Method for guaranteeing information exchange security in data environment
By adopting the "zero trust" mechanism and the "verification first and connection" security policy during the data exchange process, the problem of insufficient traditional data protection measures is solved, the security and compliance of the data exchange process is achieved, the data access process is simplified, and the efficiency of cross-organization collaboration is improved.
Patent Information
- Application Number
- CN202510195545.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-10-23
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-13
AI Technical Summary
In modern and complex cross-domain data exchange scenarios, traditional data protection measures are not enough to deal with cyber attacks and internal threats, especially in multi-party collaboration, remote work and cloud computing environments, data security and compliance are difficult to guarantee.
Adopt the "zero trust" mechanism and through the "verification first and connection" security policy, ensure that each data access is strictly authenticated, a data access control policy is generated, and data access is audited in real time to ensure the security and compliance of the data exchange process.
Through strict identity authentication and access control, minimize the risk of cyber attacks and internal threats, prevent unauthorized access, simplify data access processes, and improve the efficiency and convenience of cross-organization collaboration.
Smart Images

Figure CN120150989A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security and information exchange, and specifically provides a method for ensuring the security of information exchange in a data environment. Background Art
[0002] With the acceleration of digital transformation, data has become the core asset of enterprises and institutions. At the same time, the cross-border circulation and sharing of data have increased day by day, which while promoting information exchange and business innovation, also brings unprecedented security challenges. Traditional data protection measures usually rely on boundary protection and fixed security policies, but in modern complex cross-domain data exchange scenarios, these measures are no longer sufficient.
[0003] Current security architectures generally assume that the internal network is trustworthy and protect data circulation in a trust boundary manner. However, as the boundaries between internal and external enterprise networks gradually blur, this "default trust" model poses huge risks. Especially in multi-party collaboration, remote work, and cloud computing environments, where data is frequently exchanged between different organizations, vulnerabilities in any link may lead to the leakage or tampering of sensitive data.
[0004] In addition, the continuous development of network attack technologies, as Figure 1 shown, has made traditional firewalls and defense strategies gradually ineffective. Attackers can break through traditional boundary protection through various means, bypass security measures using system vulnerabilities, phishing attacks, etc., and even hide their traces during the attack, posing a great potential threat to data security.
[0005] To address these new security challenges, the zero-trust architecture has gradually become an important development direction in the field of data protection. Zero trust requires strict identity authentication and access control regardless of whether the data request comes from inside or outside. This concept breaks through the limitations of traditional security models and provides a more flexible and controllable security protection method, especially in the complex environment of cross-border data flow and sharing.
[0006] However, the implementation of the zero-trust model is not without challenges. In a dynamic and heterogeneous modern network environment, implementing fine-grained access control and real-time authentication requires handling a large number of identity authentication, authorization, and data auditing issues, which places higher requirements on the scalability and flexibility of the technology. Therefore, how to ensure the security and compliance of the data exchange process while guaranteeing the convenience of data sharing has become an urgent technical problem to be solved. Summary of the Invention
[0007] In view of the problems in the background art, the present invention provides a method for ensuring the security of information exchange in a data environment, and the technical solution includes the following steps:
[0008] Release data, generate a data link, and initiate a verification request before accessing the protected data;
[0009] Receive the verification request and parse it to obtain user information, aggregate the user information and find the corresponding institution to initiate a query;
[0010] Authenticate and verify based on the user information, and return an identity authentication statement;
[0011] Notify the authorized user to access with the identity authentication statement and identity information, generate a data access control policy, return the authorization information, and access the data according to the real data identification address.
[0012] The beneficial effects of the present invention are as follows:
[0013] 1. Enhance data security: Based on the "zero trust" mechanism, the present invention adopts a security policy of "verify first and then connect" to ensure that each data access undergoes strict identity verification, minimizing the risks of cyberattacks and internal threats.
[0014] 2. Prevent unauthorized access: Data users cannot directly obtain the real address of the protected data and can only access the data after passing the identity verification. This design effectively prevents unauthorized access and potential attack behaviors, enhancing the security during the data sharing process.
[0015] 3. Simplify the data access process: By automatically generating accurate access control policies and auditing data access in real time, the present invention simplifies the data sharing process while ensuring security, improving the efficiency and convenience of cross-organization collaboration. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a diagram of a traditional network security model.
[0017] Figure 2 It is a schematic flowchart of an embodiment of a method for ensuring secure information exchange in a data environment according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The present invention will be further described in detail below with reference to the accompanying drawings.
