Data circulation method and platform, electronic equipment and storage medium

The construction of management virtual machines through the data flow platform and trusted execution environment technology solves the problem of insufficient security during data flow, and realizes secure access and processing of data resources between different roles.

CN120474741APending Publication Date: 2025-08-12NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510526734.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

During the data flow process, traditional data security protection technology fails and cannot effectively protect data resources, especially when data is out of the domain, its security cannot be ensured.

Method used

Through the data flow platform, establish connections with user equipment of different roles, use trusted execution environment technology to build and manage virtual machines, realize secure access and processing of data resources, and ensure the security of data flow through audit mechanisms.

Benefits of technology

It realizes security guarantees during data circulation, prevents data theft and attacks, and ensures secure access and processing of data resources between different roles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474741A_ABST
    Figure CN120474741A_ABST
Patent Text Reader

Abstract

The invention discloses a data circulation method and platform, electronic equipment and a storage medium, and relates to the technical field of data security. The method is applied to a data transfer platform, the platform is respectively connected with first user equipment with a role as a data source party and second user equipment with a role as a data processing party, and the method comprises the following steps: when a data processing contract initiated by the second user equipment takes effect, sending the data processing contract to the first user equipment; instructing the first user equipment to send access information to the second user equipment; instructing the second user equipment to access data resources of the first user equipment based on the access information, and executing data processing operation on the accessed data resources; instructing the first user equipment to audit an access record generated by the access of the second user equipment to obtain an audit result; wherein the audit result is used for indicating whether the second user equipment has an access attack behavior or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a data flow method, platform, electronic device and storage medium. Background Art

[0002] Data, as a new production factor, is the foundation of digitalization, networking, and intelligence. It has been rapidly integrated into various links such as production, distribution, circulation, consumption, and social service management, profoundly changing the mode of production, lifestyle, and social governance. It has become a new type of resource with extremely high value.

[0003] Data elements refer to data resources that exist in electronic form and participate in production and business activities through computation and play a significant role. They are the core engine driving the development of the digital economy and a key support for enabling the digital transformation and intelligent upgrade of industries. To this end, a three-rights separation framework has been proposed: the right to hold data resources, the right to process and use data, and the right to operate data products, to provide guidance for the development and construction of data elements. However, this involves the transmission, processing, and sharing between systems, platforms, or devices, as well as the generation, storage, transmission, migration, processing, use, and operation of various data. Therefore, ensuring the security of data flow becomes particularly important during the data flow process. Summary of the Invention

[0004] The present application provides a data flow method, platform, electronic device and storage medium to ensure the security of data flow.

[0005] In a first aspect, a data transfer method is provided for use on a data transfer platform. The platform is connected to a first user device that serves as a data source, and a second user device that serves as a data processor. The method includes:

[0006] When the data processing contract initiated by the second user equipment takes effect, instructing the first user equipment to send access information to the second user equipment;

[0007] instructing the second user equipment to access the data resources of the first user equipment based on the access information, and to perform a data processing operation on the accessed data resources;

[0008] Instruct the first user device to audit the access record generated by the second user device's access to obtain an audit result; wherein the audit result is used to indicate whether the second user device has an access attack behavior.

[0009] In an embodiment of the present application, the data flow platform can establish connections with user devices of different roles and provide different functional requirements for different user devices. When the data processing contract initiated by the second user device takes effect, the first user device is instructed to send access information to the second user device; the second user device is instructed to access the data resources of the first user device based on the access information, and perform data processing operations on the accessed data resources; the first user device is instructed to audit the access records generated by the access of the second user device, and obtain an audit result indicating whether the second user device has an access attack behavior, so as to ensure the security of data flow.

[0010] In some embodiments, the instructing the second user equipment to access the data resource of the first user equipment based on the access information includes:

[0011] If the data resource is file set data, instruct the second user device to access the file set data based on the SMB protocol and file access information; wherein the file access information includes a file identifier of the file set data, and account information and an account password that has read-only access to the file set data; or

[0012] If the data resource is database data, instructing the second user device to access the database data based on database access information; wherein the database access information includes account information and an account password for reading only the database data; or

[0013] If the data resource is interface data, the second user equipment is instructed to select an interface access item corresponding to the interface data in a user interface to access the interface data.

[0014] In some embodiments, the instructing the first user device to audit the access record generated by the access of the second user device includes:

[0015] If the data resource is the file set data, instruct the first user device to audit the access log generated by the second user device's access; wherein the access log includes at least the user information of the second user device, and the start timestamp, file starting position, file path, and file offset of the access to the file set data; or

[0016] If the data resource is the database data or the interface data, the first user equipment is instructed to audit the access traffic generated by the access of the second user equipment; wherein the access traffic includes at least uplink traffic and downlink traffic.

[0017] In some embodiments, performing a data processing operation on the accessed data resource includes:

[0018] instructing the second user device to process the data resource in the processing virtual machine to obtain processing results and derived data of the data resource; wherein the processing virtual machine is connected only to the management virtual machine of the second user device, and the management virtual machine of the second user device is built based on trusted execution environment technology;

[0019] Instruct the second user device to perform a product ownership agreement operation based on the processing results and at least one participant participating in the review of the processing results to obtain a data product of the processing results.

