Method and system for data access and usage control of a trusted data space

By integrating connectors and management modules into the data user's terminal, encrypted data storage and processing are achieved, solving the problem of data leakage in cross-institutional and cross-entity data sharing and circulation, and ensuring data security and processing performance.

CN120744947BActive Publication Date: 2026-03-27BEIJING DIGITAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing data sharing and exchange platforms and data space access control schemes pose a risk of data leakage in cross-organizational and cross-entity data sharing and circulation, or fail to meet data processing needs in application scenarios with high performance requirements.

Method used

By integrating a data user connector, a security control area management module, and a result output area management module into the data user terminal, encrypted data storage and processing are achieved. Combined with key management and security auditing mechanisms, this ensures that data is processed within the security control area and stored encrypted in the result output area, preventing data leakage.

Benefits of technology

It completely solves the problem of data leakage in cross-institutional and cross-entity data sharing and circulation, while still meeting data processing needs in high-performance application scenarios, ensuring data security and controllability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744947B_ABST
    Figure CN120744947B_ABST
Patent Text Reader

Abstract

The application provides a data access and use control method and system of a trusted data space, and the method is applied to a data user terminal; the data user terminal is integrated with data user connectors, a security control area management module and a result output area management module which are connected with each other; the security control area management module supports deploying a data processing application program in a security control area; through the setting of the security control area, the result output area and the corresponding management modules and the corresponding processing flow, the data user application program can directly access the original plaintext data of specified data, but cannot take the plaintext data out of the security control area; the result data processed by the application program can only be written into the result output area, and through the mechanism of first forcibly encrypting the result data and then auditing, the data leakage from the channel is prevented, and the security problems such as data leakage of the trusted data space in the sharing and circulation of cross-institutions, cross-subjects and cross-regions are completely solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of trusted data, in particular to a data access and use control method and system of a trusted data space. BACKGROUND

[0002] The trusted data space is an infrastructure for data resource open interconnection and data circulation application, is a data application ecology driven by consensus rules and co-created by multiple parties, is an important carrier for promoting the scale circulation and utilization of data resources, and is an important carrier for building a data element market to release the value of data. It provides data processing and utilization, data trusted computing, data trusted exchange, asset notarization and traceability, data security, and other capabilities, so that data can be provided, circulated, used, and secured.

[0003] The trusted data space technology system can be divided into three capabilities: trusted management and control, resource interaction, and value co-creation. Trusted management and control mainly includes the registration and verification of various subject identities, the access verification of connectors, data access and use control strategies, privacy computing, data sandbox integration, etc. Resource interaction mainly includes data publishing, market, search, and data transaction and delivery capabilities. Value co-creation mainly includes various assessment, clearing and auditing, and data development and utilization capabilities.

[0004] The access connector is a standardized software system or a terminal device combining software and hardware that connects data circulation subjects (various institutions, including government agencies, enterprises and institutions, etc.) with data circulation platforms such as trusted data spaces, and can be deployed on the terminal side or enterprise side. Data of data supply and demand subjects such as government departments, enterprises, and individuals can be accessed to data circulation platforms such as trusted data spaces through access connectors, realizing the rapid access and delivery of data resources / data assets / data products.

[0005] Compared with traditional data sharing and exchange platforms, traditional data sharing and exchange platforms mainly focus on the exchange of data within an institution or subject, and generally exchange plaintext data without considering data leakage within the institution (there are also data security components, mainly considering that data cannot be leaked to the outside). Trusted data space mainly focuses on cross-institution and cross-subject data sharing and exchange, so it introduces more security management and control capabilities, including data access and use control technology, privacy computing, data sandbox, blockchain, etc. Trusted data space not only supports traditional data plaintext sharing, but also supports more secure and controllable data sharing and circulation, realizing "usable but invisible" and "usable and controllable".

[0006] Existing sharing and exchange and data space access and use control schemes include three schemes: traditional data sharing and exchange platforms, data spaces + conventional data access and use control technology, and data spaces + privacy computing technology. The problems of the three schemes are as follows:

[0007] (1) Traditional data sharing exchange platform problems

[0008] The traditional data sharing exchange platform is generally only used for intra-agency data circulation and sharing, and does not provide related technologies for controllable circulation of data security. When applied to cross-agency and cross-subject scenarios, the user obtains plaintext data, and there is no subsequent control mechanism, which can be arbitrarily processed, resulting in a high risk of data leakage.

[0009] (2) Data space + conventional data access & usage control technology problems

[0010] The introduction of conventional data access & usage control security circulation technology in the data space can prevent data from being downloaded and copied again after the data user obtains the data, which reduces the risk of data leakage to a certain extent. However, since the application program of the user directly accesses the original plaintext data, the application program can copy the data and save it during processing, thereby bypassing the conventional data access & usage control strategy, and there is still a risk of data leakage.

