Data delivery method and device based on trusted space and medium
By building a one-way data transmission channel between the production library and the delivery library, and performing multi-level encryption and integrity tests in the trusted computing space, the problem that traditional data transmission technology is difficult to ensure the security of data transmission is solved, and the entire data delivery process is safe and controllable.
Patent Information
- Application Number
- CN202510284875.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-07-01
AI Technical Summary
When traditional data transmission technology faces complex network attacks, it is difficult to fully ensure the security and controllability of the data transmission process, especially in data transmission scenarios between production and delivery databases.
By building a one-way data transmission channel between the production library and the delivery library, and performing multi-level encryption and integrity tests in the trusted computing space, we ensure that data can only flow from the production library to the delivery library, eliminating the risk of reverse transmission.
It realizes the security and controllability of the entire data delivery process, ensures the confidentiality and integrity of data during transmission through multiple technical means, and provides reliable data delivery guarantees for areas with high security requirements.
Smart Images

Figure CN120238337A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and particularly to a data delivery method, apparatus, and device based on a trusted space. Background Art
[0002] With the rapid development of information technology and the popularization of the Internet, the transmission and delivery of data have become increasingly important in various business applications. However, during the process of data transmission and delivery, security issues have always been challenges that cannot be ignored. Whether it is the protection of personal privacy data or the transmission of enterprise sensitive information, data faces many potential security risks when crossing different network environments, such as data leakage, tampering, forgery, etc.
[0003] Traditional data transmission technologies usually rely on encryption algorithms and access control mechanisms to ensure the confidentiality, integrity, and access rights of data. However, these methods often have certain limitations in practical applications, especially in the data transmission scenario between the production database and the delivery database. Although encryption can ensure the confidentiality of data during transmission, it cannot effectively prevent data from being tampered with or lost during transmission, and the access control mechanism depends on trusted authentication. Once an attacker successfully bypasses the authentication mechanism, the data may be exposed to an untrusted environment. Therefore, traditional security protection measures are difficult to fully guarantee the security and controllability of the data transmission process in the face of complex network attacks. Summary of the Invention
[0004] To solve the above problems, this application proposes a data delivery method based on a trusted space, which is applied within the trusted space. The method includes:
[0005] Determine the production database and the delivery database for data delivery, and build a one-way data transmission channel between the production database and the delivery database;
[0006] Obtain the data to be delivered in the production database, and perform multi-level encryption on the data to be delivered;
[0007] Through the one-way data transmission channel, transmit the encrypted data to be delivered to the delivery database to obtain the delivered data, and perform an integrity test on the delivered data;
[0008] When it is determined that the delivered data is complete, delete the copy of the data to be delivered in the production database.
[0009] On the other hand, this application also proposes a data delivery device based on a trusted space, including:
[0010] At least one processor; and,
[0011] A memory communicatively connected to the at least one processor; wherein,
[0012] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the data delivery method based on a trusted space as described in the above example.
[0013] On the other hand, the present application also proposes a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are configured to be the data delivery method based on a trusted space as described in the above example.
[0014] The data delivery method based on a trusted space proposed by the present application can bring the following beneficial effects:
[0015] From data extraction, transmission to delivery, security protection measures are implemented throughout the process. Through multiple technical means such as a trusted computing space, a one-way transmission channel, encryption verification, access control, an audit mechanism, and data destruction, the entire process of data delivery is made secure and controllable, providing reliable data delivery guarantee for fields with high security requirements.
[0016] Implemented based on a hardware-level trusted execution environment to ensure the security and trustworthiness of the data transmission environment. Through hardware isolation technology and a data flow control mechanism, it is ensured that data can only flow from the production library to the delivery library, eliminating the risk of reverse transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0018] Figure 1 It is a schematic flow chart of a data delivery method based on a trusted space in an embodiment of the present application;
[0019] Figure 2 It is a schematic flow chart of the specific process of data delivery in an embodiment of the present application;
[0020] Figure 3 It is a schematic flow chart of the transmission of specific service data in an embodiment of the present application;
[0021] Figure 4 It is a schematic diagram of a data delivery device based on a trusted space in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments of this application and the corresponding drawings. Apparently, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0023] The technical solutions provided by each embodiment of this application will be described in detail below in conjunction with the drawings.