[0020] In some embodiments, before instructing the second user device to process the data resource in the processing virtual machine to obtain the processing results and derived data of the data resource, the method further includes:

[0021] A remote desktop gateway tool is used to deploy a virtual desktop for accessing the processing virtual machine; wherein the virtual desktop is provided with operation restriction permissions of the second user device on the data resource.

[0022] In some embodiments, the platform is connected to a third user device whose role is a data operator;

[0023] After performing the data processing operation on the accessed data resource, the method further includes:

[0024] When the data operation contract initiated by the third user device takes effect, the data product is migrated to the management virtual machine of the second user device; wherein the management virtual machine of the third user device is built based on the trusted execution environment technology;

[0025] Instruct the third user device to operate the data product according to the operation deployment plan and the data operation contract; wherein the operation deployment plan is configured by the second user device, and the operation deployment plan is a software package type and / or a container image type.

[0026] In some embodiments, the method further comprises:

[0027] Instruct the first user equipment to establish a communication relationship between the first user equipment and the second user equipment based on the IP address and / or user identification of the second user equipment, and instruct the second user equipment to establish a communication relationship between the first user equipment and the second user equipment based on the IP address and / or user identification of the first user equipment.

[0028] In a second aspect, a data transfer platform is provided, wherein the platform is connected to a first user device that serves as a data source and a second user device that serves as a data processor, respectively, and includes:

[0029] The visual operation sub-unit of the first user device is configured to, when the data processing contract initiated by the second user device takes effect, instruct the first user device to send access information to the second user device; and to instruct the first user device to audit access records generated by access by the second user device to obtain audit results; wherein the audit results are used to indicate whether the second user device has engaged in an access attack;

[0030] The visual operation subunit of the second user equipment is used to instruct the second user equipment to access the data resources of the first user equipment based on the access information, and perform data processing operations on the accessed data resources.

[0031] According to a third aspect, an electronic device is provided, including:

[0032] A memory for storing a computer program; a processor for implementing any one of the method steps in the first aspect when executing the computer program stored in the memory.

[0033] According to a fourth aspect, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method steps according to any one of the first aspects are implemented.

[0034] For each of the above-mentioned aspects from the second to the fourth aspects and the technical effects that may be achieved by each of the aspects, please refer to the above-mentioned description of the technical effects that can be achieved by the first aspect or various possible solutions in the first aspect, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 Schematic diagram of application scenarios applicable to the embodiments of this application;

[0036] Figure 2 A schematic diagram of the deployment architecture of a data flow platform provided in an embodiment of the present application;

[0037] Figure 3 A schematic diagram of a confidential virtual machine corresponding to a role provided in an embodiment of the present application;

[0038] Figure 4 A flowchart of a data transfer method provided in an embodiment of the present application;

[0039] Figure 5 A logical diagram of accessing data resources in a processing virtual machine provided in an embodiment of the present application;

[0040] Figure 6 A schematic diagram of a data transfer platform provided in an embodiment of the present application;

[0041] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. Unless there is a conflict, the embodiments in the present application and the features in the embodiments can be combined with each other in any way. In addition, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in an order different from that here.

[0043] The terms "first" and "second" in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of its variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in this application can mean at least two, for example, two, three or more, and the embodiments of this application are not limited thereto.

[0044] The following description of exemplary embodiments of the present application is made in conjunction with the accompanying drawings, which include various details of the embodiments of the present application to facilitate understanding, and they should be considered as merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope disclosed in this application. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted in the following description. It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned, which should be considered as exemplary, and their purpose is only to illustrate the feasibility of the implementation of the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0045] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are first explained below.

[0046] (1) The Server Message Block (SMB) protocol is a network file sharing protocol that allows client computers to access files, printers, and other resources on remote servers. SMB provides authentication, data encryption, and concurrency control features, supporting file sharing across different operating systems for efficient and secure file access and resource sharing.

[0047] (2) Trusted Execution Environment (TEE) provides hardware-level system isolation and trusted roots, supports data security assurance capabilities based on technical trust, and ensures that the code and data loaded within the secure area are protected in terms of confidentiality and integrity.

[0048] (3) Transparent storage encryption technology is an encryption mechanism for file storage security that can automatically encrypt and decrypt files without affecting normal user use. When the file is stored, the system automatically encrypts it, keeping it in ciphertext on the storage medium; when the user has appropriate permissions and accesses the file in a controlled environment, the system automatically decrypts it, presenting it in plaintext in the memory. Transparent encryption usually relies on the support of the operating system or driver layer, is transparent to the application, and does not affect its normal read and write operations. Once the file leaves the controlled environment, due to the lack of an automatic decryption mechanism, unauthorized access will not be able to read the plaintext content, thereby effectively protecting the confidentiality of the file.

[0049] (4) A virtual machine (VM) is a computer program or system that simulates the hardware operating environment of a physical computer through software, allowing multiple operating systems to run simultaneously on the same physical machine.

[0050] (5) The host machine is a physical computer that runs virtualization software and provides computing resources (such as memory, storage, and network) to the virtual machine.

