Cross-network and cross-domain data exchange responsibility establishment method, equipment and medium
By building a full life cycle policy chain for cross-network and cross-domain data exchange systems, and combining data exchange logs, fingerprints, and path restoration, the lack of rights and responsibilities confirmation in cross-domain data exchange is solved, and comprehensive and accurate responsibility determination of abnormal exchange behaviors is achieved.
Patent Information
- Application Number
- CN202511195062.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-26
AI Technical Summary
Existing technologies make it difficult to fully identify the responsible parties for abnormal exchange behaviors in cross-network and cross-domain data exchange, especially when restoring the exchange path due to the lack of policy verification, resulting in insufficient responsibility confirmation.
Build a full life cycle policy chain for cross-network and cross-domain data exchange systems, verify the log compliance of abnormal exchange behaviors through data exchange logs, data fingerprints and exchange path restoration, combined with exchange policies, and clarify the rights and responsibilities of the parties.
It achieves comprehensive and accurate confirmation of rights and responsibilities for abnormal behaviors in cross-network and cross-domain data exchange, completes the policy verification of exchange path restoration, and improves the accuracy and comprehensiveness of responsibility determination.
Smart Images

Figure CN120729635A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of data exchange technology, and in particular relates to a method, device and medium for establishing rights and responsibilities for cross-network and cross-domain data exchange. Background Art
[0002] Cross-network and cross-domain data exchange systems are being used more and more widely. Business systems use these systems to exchange data between different networks. When abnormal exchange behaviors such as the spread of malicious code or leakage of sensitive information are discovered, technical means are needed to confirm the responsible parties for information leakage and risk spread so that managers can understand the situation or hold them accountable.
[0003] A common approach involves auditing data exchange logs, tracing back data exchange log information to identify the subject, object, time, and event of the leak or risk. This approach is relatively simple and suitable for cross-network, cross-domain exchange scenarios with fixed or single services and a small number of exchanges. While using data exchange logs to clarify responsibilities lacks the core element of the data itself, it only indicates that the subject or object has engaged in anomalous behavior, but cannot prove that the leaked or disseminated information originated with that subject or object. Therefore, data fingerprinting is introduced to confirm responsibilities. Business systems extract and store data fingerprints before cross-network exchanges. During the audit, the data fingerprint of the leaked or disseminated information is extracted and compared with the data fingerprint database to identify the subject of the leak or dissemination. Furthermore, cross-network, cross-domain data exchange audits employ a path restoration method, recording each node through which data was exchanged across networks and domains. During the audit, the path of the leaked or disseminated information exchanged can be restored, thereby reconstructing the entire process of the anomalous exchange behavior and clarifying the subject responsible for the information leak and risk dissemination. Technical means such as data exchange log verification, data fingerprint comparison, and exchange path restoration have been able to generally confirm the responsible party for leaks or spread. However, data exchange logs are generated based on the execution of exchange policies. The lack of exchange policy verification to confirm the ownership and responsibility of abnormal exchange behavior makes it difficult to fully verify the party's responsibility. Currently, there is no evidence of exchange path restoration or verification of data exchange log compliance through exchange policies during data exchange log audits.
[0004] Patent CN115914005A discloses a data auditing system and method. The initiator distributes data security policies and data to each inspection device. The inspection device then inspects the data according to the data security policy and reports the log. During the audit, the operation logs of the inspection devices are audited based on the data security policy to obtain audit results, thus achieving compliance audit of cross-domain data. This patent focuses on auditing data provided by the initiator.
[0005] Patent CN116418587A describes a method and system for auditing and tracking cross-domain data exchange behavior. The invention includes event collection, preliminary analysis, anomaly detection, and behavior tracking, enabling precise behavior viewing, user behavior statistics, and exchange behavior backtracking. This patent primarily analyzes collected events to enable auditing of cross-network and cross-domain exchanges.
[0006] Patent CN116723049A describes a hierarchical data fingerprint audit and traceability method for cross-network exchanges. Prior to exchange, hierarchical data fingerprints are collected, extracted, and stored. During audit and traceability, hierarchical data fingerprints are extracted from the files to be traced and compared with fingerprints in a fingerprint database to complete traceability. This patent primarily uses pre-collected hierarchical data fingerprints to trace data.
