Data access and use control method and system for trusted data space

By integrating the data access and usage control methods of connectors and management modules in the data user terminals, data encryption storage and processing are achieved, which solves the problem of data leakage in cross-institutional and cross-entity data sharing and circulation, and ensures data security and processing performance.

CN120744947AActive Publication Date: 2025-10-03BEIJING DIGITAL INTELLIGENCE TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510849658.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-10-03
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

Existing data sharing, exchange, and data space access and use control solutions pose data leakage risks in cross-institutional and cross-entity data sharing and circulation, or cannot meet data processing needs in application scenarios with high performance requirements.

Method used

By integrating the data consumer connector, security control area management module and result output area management module in the data consumer terminal, data encryption storage and processing are realized. Combined with key management and security audit mechanisms, it is ensured that data is accessed and processed within the security control area, and the processing results are encrypted and audited in the result output area to prevent data leakage.

Benefits of technology

It completely solves the problem of data leakage during cross-institutional, cross-entity, and cross-regional sharing and circulation. At the same time, it can still meet data processing needs in application scenarios with high performance requirements, ensuring data security and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744947A_ABST
    Figure CN120744947A_ABST
Patent Text Reader

Abstract

The invention provides a data access and use control method and system for a trusted data space. The method is applied to a data user terminal. A data user connector, a safety control area management module and a result output area management module which are connected pairwise are integrated in the data user terminal; the security control area management module supports deployment of a data processing application program in a security control area; through setting of the security control area, the result output area and the corresponding management module and the corresponding processing flow, the data user application program can directly access the original plaintext data of the specified data, but cannot take the plaintext data out of the security control area; the result data processed by the application program can only be written into the result output area, the data is prevented from being leaked from the channel through a mechanism of firstly forcibly encrypting the result data and then auditing the result data, and the safety problems of data leakage and the like during cross-mechanism, cross-body and cross-area sharing and circulation of the data of the trusted data space are thoroughly solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of trusted data technology, and in particular to a method and system for controlling data access and use of a trusted data space. Background Art

[0002] The trusted data space is the infrastructure for the open interconnection of data resources and the circulation and application of data. It is a data application ecosystem driven by consensus rules and co-created by multiple parties. It is an important carrier for promoting the large-scale circulation and utilization of data resources and building a data factor market to release the value of data. It provides data processing and utilization, data trusted computing, data trusted exchange, asset notarization and traceability, data security and other capabilities, so that data can be supplied, circulated, used well and ensured safety.

[0003] The trusted data space technology system can be divided into three major capabilities: trusted governance, resource interaction, and value co-creation. Trusted governance primarily includes identity registration and verification of various entities, access verification of connectors, data access and usage control policies, privacy computing, and data sandbox integration. Resource interaction primarily includes data publishing, market, retrieval, data trading, and delivery capabilities. Value co-creation primarily includes various types of assessment, liquidation audit, and data development and utilization capabilities.

[0004] Access connectors are standardized software systems or hardware-based terminal devices that connect data circulation entities (various organizations, including government agencies, enterprises, and institutions) with data circulation platforms such as trusted data spaces. They can be deployed on both the terminal and enterprise sides. Data supply and demand entities, such as government departments, enterprises, and individuals, can access data through access connectors to trusted data spaces and other data circulation platforms, enabling rapid access and delivery of data resources, data assets, and data products.

[0005] Compared with traditional data sharing and exchange platforms, traditional data sharing and exchange platforms are mainly positioned for the exchange of data within an organization or entity, which is generally the exchange of plaintext data. There is no need to consider issues such as data leakage within the organization (there are also data security components, mainly considering that data cannot be leaked to the outside); trusted data spaces are mainly positioned for cross-institutional and cross-entity data sharing and exchange, and therefore introduce more security management capabilities, including data access and usage control technology, privacy computing, data sandbox, blockchain and other technologies. Trusted data spaces not only support traditional plaintext data sharing methods, but also support more secure and controllable data sharing and circulation, realizing the "available but invisible" and "available and controllable" data.

[0006] Existing solutions for sharing, exchanging, and controlling access to data spaces include: traditional data sharing and exchanging platforms, data spaces combined with conventional data access and usage control technology, and data spaces combined with privacy-preserving computing technology. These three solutions present the following challenges:

[0007] (1) Problems with traditional data sharing and exchange platforms

[0008] Traditional data sharing and exchange platforms are generally only used for data circulation and sharing within an organization, and do not provide relevant technologies for secure and controllable data circulation. When applied to cross-institutional and cross-entity scenarios, users obtain plaintext data and there is no subsequent management and control mechanism, so they can process it arbitrarily, resulting in a great risk of data leakage.