[0051] Currently, traditional data security technologies are almost ineffective during data transfer, as data leaves the domain. For example, traditional bastion hosts can record the actions of internal operations personnel, thereby deterring malicious personnel from stealing data. However, when data leaves the domain, even if the bastion host is enabled, if the operations personnel have the intention to steal data, even with bastion host audits, the data source providing the data resources will not be able to view the specific audit content, and naturally cannot ensure that their data is effectively protected.

[0052] In view of this, embodiments of the present application provide a data flow method, platform, electronic device and storage medium to ensure security during data flow.

[0053] The following briefly introduces the application scenarios to which the technical solutions of the embodiments of the present application can be applied. It should be noted that the application scenarios described below are only used to illustrate the embodiments of the present application and are not limiting. In specific implementation, the technical solutions provided by the embodiments of the present application can be flexibly applied according to actual needs.

[0054] Figure 1 The following is a schematic diagram of an application scenario applicable to embodiments of the present application. As shown in the figure, the application scenario primarily includes: a data transfer platform 100a, user device 1, user device 2, and user device 3. Specifically, data transfer platform 100a can exchange information with user device 1, user device 2, and user device 3, respectively, via a communication network. The communication methods employed by the communication network may include wireless communication and wired communication.

[0055] In some scenarios, user device 1, user device 2, and user device 3 can respectively access the network through cellular mobile communication technology and communicate with the data flow platform 100a. The cellular mobile communication technology may include the fifth generation mobile communication (5th Generation Mobile Networks, 5G) technology, or the future 6G technology.

[0056] In some scenarios, user device 1, user device 2, and user device 3 can respectively access the network and communicate with the data flow platform 100a through short-range wireless communication. The short-range wireless communication method may include Wireless Fidelity (Wi-Fi) technology.

[0057] The present application embodiment does not impose any restrictions on the number of the above devices. Figure 1 As shown, only user equipment 1, user equipment 2, user equipment 3 and data flow platform 100a are described as examples, and the above devices and their respective functions are briefly introduced below.

[0058] User equipment 1, user equipment 2, and user equipment 3 are all devices that can provide voice and / or data connectivity to users, including: handheld terminal devices with wireless connection functions, vehicle-mounted terminal devices, etc. For example, they include but are not limited to: mobile phones, tablet computers, laptop computers, PDAs, mobile Internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminal devices in industrial control, wireless terminal devices in unmanned driving, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, or wireless terminal devices in smart homes, etc.

[0059] Furthermore, user device 1, user device 2, and user device 3 each connect to the data flow platform 100 as a different role; for example, user device 1 establishes a connection relationship with the data flow platform 100a as the data source, user device 2 establishes a connection relationship with the data flow platform 100a as the data processor, and user device 3 establishes a connection relationship with the data flow platform 100a as the data operator, and user devices with different roles have different data elements flowing on the data flow platform 100a, and the corresponding rights to different data elements are also different.

[0060] In addition, a client associated with the data transfer platform 100a may be installed on user device 1, user device 2, and user device 3. The client may be software (e.g., an APP, a browser, etc.), or a web page, a mini-program, etc. In the embodiment of the present application, user device 1, user device 2, and user device 3 may use the client associated with the data transfer platform 100a to implement their respective data security transfer processes.

[0061] Furthermore, after any user device downloads the data transfer platform 100a through the client, a corresponding platform operator can be configured for it to support the subsequent operation of the data transfer platform 100a.

[0062] It should be noted that if the physical equipment on which the data flow platform 100a is based does not belong to a certain organization and there is a cross-institutional collaborative construction, then the configured platform operator can only be a local platform operator for the organization, rather than a global platform operator. The main purpose of the platform operator is to manage local hardware devices and provide support for the creation of other local users. It may not directly participate in the data security flow process; for example, after the user device obtains the data flow platform 100a, the platform operator should be able to view and manage the platform's CPU, memory, disk and other contents, and can also register users (tenants) using the platform and allocate corresponding physical resources to the user.

[0063] like Figure 2 As shown, a deployment architecture diagram of a data flow platform provided in an embodiment of the present application is exemplarily shown.

[0064] exist Figure 2In the present invention, a chip that supports TEE (such as Haiguang chip) is used at the bottom layer of the host machine to ensure that the data in the virtual machine is encrypted at the host machine level to prevent data theft through hardware attacks such as memory cold start, and the trusted operation unit is combined with the TEE chip to provide hardware-level security protection; the visual operation unit is a unit for managing and monitoring virtual machines. The unit can create, configure and manage visual operation sub-units of different roles, and provide visual operation interfaces for different roles, which simplifies the user's operation process; further, it can also be pre-configured: the data resource management domain virtual machine image can be used to manage the data resources provided by the data source to ensure the security of the data resources during the access process; the data processing domain virtual machine image can be used for the data processing party to process and use data resources to ensure the security of the data during the processing process; the data product operation domain virtual machine image can be used for the operation of data products to ensure the security of data products during the operation process.

[0065] In some embodiments, the visual operation subunit of the first user device is used to instruct the first user device to perform a data publishing operation; the visual operation subunit of the second user device is used to instruct the second user device to perform a data processing contract operation; and the visual operation subunit of the third user device is used to instruct the third user device to perform a data operation contract operation.