[0007] In response to the problem that the elements are incomplete and the rights and responsibilities of abnormal exchange behaviors cannot be fully clarified during the audit of cross-network and cross-domain data exchange, this application proposes to build an exchange policy chain to support the audit of abnormal exchange behaviors, and comprehensively adopt data exchange logs, data fingerprints, exchange paths, exchange policies, etc. to confirm rights and responsibilities. When the exchange path is restored, the exchange policy is synchronously restored to confirm the compliance of the data exchange log with the exchange policy, and the status and elements when the abnormal exchange behavior occurs are fully and truly reproduced to determine the rights and responsibilities of abnormal cross-network and cross-domain data exchange behaviors. Summary of the Invention
[0008] The purpose of this application is to: confirm that the responsible parties for cross-network and cross-domain data exchange that involves leakage of sensitive information or spread of security risks need to check data exchange logs, compare data fingerprints, and restore exchange paths. In order to fully confirm the responsible parties for abnormal exchange behavior, it is necessary to verify the compliance of abnormal exchange logs through exchange policies. This application mainly solves the problem of policy restoration when restoring exchange paths, thereby verifying the compliance of abnormal exchange behavior logs and providing support for abnormal exchange behavior audits and determination of rights and responsibilities. At the same time, it solves the problem of establishing consistency in rights and responsibilities for cross-network and cross-domain data exchange based on data exchange logs, data fingerprints, exchange paths, and exchange policies.
[0009] On the one hand, the purpose of this application is achieved through the following technical solutions: A method for establishing rights and responsibilities for cross-network and cross-domain data exchange, the method comprising: Build a full life cycle strategy chain for cross-network and cross-domain data exchange systems, When auditing data exchange behavior, the rights and responsibilities of cross-network and cross-domain data exchange are clearly defined based on the policy-based restoration method, including: restoring the exchange path based on data exchange logs, comparing malicious code or sensitive information data fingerprints, and restoring exchange policy measures to establish the rights and responsibilities of the subjects.
[0010] According to a preferred embodiment, when a cross-network and cross-domain data exchange system formulates or changes a data exchange policy, the policy attributes include at least: number, content, status, last change time, last integrity value, current change time, and current integrity value.
[0011] According to a preferred embodiment, the content of the policy attributes includes: policy identifier, data sender identifier, data receiver identifier, data type, and checking rules, wherein the policy identifier is used to uniquely identify the policy.
[0012] According to a preferred embodiment, the status in the policy attribute includes two types: valid status and archived status. The valid state indicates that the policy is actually valid, and the audit state indicates that the corresponding policy is used for data exchange behavior audit.
[0013] According to a preferred embodiment, the policy in the effective state is a formulated policy, including: issuing, executing, and changing; Policies in the archived state cannot be issued, executed, changed, or deleted. Policies in the valid state are changed to the archived state through archiving or deletion operations when they are no longer in use.
[0014] According to a preferred embodiment, the policy comprises: the last change time, the last integrity value, the current change time, and the current integrity value to form a policy chain data structure; The last change time and the current change time of the first policy formulation are both taken as the current time value, and the last integrity value is set to all 0s.
[0015] According to a preferred embodiment, the attributes of the data exchange log include at least a log identifier, a log time, a data sender identifier, a data receiver identifier, a data type, a data fingerprint, and a log description. The data fingerprint is calculated when the data exchange log is reported. The process of clarifying the rights and responsibilities of cross-network and cross-domain data exchange based on the policy-based rights and responsibilities restoration method includes: When restoring abnormal exchange behavior, the data is determined through the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain through the log time of the data exchange, the inspection rules are determined by comparing the data sender identifier, data receiver identifier, and data type in the log and policy, the data exchange behavior elements are restored, the inspection rules are manually identified, and the rights and responsibilities are determined.
[0016] According to a preferred embodiment, the specific process of determining rights and responsibilities through policy restoration includes: Based on the log time of data exchange behavior, the policy is queried in both "valid" and "archived" states. Verify the integrity value of this policy; Verify the last policy integrity value; Extract policy content; Find and compare the policy content with the data sender identifier in the log information; Find and compare the policy content with the data recipient identifier in the log information; Compare data types; Compare data fingerprints; Traverse the corresponding policy inspection rules and manually determine whether the data exchange log information complies with the inspection rules; Through the above steps, if the data exchange log is consistent with the inspection rules, the responsible party of the abnormal exchange behavior can be confirmed.
[0017] On the other hand, the present application also discloses: An electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the aforementioned method by executing the instructions stored in the memory.
