storage controller determines whether to perform transparent encryption on the first data according to the importance level of this category. Transparent encryption is preferentially performed on data of relatively high importance. When the first tag is the category to which the first data belongs, the storage controller determines whether to perform transparent encryption on the first data according to the level of this level. The storage controller can preferentially perform transparent encryption on highly sensitive data and data with strong destructiveness.
[0218] Fourth, perform retention period management on high-level data. For high-level or highly sensitive data, the longer this type of data is stored on the storage device, the greater the risk of leakage. And once this type of data is leaked, compared with the leakage of other data, the consequences are more serious. Therefore, it is necessary to perform retention period management on the first data with the first tag being high level. When the retention period of this type of data ends, the storage controller automatically deletes this type of data.
[0219] In the embodiments of the present application, the division of the first data is performed by the storage controller of the storage device. The storage controller only receives the target policy and does not participate in the formulation of the target policy, nor does it need to obtain knowledge related to data recognition. Therefore, the storage controller cannot recognize the semantics of the first data. Further, in the embodiments of the present application, the device for formulating the division policy is separated from the device for dividing the data. The storage controller that executes the data division does not need to obtain the knowledge related to data recognition necessary for formulating the division. Therefore, although the storage controller stores the first data, that is, the data to be divided, it cannot recognize the semantics of this data, thus preventing the leakage of information of the data to be divided.
[0220] In addition, by dividing the data through the storage controller in the storage device, since the data is stored in the storage device, compared with dividing the data through other devices, directly dividing the data in the storage device can achieve near-source analysis of the data and reduce the I / O overhead of the data.
[0221] The following combines 2 examples to illustrate the above Figure 2 shown method.
[0222] The following 4 examples are all Figure 2 possible implementation manners of the shown method. Among them, Example 1 is an illustrative example where the execution entity of the method in Figure 2 is the storage controller, and Example 2 is an illustrative example where the execution entity of the method in Figure 2 is the storage management device.
[0223] Example 1
[0224] Example 1 is an illustrative example of data division by the storage device.
[0225] Figure 4 is a schematic diagram of the main functional modules of each device in Example 1, Figure 4 mainly includes the following devices: a third-party device, a storage management device, a storage device, and an application. The functions of each device are as follows:
[0226] The third-party device is used to formulate the target policy and perform the configuration of the target policy. The third-party device can directly configure the target policy in the storage device, or first configure the target policy in the storage management device, and then the storage management device forwards the target policy to the storage device.
[0227] The storage management device is used to manage the data stored in the storage device.
[0228] The storage device is used to store data, divide the stored data, and provide data security protection for near data.
[0229] An application is used to read data from a storage device and use this data for business purposes or data sharing. Specifically, a general application reads the label of the corresponding data in the storage management device through a data security proxy to obtain the data level, and uses the data according to the level; a general application can also directly read the label of the data through the label reading interface of the storage management device; if it is a sharing application, it can read the data encapsulated with labels in the storage management device through the data security proxy module and then perform data sharing; or it can directly read the data encapsulated with labels through the label reading interface of the storage management device and then perform data sharing.
[0230] The following introduces the storage management device and the modules included in the storage management device:
[0231] First, introduce the modules included in the storage management device. The storage management device includes an asset management module, which is used to: manage the data in the storage device, and is also used to connect to a third-party device to obtain a target policy and send it to the storage controller of the storage device.
[0232] Next, introduce the modules included in the storage device. The storage management device includes the following modules: a partitioning module, a label management module, and a label-based security protection module. The functions of each module are as follows:
[0233] First, the partitioning module is used to partition data according to the target policy and accelerate the data partitioning based on the hardware capabilities of the storage management device. Specifically, the partitioning module partitions the data through partitioning algorithms based on regular expressions and AI, etc. The partitioning module can also accelerate the data partitioning process with the help of dedicated hardware.
[0234] Second, the label management module is used to uniformly manage the labels used to describe data in the storage management device. Specifically, it includes: storage of labels: storing the labels in the metadata of the data, or storing them separately as label files, or storing the labels in the data content; encapsulation of data and labels: when the labels are stored in independent files or metadata, when the data is shared, the label management module sends the labels and data associated; when the labels are stored in the data content, the label management module directly sends the data.
