A method, device and medium for establishing rights and responsibilities of cross-network cross-domain data exchange

By constructing a full lifecycle policy chain for cross-network and cross-domain data exchange systems, and combining data exchange logs, fingerprints, and path reconstruction, the compliance of exchange policies is verified, which solves the shortcomings in the confirmation of rights and responsibilities in cross-network and cross-domain data exchange and achieves a more comprehensive determination of responsibilities.

CN120729635BActive Publication Date: 2025-11-18NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511195062.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-18
Estimated Expiration
2045-08-26

AI Technical Summary

Technical Problem

Existing technologies make it difficult to fully identify the responsible parties for abnormal exchange behavior in cross-network and cross-domain data exchange, especially when restoring the exchange path, due to the lack of verification of the exchange strategy, resulting in insufficient identification of responsibility.

Method used

Construct a full lifecycle policy chain for cross-network and cross-domain data exchange systems. By comprehensively reconstructing data exchange logs, data fingerprints, and exchange paths, and combining the verification of log compliance with exchange policies, clarify the responsible parties for abnormal exchange behaviors.

Benefits of technology

It enables comprehensive and accurate confirmation of responsibilities for abnormal behavior in cross-network and cross-domain data exchange, fills the gap in policy verification during exchange path restoration, and improves the accuracy and comprehensiveness of responsibility determination.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729635B_ABST
    Figure CN120729635B_ABST
Patent Text Reader

Abstract

The application discloses a cross-network cross-domain data exchange right and responsibility establishment method, equipment and medium, and the cross-network cross-domain data exchange right and responsibility establishment method comprises the following steps: constructing a cross-network cross-domain data exchange system full-life-cycle policy chain; when auditing a data exchange behavior, the right and responsibility subject of cross-network cross-domain data exchange is determined based on a policy restoration right and responsibility method, and the method comprises the following steps: according to data exchange logs, comparing malicious codes or sensitive information data fingerprints, restoring an exchange path, and restoring an exchange strategy measure to determine the right and responsibility subject. The application mainly solves the problem of policy restoration when the exchange path is restored, thereby verifying the compliance of abnormal exchange behavior logs, and providing support for abnormal exchange behavior auditing and right and responsibility determination. Meanwhile, the application solves the problem of establishing the consistency of the cross-network cross-domain data exchange right and responsibility according to data exchange logs, data fingerprints, an exchange path and an exchange strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data exchange technology, and in particular relates to a method, device and medium for establishing rights and responsibilities in cross-network and cross-domain data exchange. Background Technology

[0002] Cross-network and cross-domain data exchange systems are becoming increasingly widely used. Business systems use these systems to exchange data across different networks. When abnormal exchange behaviors such as the spread of malicious code or the leakage of sensitive information are discovered, it is necessary to use technical means to identify the responsible parties for the information leakage and risk spread so that managers can understand the situation or hold those responsible accountable.

[0003] A common approach is data exchange log auditing, which involves tracing back data exchange log information to identify the subject, object, time, and event of the leak or risk. This method is relatively simple and suitable for cross-network and cross-domain exchange scenarios with fixed or simple business operations and a small number of exchanges. However, using data exchange logs to clarify responsibilities lacks the core element of the data itself. It only indicates that the subject or object has abnormal behavior, but cannot prove that the leaked or disseminated information was generated by that subject or object. Therefore, data fingerprinting is introduced to participate in the confirmation of responsibilities. Before cross-network exchange, the business system extracts and stores data fingerprints. During auditing, the data fingerprints of leaked or disseminated information are extracted, and the subject of the leak or dissemination is identified by searching the data fingerprint database and comparing the similarity of the data fingerprints. Simultaneously, cross-network and cross-domain data exchange auditing also employs a path reconstruction method, recording each node through which the data passes during cross-network and cross-domain exchange. During auditing, the exchange path of the leaked or disseminated information is reconstructed, thereby reproducing the entire process of abnormal exchange behavior and clarifying the responsible parties for information leakage and risk dissemination. While technical means such as data exchange log verification, data fingerprint comparison, and exchange path reconstruction can largely identify the responsible parties for leaks or dissemination, data exchange logs are generated based on the execution results of exchange policies. The identification of responsibility for abnormal exchange behavior lacks verification of the exchange policy, making it difficult to fully prove the responsible party's liability. Currently, there is no evidence to demonstrate the compliance of data exchange logs through exchange policy verification during exchange path reconstruction or data exchange log auditing.