[0011] (3) Data space + privacy computing technology problems

[0012] The introduction of privacy computing technology in the data space prevents the data user from directly obtaining the original data and only allows the data user to obtain the results after data computing and processing, which basically avoids the risk of data leakage. The main problem of privacy computing is that the high complexity of computing and communication overhead leads to a sharp decline in data processing performance, which cannot meet the requirements of applications with high performance requirements, and cannot be solved by privacy computing technology in some application scenarios that require direct access to the original data. For example, in the AI model training scenario, the data provider and the model training party belong to different agencies, and the model training party must perform data annotation and model training related work on the original data. At this time, privacy computing technology cannot be used to process data.

[0013] In summary, the existing sharing exchange and data space access and usage control scheme has problems of data leakage or use restrictions, and a serious decline in performance when sharing and circulating data sets / files. SUMMARY

[0014] The purpose of the present application is to provide a trusted data space data access and usage control method and system, which can solve the problem of data leakage when sharing and circulating data sets / files in a trusted data space.

[0015] In a first aspect, the application provides a data access and use control method of a trusted data space. The method is applied to a data user terminal. The data user terminal is integrated with data user connectors, a security control area management module and a result output area management module which are connected with each other. The security control area management module supports deployment of a data processing application in a security control area. The data user terminal is communicatively connected with a trusted data space management platform and a data provider connector in a data provider terminal. The method comprises: initiating, by the data user connector, an acquisition request for specified data and a corresponding access and use control policy to the data provider connector, receiving encrypted specified data and the access and use control policy returned by the data provider connector according to the acquisition request, and storing the encrypted specified data in the security control area managed by the security control area management module; wherein the access and use control policy is used for the data user to view and perform data access and use based on the security control area and the result output area according to the policy; performing, by the data processing application, access and processing of the encrypted specified data with the aid of the data user connector, caching a data processing result, and saving the encrypted data processing result to the result output area managed by the result output area management module; initiating, by the result output area management module, a data security audit request for the encrypted data processing result to the data provider connector with the aid of the data user connector, so that the data provider connector performs data security audit, and performing, by the data processing application, corresponding operations based on the security audit result with the aid of the data user connector.

[0016] Further, the step of performing, by the data processing application, access and processing of the encrypted specified data with the aid of the data user connector, and caching a data processing result comprises: initiating, by the data processing application, an access request for the encrypted specified data to the data user connector, so that the data user connector initiates a first key acquisition request to the data provider connector, and receives a first key returned by the data provider connector according to the first key acquisition request; the data user connector returns the first key to the data processing application; the data processing application decrypts the encrypted specified data according to the first key, and performs corresponding processing on the decrypted data according to actual needs, and caches the data processing result.

[0017] Further, the step of saving the encrypted data processing result to the result output area managed by the result output area management module through the data processing application and the data user connector includes: the data processing application sends a write operation request of writing the data processing result to the result output area to the data user connector, so that the data user connector sends a second key acquisition request to the data provider connector and receives the second key returned by the data provider connector according to the second key acquisition request; the data user connector returns the second key to the data processing application; the data processing application encrypts the data processing result according to the second key and stores the encrypted data processing result in the result output area managed by the result output area management module.

[0018] Further, the step of initiating, by the result output area management module, a data security audit request for the encrypted data processing result to the data provider connector through the data user connector, so that the data provider connector performs data security audit, includes: the result output area management module sends a data audit request to the data user connector, triggers the data user connector to forward the data audit request and the encrypted data processing result to the data provider connector, so that the data provider connector decrypts the encrypted data processing result according to the data audit request and performs data security audit.

[0019] Further, the step of performing corresponding operations by the data user connector based on the security audit result through the data processing application includes: if the security audit result is passed, the data user connector receives the decrypted data processing result returned by the data provider connector and stores the decrypted data processing result in the result output area, so as to provide the data processing result for download, storage or other operations through the data processing application; if the security audit result is not passed, the data user connector receives the audit failure reason returned by the data provider connector and optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application, so as to re-perform the subsequent steps of decryption, processing and caching the processing result.

[0020] Further, the method further includes: when the data user connector receives a data destruction instruction triggered by the data provider connector in response to the expiration of the specified data use period determined by the data provider connector and the data user connector, the data user connector determines whether the specified data needs to be renewed; if not, the specified data and other temporary files generated in the processing process are destroyed; if yes, the access permission of the specified data is suspended, the data provider of the trusted data space management platform is applied for the renewal of the specified data, and the data transaction application is triggered; if the transaction application is passed, the normal access and processing are continued; if the transaction application is not passed, the specified data and other temporary files generated in the processing process are destroyed.