[0018] On the other hand, the present application also discloses: A computer-readable storage medium is used to store instructions, and when the instructions are executed, the above method is implemented.
[0019] The aforementioned main solution of this application and its further options can be freely combined to form multiple solutions, all of which can be adopted and protected by this application. After understanding the solution of this application, those skilled in the art will understand that there are many combinations based on existing technology and common knowledge, all of which are technical solutions to be protected by this application, and these are not exhaustive here.
[0020] Beneficial effects of this application: Cross-network, cross-domain data exchange involves two primary responsibilities: the business system and the cross-network, cross-domain data exchange system. When the business system provides data exchange anomaly logs, raising concerns about information leakage and risk spread, and the cross-network, cross-domain data exchange system lacks matching anomaly exchange logs, the policy chain in this application can be used to determine whether the policy is the cause of the anomaly.
[0021] This application proposes the use of a cryptographic mechanism to construct a policy chain based on policy change time, thereby clarifying the rights and responsibilities within the cross-network and cross-domain data exchange system. This application does not limit the specific implementation parameters and storage methods of the policy chain. During engineering implementation, multiple methods are supported to implement the policy chain's rights and responsibilities confirmation capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a schematic diagram of the data structure of the strategy chain of this application; Figure 2 It is a schematic diagram of the process of determining rights and responsibilities through strategic restoration; Figure 3 This is a schematic diagram of the electronic device structure corresponding to implementation 2 of this application. DETAILED DESCRIPTION
[0023] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other unless they conflict.
[0024] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0025] Example 1 refer to Figure 1 and Figure 2 As shown, the present application discloses a method for establishing rights and responsibilities for cross-network and cross-domain data exchange, the method comprising: Build a full life cycle policy chain for cross-network and cross-domain data exchange systems; when auditing data exchange behaviors, clarify the rights and responsibilities of cross-network and cross-domain data exchange based on the policy-based restoration of rights and responsibilities method, including: based on data exchange logs, comparing malicious code or sensitive information data fingerprints, restoring exchange paths, and restoring exchange policy measures to establish the rights and responsibilities of the subjects.
[0026] (1) Design of a full life cycle strategy chain for cross-network and cross-domain data exchange systems When exchanging business system data across networks and domains, the requirements are generally clear, with the format and content largely defined. In most scenarios, a one-time exchange policy based on these requirements is sufficient. However, there are also business needs such as adding or removing policies, and management needs such as tightening policies. To restore abnormal exchange behavior and restore exchange policies, all exchange policies must be preserved and the authenticity of historical exchange policies must be guaranteed.
[0027] When a cross-network and cross-domain data exchange system formulates or changes a data exchange policy, the policy attributes shall at least include: number, content, status, last change time, last integrity value, current change time, and current integrity value. Figure 1 As shown in the figure, the policy chain data structure consists of the last change time, the last integrity value, the current change time, and the current integrity value. The integrity value is calculated using a cryptographic mechanism. The change time is accurate to milliseconds.
[0028] The policy attributes include: policy identifier, data sender identifier, data receiver identifier, data type, check rule 1...check rule n and other attributes, among which the policy identifier is used to uniquely identify the policy.
[0029] The policy attributes contain two states: valid and archived. The valid state indicates that the policy is actually in effect, while the audit state indicates that the policy is used for data exchange audits. The integrity value includes all the preceding fields.
[0030] During design and implementation, the last change time and the current change time of the first policy formulation are both taken as the current time value, and the last integrity value is set to all 0s.
[0031] A policy in the valid state is a formulated policy, including: issuance, execution, and change; a policy in the archived state cannot be issued, executed, changed, or deleted. When a policy in the valid state is no longer in use, it is changed to the archived state through archiving or deletion operations.
[0032] (2) Strategy to restore rights and responsibilities There are three main parties with rights and responsibilities in cross-network and cross-domain data exchange: the data sender, the cross-network and cross-domain data exchange system, and the data receiver. The establishment of rights and responsibilities for cross-network and cross-domain data exchange mainly involves auditing abnormal exchange behaviors such as the spread of malicious code or leakage of sensitive information. The parties with rights and responsibilities can be established by comprehensively adopting technical measures such as checking data exchange logs, comparing malicious code or sensitive information data fingerprints, restoring exchange paths, and restoring exchange strategies.