[0066] In some embodiments, the visual operation sub-unit of the first user device is used to instruct the first user device to send access information to the second user device when the data processing contract initiated by the second user device takes effect; and to instruct the first user device to audit the access records generated by the access of the second user device to obtain an audit result; wherein the audit result is used to indicate whether the second user device has an access attack behavior.

[0067] In some embodiments, the visual operation subunit of the second user device is used to instruct the second user device to access the data resources of the first user device based on the access information, and perform data processing operations on the accessed data resources.

[0068] In some embodiments, the visual operation sub-unit of the second user device is used to migrate the data product to the management virtual machine of the second user device when the data operation contract initiated by the third user device takes effect; wherein, the management virtual machine of the third user device is built based on the trusted execution environment technology; instruct the third user device to operate the data product in accordance with the operation deployment plan and the data operation contract; wherein, the operation deployment plan is configured by the second user device, and the operation deployment plan is a software package type and / or a container image type.

[0069] In some embodiments, the visual operation sub-unit of the first user device can be used to organize the original data after the first user device migrates the original data to the corresponding visual operation sub-unit to obtain data resources; in response to the user operation of clicking the data publishing option on the user interface corresponding to the visual operation sub-unit, the data resource is published, and the metadata corresponding to the published data resource is synchronized to the public service unit.

[0070] Specifically, if the data resource is file set data, it can be uploaded through web page transmission or through the built-in server in the confidential virtual machine corresponding to the first user device; if the data resource is database data, it can be uploaded by the platform's built-in database engine container image (or temporarily obtained and imported from the public service unit). When the user needs to upload database data, a corresponding data resource library engine is created within the platform based on the original database engine, and an unused port is selected for public disclosure; the platform will randomly create a database account with read and write permissions and inform the user, after which the user can migrate data based on the account. Furthermore, to ensure data security, the management account of the database engine (such as the root account) is not open to the user, but is controlled by the platform background; if the data resource is interface data, an API interface template can be provided for the user to fill in according to the actual situation, and the platform will establish a network connection with the relevant interface to verify the correctness of the interface and automatically forward subsequent data.

[0071] In some embodiments, the raw data may include at least three categories: folders, databases (e.g., MySQL, postgreSQL, mongoDB, etc.), and data interfaces (e.g., Representational State Transfer (RESTful API), GraphQL API, etc.); the metadata corresponding to the data resource includes but is not limited to the hash value (used to characterize the uniqueness of the data resource), attributes, type, name, etc. corresponding to the data resource.

[0072] Furthermore, if the data resource is file set data, it is marked based on the hash value list of all sorted files in the file set data; if the data resource is database data, it is marked according to the hash value of its dump file; if the data resource is interface data, it is marked with a hash value based on the standard format interface that can be automatically mapped by its registered interface.

[0073] In some embodiments, the data publishing options include multiple publishing methods. For example, all user devices on the data flow platform 100a can know the above-mentioned meta-information. For example, user devices that have established a communication relationship with the first user device can know the above-mentioned meta-information. For another example, only the first user device knows the above-mentioned meta-information, etc.

[0074] In other embodiments, after publishing the metadata, the visual operation sub-unit of the first user device is also used to: obtain a title application material template related to the data resource from the public service unit, and apply for a resource title certificate for the data resource from the external platform based on the title application material template; at the same time, the public service unit is also used to review the uploaded resource title certificate, and if the review is passed, the resource title certificate will be credibly stored.

[0075] Based on the above Figure 2 In the architecture shown, user devices with different roles can require the platform operator to create a corresponding confidential management virtual machine according to their own roles, such as Figure 3 As shown, it is assumed that the participants (data source, data processor, and data operator) are in the same host machine. In reality, it is possible that in a host machine cluster composed of multiple host machines, management virtual machines of different roles correspond to different visual operation sub-units.

[0076] Furthermore, the management virtual machine can be set with at least three roles, such as "administrator", "operator" and "auditor", so that the user equipment of the data source (such as Figure 1 User equipment 1 shown), user equipment of the data processing party (such as Figure 1 User equipment 2 shown in the figure), user equipment of the data operator (such as Figure 1 The user device 3) shown can be specifically configured with relevant roles according to their respective needs, and when configuring management virtual machines of different roles, corresponding public keys and private keys will be generated to indicate the identity of user devices of different roles. Here, the trusted operation unit based on the TEE chip and the host machine can ensure that the started virtual machine runs in a confidential state; a remote proof report can be generated inside the virtual machine to prove that it is in a confidential virtual machine.

[0077] It should be noted that the above Figure 3 The confidential virtual machine shown is not limited to the specific operating system version. It can be a common and well-known Linux system such as Ubuntu, or a domestic trusted operating system, etc.

[0078] In some scenarios, the data transfer platform 100a further includes a public service unit for storing metadata corresponding to the published data resource after user device 1 completes the data publishing operation; for storing the generated data processing contract after user device 2 completes the data processing contract operation; and for storing the generated operation contract after user device 3 completes the data operation contract operation. It should be noted that the storage method for each of the above contracts can be blockchain storage or other methods, and this embodiment of the application does not limit this.

[0079] To further illustrate the technical solutions provided by the embodiments of the present application, this is described in detail below with reference to the accompanying drawings and specific implementation methods. Although the embodiments of the present application provide the method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on routine or no creative labor. In the steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiments of the present application. The method may be executed or executed in parallel in the order of the methods shown in the embodiments or drawings during the actual processing process or when the device is executed.