[0021] Further, before the step of initiating, by the data user connector, a request for obtaining the specified data and the corresponding access use control policy to the data provider connector, the method further comprises: sending, by the data user connector, a delivery request for the specified data to the trusted data space management platform after the data transaction is completed, and receiving a data provider connector address returned by the trusted data space management platform according to the delivery request.

[0022] Further, the access use control policy comprises: the security control area management module has the function of encrypting the stored data and providing the data access use function, and in combination with the result output area management module, implements the step of initiating the data security audit request, and performs the subsequent processing function when the data provider passes or fails the audit; the security control area management module supports the installation and deployment of the data processing application program of the data user in the security control area; the security control area allows writing data to the result output area and restricts writing data to other external storage devices other than the result output area; other external access other than the result output area can be directly restricted through network isolation, including: all operations that may cause data leakage when the external client accesses through the security desktop technology integrated in the data user connector, such as copying, downloading, printing, and screen capturing; the result output area allows providing download, storage, or other operations to the outside after the data security audit passes.

[0023] Further, the first key and the second key are different, and the first key and the second key are stored in the memory of the data user connector and are provided with an expiration time.

[0024] In a second aspect, the application further provides a data access and use control system of a trusted data space, which comprises a data provider terminal, a data user terminal, and a trusted data space management platform connected in pairs; the data user terminal is integrated with a data user connector, a security control area management module, and a result output area management module connected in pairs; the security control area management module supports the deployment of a data processing application program in a security control area; the data user connector is connected with a data provider connector in the data provider terminal; and the data user terminal is used to execute the method according to the first aspect.

[0025] The application provides a data access and use control method and system of a trusted data space, and the method is applied to a data user terminal; the data user terminal is integrated with data user connectors, a security control area management module and a result output area management module which are connected with each other; the security control area management module supports deploying a data processing application program in a security control area; the data user terminal is in communication connection with a trusted data space management platform and a data provider connector in a data provider terminal; firstly, the data user connector initiates an acquisition request of specified data and a corresponding access and use control strategy to the data provider connector, receives the encrypted specified data and the access and use control strategy returned by the data provider connector according to the acquisition request, and stores the encrypted specified data in the security control area managed by the security control area management module; wherein the access and use control strategy is used for the data user to view and perform data access and use based on the security control area and the result output area according to the strategy; then the data processing application program accesses and processes the encrypted specified data by means of the data user connector, caches the data processing result, and saves the encrypted data processing result to the result output area managed by the result output area management module; finally, the result output area management module initiates a data security audit request of the encrypted data processing result to the data provider connector by means of the data user connector, so that the data provider connector performs data security audit, and the data processing application program performs corresponding operation based on the security audit result by means of the data user connector. Through the setting of the security control area, the result output area and the corresponding management modules and the corresponding processing flow, the data user application program can directly access the original plaintext data of the specified data, but cannot take the plaintext data out of the security control area; the result data processed by the application program can only be written into the result output area, and the mechanism of forcibly encrypting the result data and then auditing also prevents the data from leaking through this channel; thereby, the security problems such as data leakage of the data set / file type data of the trusted data space in the cross-institution, cross-subject and cross-region sharing and circulation are completely solved. BRIEF DESCRIPTION OF DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without any creative effort.

[0027] Figure 1 A schematic diagram of a traditional data sharing and exchange platform in the prior art;

[0028] Figure 2A platform architecture diagram of a data space + conventional data access & use control technology in the prior art;

[0029] Figure 3 A platform architecture diagram of a data space + privacy computing technology in the prior art;

[0030] Figure 4 A schematic diagram of a data access and use control system of a trusted data space provided by an embodiment of the present application;

[0031] Figure 5 A flowchart of a data access and use control method of a trusted data space provided by an embodiment of the present application;

[0032] Figure 6 A flowchart of multi-terminal interaction provided by an embodiment of the present application;

[0033] Figure 7 A flowchart of another multi-terminal interaction provided by an embodiment of the present application;

[0034] Figure 8 A flowchart of another multi-terminal interaction provided by an embodiment of the present application. DETAILED DESCRIPTION

[0035] The technical solutions of the present application will be described clearly and completely below in conjunction with embodiments. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0036] The existing sharing exchange and data space access and use control solutions include three solutions of a traditional data sharing exchange platform, a data space + conventional data access & use control technology, and a data space + privacy computing technology. The specific implementation processes and existing problems of the three solutions are as follows:

[0037] Referring to Figure 1The architecture diagram of the conventional data sharing exchange platform is shown. The conventional data sharing exchange platform usually has a centralized management platform, which manages and controls the data transmission requirements of various data providers and data users, and deploys front-end machines at the providers and users. When there is a data set / file exchange requirement, the management platform issues control instructions to the data provider front-end machine. The front-end machine reads the data set / file data from the data source using conventional file ETL technology and writes it to the data user front-end machine. The user front-end machine writes it to the local storage for local application system access. However, the conventional data sharing exchange platform is generally only used for intra-agency data circulation and sharing, and does not provide related technologies for safe and controllable data circulation. When applied to cross-agency and cross-subject scenarios, the user gets the plaintext data, and there is no subsequent control mechanism, which can be arbitrarily processed, resulting in a high risk of data leakage.

