Security sandbox system of trusted data space
By encrypting the data source module for collection and transmission, and combining it with the environmental isolation deployment of the data security sandbox platform, the balance between data security and utilization in the data sharing platform is resolved. This enables secure data sharing and legal use, reduces the risk of data leakage, and promotes the mining of data value.
Patent Information
- Application Number
- CN202510935722.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-11-07
AI Technical Summary
Existing data sharing platforms struggle to achieve efficient utilization while ensuring data security, and they cannot effectively balance the relationship between data sharing and security protection, resulting in insufficient data visibility and controllability.
Encrypted data collection and transmission are achieved through the data source module, combined with the environment isolation deployment of the data security sandbox platform module. Data transmission is encrypted using the SSL/TLS protocol, and an environment isolation unit is built on the platform module. Virtualization technology is used to create independent debugging, running, and online environments, and encryption algorithms and access control measures are used to ensure data security.
It achieves the encryption of data during the data transfer process and the isolation of the operating environment, reduces the risk of data leakage, ensures a clear separation between data ownership and usage rights, and promotes the legal and compliant sharing and value mining of data.
Smart Images

Figure CN120915488A_ABST
Abstract
Description
[0001] The present application relates to the technical field of data security, and in particular to a secure sandbox system of a trusted data space. BACKGROUND
[0002] In today's digital wave sweeping era, data has become the core production factor driving the development of various industries. With the vigorous development of big data, artificial intelligence and other technologies, data sharing and circulation are becoming increasingly important for tapping the potential value of data and promoting innovation cooperation. For example, in the medical field, data sharing between medical institutions helps improve disease research and diagnosis methods; in the financial field, data circulation between different financial institutions can help risk assessment and financial product innovation.
[0003] However, in the process of data sharing and circulation, data faces many security risks, like a ship sailing in a stormy sea. Data leakage incidents occur frequently, such as some enterprise databases being hacked, resulting in a large amount of user sensitive information being leaked, causing huge property losses and privacy violations to users. Data misuse problems also abound, and some institutions use data for commercial marketing and other unintended purposes without the full authorization of the data owner.
[0004] Traditional data processing mode seems to be in a dilemma when dealing with these problems. On the one hand, it is difficult to achieve efficient data sharing and utilization while ensuring data security; on the other hand, it is also difficult to effectively balance the subtle relationship between data sharing and utilization and security protection. The existing data sharing platform is like a city without a solid city wall, and there is a problem of insufficient data visibility and controllability. Data users may excessively obtain data beyond the authorized scope, while data owners have difficulty in accurately monitoring and controlling the use of data. This situation leads to the inability to effectively achieve the ideal state of data usability, invisibility, controllability and measurability.
[0005] Therefore, there is an urgent need for an innovative secure sandbox system, like a solid fortress for data sharing and circulation, to solve the above-mentioned difficulties and ensure that data maximizes its value in a secure environment. SUMMARY
[0006] In order to overcome the existing problems, the embodiments of the present application provide a secure sandbox system of a trusted data space, which constructs multiple security lines for data by encrypted collection and transmission of a data source module and environment isolation deployment of a data security sandbox platform module. Data is always in an encrypted state during circulation, and different operating environments are isolated from each other, greatly reducing the risk of data leakage.
[0007] The technical scheme adopted by the embodiments of the present application to solve the technical problems is: A secure sandbox system of a trusted data space comprises a data source module, a data security sandbox platform module and an interaction layer module: The data source module deploys a data security encryption collector. A specially designed data security encryption collector is installed on a server or terminal device where the data source module is located. The collector uses an advanced encryption algorithm, such as the AES (Advanced Encryption Standard) algorithm, to encrypt the collected initial data. The initial data is encrypted and collected, and the encrypted data is transmitted to the data security sandbox platform module through an encrypted transmission channel. The encrypted transmission channel is based on the SSL / TLS protocol, and both parties are authenticated through digital certificates. The message authentication code is used to ensure data integrity, and only the data source administrator has the right to decrypt the calculation. To ensure the security of the encrypted data during transmission, an encrypted transmission channel is established between the data source module and the data security sandbox platform module. The channel uses the SSL / TLS (Secure Sockets Layer / Transport Layer Security) protocol for data transmission encryption to prevent data from being stolen or tampered with during network transmission. The data security encryption collector of the data source module uses an encryption algorithm to encrypt the initial data. The encryption algorithm is based on a symmetric key system or an asymmetric key system. In the data source module, the data security encryption collector uses an adaptive encryption strength adjustment algorithm for different types of data, as follows: ; Wherein, is the data sensitivity, is the data volume, is the encryption