[0080] Figure 4 A flowchart of a data transfer method provided in an embodiment of the present application, which can be implemented by a data transfer platform (such as Figure 1 The data transfer platform 100a) shown in FIG. 1 is used to ensure the security of the data transfer process. Figure 4 As shown, the process includes the following steps:

[0081] 401: When the data processing contract initiated by the second user equipment takes effect, instruct the first user equipment to send access information to the second user equipment.

[0082] In this step, the second user equipment may refer to Figure 1 In the user equipment 2, the first user equipment may refer to Figure 1 User device 1 in.

[0083] In some embodiments, the data processing contract initiated by the second user device may be: in response to a user operation that initiates the data processing contract signing process on the data flow platform, the data processing contract is negotiated with one or more relevant first user devices, and after each party digitally signs the negotiated data processing contract with its own private key, the data processing contract becomes effective on the platform; further, the data processing contract may at least include: metadata of the data resources used for processing, the processing period, the results requirements of the processing results, and at least one participant participating in the review of the processing results; the retention scope of derivative data generated based on the processing of data resources, the ownership of the derivative data, and at least one participant participating in the review of the derivative data.

[0084] In other embodiments, all parameters in the data processing contract signing process can be retained in the form of files such as json or yaml, and the effective data processing contract can also be sent to the public service unit for credible evidence.

[0085] 402: Instruct the second user equipment to access the data resources of the first user equipment based on the access information, and perform data processing operations on the accessed data resources.

[0086] In some embodiments, instructing the second user equipment to access the data resources of the first user equipment based on the access information may include the following situations:

[0087] Case 1: If the data resource is file set data, the second user device is instructed to access the file set data based on the SMB protocol and file access information; wherein the file access information includes the file identifier of the file set data, and the account information and account password of the read-only file set data, so that the management virtual machine of the second user device uses the built-in SMB client to complete the data mounting.

[0088] Case 2: If the data resource is database data, the second user device is instructed to access the database data based on the database access information; wherein the database access information includes account information and an account password for reading only the database data.

[0089] In case 3, if the data resource is interface data, the second user device is instructed to select the interface access item corresponding to the interface data in the user interface to access the interface data. In other embodiments, the second user device can apply to create several Linux or Windows version processing virtual machines (the processing virtual machines can be regular virtual machines, not confidential virtual machines) for processing needs; the created virtual machine image template can be downloaded from the public service unit of the platform. The platform has a built-in whitelist of images that can be used for startup, and the processing virtual machine is configured with a bridge network. At startup, the tap interface used by the processing virtual machine is recorded for the second user device to connect to, thereby preventing some malicious other user devices from stealing information through the network.

[0090] Furthermore, the ebtables tool can be used to ensure that the processing VM is connected only to the management VM of the second user device, preventing other devices from stealing data resources. For example, assuming the tap port of the management VM of the second user device is tap1, and the tap port of the processing VM is tap2; after creating the processing VM, immediately execute the following four instructions at the host level: ebtables-A FORWARD-i tap1-o tap2-j ACCEPT; ebtables-A FORWARD-i tap2-otap1-j ACCEPT; ebtables-DFORWARD-i tap2-j DROP; ebtables-D FORWARD-o tap2-j DROP. The first two instructions allow traffic between the processing VM and the management VM, while the last two instructions discard traffic from other processing VMs.

[0091] In other embodiments, a remote desktop gateway tool is used to deploy a virtual desktop for accessing the processing virtual machine; wherein, the virtual desktop is provided with a second user device's restricted permissions for operating the data resources, thereby preventing the data resources from being copied, screenshoted, transmitted externally, etc. during the data processing process.

[0092] Furthermore, the Guacamole tool can be used to customize permissions for the virtual desktop used to access the processing virtual machine (for example, adding front-end watermark setting logic; at the same time, setting the password of the highest-privilege account of the component (virtual desktop) to be imported externally during initial startup). When the second user device is started, the platform can randomly generate the account password of the highest-privilege account and automatically start the component, and this account password can be kept secret from the user. It should be noted that the virtual desktop can provide support for various mainstream development modes (Linux command line, Linux desktop, Windows desktop) and other situations, and this embodiment of the application does not limit this.

[0093] like Figure 5 As shown in FIG, a logic diagram of accessing data resources in a processing virtual machine is shown as an example. Figure 5 In the embodiment, a layer of reverse proxy and SMB mapping is added to the management virtual machine of the second user device, so that from the perspective of the processing virtual machine, the data resources are provided by the management virtual machine of the second user device, and the management virtual machine of the second user device actually transfers the traffic of database data to the data resource library engine of the first user device through the reverse proxy; and actually transfers the traffic of interface data to the interface access port of the first user device; for file set data, the management virtual machine can start an SMB server (which can be set to read-only sharing, that is, the file cannot be modified on the mount point side) to provide the file set data mounted from the first user device to the processing virtual machine.