[0033] The attributes of a data exchange log include at least log ID, log time, data sender ID, data receiver ID, data type, data fingerprint, and log description. The data fingerprint is calculated when the data exchange log is reported.
[0034] The process of clarifying the rights and responsibilities of cross-network and cross-domain data exchange based on the policy-based rights and responsibilities restoration method includes: When restoring abnormal exchange behavior, the data is determined through the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain through the log time of the data exchange, the inspection rules are determined by comparing the data sender identifier, data receiver identifier, and data type in the log and policy, the data exchange behavior elements are restored, the inspection rules are manually identified, and the rights and responsibilities are determined.
[0035] The principle of determining rights and responsibilities through policy restoration is as follows Figure 2 As shown, the specific process includes: Based on the log time of data exchange behavior, the policy is queried in both "valid" and "archived" states. Verify the integrity value of this policy; Verify the last policy integrity value; Extract policy content; Find and compare the policy content with the data sender identifier in the log information; Find and compare the policy content with the data recipient identifier in the log information; Compare data types; Compare data fingerprints; Traverse the corresponding policy inspection rules and manually determine whether the data exchange log information complies with the inspection rules; Through the above steps, if the data exchange log is consistent with the inspection rules, the responsible party of the abnormal exchange behavior can be confirmed.
[0036] Data and exchange strategies are the core elements for establishing the rights and responsibilities of cross-network and cross-domain data exchange. When auditing abnormal exchange behaviors, adding exchange strategies, completing core elements, and restoring exchange behaviors, the exchange strategies are restored synchronously. By manually judging the compliance of inspection rules with log information, the rights and responsibilities of abnormal exchange behaviors are determined, and the responsibilities of the exchange subjects can be determined more fully and accurately. This application combines the characteristics of the cross-network and cross-domain data exchange strategy life cycle, proposes to use a cryptographic mechanism to construct a policy chain based on the exchange strategy change time, and uses data exchange logs, data fingerprints, exchange strategies and other elements to fully and completely restore abnormal exchange behaviors, solving the limitations of cross-network and cross-domain data exchange using data exchange logs and data fingerprints to determine responsibilities, and also facilitates engineering implementation.
[0037] Example 2 like Figure 3 As shown, based on Example 1, this embodiment further discloses an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; the specific connection medium between the processor and the memory is not limited in the embodiment of the present invention.
[0038] Figure 3 The example in this article is that the processor and memory are connected via a bus. Figure 3 The connections between the other components are shown in bold lines, which are only for illustration and not intended to be limiting. The bus can be divided into address bus, data bus, control bus, etc. Figure 3 The processor is represented by a single thick line, but this does not mean that there is only one bus or only one type of bus. Alternatively, the processor can also be called a controller, without any limitation on the name.
[0039] In this embodiment, the memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the method described in Embodiment 1 by executing the instructions stored in the memory. The processor can implement Figure 3 The functions of each module in the device shown.
[0040] Among them, the processor is the control center of the device, which can use various interfaces and lines to connect the various parts of the entire control device, and monitor the device as a whole by running or executing instructions stored in the memory and calling data stored in the memory, the various functions of the device and processing data.
[0041] In an optional design, the processor may include one or more processing units, and the processor may integrate an application processor and a modem processor, wherein the application processor primarily processes the operating system, user interface, and application programs, and the modem processor primarily processes wireless communications. It is understood that the modem processor may not be integrated into the processor. In some embodiments, the processor and memory may be implemented on the same chip, or in some embodiments, they may be implemented on separate chips.
[0042] The processor may be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a method for establishing rights and responsibilities for cross-network and cross-domain data exchange disclosed in an embodiment of the present invention may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0043] As a non-volatile computer-readable storage medium, memory can be used to store non-volatile software programs, non-volatile computer executable programs and modules. Memory can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card-type memory, random access memory (Random Access Memory, RAM), static random access memory (Static Random Access Memory, SRAM), programmable read-only memory (Programmable Read Only Memory, PROM), read-only memory (Read Only Memory, ROM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), magnetic memory, disk, optical disk, etc. Memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in the embodiment of the present invention can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.
[0044] By designing and programming the processor, the code corresponding to the method for establishing rights and responsibilities for cross-network and cross-domain data exchange described in the aforementioned embodiment can be embedded in the chip, thereby enabling the chip to execute the steps of the method described in the aforementioned embodiment during operation. Designing and programming the processor is well known to those skilled in the art and will not be further described here.