strength, , , is a coefficient set according to actual security requirements and system performance. The algorithm can dynamically adjust the encryption strength according to the data characteristics, optimizing system performance while ensuring data security. The data security sandbox platform module constructs an environment isolation deployment unit. The environment isolation deployment unit supports debugging environment deployment, running environment deployment and online environment deployment to realize physical and logical environment separation. In the running environment deployment of the data security sandbox platform module, to ensure reasonable allocation of computing resources, a resource allocation algorithm based on queuing theory is used. Let the task queue length be , the average arrival rate of tasks be , the average service rate of tasks be , and the resource allocation ratio be calculated by the following formula: ; Wherein, The algorithm can dynamically adjust resource allocation according to task load and improve computing efficiency for a preset task queue length threshold value; The debugging environment of the data security sandbox platform module is an independent environment applied by a user alone, and the environment is equipped with simulated data similar to the real data format but different in content, which is used for task debugging; The running environment extracts original encrypted data from the data source module for calculation after the calculation task is approved, and automatically destroys the running environment and the data therein after the task is completed; The API gateway configured by the online environment deployment adopts the OAuth2.0 authentication and authorization protocol to perform identity authentication and authorization on the user or application calling the API; The interaction layer module interacts with the data security sandbox platform module through the API security gateway; the API security gateway of the interaction layer module is configured with IP address filtering rules and an access control list to perform data format checking on the API request, and the request that does not meet the format requirement is rejected; the API security gateway is deployed at the network boundary between the interaction layer module and the data security sandbox platform module, and filters and security checks the incoming and outgoing data; When an external user or application requests a data service through the interaction layer module, the request first reaches the API security gateway, the API security gateway performs identity authentication and authorization verification on the request, and after the verification is passed, forwards the request to the online environment of the data security sandbox platform module, the online environment processes the request and returns the result, the result again passes through the API security gateway, and the API security gateway performs security checks such as sensitive information filtering on the returned result to ensure that the data returned to the user or application meets the security requirements; In the interaction process between the interaction layer module and the data security sandbox platform module, a verification mechanism combining a timestamp and a random number is adopted to prevent replay attacks, wherein the current time is denoted as , the random number generated by the sender is denoted as , the verification function of the receiver is denoted as , and the verification passing condition is: and ; wherein, is the timestamp received by the receiver, is the allowed time error range, is the random number received by the receiver, and the mechanism effectively enhances the security of system interaction.
[0008] The advantages of the embodiments of the application are: Through the encrypted collection and transmission of the data source module and the environment isolation deployment of the data security sandbox platform module, multiple security lines are built for the data, the data is always in an encrypted state in the circulation process, and different operating environments are isolated from each other, so that the risk of data leakage is greatly reduced.
[0009] By using the encryption technology and the permission control means, the clear separation of data ownership and use right is realized, the data owner can ensure the data ownership not to be infringed by controlling the decryption permission, and meanwhile, the data user who is authorized can be granted the use right of the data under the safe premise, so that the needs of the data user for analyzing and modeling the data are met, the control right of the data owner over the data is ensured, the legal and compliant sharing of the data is promoted, and the mining and utilization of the data value are promoted. BRIEF DESCRIPTION OF DRAWINGS
[0010] Figure 1 The figure is a flowchart of the present application. DETAILED DESCRIPTION
[0011] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application. In addition, in the following description, the "up", "down", "left", "right" and the like are consistent with the up, down, left and right of the drawings, and "first", "second" and the like are used for description and differentiation, and have no other special meanings.
[0012] The security sandbox system of the trusted data space provided in the embodiments of the present application solves the problems in the prior art, multiple security lines are built for the data through the encrypted collection and transmission of the data source module and the environment isolation deployment of the data security sandbox platform module, the data is always in an encrypted state in the circulation process, and different operating environments are isolated from each other, so that the risk of data leakage is greatly reduced.
[0013] By using the encryption technology and the permission control means, the clear separation of data ownership and use right is realized, the data owner can ensure the data ownership not to be infringed by controlling the decryption permission, and meanwhile, the data user who is authorized can be granted the use right of the data under the safe premise, so that the needs of the data user for analyzing and modeling the data are met, the control right of the data owner over the data is ensured, the legal and compliant sharing of the data is promoted, and the mining and utilization of the data value are promoted.