[0235] Third, the label-based security protection module is used to perform data security protection on the data in the storage device according to its label. The data security protection methods include but are not limited to: providing a label-based data access control mechanism; transparently encrypting important categories or high-level data in the storage device; isolating and storing the stored data according to levels or categories; or performing retention period management on high-level data and automatically deleting high-level data at the end of the retention period.
[0236] Figure 5 It is a schematic diagram of cooperation among various devices in Embodiment 1. In Figure 5 , the third-party device can configure the target policy in two ways, including: configuring the target policy in the storage management device, and then the storage management device forwards the target policy to the storage device. The other is to configure the target policy in the storage device. After receiving the target policy, the storage device divides the data with the help of dedicated hardware to obtain the labels of the data. Then, it manages the data labels and performs label-based security protection on the stored data. Figure 5 Taking the computing server as an example of the first device in
[0237] Figure 6 It is a schematic diagram of the process of Embodiment 1. Figure 6 The specific process includes:
[0238] Step 601, the third-party device formulates a target policy.
[0239] The third-party device formulates a target policy according to the identification object. For example, the identification object: mobile phone number; the target policy: {regular expression / ^1[3456789]\d{9}$ / , first level}.
[0240] Step 602, the third-party device sends the target policy to the storage management device.
[0241] Specifically, the third-party device can send the target policy to the storage management device through Interface 1.
[0242] Interface 1: The interface for the third-party device to dock with the storage management device interface.
[0243] The protocol based on Interface 1: Hypertext Transfer Protocol (HTTP, hypertext transfer protocol).
[0244] The name of Interface 1: classify Policy.
[0245] The interface parameters of Interface 1:
[0246] Table 1: The interface parameters of Interface 1
[0247] Serial Number Parameter Type Remarks Whether Mandatory 1 Policy Name String None Yes 2 Policy Content String None Yes
[0248] Among them, the interface parameters can also be "rule set name" and "rule set content".
[0249] Return value: Success: 1; Failure: 0; where "Success: 1" means that the target policy is successfully sent, and "Failure: 0" means that the target policy is not sent successfully.
[0250] Step 603: The storage management device sends the target policy to the storage device.
[0251] Specifically, the storage management device can send the target policy to the storage device through Interface 2.
[0252] Interface 2: The interface between the storage management device and the storage device interface:
[0253] The protocol on which Interface 2 is based: Management protocol.
[0254] The name of Interface 2: classifyPolicyCofigure.
[0255] The interface parameters of Interface 2:
[0256] Table 2: The interface parameters of Interface 2
[0257] Serial Number Parameter Type Remarks Whether Mandatory 1 Policy Name String None Yes 2 Policy Content String None Yes
[0258] Among them, the interface parameters can also be "rule set name", "rule set content".
[0259] Return value: Success: 1; Failure: 0; Among them, "Success: 1" means that the target policy is successfully sent, and "Failure: 0" means that the target policy is not sent successfully.
[0260] Step 604: The storage device divides the data according to the target policy to obtain the corresponding label of the data.
[0261] The storage device can accelerate data division with the help of dedicated hardware. Specifically, it includes: The storage controller configures the target policy in the dedicated hardware: constructs a fast data reading protocol between the CPU of the storage device and the dedicated hardware, and the dedicated hardware can quickly read the data into the dedicated hardware, and instructs the dedicated hardware to divide the data according to the target policy. Specifically, in the dedicated hardware, the data division task can be executed through classification or division algorithm components.
[0262] Step 605: The storage device binds the stored data with the corresponding label.
[0263] The storage device binds the stored data with the corresponding label: stores the first label in the metadata of the first data, stores the first label in the label file, or stores the first label in the data content of the first data.
[0264] Step 606: Perform security protection on the data based on the label.
[0265] In a storage device, data is securely protected based on data tags, including isolating and storing data with different tags according to the data tags, controlling users' access behaviors based on the data tags, and transparently encrypting data according to the tags, etc.
[0266] Step 607, the storage device shares tags with the application.
[0267] The application can trigger the storage device to share tags by sending messages or other means. The application can obtain the tags in the storage device in the following ways: A general application reads the tags of the corresponding data in the storage device through a data security proxy to obtain the data level and use the data according to the level; A general application can directly read the tags of the data through the tag reading interface of the storage device; In a sharing scenario, the application can read the data with tags encapsulated in the storage device through a data security proxy module and then perform data sharing; Or the application can directly read the data with tags encapsulated through the tag reading interface of the storage device.