[0094] In some embodiments, performing data processing operations on the accessed data resources includes:

[0095] Instruct the second user device to process the data resources in the processing virtual machine to obtain the processing results and derivative data of the data resources; wherein, the processing virtual machine is only connected to the management virtual machine of the second user device (specifically, the ebtables tool can be used), and the management virtual machine of the second user device is built based on the trusted execution environment technology; instruct the second user device to execute the product ownership agreement operation based on the processing results and at least one participant participating in the review of the processing results to obtain the data product of the processing results.

[0096] It should be noted that all parties with audit rights in the data processing contract can audit the processing results and derived data to ensure that the processing results do not contain any illegal information. The audit method can be manual audit or automatic audit based on preset rules. This embodiment of the present application does not limit this.

[0097] In some embodiments, information such as the ownership composition of data products can also be described in JSON; if the participants confirm that the product ownership is correct, the platform will also sign the relevant JSON using the corresponding private key and send it to other participants and public service units for evidence storage.

[0098] In other embodiments, the second user device may be instructed to pre-open an independent and initially empty processing folder or database engine to facilitate storage of the processing results and derived data generated by the processing virtual machine during the processing process. The processing results are composed of a number of sub-processing results, each of which is in the form of a file set or database. Each sub-processing result may also be marked with a unique tag such as a hash value. If the processing results and derived data are file set data, they can be transmitted using SMB mounting (read-write mode). If the processing results and derived data are database data, they can be transmitted directly over the network.

[0099] In other embodiments, after completing the processing of data resources in the processing virtual machine and submitting the derived data and processing results, the processing can be confirmed to be completed. After confirmation, the processing virtual machine can be removed for the sake of data security and resource release.

[0100] In other embodiments, after performing data processing operations on the accessed data resources, the method further includes:

[0101] When the data operation contract initiated by the third user device takes effect, the data product is migrated to the management virtual machine of the second user device; wherein, the management virtual machine of the third user device is built based on the trusted execution environment technology; the third user device is instructed to operate the data product in accordance with the operation deployment plan and the data operation contract; wherein, the operation deployment plan is configured by the second user device, and the operation deployment plan is a software package type and / or a container image type.

[0102] In some embodiments, the migration of the data product to the management virtual machine of the second user device may include the following forms:

[0103] Form 1: When the data product is in the form of a file set, it can be mounted through the SMB protocol, and then a full copy is performed to complete the data migration.

[0104] Form 2: When the data product is in database form, a database engine of the same type as the product component can be opened on the third user device side, and the relevant data products can be synchronized from the database of the second user device to the database engine opened on the third user device through the database standard access interface.

[0105] Form 3: When the data product is in the form of interface data, the corresponding interface access method is provided to the management virtual machine of the third user device for the user to select in the corresponding user interface.

[0106] In other embodiments, the platform may also assist a third user device in generating the materials required for the product ownership certificate based on the data operation contract.

[0107] Furthermore, for the operational deployment plan of the software package type, the configuration content may include the file set data used by the service, the location where the file set data needs to be placed in the management virtual machine, several environment variables required for the process to run, the startup command required for the process, etc.; for the container image type, the configuration content may include the container image on which the service is based, the file set data required, the location where the file set data needs to be mounted in the service container environment, the environment variable information required by the container image (such as account password), the startup command required by the container image, etc.

[0108] It should be noted that in actual scenarios, multiple processes and containers may be required to collaborate; therefore, for the operation of the same data product, the second user device can provide multiple service startup parameter configurations based on the data product, as well as configuration-related startup sequences, etc.

[0109] In other embodiments, for the derivative data generated in the process of operating the data product, the user operates the user interface corresponding to the visual operation sub-unit of the third user device and notifies the user (participant) with the holding right to access and obtain the data in accordance with the operation contract. In addition, the user can also assist in the generation of application materials for the confirmation of ownership of the derivative data in accordance with the operation contract, so that the participant with relevant rights can further confirm the relevant holding rights on their own.

[0110] 403: Instruct the first user device to audit the access record generated by the second user device's access to obtain an audit result; wherein the audit result is used to indicate whether the second user device has an access attack behavior.

[0111] In some embodiments, instructing the first user device to audit the access record generated by the second user device's access may include the following situations:

[0112] Case 1: If the data resource is file set data, the first user device is instructed to audit the access log generated by the second user device's access; wherein the access log includes at least the user information of the second user device, as well as the start timestamp of accessing the file set data, the file starting position, the file path, and the file offset.

[0113] For example, when the second user device accesses the file based on the file access information, an access log will be retained on the improved SMB server of the first user device (for example, 1724912043|samba|pread_send|ok| / home / sf / share / b.txt|0|32768; where "|" is a separator, 1724912043 is the start timestamp, which is converted into the real time 2024-08-29 14:14:03, samba is the user name, pread_send represents the SMB server sending data, OK represents a successful operation, / home / sf / share / b.txt represents the file path, 0 represents the starting position of the file, and 32768 represents the file offset) so that the access behavior of the second user device can be quantitatively audited.

[0114] Case 2: If the data resource is database data or interface data, the first user device is instructed to audit the access traffic generated by the second user device; wherein the access traffic includes at least uplink traffic and downlink traffic, so as to be able to quantitatively audit the access behavior of the second user device.