[0014] The technical solution in this application is to solve the above problems, and the overall approach is as follows: Example
[0015] This embodiment provides a secure sandbox system for a trusted data space, such as... Figure 1 As shown, it includes a data source module, a data security sandbox platform module, and an interaction layer module: The data source module deploys a data security encryption collector. This specially designed collector is installed on the server or terminal device where the data source module resides. It employs advanced encryption algorithms, such as AES (Advanced Encryption Standard), to encrypt the initial data collected. The deployment method can be customized based on the type and characteristics of the data source. For example, for database data sources, it can be integrated as a database plugin to monitor and encrypt data changes in the database in real time. For file data sources, file system hook technology can be used to encrypt the data during the file reading phase. This encrypted data is then transmitted to the data security sandbox platform module via an encrypted transmission channel based on SS (Security Security Sandbox). The L / TLS protocol is used for authentication between the two parties through digital certificates and message authentication codes to ensure data integrity. Only the data source administrator has the authority to decrypt and calculate. To ensure the security of the encrypted data during transmission, an encrypted transmission channel is established between the data source module and the data security sandbox platform module. This channel uses the SSL / TLS (Secure Sockets Layer / Transport Layer Security) protocol to encrypt data transmission, preventing data from being stolen or tampered with during network transmission. When establishing the channel, authentication is required. The data source module and the data security sandbox platform module verify each other's digital certificates to ensure the legitimacy of both parties. At the same time, the integrity of the transmitted data is verified by calculating the hash value of the data and verifying it at the receiving end to ensure that the data has not been changed during transmission. Among them, the data security encryption collector of the data source module uses an encryption algorithm to encrypt the initial data. The encryption algorithm is based on a symmetric key system or an asymmetric key system. In the data source module, the data security encryption collector uses an adaptive encryption strength adjustment algorithm for different types of data, as shown in the following formula: ; in, For data sensitivity, For data volume, For encryption strength, , , The coefficient is set according to actual safety requirements and system performance, and the encryption strength can be dynamically adjusted according to data characteristics through the algorithm, so as to optimize system performance while ensuring data security. The data security sandbox platform module constructs an environment isolation deployment unit, which supports debugging environment deployment, running environment deployment and online environment deployment to realize environment separation in physical and logical layers. In the running environment deployment of the data security sandbox platform module, in order to ensure the reasonable allocation of computing resources, a resource allocation algorithm based on queuing theory is adopted, the task queue length is , the average arrival rate of tasks is , the average service rate of tasks is , and the resource allocation ratio is calculated by the following formula: ; Among them, is a preset task queue length threshold, and the resource allocation can be dynamically adjusted according to the task load through the algorithm to improve the computing efficiency. By adopting the above technical scheme: the environment isolation deployment unit is constructed: on the server cluster of the data security sandbox platform module, the environment isolation deployment unit is constructed, which uses virtualization technology to create multiple mutually isolated virtual environments for debugging environment deployment, running environment deployment and online environment deployment. At the physical level, through the reasonable allocation of server hardware resources, it is ensured that different environments will not affect each other due to resource competition. At the logical level, each virtual environment has independent operating system, application program and data space, realizing complete logical isolation.
[0016] Debugging environment deployment: when the user needs to debug the task, the debugging environment application is submitted to the system, and the system creates a debugging environment for the user according to the user's application in the environment isolation deployment unit. The debugging environment is equipped with necessary debugging tools and simulation data, which has similar format and characteristics with real data but does not contain sensitive information. The user can debug the data analysis task in this independent environment, familiarize with the task flow and verify the correctness of the algorithm. During the debugging process, the debugging environment is completely isolated from other environments and will not affect the real data and other users' tasks.
[0017] Running environment deployment: After the computing task is approved, the system extracts the original encrypted data from the data source module and transmits it to the running environment. The running environment is also created based on virtualization technology and has complete software and hardware resources required for data analysis and calculation. In the running environment, the encrypted data is first decrypted and calculated, and then the data is analyzed, modeled, etc. according to the task requirements. After the task is completed, the system automatically destroys the running environment and the data contained therein to ensure that the data is not leaked. The destruction process of the running environment includes deleting the file system of the virtual environment, releasing the occupied hardware resources, and clearing the related log records, etc. to ensure the complete deletion of the data.
[0018] Online environment deployment: Online environment deployment is used to provide data services to the outside world. In the online environment, an API security gateway is configured. The API security gateway uses authentication and authorization protocols such as OAuth 2.0 to authenticate and authorize users or applications that call APIs. Only authorized users or applications can access the services provided by the online environment. At the same time, the API security gateway monitors and controls the traffic of API calls in real time to prevent malicious attacks and abuse. For example, the API call frequency of each user or application is limited. When the call frequency exceeds the limit, subsequent calls are automatically blocked, and relevant logs are recorded for tracing.
[0019] The interaction layer module interacts with the data security sandbox platform module through the API security gateway. The API security gateway of the interaction layer module is configured with IP address filtering rules and access control lists to perform data format verification on API requests and reject requests that do not meet the format requirements. By adopting the above technical solutions: API security gateway configuration: the interaction layer module interacts with the data security sandbox platform module through the API security gateway. The API security gateway is deployed at the network boundary between the interaction layer module and the data security sandbox platform module to filter and check the incoming and outgoing data. The API security gateway is configured with a series of security policies such as IP address filtering, access control lists (ACLs), etc. Only legitimate IP addresses and authorized requests are allowed to pass through. At the same time, the API request is subjected to data format verification to ensure that the request data meets the specified format and prevent maliciously constructed requests from damaging the system.