[0024] As Figure 1 shown, an embodiment of this application provides a data delivery method based on a trusted space, including:
[0025] S101: Determine the production library and the delivery library for data delivery, and build a one-way data transmission channel between the production library and the delivery library.
[0026] Specifically, determine the production library and the delivery library for data delivery, where the production library is the source of data and the delivery library is the receiving target of data delivery. Through hardware isolation technology (such as a one-way network gateway) and a data flow control mechanism, a one-way data transmission channel is built between the production library and the delivery library to ensure that data can only flow from the production library to the delivery library at the physical and logical levels, eliminating the security risks brought by reverse transmission.
[0027] In the embodiment of this application, the one-way data transmission channel supports a data fragmentation transmission mechanism, which divides the data into multiple segments for separate transmission, thereby reducing the risk of data leakage caused by a single point of failure.
[0028] It should be noted that, as Figure 2 shown, before data transmission, a trusted computing space is built between the production library and the delivery library based on a hardware-level trusted execution environment (TEE), and through the computer's hardware encryption module and secure boot mechanism, the operating environment of the computing space and the permissions of accessing users are dynamically verified, which can effectively resist malicious software intrusion and illegal tampering by unauthorized users, ensuring a highly trusted data transmission environment.
[0029] S102: Obtain the data to be delivered in the production library and perform multi-level encryption on the data to be delivered.
[0030] Specifically, obtain the data to be delivered in the production database, obtain the first hash value of the data to be delivered through a hash algorithm, and perform multi-level encryption on the data to be delivered through a symmetric encryption algorithm and an asymmetric encryption algorithm to ensure the confidentiality of the data during transmission. Even if the data is intercepted, it is difficult for an attacker to decrypt and obtain the information therein.
[0031] In the embodiments of the present application, the encryption strength can also be dynamically adjusted in real time according to the data sensitivity level. Specifically, the data is classified according to the sensitivity level, and for data with different sensitivity levels, corresponding encryption algorithms and encryption strengths are preset. For example, for highly sensitive data, an encryption algorithm with high encryption strength and good security is selected, such as using the AES-256-bit encryption algorithm, and the AES key is encrypted with the RSA-4096-bit key. At the same time, the status and environmental changes of the data to be delivered in each link during the transmission process are monitored in real time.
[0032] During the data transmission process, if abnormal fluctuations in the network are detected, or potential attack risks are detected, for highly sensitive data, the encryption strength will be further increased, such as increasing the number of encryption rounds, updating the key, etc. When the data is transmitted from an environment with a high security level to an environment with a relatively low security level, the system will automatically adjust the encryption strength to adapt to the security requirements of the new environment while ensuring the accessibility and processing efficiency of the data.
[0033] Obtain the key information during the transmission process. The key information includes the transmission time, the operating entity, the data identifier, and the data volume. Based on the key information, a corresponding digital signature is generated through an asymmetric encryption algorithm, and the key information and the corresponding digital signature are stored in the transmission log.
[0034] For example, in the hospital's patient diagnosis and treatment database (production database), data such as patient medical records and examination reports are stored. The data selected for medical research is used as the data to be delivered. Then, a multi-level encryption method combining symmetric encryption (such as AES) and asymmetric encryption (such as RSA) is adopted. First, the AES algorithm is used to quickly encrypt a large amount of data to improve the encryption efficiency; then the RSA algorithm is used to encrypt the AES key to ensure the security of the key.
[0035] S103: Through the one-way data transmission channel, transmit the encrypted data to be delivered to the delivery library to obtain the delivered data, and perform an integrity test on the delivered data.
[0036] Specifically, through the pre-constructed one-way data transmission channel, the encrypted data to be delivered is transmitted to the delivery library to form the delivered data. The integrity of the delivered data is verified through a hash algorithm (such as SHA-256) to ensure that the data has not been tampered with during the transmission process.