[0009] (2) Data space + conventional data access and usage control technology issues

[0010] By introducing secure circulation technology for conventional data access and usage control in the data space, after the data user obtains the data, the data can be prevented from being downloaded or copied a second time through usage control technology, which reduces the risk of data leakage to a certain extent. However, since the user's application will directly access the original plaintext data, the application can copy and save the data by itself during the processing process, thereby bypassing the conventional data access and usage control policy, and the risk of data leakage still exists.

[0011] (3) Issues with Data Space + Privacy Computing Technology

[0012] By introducing privacy-preserving computing technology into the data space, data users cannot directly access the original data, only the results of data processing, which essentially avoids the risk of data leakage. The main problem with privacy-preserving computing is that the high complexity of computation and communication overhead leads to a sharp decline in data processing performance, which cannot be met in application scenarios with high performance requirements. At the same time, some application scenarios require direct access to raw data, which cannot be solved by privacy-preserving computing technology. For example, in the scenario of AI model training, the data provider and the model trainer belong to different organizations. The model trainer must perform data labeling and model training on the raw data, and privacy-preserving computing technology cannot be used to process the data in this case.

[0013] In summary, existing shared exchange and data space access control solutions may cause data leakage, usage restrictions, severe performance degradation, and other issues for the sharing and circulation of data sets / files. Summary of the Invention

[0014] The purpose of this application is to provide a data access and use control method and system for a trusted data space, which can solve the problem of data leakage when data sets / files in the trusted data space are shared and circulated.

[0015] In the first aspect, the present application provides a data access and usage control method for a trusted data space, which is applied to a data user terminal; the data user terminal is integrated with a pairwise connected data user connector, a security control area management module, and a result output area management module; the security control area management module supports the deployment of data processing applications in the security control area; the data user terminal is respectively communicated with the trusted data space management platform and the data provider connector in the data provider terminal; the method comprises: initiating an acquisition request for specified data and corresponding access and usage control policy to the data provider connector through the data user connector, receiving the encrypted specified data and access and usage control policy returned by the data provider connector according to the acquisition request, and storing the encrypted specified data in the secure A security control area managed by the control area management module; wherein the access and use control policy is used for data users to view and access and use data based on the security control area and the result output area in accordance with the policy; access and process encrypted specified data with the help of the data consumer connector through the data processing application, cache the data processing results, and save the encrypted data processing results to the result output area managed by the result output area management module; initiate a data security audit request for the encrypted data processing results to the data provider connector through the result output area management module with the help of the data consumer connector, so that the data provider connector performs a data security audit, and perform corresponding operations based on the security audit results through the data consumer connector with the help of the data processing application.

[0016] Furthermore, the above-mentioned steps of accessing and processing the encrypted designated data with the help of the data consumer connector through the data processing application and caching the data processing results include: initiating an access request for the encrypted designated data to the data consumer connector through the data processing application, so that the data consumer connector initiates a first key acquisition request to the data provider connector, and receives the first key returned by the data provider connector according to the first key acquisition request; the data consumer connector returns the first key to the data processing application; the data processing application decrypts the encrypted designated data according to the first key and performs corresponding processing on the decrypted data according to actual needs, and caches the data processing results.

[0017] Furthermore, the above-mentioned step of saving the encrypted data processing result to the result output area managed by the result output area management module through the data processing application and the data consumer connector includes: the data processing application sends a write operation request to the data consumer connector to write the data processing result to the result output area, so that the data consumer connector sends a second key acquisition request to the data provider connector, and receives the second key returned by the provider connector according to the second key acquisition request; the data consumer connector returns the second key to the data processing application; the data processing application encrypts the data processing result according to the second key, and stores it in the result output area managed by the result output area management module.

[0018] Furthermore, the above-mentioned step of initiating a data security audit request for the encrypted data processing result to the data provider connector with the help of the data user connector through the result output area management module, so that the data provider connector performs a data security audit, includes: the result output area management module sends a data audit request to the data user connector, triggering the data user connector to forward the data audit request and the encrypted data processing result to the data provider connector, so that the data provider connector decrypts the encrypted data processing result according to the data audit request and performs a data security audit.

[0019] Furthermore, the above-mentioned step of performing corresponding operations based on the security audit result through the data consumer connector with the help of the data processing application includes: if the security audit result is passed, the data consumer connector receives the decrypted data processing result returned by the data provider connector, and stores the decrypted data processing result in the result output area, so as to provide the download, storage or other operations of the data processing result to the outside through the data processing application; if the security audit result is failed, the data consumer connector receives the reason for the audit failure returned by the data provider connector, and optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application, so as to re-perform the subsequent decryption, processing, and caching steps of the processing results.

[0020] Furthermore, the above method also includes: when the data user connector receives a data destruction instruction triggered by the data provider connector judging that the specified data usage period agreed upon in the transaction between the two parties has expired, it determines whether the specified data needs to be renewed; if not, destroy the specified data and other temporary files generated by the associated processing process; if so, suspend the access rights to the specified data, apply to the data provider of the trusted data space management platform for renewal of the specified data, and trigger a data transaction application; if the transaction application is approved, continue normal access and processing; if the transaction application is not approved, destroy the specified data and other temporary files generated by the associated processing process.