[0019] As Figure 2 shown in the embodiment of the present invention, it includes:
[0020] Definition of participants and data roles:
[0021] Data Consumer: A data consumer refers to an individual or organization that requests access to and utilizes data in the data space. Data consumers typically need to verify their identities to ensure they have the right to access specific data resources. In the present invention, the access rights of data consumers are strictly controlled by the verification mechanism, and unauthenticated users cannot obtain any data.
[0022] Data Provider: The data provider is responsible for publishing and sharing data in the data space. The role of the data provider is to ensure the confidentiality, integrity, and availability of the data, while controlling which users can access the data. The data provider sets strict access conditions for the use of the data to ensure that the data is not accessed by unauthorized entities.
[0023] Data Resource: In the present invention, a data resource refers to the set of all accessible data in the data space. This data can be structured (such as database records) or unstructured (such as text files, video files, etc.). The data provider publishes the data and controls access to the data, ensuring that the data is only available to authenticated users. User Verification Module: It is the core that processes and verifies user identity requests. It is responsible for verifying requests and interacting with the user identity management module to implement the authentication operation. On the other hand, it is also responsible for controlling the access control module to perform data usage control operations.
[0024] Core Function Module:
[0025] Identity Authentication Module: This module is one of the core components of the present invention and is responsible for verifying the identity of users who request access to data. Each time a data consumer initiates a request, the identity authentication module interfaces with an external identity authentication service and verifies the legitimacy of the data consumer through various authentication methods (such as passwords, certificates, or multi-factor authentication, etc.).
[0026] Access Control Module: The access control module monitors all access requests to data resources in real time. After the data consumer passes the identity authentication, the access control module decides whether to allow the user to access the data. By default, all access requests are rejected, and only after successfully passing the identity authentication and having the permissions authorized, will the access control module unlock the corresponding data resources.
[0027] Permission Management Module: This module is responsible for dynamically managing the permissions of data consumers. It determines the scope of resources that data consumers can access and the usage methods based on the settings of the data provider and the results of user identity verification. At the same time, it also manages the effective time of access to ensure that the time window for data access is limited to the authorized validity period.
[0028] Data Access Process:
[0029] When a data consumer initiates a request, it first submits an authentication request through the user authentication module. This module interacts with an external authentication service to verify whether the user's identity is legal. If the verification passes, the system generates an identity statement and passes it to the access control module. The access control module determines whether to allow access to the data based on the identity statement and the user's permissions. Only after passing the identity authentication and permission verification can the data consumer obtain the real address of the data and access the corresponding data resources.
[0030] Successful authentication: After the authentication passes, the access control module will, according to the pre-determined access control policy, allow the data consumer to access specific data resources, and will record the duration and method of each access.
[0031] Authentication failure: If the user's identity fails to pass the authentication, the system will directly reject the access request and return an error message to ensure that unauthorized users cannot access any data.
[0032] System security design:
[0033] The present invention ensures the security of the data exchange process within the data space through strict identity authentication and access control. All data requests must go through authentication and authorization, avoiding the risks of unauthorized access and information leakage. The system adopts a "zero trust" model, and both internal users and external users need to undergo identity authentication and authorization. Each data access is regarded as a potential threat, and only after the authentication passes can the access be released.
[0034] Identity protection: When all data consumers access data, they cannot directly obtain the real address or resource link of the data. Only after passing the identity authentication and obtaining authorization will they obtain the real access address, which can prevent the data from being obtained by malicious users or unauthorized personnel.
[0035] Dynamic access control: The access permissions change dynamically according to the requirements of the data provider, and the system can flexibly set the access duration and specific access methods. The permissions of each data consumer may vary at different times and in different situations, so as to better meet various changing security requirements.
[0036] Security guarantee:
[0037] The design of the present invention fully considers potential risks such as cyber attacks and data leakage. Through the "verify first then connect" security mechanism, data resources will not be exposed to any user or system before being verified. This way significantly reduces the risk that the data may be attacked at the initial stage of connection, ensuring the security and compliance of each data interaction.
[0038] This embodiment also relates to an electronic device and a storage medium. The electronic device includes a memory, a processor, and a computer program stored in the memory. When the processor executes these programs, the method for secure data interaction in a data space proposed by the present invention can be implemented. Specifically, the processor executes relevant steps according to program instructions to ensure the smooth implementation of operations such as secure data transmission, access control, and identity authentication.
[0039] In addition, the present invention also provides a storage medium, which contains a computer program. When the computer program is executed on a processor, it will implement the data security interaction method in the data space. The storage medium can be various common storage devices, such as a hard disk, a solid state drive, an optical disk, a USB flash drive, etc., all of which can store the program code required to execute the method of the present invention.