[0268] Step 608, the application reads the tags of the data.
[0269] When the storage controller sends tags and data to the application for binding, the application obtains the tags of the data according to the binding relationship and verifies them. Only after the verification passes can the data be correctly used.
[0270] Optionally, when the storage controller directly sends data to the application and the tag is carried in the data content of the data, the first device needs to parse the data to obtain the tag carried therein, or parse the data through a data proxy, and then the data proxy sends the obtained first tag to the application.
[0271] Optionally, the application that obtains the first tag can control the tags of the shared data and provide the tags externally.
[0272] It can be seen that Example 1 has the following beneficial effects: First, in Example 1, the formulation of the partitioning strategy and the execution of data partitioning are separated. In Example 1, a third-party device formulates the partitioning strategy, and the storage device only serves as the device for executing data partitioning. The storage device does not acquire knowledge related to the semantics of the data, so the storage device cannot understand the semantics of the recognition result, reducing the risk of data leakage. Second, by partitioning the data through the storage controller, near-source analysis of the data is achieved, improving the efficiency of data partitioning, and the storage controller can quickly partition the data through hardware acceleration. Third, in Example 1, data security protection is carried out based on tags, optimizing the data protection method in the storage device. In Example 1, the access behavior of users is controlled based on tags, so that the access behavior of data with a high level or belonging to an important category is more strictly controlled, and this type of data can be protected more effectively. In Example 1, important data is encrypted through transparent encryption, without changing the upper-layer application, and the upper-layer application is unaware of this, and the access method of the application to the data stored in the storage device is not changed. Fourth, in Example 1, data tag management is carried out, which is convenient for other devices to use and manage. The tags obtained by the storage management device can be publicly used externally, and the outside world can directly reuse the partitioning results of the storage management device. The storage device manages the tags of the data, including binding and storing the tags with the data, and also includes that after sharing the data with the application, the application can also manage the tags of the shared data and provide tags externally.
[0273] Example 2
[0274] Example 2 is an example description of data partitioning by the storage management device.
[0275] Figure 7 is a schematic diagram of the main functional modules of each device in Example 2, Figure 7 which includes the following devices: a third-party device, a storage management device, a storage device, and an application. The functions of each device are as follows:
[0276] The third-party device is used to formulate a target strategy and configure the target strategy, where the target strategy can be directly configured in the storage device, or the target strategy can be first configured in the storage management device, and then the storage management device forwards the target strategy to the storage device.
[0277] The storage management device, the main role of the storage management device is to manage the storage device, including configuration, operation and maintenance, etc.
[0278] The storage management device is used to manage the data stored in the storage device.
[0279] An application for reading data from a storage device and using the data for business use or data sharing. Specifically, a general application reads the tags of the corresponding data in the storage management device through a data security proxy to obtain the data level, and uses the data according to the level; a general application can also directly read the tags of the data through the tag reading interface of the storage management device; if it is a sharing application, it can read the data encapsulated with tags in the storage management device through the data security proxy module and then perform data sharing; or it can directly read the data encapsulated with tags through the tag reading interface of the storage management device and then perform data sharing.
[0280] The following introduces the storage management device and the modules included in the storage management device:
[0281] First, introduce the storage management device. The storage management device includes the following modules: a partitioning module, a tag management module, and an asset management module. The functions of each module are as follows:
[0282] First, the partitioning module is used to partition data according to a target policy and accelerate the data partitioning based on the hardware capabilities of the storage management device. Specifically, the partitioning module partitions the data through a partitioning algorithm based on regular expressions and AI, etc. The partitioning module can also accelerate the data partitioning process with the help of dedicated hardware.
[0283] Second, the tag management module is used to uniformly manage the tags used to describe data in the storage management device. Specifically, it includes: storage of tags: storing the tags in the metadata of the data, or storing them separately as a tag file, or storing the tags in the data content; encapsulation of data and tags: when the tags are stored in an independent file or metadata, when the data is shared, the tag management module sends the tags and data associated; when the tags are stored in the data content, the tag management module directly sends the data.
[0284] Third, the asset management module is used to manage the data in the storage device, including data directory, data grading, data life cycle management, etc.; it is also used to protect the data security of the data in the storage management device. Among them, the ways of data security protection include but are not limited to: providing a data access control mechanism based on tags; transparently encrypting important categories or high-level data in the storage device; isolating and storing the stored data according to levels or categories; or performing retention period management on high-level data and automatically deleting high-level data at the end of the retention period.