[0021] Furthermore, before the above-mentioned step of initiating a request to obtain the specified data and the corresponding access and usage control policy to the data provider connector through the data user connector, it also includes: after the data transaction is completed, the data user connector sends a delivery request for the specified data to the trusted data space management platform, and receives the data provider connector address returned by the trusted data space management platform according to the delivery request.

[0022] Furthermore, the above-mentioned access and use control strategy includes: the security control area management module has the function of encrypting and storing data and providing data access and use functions, and is combined with the result output area management module to initiate data security audit requests, and perform subsequent processing functions when the data provider passes or fails the audit; the security control area management module supports the installation and deployment of the data user's data processing application in the security control area; the security control area allows data to be written to the result output area, and restricts writing data to other external storage devices except the result output area; other external access outside the result output area can be directly restricted through network isolation, including: through the secure desktop technology integrated in the data user connector to limit all operations such as copying, downloading, printing, and screenshots that may lead to data leakage during external client access; the result output area allows external downloading, storage or other operations after the data security audit is passed.

[0023] Furthermore, the first key and the second key are different, and both the first key and the second key are stored in the data consumer connector memory and are set with an expiration time.

[0024] In the second aspect, the present application also provides a data access and usage control system for a trusted data space, the system including a data provider terminal, a data user terminal and a trusted data space management platform that are connected in pairs; the data user terminal is integrated with a pair-connected data user connector, a security control area management module and a result output area management module; the security control area management module supports the deployment of data processing applications in the security control area; the data user connector is connected to the data provider connector in the data provider terminal; the data user terminal is used to execute the method described in the first aspect.

[0025] The present application provides a data access and use control method and system for a trusted data space, in which the method is applied to a data user terminal; the data user terminal is integrated with a pairwise connected data user connector, a security control area management module, and a result output area management module; the security control area management module supports the deployment of data processing applications in the security control area; the data user terminal is respectively communicated with the trusted data space management platform and the data provider connector in the data provider terminal; first, a request for obtaining specified data and corresponding access and use control policies is initiated to the data provider connector through the data user connector, the encrypted specified data and access and use control policies returned by the data provider connector according to the acquisition request are received, and the encrypted specified data is stored in the security control area The security control area managed by the domain management module; wherein, the access and use control policy is used for data users to view and access and use data based on the security control area and the result output area in accordance with the policy; then, the data processing application uses the data consumer connector to access and process the encrypted specified data, caches the data processing results, and saves the encrypted data processing results to the result output area managed by the result output area management module; finally, the result output area management module uses the data consumer connector to initiate a data security audit request for the encrypted data processing results to the data provider connector, so that the data provider connector performs a data security audit, and the data consumer connector uses the data processing application to perform corresponding operations based on the security audit results. Through the setting of security control areas, result output areas and corresponding management modules and the corresponding processing procedures, this application enables data user applications to directly access the original plaintext data of specified data, but cannot take this plaintext data out of the security control area; the result data processed by the application can only be written to the result output area, and the mechanism of forcibly encrypting the result data before reviewing it also prevents data leakage from this channel; thereby completely solving the security issues such as data leakage of data sets / file type data in the trusted data space when they are shared and circulated across institutions, entities and regions. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the specific implementation methods or the description of the prior art. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0027] Figure 1 This is an architectural diagram of a traditional data sharing and exchange platform in the prior art;

[0028] Figure 2This is a platform architecture diagram of a data space + conventional data access and usage control technology in the existing technology;

[0029] Figure 3 This is a platform architecture diagram of a data space + privacy computing technology in existing technologies;

[0030] Figure 4 A schematic diagram of a data access and use control system for a trusted data space provided in an embodiment of the present application;

[0031] Figure 5 A flowchart of a method for controlling data access and use of a trusted data space provided in an embodiment of the present application;

[0032] Figure 6 A flowchart of multi-terminal interaction provided in an embodiment of the present application;

[0033] Figure 7 A flowchart of another multi-terminal interaction provided in an embodiment of the present application;

[0034] Figure 8 A flowchart of another multi-terminal interaction provided in an embodiment of the present application. DETAILED DESCRIPTION

[0035] The following will clearly and completely describe the technical solutions of this application in conjunction with the embodiments. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0036] Existing solutions for sharing, exchanging, and controlling access to data spaces include: traditional data sharing and exchanging platforms, data spaces combined with conventional data access and usage control technology, and data spaces combined with privacy-preserving computing technology. The specific implementation processes and existing problems of these three solutions are as follows:

[0037] See also Figure 1The architecture diagram of a traditional data sharing and exchange platform is shown. Traditional data sharing and exchange platforms typically have a centralized management platform that manages and controls the data transmission needs of various data providers and users. Front-end processors are deployed on both the provider and user sides. When there's a need to exchange datasets or files, the management platform issues control instructions to the data provider's front-end processor. The front-end processor uses conventional file ETL and other technologies to read the dataset or file data from the data source and write it to the data user's front-end processor. The user's front-end processor then writes it to local storage for access by local application systems. However, traditional data sharing and exchange platforms are generally only used for data circulation and sharing within an organization and lack the relevant technologies for secure and controllable data circulation. When applied to cross-organizational and cross-entity scenarios, users obtain plaintext data and, without any subsequent control mechanisms, can manipulate it arbitrarily, leading to a significant risk of data leakage.

[0038] See also Figure 2 The platform architecture diagram shown here shows a data space + conventional data access and usage control technology. This technology, combined with a connector solution, enables data circulation and delivery. First, the data provider publishes a data product in the data space for external use, along with a data access and usage control policy. The data user obtains the data product information in the data space and initiates a data transaction request. After the transaction is completed, the data provider transfers the data to the data user via a connector. The user's connector retrieves the data and writes it to local storage, obtaining the accompanying access and usage control policy information. The user application accesses and processes the data, triggering deletion of the data after processing is complete or the usage period expires. While the introduction of secure circulation technology with conventional data access and usage control in the data space prevents data downloading and secondary copying after the data user obtains it, this reduces the risk of data leakage to a certain extent. However, because the user application directly accesses the original plaintext data, it can copy and save the data during processing, thereby bypassing the conventional data access and usage control policy. This still poses a risk of data leakage.

[0039] See also Figure 3The platform architecture diagram for Data Space + Privacy Computing technology shown in the figure above implements data circulation and delivery through a Data Space + Privacy Computing + Connector solution. First, a data provider publishes a data product in the Data Space for external use. After obtaining the data product information in the Data Space, a data consumer initiates a data transaction request. After the transaction is completed, the data consumer initiates privacy computing modeling with the data provider. After the modeling is completed, the consumer's application can use the processed data through privacy computing. Since the data obtained through privacy computing is not the original data, but only the calculation results, the original data is guaranteed not to be leaked. However, with the introduction of privacy computing technology in the Data Space, data consumers cannot directly access the original data, only the results of the calculations, which largely avoids the risk of data leakage. The main problem with privacy computing is that the high complexity of computation and communication overhead leads to a sharp decline in data processing performance, making it unsuitable for applications with high performance requirements. Furthermore, some applications require direct access to raw data, which cannot be solved by privacy computing technology. For example, in the AI ​​model training scenario, the data provider and the model trainer belong to different organizations. The model trainer must perform data annotation and model training on the original data, making privacy computing technology unsuitable for data processing.

[0040] Based on this, the present invention provides a method and system for controlling data access and usage in a trusted data space, which can address the data leakage issue during the sharing and circulation of data sets / files in the trusted data space. To facilitate understanding of the present invention, the present invention first provides a detailed introduction to the method for controlling data access and usage in a trusted data space disclosed in the present invention.

[0041] The embodiment of the present application provides a data access and use control method for a trusted data space, which is applied to a data user terminal in a data access and use control system for a trusted data space; see Figure 4 As shown, the data access and use control system of the trusted data space also includes: a trusted data space management platform and a data provider terminal; wherein the data user terminal is integrated with two-connected data user connectors, a security control area management module and a result output area management module; the security control area management module supports the deployment of data processing applications in the security control area; the data user terminal is respectively communicated with the trusted data space management platform and the data provider connector in the data provider terminal.

[0042] After completing the data product transaction with the data provider, the data user needs to deploy a data processing application in the security control area of ​​the data user's terminal when accessing and using the data product, so as to achieve access and use of the data product.

[0043] In this embodiment, the data processing application is responsible for completing data processing, such as reading and writing data. The security control area management module and the result output area management module ensure that the application's data processing is completed within constraints. This provides a security mechanism to prevent the application from reading or writing data beyond the scope permitted by the access and use control policy. Without these constraints and restrictions, the application could privately store data, leading to the risk of data leakage.

[0044] The above security control area and result output area are defined below:

[0045] 1) Definition of security control area

[0046] The Security Control Area Management module integrates the management capabilities of security control areas. It supports the installation and deployment of data consumer applications within the security control area, enabling the computation and storage of relevant data resources. It also provides secure encrypted storage and supports the storage of data sets and files obtained from data providers within the security control area.

[0047] Data sets / files are encrypted and stored in the data consumer's security control area. The key is provided by the data provider. When the data consumer accesses the data, the key is temporarily obtained from the data provider by the data consumer connector. The key is temporarily stored in the user connector's memory and not stored on the local hard disk. The connector should ensure the security of the key. The key will expire. When the key expires but the data consumer still has access rights, it must be obtained from the data provider again.