[0004] Patent CN115914005A discloses a data auditing system and method. In this system, the initiator distributes data security policies and data to various inspection devices. The inspection devices inspect the data according to the data security policies and report logs. During auditing, the system audits the operation log sets of the inspection devices based on the data security policies to obtain audit results, thus achieving compliance auditing of cross-domain data. This patent emphasizes using data provided by the initiator for auditing.

[0005] Patent CN116418587A discloses a method and system for auditing and tracing cross-domain data exchange behavior. The invention includes event collection, preliminary analysis, anomaly detection, and behavior tracking, enabling precise behavior viewing, user behavior statistics, and backtracking of exchange behavior. This patent primarily analyzes collected events to achieve auditing of cross-network and cross-domain data exchange.

[0006] Patent CN116723049A describes a hierarchical data fingerprint auditing and tracing method for cross-network exchange. Before the exchange, hierarchical data fingerprints of files are collected, extracted, and stored. During auditing and tracing, the hierarchical data fingerprints of the files to be traced are extracted and compared with fingerprints in a fingerprint database to complete the tracing. This patent primarily employs the pre-collection of hierarchical data fingerprints for data tracing.

[0007] To address the issue of incomplete data elements and the inability to fully clarify the responsible parties for abnormal exchange behavior during cross-network and cross-domain data exchange audits, this application proposes to construct an exchange strategy chain to support the audit of abnormal exchange behavior. This chain comprehensively utilizes data exchange logs, data fingerprints, exchange paths, and exchange strategies to confirm responsibilities. When restoring the exchange path, the exchange strategy is restored simultaneously to confirm the conformity between the data exchange logs and the exchange strategy. This fully and accurately reproduces the state and elements at the time of the abnormal exchange behavior, thereby determining the responsibilities for abnormal cross-network and cross-domain data exchange behavior. Summary of the Invention

[0008] The purpose of this application is to address the need to verify data exchange logs and compare data fingerprints to confirm the responsible parties for sensitive information leakage or security risk propagation during cross-network and cross-domain data exchange, thereby reconstructing the exchange path. To fully confirm the responsible parties for abnormal exchange behavior, it is necessary to verify the conformity of the abnormal exchange logs through the exchange policy. This application primarily solves the problem of policy restoration during exchange path reconstruction, thereby verifying the conformity of abnormal exchange behavior logs and providing support for auditing abnormal exchange behavior and determining responsibilities. It also solves the problem of establishing consistency in responsibilities for cross-network and cross-domain data exchange based on data exchange logs, data fingerprints, exchange paths, and exchange policies.

[0009] On the one hand, the objective of this application is achieved through the following technical solution:

[0010] A method for establishing responsibilities in cross-network and cross-domain data exchange, the method comprising:

[0011] Construct a full lifecycle strategy chain for cross-network and cross-domain data exchange systems.

[0012] When auditing data exchange activities, the responsible parties for cross-network and cross-domain data exchange are clarified based on the strategy restoration and responsibility method. This includes: restoring the exchange path and establishing the responsible parties based on data exchange logs and comparing malicious code or sensitive information data fingerprints.

[0013] According to a preferred implementation, when formulating or changing data exchange strategies, the cross-network and cross-domain data exchange system includes at least the following strategy attributes: number, content, status, last change time, last integrity value, current change time, and current integrity value.

[0014] According to a preferred embodiment, the policy attributes include: policy identifier, data sender identifier, data receiver identifier, data type, and inspection rules, wherein the policy identifier is used to uniquely identify the policy.

[0015] According to a preferred implementation, the states in the policy attributes include two types: valid state and archived state.

[0016] A valid status indicates that the strategy is actually effective, while an audit status indicates that the corresponding strategy is used for auditing data exchange behavior.

[0017] According to a preferred implementation, the strategy for the effective state is a pre-defined strategy, including: issuing, executing, and changing;

[0018] Policies in the archived state cannot be issued, executed, changed, or deleted. When a policy in the valid state is no longer used, it can be changed to the archived state through an archive or delete operation.

[0019] According to a preferred implementation, the strategy is structured by: last change time, last integrity value, current change time, and current integrity value.

[0020] The last change time and the current change time for the initial strategy formulation are both taken as the current time value, and the last integrity value is set to all 0.

[0021] According to a preferred embodiment, the attributes of the data exchange log include at least log identifier, log time, data sender identifier, data receiver identifier, data type, data fingerprint, and log description, wherein the data fingerprint is calculated and obtained when the data exchange log is reported;

[0022] The process of clarifying the responsible parties for cross-network and cross-domain data exchange based on the strategy restoration responsibility method includes:

[0023] When restoring abnormal exchange behavior, the data is identified by the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain by the log time of the data exchange, and the inspection rules are determined by comparing the data sender identifier, data receiver identifier and data type in the log and the policy. The elements of the data exchange behavior are restored, and the inspection rules are judged manually to determine the rights and responsibilities.