[0115] For example, for database data, the second user device accesses the database based on the database access information. Since the first user device has built-in database auditing capabilities, it can audit the upstream and downstream traffic corresponding to the database access information, so as to quantitatively audit the access behavior of the second user device; for interface data, the management virtual machine of the first user device encapsulates the data interface through reverse proxy tools such as nginx, and provides it to the user interface of the second user device for display; when the corresponding interface access item is selected in the user interface, since the encapsulation part integrates traffic auditing capabilities, the access traffic size of the second user device can be recorded, so the access behavior of the second user device can be quantitatively audited.

[0116] In other embodiments, the first user device may be instructed to establish a communication relationship between the first user device and the second user device based on the IP address and / or user identifier of the second user device, and the second user device may be instructed to establish a communication relationship between the first user device and the second user device based on the IP address and / or user identifier of the first user device, so as to achieve interconnection between the devices. Similarly, if a third user device wants to establish a communication relationship with the first user device and / or the second user device, it can also be implemented in this manner, and the embodiments of this application will not be repeated here.

[0117] In an embodiment of the present application, the data flow platform can establish connections with user devices of different roles and provide different functional requirements for different user devices. When the data processing contract initiated by the second user device takes effect, the first user device is instructed to send access information to the second user device; the second user device is instructed to access the data resources of the first user device based on the access information, and perform data processing operations on the accessed data resources; the first user device is instructed to audit the access records generated by the access of the second user device, and obtain an audit result indicating whether the second user device has an access attack behavior, so as to ensure the security of data flow.

[0118] Figure 6 A schematic diagram of a data transfer platform provided in an embodiment of the present application. Figure 6 The data transfer platform creates a visual operation subunit 1 corresponding to the data source for the first user device, a visual operation subunit 2 corresponding to the data processing party for the second user device, and a visual operation subunit 3 corresponding to the data operator for the third user device.

[0119] First, the user on the data source side uses the visual operation sub-unit 1 to publish data resources. The user on the data processing side uses the visual operation sub-unit 2 to initiate the data processing contract process. After reaching an agreement with the user on the data source side, the negotiated data processing contract is uploaded to the platform's public service unit for trusted evidence storage.

[0120] Secondly, the user of the data processing party uses the visual operation sub-unit 2 to access the data resources of the first user device. Furthermore, the user of the data source party uses the visual operation sub-unit 1 to audit the access records of the second user device to determine whether there is any access attack behavior;

[0121] Then, after the user of the data processing party successfully accesses the data resource using the visual operation sub-unit 2, the visual operation sub-unit 2 processes the data resource through the processing virtual machine applied for from the platform to form the processed derivative data and processing results, and agrees with the data source party on the product ownership of the processing results to form a data product, and uploads the agreed product ownership agreement to the public service unit of the platform for credible evidence storage;

[0122] Next, the data operator's user uses the visual operation sub-unit 3 to initiate the data operation contract process for the data product. After reaching an agreement with the data source and data processor, the negotiated data operation contract is uploaded to the platform's public service unit for trusted evidence storage.

[0123] Finally, the user of the data operator uses the visual operation sub-unit 3 to migrate the data product, and prepares the operation environment based on the operation deployment plan configured by the data processor, and uploads the corresponding product title certificate to the public service unit for trusted evidence storage, and starts the operation service to operate the corresponding data product until the operation period agreed in the data operation contract, and obtains the derivative data generated by the operation.

[0124] Based on the same technical concept, an electronic device is also provided in an embodiment of the present application, which can realize the functions of the aforementioned data flow platform.

[0125] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0126] At least one processor 701, and a memory 702 connected to the at least one processor 701. The specific connection medium between the processor 701 and the memory 702 is not limited in the embodiment of the present application. Figure 7 In the example, the processor 701 and the memory 702 are connected via a bus 700. Figure 7 The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 7 The diagram is represented by only one thick line, but this does not mean that there is only one bus or one type of bus. Alternatively, the processor 701 may also be referred to as a controller, without limitation to the name.

[0127] In the embodiment of the present application, the memory 702 stores instructions that can be executed by at least one processor 701. The at least one processor 701 can execute a data processing method discussed above by executing the instructions stored in the memory 702. The processor 701 can implement Figure 2 The functions of each module in the device shown.

[0128] Among them, the processor 701 is the control center of the device, which can use various interfaces and lines to connect the various parts of the entire control device, and monitor the device as a whole by running or executing instructions stored in the memory 702 and calling data stored in the memory 702, the various functions of the device and processing data.

[0129] In the embodiment of the present application, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. The application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily processes wireless communications. It is understood that the modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 may be implemented on the same chip. In some embodiments, they may also be implemented on separate chips.

[0130] The processor 701 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of a data flow method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.

[0131] The memory 702 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 702 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 702 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.

[0132] By designing and programming the processor 701, the code corresponding to the data flow method described in the above embodiment can be fixed into the chip, so that the chip can execute the data flow method during operation. Figure 4The embodiment shown is a data transfer method. How to design and program the processor 701 is a well-known technology to those skilled in the art and will not be described in detail here.

[0133] It should be noted here that the above-mentioned electronic device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0134] Based on the same technical concept, embodiments of the present application provide a computer storage medium comprising computer program code. When the computer program code is executed on a computer, the computer executes any of the data transfer methods discussed above. Because the principles underlying the problem solved by the computer storage medium are similar to those of the data transfer method, the implementation of the computer storage medium can be referred to as the implementation of the method, and any repetitions will not be repeated.