[0037] During the data transmission process, it also includes: extracting the key features of the encrypted data to be delivered, performing feature analysis on the key features, and based on the analysis results, determining whether there is an abnormality in the transmission process. Among them, the key features include the ciphertext length and character frequency distribution of the encrypted data to be delivered. Comparing the ciphertext length and character frequency distribution with a pre-trained benchmark model to obtain a comparison deviation, and determining whether the comparison deviation is higher than a preset threshold. If so, it is determined that an abnormality has occurred in the transmission process, the transmission is paused and an alarm is triggered. If not, the transmission continues until all the encrypted data to be delivered is transmitted to the delivery library.
[0038] It should be noted that under normal circumstances, the ciphertext length and character frequency of the same type of encrypted data will show a certain pattern. If these statistical features show obvious abnormalities during the transmission process, such as a sudden significant increase in the ciphertext length or a significant change in the character frequency distribution, it may indicate the existence of abnormal data access or tampering behavior.
[0039] Furthermore, obtain the first hash value corresponding to the data to be delivered, obtain the second hash value of the delivered data through a hash algorithm, compare the first hash value with the second hash value, and determine whether they are consistent. If so, it is determined that the delivered data is complete. If not, it is determined that the delivered data is incomplete and there is a risk of tampering. Generate an exception report based on the tampering risk and send the exception report to the management personnel.
[0040] S104: When it is determined that the delivered data is complete, delete the copy of the data to be delivered in the production library.
[0041] Specifically, when it is determined that the delivered data is complete, trigger a data destruction event, query all the data to be delivered in the production library, and use a secure deletion algorithm (such as DoD 5220.22-M) to irreversibly delete all the data to be delivered. The algorithm can overwrite the data storage area multiple times to make the original data irrecoverable, effectively preventing security risks brought by data residue.
[0042] It should be noted that the embodiment of the present application also includes a data destruction verification function. After the data deletion operation is executed, the data storage area is detected to ensure that the data copy is completely deleted and irrecoverable, preventing security risks brought by data residue. Specifically, when detecting the data storage area, on the one hand, the storage medium will be scanned to check whether there are still recognizable original data features in the original data area. For example, checking file header information, specific data structures, etc. On the other hand, the internal storage status information of the storage device is obtained through the management interface of the storage device to check whether the data blocks have been truly released or overwritten. Through data overwrite technology, that is, using random characters or specific patterns to overwrite the original data storage area multiple times to make the original data irrecoverable. For example, in a solid-state drive, combined with the TRIM instruction, the main control chip knows which storage units can be erased, further ensuring data destruction.
[0043] As Figure 3 shown, consumer-related sensitive business programs are encapsulated into program blind boxes (JAR files), and the programs run in a managed state. At the same time, the data analysis results enter the system through the regulatory white box in formats such as JSON, XML, and BSON. The regulatory white box will perform secure access, review, and traffic supervision on the data. The data delivery library is within the trusted computing space and contains various e-commerce-related data repositories such as network retail summary data and agricultural product summary data, such as e-commerce enterprise libraries and e-commerce store libraries, and finally forms a business topic library. Consumer data is processed by sensitive business programs and enters the data delivery library within the trusted computing space after being subject to multiple supervisions by the regulatory white box, ensuring the security and compliance of the data delivery process. The processed results can be output for consumers to use.
[0044] In the embodiments of the present application, security protection measures are implemented throughout the process from data extraction, transmission to delivery. Through multiple technical means such as trusted computing space, unidirectional transmission channels, encryption verification, access control, audit mechanisms, and data destruction, the entire process of data delivery is made secure and controllable, providing reliable data delivery guarantees for fields with high security requirements.
[0045] Implemented based on a hardware-level trusted execution environment to ensure the security and trustworthiness of the data transmission environment. Through hardware isolation technology and data flow control mechanisms, it is ensured that data can only flow from the production library to the delivery library, eliminating the risk of reverse transmission.
[0046] As shown in Figure 4, the embodiments of the present application also propose a data delivery device based on a trusted space, including:
[0047] At least one processor; and,
[0048] A memory communicatively connected to the at least one processor; wherein,
[0049] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a data delivery method based on a trusted space as described in any of the above embodiments.
[0050] The embodiments of the present application also provide a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are set to: a data delivery method based on a trusted space as described in any of the above embodiments.
[0051] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device and medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments.
[0052] The devices and media provided in the embodiments of this application correspond one by one to the methods. Therefore, the devices and media also have beneficial technical effects similar to those of their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be elaborated here.