[0285] Then introduce the storage device. The storage device includes a security management module, which is used to perform access control on the data stored in the storage device. Specifically, after the storage device receives the label sent by the storage management device, it performs access control on the stored data based on the label.
[0286] Figure 8 It is a schematic diagram of the cooperation between various devices in Embodiment 2. In Figure 8 the third-party device configures the target policy in the storage management device. After the storage management device configures the target policy, it divides the data with the help of dedicated hardware to obtain the labels of the data. Then it manages the data labels and performs label-based security protection on the stored data. Figure 8 Taking the computing server as an example of the first device in
[0287] Figure 9 It is a schematic flowchart of Embodiment 2. Figure 9 The specific process includes:
[0288] Step 901, the third-party device formulates a target policy.
[0289] Step 902, the third-party device sends the target policy to the storage management device.
[0290] The above Step 901 and Step 902 are similar to Step 601 and Step 602 in Embodiment 1, and will not be elaborated here.
[0291] Step 903, the storage device sends the data to the storage management device.
[0292] The data in Step 903 is the data that needs to be divided.
[0293] Step 904, the storage management device divides the data according to the target policy to obtain the labels corresponding to the data.
[0294] Step 905, the storage device binds the stored data with the corresponding labels.
[0295] The above Step 904 and Step 905 are similar to Step 604 and Step 605 in Embodiment 1, and will not be elaborated here.
[0296] Step 906, the storage management device performs a security risk analysis on the data.
[0297] This security risk analysis includes: formulating a data map of the data based on the divided labels; performing compliance analysis on the data or tracing and auditing the data.
[0298] Step 907, the storage management device formulates an access control plan according to the result of the security risk analysis and the label of the data.
[0299] The storage management device formulates a security policy according to the security risk analysis of the first data; the storage management device formulates an access control plan for the first data according to the first label and the security policy, and the access control plan is a mapping relationship between the type of access behavior and the way of controlling data access.
[0300] Step 908, the storage management device sends the access control plan to the storage device.
[0301] The storage management device can also send the label of the data and the access control plan to the storage device at the same time, so that the storage device can determine the category or level of the data, as well as the access control plan for this category or level of data.
[0302] Step 909, the storage device controls the access behavior.
[0303] After receiving the access control plan sent by the storage management device, the storage device records the user's access behavior, and when the user's access behavior conforms to the characteristics of the behavior with security risks in the access control plan, the user's behavior is controlled according to the access control plan.
[0304] Step 910, the storage management device shares the label with the application.
[0305] Step 911, the application reads the label of the data.
[0306] The above steps 910 and 911 are the same as steps 607 and 608 in Embodiment 1, and will not be elaborated here.
[0307] As can be seen, Embodiment 2 has the following beneficial effects: First, the formulation of the partitioning strategy is separated from the execution of data partitioning. The partitioning strategy is formulated by a third-party device, and the storage management device only serves as the device for executing data partitioning. The storage management device does not acquire knowledge related to the semantics of the data, so the storage management device cannot understand the semantics of the recognition result, reducing the risk of data leakage. Second, the data is stored in the storage device, and both the storage management device and the storage device belong to the scope of storage services. A data fast reading protocol is usually established between the storage management device and the storage device, and they are usually in the same network. Therefore, compared with data partitioning by other devices, partitioning by the storage management device can quickly obtain the data to be partitioned and quickly implement the partitioning of the data. Third, the data is protected based on tags, optimizing the data protection method in the storage device. In Embodiment 2, a security risk analysis is performed on the data, and the access behavior of the user is controlled based on the tags and the security risk analysis results and tags. Thus, for data with a high user access level or belonging to important categories, as well as data with security risks, the behavior is more strictly controlled, and this type of data can be protected more effectively. Fourth, the data tags are managed, facilitating the use of tags. The tags obtained by the storage management device can be publicly used externally, and the outside world can directly reuse the partitioning results of the storage management device. The storage management device manages the tags of the data, including binding and storing the tags with the data, and also includes that after sharing the data with other storage devices, other storage management devices can also manage the tags of the shared data and provide the tags externally.
[0308] The embodiments of the present application have been described from the perspective of the method above. Next, the communication device in the embodiments of the present application will be introduced from the perspective of the specific device implementation.