[0024] According to a preferred implementation, the specific process of determining the rights and responsibilities through strategy restoration includes:

[0025] Based on the log time of the data exchange behavior, the strategy can be retrieved in both "valid" and "archived" states.

[0026] Verify the integrity value of this policy;

[0027] Verify the integrity value of the previous policy;

[0028] Extract strategy content;

[0029] Search and compare the data sender identifier in the strategy content and log information;

[0030] Search and compare the data recipient identifier in the strategy content and log information;

[0031] Compare data types;

[0032] Compare data fingerprints;

[0033] The corresponding policy check rules are iterated through, and the data exchange log information is manually judged to be consistent with the check rules.

[0034] If the data exchange log matches the inspection rules through the above steps, the responsible party for the abnormal exchange behavior can be identified.

[0035] On the other hand, this application also discloses:

[0036] An electronic device includes: at least one processor; and a memory communicatively connected to said at least one processor;

[0037] The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the instructions stored in the memory to perform the aforementioned method.

[0038] On the other hand, this application also discloses:

[0039] A computer-readable storage medium for storing instructions that, when executed, cause the aforementioned method to be implemented.

[0040] The aforementioned main solution and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and are claimed in this application. Those skilled in the art, after understanding the solution of this application, will realize that there are many combinations based on the prior art and common general knowledge, all of which are technical solutions to be protected in this application, and will not be exhaustively listed here.

[0041] The beneficial effects of this application are:

[0042] Cross-network and cross-domain data exchange involves two main responsible parties: the business system and the cross-network and cross-domain data exchange system. When the business system provides abnormal data exchange logs, raising concerns about information leakage and risk spread, and the cross-network and cross-domain data exchange system does not have matching abnormal exchange logs, the policy chain described in this application can be used to determine whether the abnormal exchange behavior was caused by a policy.

[0043] This application proposes using a cryptographic mechanism to construct a policy chain based on policy change time, thereby clarifying the rights and responsibilities within a cross-network and cross-domain data exchange system. This application does not restrict the specific implementation parameters or storage method of the policy chain; during engineering implementation, multiple methods are supported to achieve the policy chain's ability to confirm rights and responsibilities. Attached Figure Description

[0044] Figure 1 This is a schematic diagram of the strategy chain data structure of this application;

[0045] Figure 2 This is a schematic diagram illustrating the process of resolving responsibilities and authority through strategy restoration;

[0046] Figure 3 This is a schematic diagram of the electronic device structure corresponding to Embodiment 2 of this application. Detailed Implementation

[0047] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, unless otherwise specified, the following embodiments and features in the embodiments can be combined with each other.

[0048] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0049] Example 1

[0050] refer to Figure 1 and Figure 2 As shown, this application discloses a method for establishing rights and responsibilities in cross-network and cross-domain data exchange, the method comprising:

[0051] Construct a full lifecycle strategy chain for cross-network and cross-domain data exchange systems; during data exchange behavior audits, clarify the responsible parties for cross-network and cross-domain data exchange based on the strategy restoration and responsibility method, including: restoring the exchange path and establishing the responsible parties based on data exchange logs and comparing malicious code or sensitive information data fingerprints.

[0052] (1) Design of the full lifecycle strategy chain for cross-network and cross-domain data exchange system

[0053] When business systems exchange data across networks and domains, the requirements are generally clear, and the format and content are basically determined. In most scenarios, an exchange strategy can be formulated once based on the requirements. However, there are also business requirements such as adding or removing strategies, and management requirements such as tightening strategies. To restore abnormal exchange behavior and restore the exchange strategy, all exchange strategies must be retained and the authenticity of historical exchange strategies must be guaranteed.

[0054] When formulating or changing data exchange policies, cross-network and cross-domain data exchange systems must include at least the following policy attributes: number, content, status, last change time, last integrity value, current change time, and current integrity value. Figure 1 As shown, the policy uses a chain data structure consisting of: last change time, last integrity value, current change time, and current integrity value; the integrity value is calculated using a cryptographic mechanism. The change time is accurate to milliseconds.

[0055] The policy attributes include: policy identifier, data sender identifier, data receiver identifier, data type, check rule 1... check rule n, etc. Among them, the policy identifier is used to uniquely identify the policy.

[0056] The policy attributes include two states: valid and archived. Valid indicates the policy is actually effective, while archived indicates the policy is used for auditing data exchange activities. The original integrity value includes all the preceding fields.