[0045] Example 3 Based on Example 1, this embodiment further discloses: a computer-readable storage medium, wherein the computer-readable storage medium is used to store instructions, and when the instructions are executed, the method described in Example 1 is implemented.
[0046] In some optional embodiments, the present invention also provides various aspects of the method for adaptively recommending instrument parameters for digital debugging of electronic products, which can also be implemented in the form of a program product, which includes program code. When the program product is run on the device, the program code is used to enable the control device to execute the steps of a method for establishing cross-network and cross-domain data exchange rights and responsibilities according to various exemplary embodiments of the present invention described above in this specification.
[0047] It should be noted that although several units or subunits of the device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to an embodiment of the present invention, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of a unit described above can be further divided into multiple units to be embodied. In addition, although the operations of the method of the present invention are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired results. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, and / or one step can be decomposed into multiple steps.
[0048] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0049] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as a combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a server, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0050] Program code for performing the operations of the present invention may be written using any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0051] Where a remote computing device is involved, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0052] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0053] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A method for establishing rights and responsibilities for cross-network and cross-domain data exchange, characterized in that: The method for establishing rights and responsibilities for cross-network and cross-domain data exchange includes: Build a full life cycle strategy chain for cross-network and cross-domain data exchange systems, When auditing data exchange behavior, the rights and responsibilities of cross-network and cross-domain data exchange are clearly defined based on the policy-based restoration method, including: restoring the exchange path based on data exchange logs, comparing malicious code or sensitive information data fingerprints, and restoring exchange policy measures to establish the rights and responsibilities of the subjects.
2. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 1, characterized in that: When a cross-network and cross-domain data exchange system formulates or changes a data exchange policy, the policy attributes shall at least include: number, content, status, last change time, last integrity value, current change time, and current integrity value.
3. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 2, characterized in that: The policy attributes include: policy identifier, data sender identifier, data receiver identifier, data type, and check rules. The policy identifier is used to uniquely identify the policy.
4. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 2, wherein: The status in the policy attributes include: valid status and archive status. The valid state indicates that the policy is actually valid, and the audit state indicates that the corresponding policy is used for data exchange behavior audit.
5. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 4, characterized in that: Valid policies are established policies, including: issuance, execution, and modification; Policies in the archived state cannot be issued, executed, changed, or deleted. Policies in the valid state are changed to the archived state through archiving or deletion operations when they are no longer in use.
6. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 4, characterized in that: The strategy is passed: the last change time, the last integrity value, the current change time, and the current integrity value constitute the strategy chain data structure; The last change time and the current change time of the first policy formulation are both taken as the current time value, and the last integrity value is set to all 0s.
7. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 1, characterized in that: The attributes of the data exchange log include at least log identifier, log time, data sender identifier, data receiver identifier, data type, data fingerprint, and log description. The data fingerprint is calculated when the data exchange log is reported. The process of clarifying the rights and responsibilities of cross-network and cross-domain data exchange based on the policy-based rights and responsibilities restoration method includes: When restoring abnormal exchange behavior, the data is determined through the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain through the log time of the data exchange, the inspection rules are determined by comparing the data sender identifier, data receiver identifier, and data type in the log and policy, the data exchange behavior elements are restored, the inspection rules are manually identified, and the rights and responsibilities are determined.
8. The method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to claim 5, characterized in that: The specific process of determining rights and responsibilities during policy restoration includes: Based on the log time of data exchange behavior, policies can be found in both the "Effective" and "Archived" states. Verify the integrity value of this policy; Verify the last policy integrity value; Extract policy content; Find and compare the policy content with the data sender identifier in the log information; Find and compare the policy content with the data recipient identifier in the log information; Compare data types; Compare data fingerprints; Traverse the corresponding policy inspection rules and manually determine whether the data exchange log information complies with the inspection rules; Through the above steps, if the data exchange log is consistent with the inspection rules, the responsible party of the abnormal exchange behavior can be confirmed.
9. An electronic device, characterized in that: include: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the method according to any one of claims 1 to 8 by executing the instructions stored in the memory.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store instructions, and when the instructions are executed, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Data transmission system and transmission method thereof
CN114095184A
Data auditing system and method
CN115914005A
Cross-network message collaborative service system model
CN116233267A
Hierarchical data fingerprint auditing and tracing method in cross-network exchange
CN116723049A
Method, device and system for data cross-domain request
US20170149934A1