[0309] Please refer to Figure 10 , the present application provides a communication device 1000, and this device 1000 includes a transceiver unit 1001 and a processing unit 1002.
[0310] As an implementation example, the communication device 1000 can implement the functions of the storage controller in the above method, so it can also achieve the beneficial effects of the above method. In the present application, the communication device 1000 can be a storage controller, a storage device, or a software module, integrated circuit, or component inside the storage device, such as a chip, without limitation. The following will take the communication device 1000 as a storage controller as an example for description.
[0311] Specifically, the transceiver unit 1001 is configured to receive a target policy, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data. The first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data. The processing unit 1002 is configured to divide the first data according to the target policy to obtain a first label of the first data, where the first data is stored in the storage device. The processing unit 1002 is further configured to bind and store the first label and the first data in the storage device or an external storage device.
[0312] In a possible implementation, the sender of the target policy is a third-party device or a storage management device. The target policy is formulated by the third-party device, and the data stored in the storage device is managed by the storage management device.
[0313] In a possible implementation, the processing unit 1002 is specifically configured to: call the transceiver unit 1001 to send the first data to a dedicated hardware, where the dedicated hardware is configured on the storage device or is independent of the storage device; call the transceiver unit 1001 to send the target policy to the dedicated hardware and instruct the dedicated hardware to divide the first data according to the target policy; call the transceiver unit 1001 to receive the first label sent by the dedicated hardware.
[0314] In a possible implementation, the first data includes second data and third data. The processing unit 1002 is specifically configured to: call the transceiver unit 1001 to send the second data to the dedicated hardware; call the transceiver unit 1001 to send the target policy to the dedicated hardware and instruct the dedicated hardware to divide the second data according to the target policy; call the transceiver unit 1001 to receive the first label of the second data sent by the dedicated hardware; divide the third data according to the target policy to obtain the first label of the third data.
[0315] In a possible implementation, the method of binding and storing includes: storing the first label in the metadata of the first data, storing the first label in a label file, or storing the first label in the data content of the first data.
[0316] In a possible implementation, the transceiver unit 1001 is further configured to: receive a first message sent by a first device, where the first message instructs to send the first label; in response to the first message, send the first label to the first device.
[0317] In a possible implementation, the transceiver unit 1001 is specifically configured to: when the first tag is stored in the tag file or the metadata of the first data, call the processing unit 1002 to bind the first data with the first tag, and send the bound first data and first tag to the first device.
[0318] In a possible implementation, the transceiver unit 1001 is specifically configured to: when the first tag is stored in the data content of the first data, send the first data to the first device.
[0319] In a possible implementation, the processing unit 1002 is further configured to: formulate an access control scheme for the first data according to the first tag, where the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access.
[0320] In a possible implementation, the processing unit 1002 is further configured to: divide the fourth data according to the target policy to obtain a second tag of the fourth data, where the fourth data is stored in the storage device, and the first tag and the second tag are different; bind and store the second tag and the fourth data in the storage device or an external storage device, and the space where the first tag and the first data are bound and stored is isolated from the space where the second tag and the fourth data are bound and stored.
[0321] As another implementation example, the communication device 1000 can implement the functions of the storage management device in the above method, and thus can also achieve the beneficial effects of the above method. In this application, the communication device 1000 can be a storage management device, or a software module, an integrated circuit or a component inside the storage management device, such as a chip, without limitation. The following takes the communication device 1000 being a storage management device as an example for description.
[0322] Specifically, the transceiver unit 1001 is configured to receive a target policy, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; obtain first data from the storage device; the processing unit 1002 is configured to divide the first data according to the target policy to obtain a first tag of the first data; the transceiver unit 1001 is further configured to send the first tag to the storage device.
[0323] In a possible implementation, the processing unit 1002 is further configured to: formulate a security policy based on the security risk analysis of the first data; formulate an access control scheme for the first data according to the first tag and the security policy, where the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access; and call the transceiver unit 1001 to send the access control scheme to the storage device.
[0324] In a possible implementation, the processing unit 1002 is specifically configured to: call the transceiver unit 1001 to send the first data to dedicated hardware, where the dedicated hardware is configured on the storage management device or the dedicated hardware is independent of the storage management device; call the transceiver unit 1001 to send the target policy to the dedicated hardware, and instruct the dedicated hardware to partition the first data according to the target policy; and call the transceiver unit 1001 to receive the first tag sent by the dedicated hardware.