[0048] After obtaining the key, the user application of the security control area can access the securely encrypted stored data; the security control area restricts the user application from writing data to storage devices outside the area, and does not allow writing to other external storage devices except the result output area; other external access outside the result output area can be directly restricted through network isolation; if there is a need for client access outside the area, the secure desktop and other technologies integrated in the connector can be used to restrict all operations that may lead to data leakage, such as copying, downloading, printing, and screenshots during external client access.

[0049] 2) Result output area definition

[0050] The Result Output Area Management module integrates the management capabilities of the Result Output Area. After the user application completes processing in the Security Control Area, it encrypts the result data and writes it to the Result Output Area. The encryption key is also controlled by the data provider and is different from the encryption key used in the Security Control Area.

[0051] When a data consumer application writes data from the secure area to the result output area, it first temporarily obtains an encryption key from the provider before encrypting the data and writing it to the storage space in the result output area. The key is also stored only in the consumer connector's memory and has a set expiration time.

[0052] The result output area management module submits a data review request to the data provider, and the data provider reviews the output data. For data that needs to be reviewed, the encrypted data is first transmitted back to the data provider through the connector. The provider decrypts the data locally and then reviews whether there are any security risks such as data leakage. If there are no risks, the decrypted data is then transmitted to the data user through the connector. The data user can then perform subsequent processing on the data according to its own business needs.

[0053] See also Figure 5 The flowchart of the data access and use control method of the trusted data space provided by the embodiment of the present application is shown, and the method specifically includes the following steps:

[0054] Step S502: Initiate a request to obtain designated data and the corresponding access and use control policy from the data provider connector via the data consumer connector, receive the encrypted designated data and the access and use control policy returned by the data provider connector in response to the acquisition request, and store the encrypted designated data in the security control area managed by the security control area management module; the access and use control policy is for the data consumer to review and access and use data based on the security control area and result output area in accordance with the policy;

[0055] The designated data includes: data sets and / or files included in the data product. The encrypted designated data is the data obtained by the provider connector after encrypting the designated data according to the designated key.

[0056] The above-mentioned access and use control strategies include: the security control area management module has the function of encrypting and storing data and providing data access and use functions, and is combined with the result output area management module to initiate data security audit requests, and perform subsequent processing functions when the data provider passes or fails the audit; the security control area management module supports the installation and deployment of the data processing application of the data user in the security control area; the security control area allows writing data to the result output area, and restricts writing data to other external storage devices except the result output area; other external access outside the result output area can be directly restricted through network isolation, including: through the secure desktop technology integrated in the data user connector to limit all operations such as copying, downloading, printing, and screenshots during external client access that may lead to data leakage; the result output area allows external downloading, storage or other operations after the data security audit is passed.

[0057] Before the step of initiating a request to the data provider connector to obtain the designated data and the corresponding access and use control policy through the data consumer connector, the method further includes: after the data transaction is completed, the data consumer connector sends a delivery request for the designated data to the trusted data space management platform, and receives the data provider connector address returned by the trusted data space management platform in response to the delivery request. Based on the data provider connector address, the method then initiates a request to obtain the designated data and the corresponding access and use control policy to the corresponding data provider connector.

[0058] Step S504: Accessing and processing the encrypted designated data through the data processing application with the aid of the data consumer connector, caching the data processing results, and saving the encrypted data processing results to the result output area managed by the result output area management module;

[0059] This step is performed when a data consumer initiates an access request for designated data through a data processing application. The data processing application, with the help of the data consumer connector, can complete operations that comply with the access and usage control policy, such as accessing and processing encrypted designated data (including decrypting the encrypted designated data and processing the decrypted data), caching data processing results, and saving the encrypted data processing results to the result output area managed by the result output area management module.

[0060] In step S506, the result output area management module initiates a data security audit request for the encrypted data processing result to the data provider connector with the help of the data consumer connector, so that the data provider connector performs a data security audit, and performs corresponding operations based on the security audit result through the data consumer connector with the help of the data processing application.

[0061] In this step, the result output area management module further sends a data security review request with the help of the data user connector, so that the data provider connector can perform a data security review. After the data security review, corresponding processing is performed to ensure the security of data use.

[0062] The data access and use control method of the trusted data space provided in the embodiment of the present application, through the setting of the security control area, the result output area and the corresponding management module and the corresponding processing flow, the data user application can directly access the original plaintext data of the specified data, but cannot take this plaintext data out of the security control area; the result data processed by the application can only be written to the result output area, and the mechanism of forcibly encrypting the result data before reviewing it also prevents data leakage from this channel; thereby completely solving the security problems such as data leakage of data sets / file type data in the trusted data space when they are shared and circulated across institutions, entities and regions.