[0038] Referring to Figure 2 The platform architecture diagram of the data space + conventional data access & usage control technology is shown. The data circulation delivery is realized by the data space + conventional data access & usage control technology + connector scheme. First, the data provider publishes data products in the data space for external use, and the data products are accompanied by data access & usage control policies. The data user initiates a data transaction request after obtaining the data product information in the data space. After the transaction is completed, the data provider transmits the data to the data user through the connector. The user connector writes the data to the local storage and obtains the accompanying access & usage control policy information. The application program accesses the data and processes it. After the processing is completed or the usage period expires, the data can be deleted. However, the conventional data access & usage control security circulation technology is introduced in the data space. After the data user gets the data, the usage control technology can prevent the data from being downloaded and copied again, which reduces the risk of data leakage to a certain extent. However, since the user application program directly accesses the original plaintext data, the application program can copy the data and save it during processing, thereby bypassing the conventional data access & usage control policy, and there is still a risk of data leakage.

[0039] Referring to Figure 3The platform architecture diagram of the data space + privacy computing technology shown realizes the circulation and delivery of data through the data space + privacy computing + connector scheme. First, the data provider publishes data products in the data space for external use; after the data user obtains the data product information in the data space, the data user initiates a data transaction request; after the transaction is completed, the data user initiates privacy computing modeling with the data provider, and after the modeling is completed, the user application can use the data processed by the privacy computing. Since the data obtained through the privacy computing is not the original data, but the calculation result data, it can be ensured that the original data will not be leaked. However, by introducing the privacy computing technology in the data space, the data user cannot directly obtain the original data, but can only obtain the result after data calculation and processing, which can basically avoid the risk of data leakage; the main problem of privacy computing is that the high complexity of calculation and communication overhead leads to a sharp decline in data processing performance, which cannot meet the requirements of application scenarios with high performance requirements, and cannot solve the problem of directly accessing the original data in some application scenarios. For example: in the scene of AI model training, the data provider and the model training party belong to different institutions, and the model training party must perform data labeling and model training related work on the original data, at which time the data processing cannot be performed through the privacy computing technology.

[0040] Based on this, the embodiment of the application provides a data access and use control method and system of a trusted data space, which can solve the problem of data leakage when a data set / file shared in the trusted data space circulates. In order to facilitate the understanding of the embodiment, first, a data access and use control method of a trusted data space disclosed by the embodiment of the application is introduced in detail.

[0041] The data access and use control method of a trusted data space provided by the embodiment of the application is applied to a data user terminal in a data access and use control system of a trusted data space; as shown in the figure, Figure 4 The data access and use control system of a trusted data space further includes a trusted data space management platform and a data provider terminal; wherein the data user terminal is integrated with a data user connector, a security control area management module and a result output area management module which are connected with each other; the security control area management module supports deploying a data processing application program in the security control area; the data user terminal is in communication connection with the data provider connector in the data provider terminal and the trusted data space management platform.

[0042] After completing the data product transaction with the data provider, the data user needs to deploy a data processing application program in the security control area of the data user terminal when accessing and using the data product, so as to realize the access and use of the data product.

[0043] In this embodiment, the data processing application is used to complete the data processing process, such as responsible for data read and write processing; the security control area management module and the result output area management module are used to control the application to process the data under the constraint condition, that is, to provide a security mechanism to limit the application from reading and writing beyond the range allowed by the access use control strategy. Without these constraints and limitations, the application can privately save data, leading to the risk of data leakage.

[0044] The security control area and the result output area are defined as follows:

[0045] 1) Security control area definition

[0046] The security control area management module integrates the management capability of the security control area. The security control area management module supports the installation and deployment of the data user application in the security control area, realizes the calculation and storage of related data resources, provides secure encrypted storage, and supports the storage of the data set / file obtained from the data provider into the security control area.

[0047] The data set / file is stored in the security control area of the data user, and the key is provided by the data provider; when the data user accesses the data, the key is temporarily obtained from the data provider by the data user connector, and the key is temporarily stored in the memory of the user connector and is not stored in the local hard disk. The connector should ensure the security of the key; the key will expire, and when the key expires and the data user still has access rights, the key needs to be reacquired from the data provider.