[0040] This invention introduces a "Zero Trust" security model, which specifically implements the principle of "verify first, connect later". The core of this security strategy is that any user or device, whether from inside or outside, is not trusted by default and must undergo strict identity authentication and authorization before gaining access rights. This mechanism significantly reduces the security risks caused by unverified connections, especially at the network level, preventing potential malicious attackers from breaking through the defense line by "connecting first, verifying later".
[0041] In this way, only legitimate users who have passed authentication can connect to data resources, and unauthenticated users or devices will not be able to access server resources, thus avoiding various network attacks such as man-in-the-middle attacks, unauthorized data access, etc. This "zero trust" mechanism ensures the security and reliability of data interaction, whether in the internal network or across external boundaries.
[0042] The embodiment of the present invention provides a method based on the above modules, comprising the following steps: generating a data link while publishing data, and initiating a verification request before accessing the protected data;
[0043] Receive verification requests and parse them, obtain user information, aggregate user information and find the corresponding organization to initiate a query;
[0044] Identify and authenticate user information based on the query results returned by the corresponding institution;
[0045] It then performs identification and authentication based on the user information and returns an identity authentication statement;
[0046] Carry an identity authentication statement and identity information to notify the authorized user to access, generate a data access control policy, return authorization information, and access data according to the real data identification address.
[0047] The implementation form of the method can be realized in various forms, including pure hardware implementation, pure software implementation, or a combination of hardware and software. Specifically, the technical solution of the present invention can be realized in the form of a computer program product, and the computer program product can be stored on various computer-readable media, such as disks, optical discs, USB storage devices, cloud storage, etc.
[0048] In specific implementation, the program code can be written in various programming languages, such as Java, C++, Python, etc. According to different application requirements, the program can run on various devices such as general-purpose computers, special-purpose computers, and embedded systems. All these devices can execute the instructions in the program through the processor, thereby realizing the various functions of data security interaction.
[0049] The computer program in the present invention can be deployed and used in various ways. Specifically, the computer program instructions can be loaded into general-purpose computers, special-purpose computers, embedded devices, etc., and the processors of these devices execute the program instructions, thereby realizing the various operations and functions defined in the present invention. These program instructions can be transmitted to the device through a transmission medium, or can be imported into the device by means of online update or local installation.
[0050] The program instructions can not only execute each step in the data interaction process, but also dynamically adjust and optimize the security policy of data access according to specific requirements. For example, when the system detects a potential security threat, the program can update the data access permissions in real time to block non-compliant access requests. All instructions and operations are executed in the device, and the operation logs are recorded in real time during the execution process for subsequent auditing and analysis.
[0051] Although the above embodiments are described based on specific technologies and implementation methods, those skilled in the art should be aware that based on the core innovative idea of the present invention, it is completely possible to modify and change the specific implementation details. These changes and modifications include, but are not limited to, improving algorithms, optimizing data storage methods, adding new verification methods, etc. All of these should be regarded as part of the present invention.
[0052] Therefore, the protection scope of the present invention is not limited to the specific embodiments described, but should cover all changes and modifications that fall within the scope of the appended claims and their equivalent technologies. Those skilled in the art can flexibly adjust the present invention according to specific requirements in different hardware platforms and application environments to achieve the best security interaction effect.
Claims
1. A method for ensuring information exchange security in a data environment, characterized in that: The following steps are involved: Publish data, generate data links, and initiate verification requests before accessing protected data; Receive verification requests and parse them, obtain user information, aggregate user information and find the corresponding organization to initiate a query; Perform identification and authentication based on user information and return an identity authentication statement; It carries the identity authentication statement and identity information to notify the authorized user of access, generates a data access control policy, returns the authorization information, and accesses the data according to the real data identification address.
2. A method for ensuring information exchange security in a data environment according to claim 1, characterized in that: The data environment may include structured data, unstructured data, semi-structured data, document files, databases, data streams, and related service interfaces.
3. A method for ensuring information exchange security in a data environment according to claim 1, characterized in that: The authorization information contained in the data access permission policy includes a unique security token and a valid identification address of the corresponding data.
4. A method for ensuring information exchange security in a data environment according to claim 1, characterized in that: The generation of data links is performed during the data publishing process.
5. A method for ensuring information exchange security in a data environment according to claim 1, characterized in that: The identification and authentication according to the user identity information is based on the query results returned by the corresponding organization.
6. A method for ensuring information exchange security in a data environment according to any one of claims 1 to 5, characterized in that: Each step in the method is implemented when a computer program is executed on a processor, and the computer program is stored in an executable storage medium.