[0063] Furthermore, the step of "accessing and processing the encrypted designated data by the data processing application with the aid of the data consumer connector, and caching the data processing results" in step 504 specifically includes the following process:

[0064] (1) initiating an access request for encrypted designated data to a data consumer connector through a data processing application, so that the data consumer connector initiates a first key acquisition request to a data provider connector, and receives a first key returned by the data provider connector according to the first key acquisition request;

[0065] (2) the data consumer connector returns the first key to the data processing application;

[0066] (3) The data processing application decrypts the encrypted designated data according to the first key and processes the decrypted data accordingly according to actual needs, and caches the data processing results.

[0067] Furthermore, the step of "saving the encrypted data processing result to the result output area managed by the result output area management module through the data processing application and the data user connector" in step S504 specifically includes the following process:

[0068] (1) The data processing application sends a write operation request to the data consumer connector to write the data processing result into the result output area, so that the data consumer connector sends a second key acquisition request to the data provider connector and receives the second key returned by the provider connector according to the second key acquisition request;

[0069] (2) the data consumer connector returns the second key to the data processing application;

[0070] (3) The data processing application encrypts the data processing result according to the second key and stores the result in the result output area managed by the result output area management module.

[0071] It should be noted that the first key and the second key are different, and both the first key and the second key are stored in the memory of the data consumer connector and are set with an expiration time.

[0072] See also Figure 6 The multi-terminal interaction flowchart shown in the figure is as follows:

[0073] a. The data user has installed the application in the security control area, completed the data transaction, and initiated the delivery of the designated data product;

[0074] b. The data space queries the corresponding data product based on product identification and other information, and returns information such as the data provider's connector address;

[0075] c. The data consumer connector initiates a connection with the data provider connector, requesting the data set / file specified in the data transaction, as well as the corresponding data access and usage control policy and other information;

[0076] d. The data provider connector encrypts the corresponding dataset / file and returns the encrypted dataset / file and information such as data access and usage control policies to the data user;

[0077] e. The data consumer connector receives the encrypted dataset / file and the corresponding data access and usage control policy information, and writes the dataset / file content into the local security control area for storage;

[0078] f. The data consumer application starts running and initiates access to the dataset / file through the connector-encapsulated interface. However, the user does not have the access key for the dataset / file locally, or the key is already expired, triggering the key acquisition process.

[0079] g. The data consumer connector initiates a request to the data provider connector to obtain the security control area key;

[0080] h. The data provider connector returns the security control zone key to the consumer connector for use by the application.

[0081] i. The data consumer application uses the key to access the specified dataset / file, perform corresponding processing, and output and cache the processing results.

[0082] Furthermore, the step of "initiating a data security audit request for the encrypted data processing result to the data provider connector through the result output area management module with the help of the data consumer connector, so that the data provider connector performs a data security audit" in step S506 specifically includes the following process:

[0083] The result output area management module sends a data review request to the data consumer connector, triggering the data consumer connector to forward the data review request and the encrypted data processing results to the data provider connector, so that the data provider connector can decrypt the encrypted data processing results according to the data review request and perform data security review.

[0084] Furthermore, the step of "performing corresponding operations based on the security audit results by using the data processing application through the data consumer connector" in step S506 includes the following process:

[0085] (1) If the security audit result is passed, the data consumer connector receives the decrypted data processing result returned by the data provider connector and stores the decrypted data processing result in the result output area, so as to provide the data processing result for downloading, storage or other operations through the data processing application;

[0086] (2) If the security audit result is failed, the data consumer connector receives the audit failure reason returned by the data provider connector, optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application to re-perform the subsequent decryption, processing, and caching processing result steps.

[0087] See also Figure 7 The multi-terminal interaction flowchart shown in the figure is as follows:

[0088] a. The data consumer application initiates a write operation and writes the processing results to the result output area through the connector-encapsulated interface. If the data consumer does not have the output area key locally or the key it holds has expired, the key acquisition process is triggered.

[0089] b. The data consumer connector initiates a request to the data provider connector to obtain the result output region key;

[0090] c. The data provider connector returns the result output region key to the data consumer connector for use by the application;

[0091] d. The data consumer application uses the key to encrypt the processing result data and writes it to the result output area;

[0092] e. The data user's application completes the output of all result data for this processing and submits a request for result data review to the data provider through the result output area management module;

[0093] f. The data consumer connector transmits all processed result data to the data provider connector, saves it to the provider's local storage, and triggers the data review process;

[0094] g. The data provider decrypts the processed data using the locally stored key and conducts a data audit to determine if there are any security issues such as raw data leakage;

[0095] The audit method can be very flexible and is not limited by the embodiments of the present application. The audit method is closely related to the type of data, application scenario, requirements of the data provider, etc. It can be manual audit or automated audit. Manual audit, such as when the data provider acts as the audit party, can ask the data user to describe the classification, format, content, and other information of the output data in detail, and the audit party manually confirms whether the output data complies with the agreed method. It can also be automated audit, where the data is read through an automated program and compared to see if there are any problems such as data leakage. The two can also be combined.