[0048] After the security control area user application acquires the key, it can access the securely encrypted data; the security control area limits the user application to write data to the storage device outside the area, and does not allow writing to other external storage devices except the result output area; other external access outside the result output area can be directly limited through network isolation; if there is a need for external client access, the connector can be integrated with security desktop technology to limit all operations that may cause data leakage such as copying, downloading, printing, and screen capture when the external client accesses.

[0049] 2) Result output area definition

[0050] The result output area management module integrates the management capability of the result output area. After the user application completes the processing in the security control area, the processing result data is encrypted and written into the result output area. The key is also controlled by the data provider and is different from the encryption key of the security control area.

[0051] When the data user application writes data from the secure area to the result output area, the encryption key is temporarily obtained from the provider, and the data is encrypted and written to the storage space of the result output area. The key is also only stored in the user connector memory, and an expiration time is set.

[0052] The result output area management module submits a data audit request to the data provider, and the data provider audits the output data. For data that needs to be audited, the encrypted data is first transmitted back to the data provider through the connector, the provider decrypts the data locally, and then audits whether there is a data leakage risk, etc. If there is no risk, the decrypted data is transmitted to the data user through the connector, and the data user can perform subsequent processing on the data according to its own business needs.

[0053] Referring to Figure 5 The flowchart of the data access and use control method of the trusted data space provided by the embodiment of the application is shown. The method specifically includes the following steps:

[0054] Step S502, the data user connector initiates a specified data and corresponding access and use control policy acquisition request to the data provider connector, receives the encrypted specified data and access and use control policy returned by the data provider connector according to the acquisition request, and stores the encrypted specified data in the secure control area managed by the secure control area management module; wherein the access and use control policy is used for the data user to view and perform data access and use based on the secure control area and the result output area according to the policy;

[0055] The specified data includes data sets and / or files included in the data product. The encrypted specified data is data obtained by the provider connector encrypting the specified data according to the specified key.

[0056] The access and use control policy includes: the secure control area management module has the function of encrypting stored data and the function of providing data access and use, and in combination with the result output area management module, initiates a data security audit request, and performs subsequent processing functions when the data provider audits pass and does not pass; the secure control area management module supports the installation and deployment of the data processing application of the data user in the secure control area; the secure control area allows writing data to the result output area and restricts writing data to other external storage devices other than the result output area; other external access outside the result output area can be directly restricted through network isolation, including: all operations that may cause data leakage when the external client accesses through the secure desktop technology integrated in the data user connector, such as copying, downloading, printing, and screen capturing; the result output area allows external downloading, storage or other operations after the data security audit passes.

[0057] Before the step of initiating, by the data user connector, a request for obtaining the specified data and the corresponding access and use control policy to the data provider connector, the method further comprises: sending, by the data user connector, a delivery request for the specified data to the trusted data space management platform after the data transaction is completed, and receiving a data provider connector address returned by the trusted data space management platform according to the delivery request. Thus, the request for obtaining the specified data and the corresponding access and use control policy is initiated to the corresponding data provider connector according to the data provider connector address.

[0058] In step S504, the data processing application initiates, by means of the data user connector, access and processing of the encrypted specified data, caches the data processing result, and saves the encrypted data processing result to the result output area managed by the result output area management module.

[0059] This step is performed when the data user initiates a request for accessing the specified data by means of the data processing application. By means of the data processing application and the data user connector, operations conforming to the access and use control policy can be performed, such as access and processing of the encrypted specified data (including a decryption process of the encrypted specified data and a processing process of the decrypted data), caching of the data processing result, and saving of the encrypted data processing result to the result output area managed by the result output area management module.

[0060] In step S506, the result output area management module initiates, by means of the data user connector, a data security audit request for the encrypted data processing result to the data provider connector, so that the data provider connector performs data security audit, and the data user connector performs corresponding operations based on the security audit result by means of the data processing application.

[0061] In this step, the result output area management module further sends, by means of the data user connector, the data security audit request, so that the data provider connector performs data security audit, and corresponding processing is performed after the data security audit, which can ensure the security of data use.

[0062] The data access and use control method of the trusted data space provided in the embodiments of the present application can ensure that the application of the data user can directly access the original plaintext data of the specified data, but cannot take the plaintext data out of the security control area; the result data processed by the application can only be written to the result output area, and the mechanism of forcibly encrypting the result data and then auditing the result data can also prevent data leakage from this channel; and thus, the security problems such as data leakage of the data set / file type data of the trusted data space in cross-institution, cross-subject, and cross-region sharing and circulation are completely solved.