[0325] In a possible implementation, the first data includes second data and third data, and the processing unit 1002 is specifically configured to: call the transceiver unit 1001 to send the second data to the dedicated hardware; call the transceiver unit 1001 to send the target policy to the dedicated hardware, and instruct the dedicated hardware to partition the second data according to the target policy; call the transceiver unit 1001 to receive the first tag of the second data sent by the dedicated hardware; and partition the third data according to the target policy to obtain the first tag of the third data.
[0326] In a possible implementation, the processing unit 1002 is further configured to store the first data in a first manner, where the first manner includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
[0327] In a possible implementation, the transceiver unit 1001 is further configured to: receive a first message sent by a first device, where the first message indicates to send the first tag; and in response to the first message, send the first tag to the first device.
[0328] In a possible implementation, the transceiver unit 1001 is specifically configured to: when the first tag is stored in the tag file or the metadata of the first data, call the processing unit 1002 to bind the first data with the first tag, and send the bound first data and first tag to the first device.
[0329] In a possible implementation, the transceiver unit 1001 is specifically configured to: when the first tag is stored in the data content of the first data, send the first data to the first device.
[0330] In a possible implementation, the processing unit 1002 is further configured to: divide the fourth data according to the target policy to obtain a second label of the fourth data, where the fourth data is stored in the storage device, and the first label is different from the second label; bind and store the second label and the fourth data in the storage device or an external storage device, and the space where the first label and the first data are bound and stored is isolated from the space where the second label and the fourth data are bound and stored.
[0331] As another implementation example, the communication device 1000 can implement the functions of the third-party device in the above method, and thus can also achieve the beneficial effects of the above method. In this application, the communication device 1000 can be a third-party device, or a software module, an integrated circuit or a component inside the third-party device, such as a chip, without limitation. The following will take the communication device 1000 being a third-party device as an example for description.
[0332] Specifically, the transceiver unit 1001 is configured to obtain a first task, where the first task instructs to identify a target object in the first data and divide the first data; the processing unit 1002 is configured to formulate a target policy according to the target object, and the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, where the first judgment rule is a mapping relationship between the composition feature and / or the structural feature of the data and the category of the data, and the second judgment rule is a mapping relationship between the composition feature and / or the structural feature of the data and the level of the data; the transceiver unit 1001 is further configured to send the target policy to the storage device or the storage management device, so that the storage device or the storage management device divides the first data according to the target policy.
[0333] It should be noted that for the content such as the information execution process of the units of the above communication device 1000, please refer to the description in the method shown in the foregoing of this application for details, which will not be elaborated here.
[0334] Figure 11 It is a schematic structural diagram of a communication device 1100 provided by an embodiment of this application. As Figure 11 shown, the communication device 1100 includes: a processor 1101 and a memory 1102.
[0335] The memory 1102 is used to store computer-readable instructions; the processor 1101 is used to call the computer-readable instructions and can execute Figure 2 all or part of the operations of the method shown.
[0336] In a specific implementation, the communication device 1100 may include a communication interface. Among them, the memory 1102, the processor 1101, and the communication interface are communicatively connected to each other. The communication interface is used to implement transceiver operations, and the processor 1101 is used to implement operations other than transceiver operations.
[0337] In the embodiments of the present application, the processor may be, for example, but not limited to any one or more of the following combinations: CPU, network processor (NP), Tensor Processing Unit (TPU), Neural network Processing Unit (NPU), application-specific integrated circuit (ASIC), programmable logic device (PLD). The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor may refer to a single processor or may include multiple processors. The processor may include one or more processing cores, and the processor executes various functional applications and data processing by running computer programs. The processor may be connected to the memory and the communication interface through a communication bus.
[0338] In an embodiment of the present application, the memory may include volatile memory, such as random access memory (RAM). The memory may also include non-volatile memory, such as flash memory, hard disk drive (HDD) or solid-state drive (SSD). The memory may further include a combination of the above types of memory. The memory may refer to a single memory or may include multiple memories. In a specific embodiment, computer-readable instructions are stored in the memory, and the computer-readable instructions include a plurality of software units, such as the transceiver unit 1001 and the processing unit 1002 described above. After the processor executes each software module, it can perform corresponding operations according to the instructions of each software module. In this embodiment, the operations performed by a software module actually refer to the operations performed by the processor according to the instructions of the software module. After the processor executes the computer-readable instructions in the memory, it can perform all or part of the operations that the communication device can perform according to the instructions of the computer-readable instructions.