[0096] h. After the review is passed, the data provider transmits the decrypted processing result data back to the data consumer connector and saves it to the result output area. The data consumer can download or copy the processing result data to other locations for subsequent processing based on business needs;

[0097] i. If the audit fails, the data provider will return the audit result and the corresponding reasons to the data user. The user will optimize the processing flow and re-process the security control area process.

[0098] Furthermore, the above method also includes: when the data user connector receives a data destruction instruction triggered by the data provider connector judging that the specified data usage period agreed upon in the transaction between the two parties has expired, it determines whether the specified data needs to be renewed; if not, destroy the specified data and other temporary files generated by the associated processing process; if so, suspend the access rights to the specified data, apply to the data provider of the trusted data space management platform for renewal of the specified data, and trigger a data transaction application; if the transaction application is approved, continue normal access and processing; if the transaction application is not approved, destroy the specified data and other temporary files generated by the associated processing process.

[0099] See also Figure 8 The multi-terminal interaction flowchart shown in the figure is as follows:

[0100] a. When the usage period of the dataset / file agreed upon in the transaction between the data provider and the parties expires, the dataset / file destruction process is triggered;

[0101] b. The data consumer connector receives the data destruction instruction and determines whether to renew the data set / file.

[0102] c. The data consumer does not need to renew the data, and the consumer connector destroys the data set / file and other temporary files generated by the associated processing;

[0103] d. The data user needs to renew the data set / file access rights, suspend the access rights to the data set / file, and apply to the data provider of the data space for renewal of the data set / file, triggering a data transaction application;

[0104] e. The transaction application for the renewal of the use of this dataset / file is approved, and the data provider extends the use period of this dataset / file. The data user will continue to handle it accordingly;

[0105] f. If the transaction request for renewal of the use of this dataset / file is not approved, the user connector will destroy this dataset / file and other temporary files generated by the associated processing.

[0106] The data access and use control method of the trusted data space provided in the embodiment of the present application includes the definition of the security control area and the result output area, the setting of the corresponding management modules, and the multi-terminal processing flow combined with the application, as well as the overdue processing flow. Through the above-mentioned multi-faceted settings, it is possible to completely solve the security issues such as data leakage of data sets / file type data in the trusted data space when they are shared and circulated across institutions, entities, and regions.

[0107] Based on the above method embodiment, the present application embodiment also provides a data access and use control system for a trusted data space, see Figure 4 As shown, the system includes a data provider terminal, a data user terminal and a trusted data space management platform that are connected in pairs; the data user terminal is integrated with a data user connector, a security control area management module and a result output area management module that are connected in pairs; the security control area management module supports the deployment of data processing applications in the security control area; the data user connector is connected to the data provider connector in the data provider terminal; the data user terminal is used to execute the method described in the above method embodiment.

[0108] The system provided in the embodiment of the present application has the same implementation principle and technical effects as those in the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the embodiment of the system, reference can be made to the corresponding content in the aforementioned method embodiment.

[0109] An embodiment of the present application also provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by the processor, the computer-executable instructions prompt the processor to implement the above-mentioned method. The specific implementation can be found in the above-mentioned method embodiment, which will not be repeated here.

[0110] The computer program products of the methods, devices, and electronic devices provided in the embodiments of the present application include a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the previous method embodiments. For specific implementation, please refer to the method embodiments and will not be repeated here.

[0111] Unless otherwise specifically stated, the relative steps, numerical expressions and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present application.

[0112] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0113] In the description of this application, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate the description of this application and simplify the description. They do not indicate or imply that the devices or components referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on this application. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0114] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The scope of protection of the present application is not limited thereto. Although the present application has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed in the present application, or perform equivalent replacements for some of the technical features thereof. These modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims.

Claims

1. A data access and use control method for a trusted data space, characterized in that: The method is applied to a data user terminal; the data user terminal integrates two-way connected data user connectors, a security control area management module, and a result output area management module; the security control area management module supports the deployment of data processing applications in the security control area; The data user terminal is respectively connected to the trusted data space management platform and the data provider connector in the data provider terminal; the method includes: Initiating a request to obtain designated data and the corresponding access and use control policy to the data provider connector through the data consumer connector, receiving the encrypted designated data and the access and use control policy returned by the data provider connector in accordance with the acquisition request, and storing the encrypted designated data in the security control area managed by the security control area management module; wherein the access and use control policy is for the data user to view and access and use the data based on the security control area and the result output area in accordance with the policy; Accessing and processing the encrypted designated data by the data processing application with the aid of the data consumer connector, caching the data processing results, and saving the encrypted data processing results to the result output area managed by the result output area management module; The result output area management module initiates a data security audit request for the encrypted data processing result to the data provider connector with the help of the data consumer connector, so that the data provider connector performs a data security audit, and the data consumer connector performs corresponding operations based on the security audit result with the help of the data processing application.