[0135] In a specific implementation process, computer storage media may include: Universal Serial Bus Flash Drive (USB), mobile hard disk, Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disk or optical disk, and other storage media that can store program code.

[0136] Based on the same technical concept, embodiments of the present application also provide a computer program product, comprising: computer program code, which, when executed on a computer, causes the computer to execute any of the data transfer methods discussed above. Because the principles underlying the problems solved by the computer program product are similar to those of the data transfer method, the implementation of the computer program product can be referred to as the implementation of the method, and any repetitions will not be repeated.

[0137] The computer program product can employ any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0138] The methods described herein can be implemented in whole or in part using software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described herein are performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, a core network device, an OAM, or other programmable device.

[0139] The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0140] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) that contain computer-usable program code.

[0141] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the instructions in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0142] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0143] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of the present invention fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A data transfer method, characterized in that: Applied to a data transfer platform, the platform is connected to a first user device that acts as a data source, and a second user device that acts as a data processor, respectively. The method includes: When the data processing contract initiated by the second user equipment takes effect, instructing the first user equipment to send access information to the second user equipment; instructing the second user equipment to access the data resources of the first user equipment based on the access information, and to perform a data processing operation on the accessed data resources; Instruct the first user device to audit the access record generated by the second user device's access to obtain an audit result; wherein the audit result is used to indicate whether the second user device has an access attack behavior.

2. The method according to claim 1, wherein The instructing the second user equipment to access the data resource of the first user equipment based on the access information includes: If the data resource is file set data, instruct the second user device to access the file set data based on the Server Message Block (SMB) protocol and file access information; wherein the file access information includes a file identifier of the file set data, and account information and an account password for reading only the file set data; or If the data resource is database data, instructing the second user device to access the database data based on database access information; wherein the database access information includes account information and an account password for reading only the database data; or If the data resource is interface data, the second user equipment is instructed to select an interface access item corresponding to the interface data in a user interface to access the interface data.

3. The method according to claim 2, wherein The instructing the first user equipment to audit the access record generated by the access of the second user equipment includes: If the data resource is the file set data, instruct the first user device to audit the access log generated by the second user device's access; wherein the access log includes at least the user information of the second user device, and the start timestamp, file starting position, file path, and file offset of the access to the file set data; or If the data resource is the database data or the interface data, the first user equipment is instructed to audit the access traffic generated by the access of the second user equipment; wherein the access traffic includes at least uplink traffic and downlink traffic.

4. The method according to claim 1, wherein The performing of data processing operations on the accessed data resources includes: instructing the second user device to process the data resource in the processing virtual machine to obtain processing results and derived data of the data resource; wherein the processing virtual machine is connected only to the management virtual machine of the second user device, and the management virtual machine of the second user device is built based on trusted execution environment technology; Instruct the second user device to perform a product ownership agreement operation based on the processing results and at least one participant participating in the review of the processing results to obtain a data product of the processing results.

5. The method according to claim 4, wherein Before instructing the second user equipment to process the data resource in the processing virtual machine to obtain the processing results and derived data of the data resource, the method further includes: A remote desktop gateway tool is used to deploy a virtual desktop for accessing the processing virtual machine; wherein the virtual desktop is provided with operation restriction permissions of the second user device on the data resource.

6. The method according to claim 4, wherein The platform is connected to a third user device whose role is a data operator; After performing the data processing operation on the accessed data resource, the method further includes: When the data operation contract initiated by the third user device takes effect, the data product is migrated to the management virtual machine of the second user device; wherein the management virtual machine of the third user device is built based on the trusted execution environment technology; Instruct the third user device to operate the data product according to the operation deployment plan and the data operation contract; wherein the operation deployment plan is configured by the second user device, and the operation deployment plan is a software package type and / or a container image type.

7. The method according to claim 1, wherein The method further comprises: Instruct the first user equipment to establish a communication relationship between the first user equipment and the second user equipment based on the IP address and / or user identification of the second user equipment, and instruct the second user equipment to establish a communication relationship between the first user equipment and the second user equipment based on the IP address and / or user identification of the first user equipment.

8. A data transfer platform, characterized in that: The platform is connected to a first user device that is a data source and a second user device that is a data processor, respectively, including: The visual operation sub-unit of the first user device is configured to, when the data processing contract initiated by the second user device takes effect, instruct the first user device to send access information to the second user device; and to instruct the first user device to audit access records generated by access by the second user device to obtain audit results; wherein the audit results are used to indicate whether the second user device has engaged in an access attack; The visual operation subunit of the second user equipment is used to instruct the second user equipment to access the data resources of the first user equipment based on the access information, and perform data processing operations on the accessed data resources.

9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the method according to any one of claims 1 to 7 when executing the computer program stored in the memory.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Access controlling method and device using virtualization

    CN102404316A

  • Data processing method, system and equipment and storage medium

    CN114417287A

  • Data operation auditing method, system and device and storage medium

    CN116015840A

  • Virtual cloud desktop resource receiving and managing method

    CN118193223A

  • Data processing method and device and electronic equipment

    CN119025496A