[0053] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0054] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a combination of multiple flows and / or blocks
[0055] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more of the flows Figure 1 or a combination of multiple flows and / or blocks
[0056] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0057] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0058] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of a computer-readable medium.
[0059] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can be implemented by any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0060] It should also be noted that the term "comprises", "comprising" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0061] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A data delivery method based on a trusted space, characterized in that: Applied in a trusted space, the method comprises: Determine a production library and a delivery library for data delivery, and build a one-way data transmission channel between the production library and the delivery library; Acquire the data to be delivered in the production library, and perform multi-level encryption on the data to be delivered; The encrypted data to be delivered is transmitted to the delivery library through the one-way data transmission channel to obtain the post-delivery data, and the post-delivery data is subjected to an integrity test; When it is determined that the delivered data is complete, the copy of the data to be delivered in the production library is deleted.
2. According to the data delivery method based on trusted space in claim 1, it is characterized in that: The obtaining of the data to be delivered in the production library and multi-level encryption of the data to be delivered specifically includes: Acquire the data to be delivered in the production database, and acquire a first hash value of the data to be delivered by using a hash algorithm; The data to be delivered is encrypted at multiple levels using symmetric encryption algorithms and asymmetric encryption algorithms.
3. A data delivery method based on a trusted space according to claim 2, characterized in that: The integrity test of the post-delivery data specifically includes: Obtaining a first hash value corresponding to the data to be delivered; Obtain a second hash value of the post-delivery data by using a hash algorithm, and compare the first hash value with the second hash value to determine whether they are consistent; If so, it is determined that the post-delivery data is complete; If not, it is determined that the post-delivery data is incomplete and there is a risk of tampering, an exception report is generated based on the tampering risk, and the exception report is sent to the management personnel.
4. The data delivery method based on a trusted space according to claim 1, characterized in that: The step of transmitting the encrypted data to be delivered to the delivery library through the unidirectional data transmission channel specifically includes: Transmitting the encrypted data to be delivered through the unidirectional data transmission channel; Extracting key features of the encrypted data to be delivered, and performing feature analysis on the key features; According to the analysis results, determine whether there is any abnormality in the transmission process; If not, continue the transmission and transmit the encrypted data to be delivered to the delivery library.
5. A data delivery method based on a trusted space according to claim 4, characterized in that: The extracting key features of the encrypted data to be delivered and performing feature analysis on the key features specifically includes: Extracting the ciphertext length and character frequency distribution of the encrypted data to be delivered; The ciphertext length and the character frequency distribution are compared with a pre-trained benchmark model to obtain a comparison deviation.
6. A data delivery method based on a trusted space according to claim 5, characterized in that: The step of judging whether there is an abnormality in the transmission process according to the analysis result specifically includes: Determine whether the comparison deviation is higher than a preset threshold; If so, it is determined that the transmission process is abnormal, the transmission is suspended and an alarm is triggered; If so, continue transmitting until all the encrypted data to be delivered are transmitted to the delivery library.
7. The data delivery method based on a trusted space according to claim 1, characterized in that: After transmitting the encrypted data to be delivered to the delivery library through the plurality of unidirectional data transmission channels, the method further comprises: Acquire key information during the transmission process, including transmission time, operation subject and data identification, and data volume; Based on the key information, a corresponding digital signature is generated through an asymmetric encryption algorithm, and the key information and the corresponding digital signature are stored in a transmission log.
8. The data delivery method based on a trusted space according to claim 1, characterized in that: When it is determined that the delivered data is complete, deleting the copy of the data to be delivered in the production database, specifically includes: When it is determined that the post-delivery data is complete, a data destruction event is triggered; All the data to be delivered are queried in the production library, and all the data to be delivered are irreversibly deleted.
9. A data delivery device based on a trusted space, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data delivery method based on a trusted space as described in any one of claims 1 to 8.
10. A non-volatile computer storage medium storing computer executable instructions, characterized in that: The computer executable instructions are configured as: a data delivery method based on a trusted space as described in any one of claims 1 to 8.
Citation Information
Cited By
NiFi-based order data delivery method and device, equipment and storage medium
CN120950498A