[0063] Further, the step of "encrypting the access and processing of the specified data by the data processing application through the data user connector, and caching the data processing result" in the above step 504 specifically includes the following processes:

[0064] (1) The data processing application initiates an access request for the encrypted specified data to the data user connector, so that the data user connector initiates a first key acquisition request to the data provider connector, and receives the first key returned by the data provider connector according to the first key acquisition request;

[0065] (2) The data user connector returns the first key to the data processing application;

[0066] (3) The data processing application decrypts the encrypted specified data according to the first key, and processes the decrypted data according to the actual needs, and caches the data processing result.

[0067] Further, the step of "storing the encrypted data processing result to the result output area managed by the result output area management module by the data processing application and the data user connector" in the above step S504 specifically includes the following processes:

[0068] (1) The data processing application sends a write operation request to the data user connector to write the data processing result to the result output area, so that the data user connector sends a second key acquisition request to the data provider connector, and receives the second key returned by the data provider connector according to the second key acquisition request;

[0069] (2) The data user connector returns the second key to the data processing application;

[0070] (3) The data processing application stores the encrypted data processing result in the result output area managed by the result output area management module.

[0071] It should be noted that the first key and the second key are different, and the first key and the second key are stored in the memory of the data user connector and are set with an expiration time.

[0072] Referring to the multi-end interaction flowchart shown in Figure 6 The specific implementation process is as follows:

[0073] a. The data user has installed the application in the security control area, the data transaction is completed, and the delivery of the specified data product is started;

[0074] b. The data space queries the corresponding data product according to the product identifier and other information, and returns the data provider connector address and other information;

[0075] c. The data user connector initiates a connection with the data provider connector, requests to obtain the data set / file specified in the data transaction, and corresponding data access & use control policy information, etc.

[0076] d. The data provider connector encrypts the corresponding data set / file, and returns the encrypted data set / file and data access & use control policy information, etc. to the data user;

[0077] e. The data user connector receives the encrypted data set / file and corresponding data access & use control policy information, etc., and writes the data set / file content into the local secure control area for storage;

[0078] f. The data user application program is started and runs, initiates access to the data set / file through the interface encapsulated by the connector, and the local access key for the data set / file is not available, or the key is held but has expired, triggering the key acquisition process;

[0079] g. The data user connector initiates a secure control area key acquisition request to the data provider connector;

[0080] h. The data provider connector returns the secure control area key to the user connector for use by the application program;

[0081] i. The data user application program uses the key to access the specified data set / file, performs corresponding processing, outputs and caches the processing result.

[0082] Further, the step of "initiating a data security audit request for the encrypted data processing result to the data provider connector through the result output area management module and the data user connector, so that the data provider connector performs data security audit" in the above step S506, specifically includes the following process:

[0083] The result output area management module sends a data audit request to the data user connector, triggers the data user connector to forward the data audit request and the encrypted data processing result to the data provider connector, so that the data provider connector decrypts and performs data security audit on the encrypted data processing result according to the data audit request.

[0084] Further, the step of "performing corresponding operations based on the security audit result through the data user connector and the data processing application program" in the above step S506 includes the following process:

[0085] (1) If the security audit result is passed, the data user connector receives the decrypted data processing result returned by the data provider connector, and stores the decrypted data processing result in the result output area, to provide the download, storage or other operations of the data processing result to the outside through the data processing application program;

[0086] (2) If the security audit result is not passed, the data user connector receives the audit not passed reason returned by the data provider connector, and optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application program, to re-perform the subsequent decryption, processing and cache processing result steps.

[0087] Referring to the multi-end interaction flowchart shown in Figure 7 The specific implementation process is as follows:

[0088] a. The data user application program initiates a write operation, and writes the processing result to the result output area through the interface encapsulated by the connector. The data user locally does not have the output area key, or holds the key but it has expired, triggering the key acquisition process;

[0089] b. The data user connector initiates a request to the data provider connector to acquire the result output area key;

[0090] c. The data provider connector returns the result output area key to the data user connector, which is provided to the application program for use;

[0091] d. The data user application program uses the key to encrypt the processing result data, and writes it to the result output area;

[0092] e. The data user application program completes the output of all result data of this processing, and initiates a result data audit application to the data provider through the result output area management module;

[0093] f. The data user connector transmits all processing result data to the data provider connector, and saves it to the local storage of the provider, triggering the data audit process;

[0094] g. The data provider decrypts the processing result data through the local storage key, and performs data audit, to check whether there is a security problem such as original data leakage;

[0095] The auditing manner can be flexible, and embodiments of the present application do not make any limitation; the auditing manner is closely related to the type of data, application scenario, requirement of the data provider, etc.; it can be manual auditing or automatic auditing; manual auditing, such as the data provider as an auditing party, can be that the data user describes the classification, format, content, etc. of the output data in detail, and the auditing party manually confirms whether the output data complies with the agreed manner; automatic auditing can be that an automatic program reads the data and compares whether the data has any leakage problem, and the two manners can be combined.