[0020] Interaction process implementation: When an external user or application requests data services through the interaction layer module, the request first reaches the API security gateway. The API security gateway performs identity authentication and authorization verification on the request. After verification, the request is forwarded to the online environment of the data security sandbox platform module. The online environment processes the request and returns the result. The result is again subjected to security checks by the API security gateway, such as sensitive information filtering, etc. to ensure that the data returned to the user or application meets the security requirements.
[0021] In order to prevent replay attack, a verification mechanism combining time stamp and random number is adopted in the interaction between the interaction layer module and the data security sandbox platform module, wherein the current time is , the random number generated by the sender is , the verification function of the receiver is , and the verification pass condition is: and ; wherein is the time stamp received by the receiver, is the allowed time error range, is the random number received by the receiver, and the security of the system interaction is effectively enhanced through the mechanism.
[0022] Finally, it should be noted that: obviously, the above embodiments are only examples for clearly illustrating the present application, and are not a limitation on the implementation. For those skilled in the art, other different forms of changes or variations can be made on the basis of the above description. Here, it is not necessary and impossible to exhaust all the implementations. The obvious changes or variations derived therefrom are still within the protection scope of the present application.
Claims
1. A secure sandbox system for a trusted data space, characterized by The data source module, the data security sandbox platform module and the interaction layer module are included: The data source module deploys a data security encryption collector for collecting and encrypting initial data and transmitting the encrypted data to the data security sandbox platform module through an encrypted transmission channel, and only the data source administrator has the permission to decrypt the calculation; The data security sandbox platform module constructs an environment isolation deployment unit which supports debugging environment deployment, running environment deployment and online environment deployment to realize environment separation in physical and logical levels; The interaction layer module interacts with the data security sandbox platform module through an API security gateway.
2. The secure sandbox system of a trusted data space of claim 1, wherein, The data security encryption collector of the data source module uses an encryption algorithm to encrypt the initial data, and the encryption algorithm is based on symmetric key system or asymmetric key system.
3. The secure sandbox system of a trusted data space of claim 1, wherein, The encrypted transmission channel is constructed based on SSL / TLS protocol, both sides are authenticated through digital certificate, and message authentication code is used to ensure data integrity.
4. The secure sandbox system of a trusted data space of claim 1, wherein, The debugging environment deployment of the data security sandbox platform module is an independent environment applied by a user, which is equipped with simulated data similar to real data format but different in content, and is used for task debugging.
5. The secure sandbox system of a trusted data space of claim 1, wherein, The running environment deployment extracts original encrypted data from the data source module for calculation after the calculation task is approved, and automatically destroys the running environment and the data therein after the task is completed.
6. The secure sandbox system of a trusted data space of claim 1, wherein, The API gateway configured in the online environment deployment uses OAuth2.0 authentication and authorization protocol to authenticate and authorize the user or application calling API.
7. The secure sandbox system of a trusted data space of claim 1, wherein, The API security gateway of the interaction layer module is configured with IP address filtering rules and access control list to check the data format of API request and reject the request not meeting the format requirements.
8. The secure sandbox system of a trusted data space of claim 1, wherein, In the data source module, the data security encryption collector uses an adaptive encryption strength adjustment algorithm for different types of data, and the formula is as follows: ; wherein, is data sensitivity, is data volume, is encryption strength, is a coefficient set according to actual security requirements and system performance, and the encryption strength can be dynamically adjusted according to data characteristics through the algorithm, so as to optimize system performance while ensuring data security.
9. The secure sandbox system of a trusted data space of claim 1, wherein, In the running environment deployment of the data security sandbox platform module, when the computing task is executed, in order to ensure the reasonable allocation of the computing resource, a resource allocation algorithm based on queuing theory is adopted, the task queue length is , the task average arrival rate is , the task average service rate is , and the resource allocation proportion is calculated by the following formula: ; wherein, is a preset task queue length threshold value, through which the algorithm can dynamically adjust resource allocation according to task load and improve computing efficiency.
10. The secure sandbox system of a trusted data space of claim 1, wherein, In the interaction between the interaction layer module and the data security sandbox platform module, a verification mechanism combining time stamp and random number is adopted to prevent replay attack, wherein the current time is denoted as , the random number generated by the sender is denoted as , the verification function of the receiver is denoted as , and the verification pass condition is that and ; wherein, is a time stamp received by the recipient, is a range of allowed time errors, is a random number received by the recipient, through which the security of the system interaction is effectively enhanced.
Citation Information
Cited By
Data trusted circulation method and system based on security sandbox in trusted data space
CN121217462A
A method and system for trusted data circulation based on a security sandbox in a trusted data space
CN121217462B
Algorithm sandbox management method, apparatus and device, and computer program product
CN122133135A