2. The method according to claim 1, characterized in that The steps of accessing and processing the encrypted designated data by the data processing application with the aid of the data consumer connector, and caching the data processing results, include: Initiating an access request for the encrypted designated data to the data consumer connector through the data processing application, so that the data consumer connector initiates a first key acquisition request to the data provider connector, and receives a first key returned by the data provider connector according to the first key acquisition request; The data consumer connector returns the first key to the data processing application; The data processing application decrypts the encrypted designated data according to the first key, processes the decrypted data accordingly according to actual needs, and caches the data processing results.

3. The method according to claim 2, characterized in that The step of saving the encrypted data processing result to the result output area managed by the result output area management module through the data processing application and the data consumer connector includes: The data processing application sends a write operation request to the data consumer connector to write the data processing result into the result output area, so that the data consumer connector sends a second key acquisition request to the data provider connector and receives the second key returned by the provider connector according to the second key acquisition request; The data consumer connector returns the second key to the data processing application; The data processing application encrypts the data processing result according to the second key and stores the encrypted result in the result output area managed by the result output area management module.

4. The method according to claim 1, wherein The step of initiating a data security audit request for the encrypted data processing result to the data provider connector by means of the data output area management module and the data consumer connector, so that the data provider connector performs a data security audit, includes: The result output area management module sends a data review request to the data consumer connector, triggering the data consumer connector to forward the data review request and the encrypted data processing result to the data provider connector, so that the data provider connector decrypts the encrypted data processing result according to the data review request and performs a data security review.

5. The method according to claim 1, wherein The step of performing corresponding operations based on the security audit result by the data consumer connector with the help of the data processing application includes: If the security audit result is passed, the data consumer connector receives the decrypted data processing result returned by the data provider connector, and stores the decrypted data processing result in the result output area, so as to provide the data processing result for downloading, storage or other operations through the data processing application; If the security audit result is failure, the data user connector receives the audit failure reason returned by the data provider connector, optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application to re-perform the subsequent decryption, processing, and caching processing result steps.

6. The method according to claim 1, wherein The method further comprises: When the data user connector receives a data destruction instruction triggered by the data provider connector judging that the usage period of the designated data agreed upon in the transaction between the two parties has expired, the data user connector determines whether the designated data needs to be renewed; If not, destroy the specified data and other temporary files generated by the accompanying processing; If so, suspend the access rights to the designated data, apply to the data provider of the trusted data space management platform for renewal of the use of the designated data, and trigger a data transaction application; if the transaction application is approved, continue normal access and processing; if the transaction application is not approved, destroy the designated data and other temporary files generated by the associated processing process.

7. The method according to claim 1, characterized in that Before the step of initiating a request for obtaining designated data and corresponding access and usage control policies to the data provider connector through the data consumer connector, the method further includes: After the data transaction is completed, the data user connector sends a delivery request for the specified data to the trusted data space management platform, and receives the data provider connector address returned by the trusted data space management platform according to the delivery request.

8. The method according to claim 1, characterized in that The access and use control strategy includes: the security control area management module has the function of encrypting and storing data and providing data access and use functions, and is combined with the result output area management module to initiate data security audit requests and perform subsequent processing functions when the data provider passes or fails the audit; The security control area management module supports the installation and deployment of data processing applications of data users in the security control area; The security control area allows writing data to the result output area, and restricts writing data to other external storage devices except the result output area; other external access outside the result output area can be directly restricted through network isolation, including: through the security desktop technology integrated in the data user connector, limiting all operations such as copying, downloading, printing, and screenshots during external client access that may lead to data leakage; the result output area allows external downloading, storage or other operations after passing the data security review.

9. The method according to claim 3, characterized in that The first key and the second key are different, and both the first key and the second key are stored in the memory of the data consumer connector and are set with an expiration time.

10. A data access and use control system for a trusted data space, characterized in that: The system includes a data provider terminal, a data user terminal and a trusted data space management platform that are connected in pairs; the data user terminal integrates a data user connector, a security control area management module and a result output area management module that are connected in pairs; the security control area management module supports the deployment of data processing applications in the security control area; the data user connector is connected to the data provider connector in the data provider terminal; the data user terminal is used to execute the method described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Data registration and trusted circulation system and method, electronic equipment and storage medium

    CN112597140A

  • Method and system for secure sharing of data between first region and second region

    CN114091058A

  • Trusted data space data management and control method and system based on contract attachment

    CN117494218A

  • Method and system for secure management of microscopic data use

    CN117592119A

  • International data space connector authority management method and related device

    CN117828626A

Cited By

  • Data sharing and circulating system and method for trusted data space

    CN121834881A