[0339] In an embodiment of the present application, there may be multiple communication interfaces, and the communication interfaces are used to communicate with other devices. The communication interfaces may include wired communication interfaces, wireless communication interfaces or a combination thereof. Among them, the wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface or a combination thereof, etc.
[0340] In the above embodiments, it can be implemented in whole or in part by hardware, firmware, or any combination thereof. When software is involved in the specific implementation process, it can be embodied in the form of a computer program product in whole or in part. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that includes one or more integrated available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as digital video discs (DVDs)), or semiconductor media (such as SSDs), etc.
[0341] The following gives an example of the system of the embodiments of the present application.
[0342] The embodiments of the present application also provide a communication system, including: a plurality of communication devices, and the plurality of communication devices may include, for example, communication devices for implementing part or all of the operations of any of the above methods.
[0343] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a magnetic disk, or an optical disc, etc.
[0344] In the embodiments of the present application, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0345] The term "and / or" in the present application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0346] The above are only alternative embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concept and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A data processing method, characterized in that, applied to a storage controller of a storage device, the method comprising: receiving a target policy, the target policy including: a first judgment rule for classifying data or a second judgment rule for grading data, the first judgment rule being a mapping relationship between the composition feature and / or the structure feature of the data and the category of the data, and the second judgment rule being a mapping relationship between the composition feature and / or the structure feature of the data and the level of the data; dividing first data according to the target policy to obtain a first label of the first data, the first data being stored in the storage device; binding and storing the first label and the first data in the storage device or an external storage device.
2. The data processing method according to claim 1, characterized in that, the sender of the target policy is a third-party device or a storage management device, the target policy is formulated by the third-party device, and the data stored in the storage device is managed by the storage management device.
3. The data processing method according to claim 1 or 2, characterized in that, the dividing the first data according to the target policy includes: sending the first data to dedicated hardware, the dedicated hardware being configured on the storage device or the dedicated hardware being independent of the storage device; sending the target policy to the dedicated hardware and instructing the dedicated hardware to divide the first data according to the target policy; receiving the first label sent by the dedicated hardware.
4. The data processing method according to claim 3, characterized in that, the first data includes second data and third data, and the dividing the first data according to the target policy includes: sending the second data to the dedicated hardware; sending the target policy to the dedicated hardware and instructing the dedicated hardware to divide the second data according to the target policy; receiving the first label of the second data sent by the dedicated hardware; dividing the third data according to the target policy to obtain the first label of the third data.
5. The data processing method according to any one of claims 1 to 4, characterized in that, the manner of binding and storing includes: storing the first label in the metadata of the first data, storing the first label in a label file, or storing the first label in the data content of the first data.
6. The data processing method according to any one of claims 1 to 5, characterized in that, after obtaining the first label of the first data, the method further includes: receiving a first message sent by a first device, the first message instructing to send the first label; responding to the first message and sending the first label to the first device.
7. The data processing method according to claim 6, characterized in that, the sending the first label to the first device includes: When the first tag is stored in the tag file or the metadata of the first data, bind the first data to the first tag, and send the bound first data and first tag to the first device.
8. The data processing method according to claim 6, wherein, sending the first tag to the first device includes: when the first tag is stored in the data content of the first data, sending the first data to the first device.
9. The data processing method according to any one of claims 1 to 8, wherein, after obtaining the first tag of the first data, the method further includes: formulating an access control scheme for the first data according to the first tag, where the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access.
10. The data processing method according to any one of claims 1 to 9, wherein, after receiving the target policy, the method further includes: dividing the fourth data according to the target policy to obtain a second tag of the fourth data, where the fourth data is stored in the storage device, and the first tag and the second tag are different; binding and storing the second tag and the fourth data in the storage device or an external storage device, and the space where the first tag and the first data are bound and stored is isolated from the space where the second tag and the fourth data are bound and stored.
11. A data processing method, wherein, applied to a storage management device, the method includes: receiving a target policy, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data, the first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; obtaining first data from the storage device; dividing the first data according to the target policy to obtain a first tag of the first data; sending the first tag to the storage device.