[0096] h. The data provider transmits the decrypted processing result data back to the data user connector, saves it to the result output area, and the data user can download or copy the processing result data to other positions for subsequent processing according to business requirements;

[0097] i. If the auditing is not passed, the data provider returns the auditing result and corresponding reason to the data user, the data user optimizes the processing flow, and re-performs the security control area processing flow.

[0098] Further, the above method further comprises: the data user connector receives a data destruction instruction triggered by the data provider connector when the data usage period specified by the transaction between the two parties expires; and judges whether the specified data needs to be renewed; if not, the specified data and other temporary files generated in the processing process are destroyed; if yes, the access permission of the specified data is suspended, the data provider of the trusted data space management platform is applied for the renewal of the specified data, and the data transaction application is triggered; if the transaction application is passed, the normal access and processing are continued; if the transaction application is not passed, the specified data and other temporary files generated in the processing process are destroyed.

[0099] Referring to the multi-end interaction flowchart shown in Figure 8 , the specific implementation process is as follows:

[0100] a. The data provider triggers the data set / file destruction flow when the data set / file usage period specified by the transaction between the two parties expires;

[0101] b. The data user connector receives a data destruction instruction, and the data user judges whether the data set / file needs to be renewed;

[0102] c. The data user does not need to renew, and the data user connector destroys the data set / file and other temporary files generated in the processing process;

[0103] d. The data user needs to renew, suspends the access permission of the data set / file, applies to the data provider of the data space for the renewal of the data set / file, and triggers the data transaction application.

[0104] e. The transaction application for the renewal of the use of the data set / file is approved, the data provider extends the use period of the data set / file, and the data user continues the corresponding processing;

[0105] f. The transaction application for the renewal of the use of the data set / file is not approved, and the data user connector destroys the data set / file and other temporary files generated by the processing process.

[0106] The data access and use control method of the trusted data space provided by the embodiments of the present application includes the definition of the security control area and the result output area, the setting of the corresponding management modules, and the combination of the multi-end processing flow of the application program and the overdue processing flow. Through the above-mentioned multi-aspect setting, the security problems such as data leakage of the data set / file type data of the trusted data space in the cross-agency, cross-subject, and cross-region sharing and circulation can be completely solved.

[0107] Based on the above-mentioned method embodiments, the embodiments of the present application also provide a data access and use control system of a trusted data space. As shown in Figure 4 The system includes a data provider terminal, a data user terminal, and a trusted data space management platform which are communicatively connected with each other. The data user terminal is integrated with a data user connector, a security control area management module, and a result output area management module which are connected with each other. The security control area management module supports the deployment of a data processing application program in the security control area. The data user connector is connected with a data provider connector in the data provider terminal. The data user terminal is used to execute the method as described in the above-mentioned method embodiments.

[0108] The system provided by the embodiments of the present application has the same implementation principle and technical effects as the above-mentioned method embodiments. For brief description, the part of the embodiments of the system which is not mentioned can be referred to the corresponding content in the above-mentioned method embodiments.

[0109] The embodiments of the present application also provide a computer readable storage medium which stores computer executable instructions. When the computer executable instructions are called and executed by a processor, the computer executable instructions cause the processor to implement the above-mentioned method. The specific implementation can be referred to the above-mentioned method embodiments, which will not be described herein again.

[0110] The computer program product of the method, device, and electronic equipment provided by the embodiments of the present application includes a computer readable storage medium which stores program codes. The instructions included in the program codes can be used to execute the method as described in the above-mentioned method embodiments. The specific implementation can be referred to the method embodiments, which will not be described herein again.

[0111] The relative positioning of components and steps, numerical expressions, and numerical values set forth in these examples are not intended to limit the scope of the present application unless otherwise specifically indicated.