[0057] When designing and implementing the strategy, the last change time and the current change time are both taken as the current time value, and the last integrity value is set to all 0.

[0058] Policies in the valid state are established policies, including: issuance, execution, and modification; policies in the archived state cannot be issued, executed, modified, or deleted. When a policy in the valid state is no longer used, it is changed to the archived state through archiving or deletion operations.

[0059] (2) Strategy Restoration of Rights and Responsibilities Method

[0060] Cross-network and cross-domain data exchange involves three main responsible parties: the data sender, the cross-network and cross-domain data exchange system, and the data receiver. Establishing the responsibilities for cross-network and cross-domain data exchange mainly involves auditing abnormal exchange behaviors such as the spread of malicious code or the leakage of sensitive information. This can be achieved by comprehensively using technical measures such as checking data exchange logs, comparing fingerprints of malicious code or sensitive information, and restoring the exchange path and strategy to establish the responsible parties.

[0061] The attributes of a data exchange log include at least the log identifier, log time, data sender identifier, data receiver identifier, data type, data fingerprint, and log description. The data fingerprint is calculated when the data exchange log is reported.

[0062] The process of clarifying the responsible parties for cross-network and cross-domain data exchange based on the strategy restoration and responsibility method includes:

[0063] When restoring abnormal exchange behavior, the data is identified by the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain by the log time of the data exchange, and the inspection rules are determined by comparing the data sender identifier, data receiver identifier and data type in the log and the policy. The elements of the data exchange behavior are restored, and the inspection rules are judged manually to determine the rights and responsibilities.

[0064] Strategy restoration determines the principle of rights and responsibilities, such as Figure 2 As shown, the specific process includes:

[0065] Based on the log time of the data exchange behavior, the strategy can be retrieved in both "valid" and "archived" states.

[0066] Verify the integrity value of this policy;

[0067] Verify the integrity value of the previous policy;

[0068] Extract strategy content;

[0069] Search and compare the data sender identifier in the strategy content and log information;

[0070] Search and compare the data recipient identifier in the strategy content and log information;

[0071] Compare data types;

[0072] Compare data fingerprints;

[0073] The corresponding policy check rules are iterated through, and the data exchange log information is manually judged to be consistent with the check rules.

[0074] If the data exchange log matches the inspection rules through the above steps, the responsible party for the abnormal exchange behavior can be identified.

[0075] Data and exchange policies are core elements for establishing accountability in cross-network and cross-domain data exchange. When auditing abnormal exchange behavior, adding exchange policies, supplementing core elements, and restoring the exchange behavior, the exchange policies are restored simultaneously. By manually judging the compliance of the rules with log information, the accountability for abnormal exchange behavior can be determined, enabling a more comprehensive and accurate assessment of the exchange subject's responsibility. This application, considering the lifecycle characteristics of cross-network and cross-domain data exchange policies, proposes using a cryptographic mechanism to construct a policy chain based on the policy change time. It employs elements such as data exchange logs, data fingerprints, and exchange policies to fully and completely restore abnormal exchange behavior, overcoming the limitations of using data exchange logs and data fingerprints for accountability in cross-network and cross-domain data exchange, and also facilitating engineering implementation.

[0076] Example 2

[0077] like Figure 3 As shown, based on Embodiment 1, this embodiment also discloses an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; the specific connection medium between the processor and the memory is not limited in this embodiment of the invention.

[0078] Figure 3 The example used is the connection between the processor and memory via a bus. The bus... Figure 3 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. Buses can be divided into address buses, data buses, control buses, etc., but for ease of representation, [the specific bus type is not shown here]. Figure 3 The processor is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, a processor can also be called a controller; there are no restrictions on the name.

[0079] In this embodiment, the memory stores instructions executable by the at least one processor. By executing the instructions stored in the memory, the at least one processor performs the method described in Embodiment 1. The processor can implement... Figure 3 The functions of each module in the device shown.

[0080] The processor is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory and calling data stored in memory, it can monitor the device's various functions and process data, thereby enabling overall monitoring of the device.

[0081] In an alternative design, the processor may include one or more processing units. The processor may integrate an application processor and a modem processor, wherein the application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles wireless communication. It is understood that the modem processor may also not be integrated into the processor. In some embodiments, the processor and memory may be implemented on the same chip; in some embodiments, they may also be implemented separately on separate chips.