12. The data processing method according to claim 11, wherein, after obtaining the first data from the storage device, the method further includes: formulating a security policy according to the security risk analysis of the first data; after obtaining the first tag of the first data, the method further includes: formulating an access control scheme for the first data according to the first tag and the security policy, where the access control scheme is a mapping relationship between the type of access behavior and the way of controlling data access; sending the access control scheme to the storage device.
13. The data processing method according to claim 11 or 12, wherein, dividing the first data according to the target policy includes: sending the first data to dedicated hardware, where the dedicated hardware is configured on the storage management device or the dedicated hardware is independent of the storage management device; Send the target policy to the dedicated hardware and instruct the dedicated hardware to partition the first data according to the target policy; Receive the first tag sent by the dedicated hardware.
14. The data processing method according to claim 13, wherein, The first data includes second data and third data. The partitioning of the first data according to the target policy includes: Send the second data to the dedicated hardware; Send the target policy to the dedicated hardware and instruct the dedicated hardware to partition the second data according to the target policy; Receive the first tag of the second data sent by the dedicated hardware; Partition the third data according to the target policy to obtain the first tag of the third data.
15. The data processing method according to any one of claims 11 to 14, wherein, After obtaining the first tag of the first data, the method further includes: Store the first data in a first manner, and the first manner includes: storing the first tag in the metadata of the first data, storing the first tag in a tag file, or storing the first tag in the data content of the first data.
16. The data processing method according to any one of claims 11 to 15, wherein, After obtaining the first tag of the first data, the method further includes: Receive a first message sent by a first device, and the first message instructs to send the first tag; In response to the first message, send the first tag to the first device.
17. The data processing method according to claim 16, wherein, The sending the first tag to the first device includes: When the first tag is stored in the tag file or the metadata of the first data, bind the first data and the first tag, and send the bound first data and first tag to the first device.
18. The data processing method according to claim 16, wherein, The sending the first tag to the first device includes: When the first tag is stored in the data content of the first data, send the first data to the first device.
19. The data processing method according to any one of claims 11 to 18, wherein, After receiving the target policy, the method further includes: Partition the fourth data according to the target policy to obtain a second tag of the fourth data. The fourth data is stored in the storage device, and the first tag and the second tag are different; Bind and store the second tag and the fourth data in the storage device or an external storage device, and the space where the first tag and the first data are bound and stored is isolated from the space where the second tag and the fourth data are bound and stored.
20. A policy formulation method, wherein, Applied to a third-party device, the method includes: Obtain a first task, and the first task instructs to identify a target object in the first data and partition the first data; Formulate a target policy according to the target object, where the target policy includes: a first judgment rule for classifying data or a second judgment rule for grading data. The first judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the category of the data, and the second judgment rule is a mapping relationship between the compositional features and / or structural features of the data and the level of the data; Send the target policy to the storage device or the storage management device so that the storage device or the storage management device divides the first data according to the target policy.
21. A communication device, Characterized in that, It includes: A communication interface and a processor; The communication interface and the processor execute the method according to any one of claims 1 to 10.
22. A communication device, Characterized in that, It includes: A communication interface and a processor; The communication interface and the processor execute the method according to any one of claims 11 to 19.
23. A communication device, Characterized in that, It includes: A communication interface and a processor; The communication interface and the processor execute the method according to claim 20.
24. A communication device, Characterized in that, It includes: A transceiver unit for performing the transceiver operations in the method according to any one of claims 1 to 10; A processing unit for performing operations other than the transceiver operations in the method according to any one of claims 1 to 10.
25. A communication device, Characterized in that, It includes: A transceiver unit for performing the transceiver operations in the method according to any one of claims 11 to 19; A processing unit for performing operations other than the transceiver operations in the method according to any one of claims 11 to 19.
26. A communication device, Characterized in that, It includes: A transceiver unit for performing the transceiver operations in the method according to claim 20. A processing unit for performing operations other than the transceiver operations in the method according to claim 20.
27. A computer-readable storage medium, Characterized in that, The medium stores instructions that, when executed by a processor, implement the method according to any one of claims 1 to 20.
28. A computer program product, Characterized in that, It includes instructions that, when running on a processor, execute the method according to any one of claims 1 to 20.
29. A communication system, Characterized in that, The system includes the communication device according to claim 21 or 24, the communication device according to claim 22 or 25, and the communication device according to claim 23 or 26.