[0112] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a nonvolatile computer readable storage medium executable by a processor. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0113] In the description of the present application, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", and the like indicate the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application. In addition, the terms "first", "second", "third" are only for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0114] Finally, it should be noted that: the above-described embodiments are only specific embodiments of the present application, used to illustrate the technical solutions of the present application, and are not limiting, the protection scope of the present application is not limited thereto, although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: any person skilled in the art within the technical scope disclosed by the present application, can still modify or easily think of changes to the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to part of the technical features; and these modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for data access and usage control of a trusted data space, characterized in that, The method is applied to a data user terminal; the data user terminal is integrated with data user connectors, a security control area management module and a result output area management module which are connected with each other; the security control area management module supports deploying a data processing application in a security control area; The data user terminal is in communication connection with a trusted data space management platform and a data provider connector in a data provider terminal; the method comprises: The data user connector initiates an acquisition request of specified data and a corresponding access and use control policy to the data provider connector, receives encrypted specified data and an access and use control policy returned by the data provider connector according to the acquisition request, and stores the encrypted specified data in a security control area managed by the security control area management module; wherein the access and use control policy is used for the data user to view and perform data access and use based on the security control area and the result output area according to the policy; The data processing application accesses and processes the encrypted specified data by means of the data user connector, caches a data processing result, and saves the encrypted data processing result to a result output area managed by the result output area management module; The result output area management module initiates a data security audit request for the encrypted data processing result to the data provider connector by means of the data user connector, so that the data provider connector performs data security audit, and the data processing application performs corresponding operation based on the security audit result by means of the data user connector; The method further comprises: When the data user connector receives a data destruction instruction triggered by the data provider connector judging that a specified data use period expires, it judges whether the specified data needs to be renewed; if not, the specified data and other temporary files generated in the processing process are destroyed; if yes, the access permission of the specified data is suspended, the data provider of the trusted data space management platform is applied for renewing the use of the specified data, and a data transaction application is triggered; if the transaction application is passed, the normal access and processing are continued; if the transaction application is not passed, the specified data and other temporary files generated in the processing process are destroyed.

2. The method of claim 1, wherein, The step of accessing and processing the encrypted specified data by means of the data user connector through the data processing application, and caching a data processing result, comprises: The data processing application initiates an access request for the encrypted specified data to the data user connector, so that the data user connector initiates a first key acquisition request to the data provider connector, and receives a first key returned by the data provider connector according to the first key acquisition request; The data user connector returns the first key to the data processing application; The data processing application decrypts the encrypted specified data according to the first key and processes the decrypted data according to actual requirements, and caches the data processing result.

3. The method of claim 2, wherein, The step of saving the encrypted data processing result to the result output area managed by the result output area management module through the data processing application and the data user connector includes: The data processing application sends a write operation request of writing the data processing result to the result output area to the data user connector, so that the data user connector sends a second key acquisition request to the data provider connector, and receives the second key returned by the provider connector according to the second key acquisition request; The data user connector returns the second key to the data processing application; The data processing application encrypts the data processing result according to the second key and stores it in the result output area managed by the result output area management module.

4. The method of claim 1, wherein, The step of initiating a data security audit request for the encrypted data processing result by the result output area management module to the data provider connector through the data user connector, so that the data provider connector performs data security audit, includes: The result output area management module sends a data audit request to the data user connector, triggers the data user connector to forward the data audit request and the encrypted data processing result to the data provider connector, so that the data provider connector decrypts the encrypted data processing result according to the data audit request and performs data security audit.

5. The method of claim 1, wherein, The step of performing corresponding operation based on the security audit result by the data user connector through the data processing application, includes: If the security audit result is passed, the data user connector receives the decrypted data processing result returned by the data provider connector, and stores the decrypted data processing result in the result output area, so as to provide the data processing result for download, storage or other operation through the data processing application; If the security audit result is not passed, the data user connector receives the audit failure reason returned by the data provider connector, optimizes the processing flow, and continues to execute the step of triggering the first key acquisition process through the data processing application, to re-perform the subsequent decryption, processing and caching of the processing result.

6. The method of claim 1, wherein, Before the step of initiating a specified data and corresponding access use control policy acquisition request to the data provider connector through the data user connector, further includes: After the data transaction is completed, the data user connector sends a delivery request of the specified data to the trusted data space management platform, and receives the data provider connector address returned by the trusted data space management platform according to the delivery request.

7. The method of claim 1, wherein, The access use control strategy comprises that the security control area management module has the function of encrypting stored data and providing data access use function, and in combination with the result output area management module, initiates a data security audit request, and when the data provider passes or fails the audit, performs subsequent processing function; The security control area management module supports installation and deployment of data processing application programs of data users in the security control area; The security control area allows writing data to the result output area and restricts writing data to other external storage devices other than the result output area; other external access other than the result output area is directly restricted through network isolation, including all operations that cause data leakage when an external client accesses through the security desktop technology integrated in the data user connector, such as copying, downloading, printing, and screen capturing; the result output area allows providing download, storage, or other operations to the outside after passing the data security audit.

8. The method of claim 3, wherein, The first key and the second key are different, and the first key and the second key are saved in the data user connector memory, and are provided with an expiration time.

9. A system for data access and usage control of a trusted data space, characterized in that The system comprises a data provider terminal, a data user terminal, and a trusted data space management platform connected in pairs; the data user terminal is integrated with a data user connector, a security control area management module, and a result output area management module connected in pairs; the security control area management module supports deployment of data processing application programs in the security control area; the data user connector is connected with a data provider connector in the data provider terminal; and the data user terminal is used to execute the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Data registration and trusted circulation system and method, electronic equipment and storage medium

    CN112597140A

  • Controllable data processing method and device based on data space and computing device cluster

    CN118713844A