[0082] The processor can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method for establishing responsibilities in cross-network and cross-domain data exchange disclosed in the embodiments of this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0083] Memory, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory can include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, etc. Memory is any other medium capable of carrying or storing desired program code having an instruction or data structure form and accessible by a computer, but is not limited thereto. In embodiments of the present invention, memory can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0084] By designing and programming the processor, the code corresponding to the method for establishing responsibilities for cross-network and cross-domain data exchange described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the steps of the method described in the foregoing embodiments during operation. How to design and program the processor is a technique well-known to those skilled in the art and will not be elaborated upon here.

[0085] Example 3

[0086] Based on Embodiment 1, this embodiment also discloses: a computer-readable storage medium for storing instructions that, when executed, cause the method described in Embodiment 1 to be implemented.

[0087] In some alternative embodiments, the present invention also provides that various aspects of the adaptive recommendation method for process instrument parameters in digital debugging of electronic products can also be implemented in the form of a program product, which includes program code. When the program product is run on a device, the program code is used to cause the control device to perform the steps in the method for establishing rights and responsibilities for cross-network and cross-domain data exchange according to various exemplary embodiments of the present invention as described above.

[0088] It should be noted that although several units or sub-units of the apparatus have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the invention, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units. Furthermore, although the operation of the method of the invention is described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0089] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0090] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a server, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0091] Program code for performing the operations of this invention can be written using any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0092] In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0093] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0094] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1The steps of the functions specified in one or more boxes. The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions and improvements made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for establishing rights and responsibilities in cross-network and cross-domain data exchange, characterized in that, The method for establishing rights and responsibilities in cross-network and cross-domain data exchange includes: Construct a full lifecycle strategy chain for cross-network and cross-domain data exchange systems. When auditing data exchange behavior, the responsible parties for cross-network and cross-domain data exchange are clarified based on the strategy restoration method, including: restoring the exchange path and restoring the exchange strategy and measures to establish the responsible parties based on data exchange logs and comparing malicious code or sensitive information data fingerprints. When formulating or changing data exchange strategies, cross-network and cross-domain data exchange systems must include at least the following policy attributes: number, content, status, last change time, last integrity value, current change time, and current integrity value. The policy attributes include two states: valid state and archived state. A valid status indicates that the policy is actually effective, while an archived status indicates that the corresponding policy is used for auditing data exchange behavior. The strategies for valid states are established strategies, including: issuing, executing, and changing. A policy in the archived state cannot be issued, executed, changed, or deleted. When a policy in the valid state is no longer in use, it can be changed to the archived state through an archive or delete operation. The attributes of the data exchange log include at least the log identifier, log time, data sender identifier, data receiver identifier, data type, data fingerprint, and log description. The data fingerprint is calculated when the data exchange log is reported. The process of clarifying the responsible parties for cross-network and cross-domain data exchange based on the strategy restoration responsibility method includes: When restoring abnormal exchange behavior, the data is identified by the data fingerprint in the data exchange log, the exchange policy is extracted from the policy chain by the log time of the data exchange, the inspection rules are determined by comparing the data sender identifier, data receiver identifier and data type in the log and the policy, the elements of the data exchange behavior are restored, the inspection rules are manually judged, and the rights and responsibilities are determined. The specific process of determining responsibilities and rights through strategy restoration includes: 1) Based on the log time of data exchange behavior, query the strategy in both "valid" and "archived" states; 2) Verify the integrity value of this policy; 3) Verify the integrity value of the previous policy; 4) Extract strategy content; 5) Locate and compare the data sender identifier in the strategy content and log information; 6) Locate and compare the data recipient identifier in the strategy content and log information; 7) Compare data types; 8) Compare data fingerprints; 9) Traverse the corresponding policy check rules and manually determine whether the data exchange log information conforms to the check rules; If the data exchange log matches the inspection rules through steps 1) to 9), the responsible party for the abnormal exchange behavior can be identified.

2. The method for establishing rights and responsibilities in cross-network and cross-domain data exchange as described in claim 1, characterized in that, The policy attributes include: policy identifier, data sender identifier, data receiver identifier, data type, and inspection rules. The policy identifier is used to uniquely identify the policy.

3. The method for establishing rights and responsibilities in cross-network and cross-domain data exchange as described in claim 1, characterized in that, The strategy uses the following data structure to form a strategy chain: last change time, last integrity value, current change time, and current integrity value. The last change time and the current change time for the initial strategy formulation are both taken as the current time value, and the last integrity value is set to all 0.

4. An electronic device, characterized in that, include: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which executes the instructions stored in the memory to perform the method as described in any one of claims 1 to 3.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store instructions that, when executed, cause the method as described in any one of claims 1 to 3 to be implemented.

Citation Information

Patent Citations

  • Data transmission system and transmission method thereof

    CN114095184A

  • Data auditing system and method

    CN115914005A