Data leakage prevention method and device, electronic equipment and storage medium
By generating real-time watermarks that are tied to permission levels and using front-end streaming rendering technology, files are divided into background and content layers. This solves the problem of accurately protecting sensitive information in traditional data protection methods, achieving real-time protection and accountability, and improving user experience.
Patent Information
- Application Number
- CN202511437163.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2026-01-23
AI Technical Summary
Traditional data protection methods are difficult to accurately protect information at different levels of sensitivity and are easily tampered with or circumvented, resulting in a high risk of leakage of corporate confidential information.
By generating real-time watermarks that are bound to permission levels and combining them with front-end streaming rendering technology, the file is divided into a background layer and a content layer, and the display effect is dynamically controlled to ensure that the watermark always covers the document area, reducing the risk of tampering.
It achieves real-time protection of sensitive information, reduces the scope of leakage, strengthens accountability, and improves user experience.
Smart Images

Figure CN121389083A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a data leakage prevention method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the deepening of digital transformation, the rapid development of internet technology has led to increasingly frequent information exchanges among enterprises, and online collaboration has become a core mode for efficient organizational operation. However, this trend is also accompanied by severe data security challenges. Security incidents such as accidental leakage of confidential information, targeted theft by hackers, and malicious damage by ransomware occur frequently, posing a serious threat to the protection of corporate intellectual property rights, the security of trade secrets, and even the maintenance of core competitiveness.
[0003] Against this backdrop, the secure protection of sensitive corporate documents has become a critical issue in online collaboration scenarios. These documents often contain high-value information such as core corporate technologies and business strategies. During cross-departmental sharing and external collaboration, they are highly susceptible to leakage risks due to lax access control and improper operational behavior. Traditional protection methods have significant limitations: for example, relying on local viewing after downloading can easily lead to files remaining on the terminal, creating a potential leakage risk; static protection methods such as full-document watermarking are insufficient for precise protection of information at different sensitivity levels within the document and are easily tampered with and circumvented. Summary of the Invention
[0004] Therefore, it is necessary to provide a data leakage prevention method, device, electronic device, and storage medium to address the aforementioned technical problems.
[0005] Firstly, this application provides a data leakage prevention method, the method comprising: In response to a request to view a target file, the access user's operation permissions are determined based on the access user's login information; wherein, the operation permissions include preview permissions and / or editing permissions; Based on the login information and the operation permissions, a real-time watermark matching the access user's permission level is generated; The target file is divided into a background layer and a content layer, and the display effect of the target file is controlled based on front-end streaming rendering; wherein, the background layer is used to display the frame containing the real-time watermark; and the content layer is used to display the document content.
[0006] In one embodiment, the login information includes an identity identifier and a dynamic token; determining the access user's operation permissions based on the access user's login information includes: Verify the validity of the dynamic token; if the validity matches the expected result, trigger a user permission query operation. Based on the identity identifier, the operation permissions corresponding to the accessing user are matched.
[0007] In one embodiment, generating a real-time watermark that matches the access user's permission level based on the login information and the operation permissions includes: Based on the login information, a real-time watermark containing the identity identifier of the accessing user and an invisible digital fingerprint is generated; The watermark density of the real-time watermark is determined based on the operation permissions.
[0008] In one embodiment, controlling the display effect of the target file based on front-end streaming rendering includes: During the loading of the target file, sensitive words in the document content are de-identified based on the access user's operation permissions. Based on the aforementioned front-end streaming rendering, the background layer is displayed at a first time, and the desensitized content layer is displayed at a second time; wherein the first time is earlier than or equal to the second time.
[0009] In one embodiment, the process of desensitizing sensitive words in the document content based on the access user's operation permissions includes: If the operation permissions do not support viewing the sensitive words, a pre-set regular expression desensitization rule library is matched according to the sensitive information type of the sensitive words to obtain the matching regular expression and replacement rule; The sensitive words are replaced based on the regular expression and the replacement rule.
[0010] In one embodiment, the method further includes: If the operation permissions allow viewing the sensitive words, the original data corresponding to the document content will be displayed; During the preview of the target file, if an unauthorized operation is received on the original data of the sensitive words, the unauthorized operation is interrupted and an alarm message is output.
[0011] In one embodiment, interrupting the unauthorized operation upon receiving an unauthorized operation on the original data of the sensitive words includes one of the following: When a copy operation for the original data is received, the copy operation is intercepted based on the rewritten kernel interface; When a screenshot operation is received on the original data, a protection mechanism is triggered and the screenshot operation is interrupted.
[0012] Secondly, this application also provides a data leakage prevention device, the device comprising: The rights confirmation module is used to determine the operation permissions of the accessing user based on the accessing user's login information in response to a request to view the target file; wherein, the operation permissions include preview permissions and / or editing permissions; The generation module is used to generate a real-time watermark that matches the access user's permission level based on the login information and the operation permissions. The display module is used to divide the target file into a background layer and a content layer, and control the display effect of the target file based on front-end streaming rendering; wherein, the background layer is used to display a frame containing the real-time watermark; and the content layer is used to display the document content.
[0013] Thirdly, this application also provides an electronic device, including a processor and a memory; wherein the memory is used to store a computer program; and the processor is configured to, when executing the computer program, implement the steps of the method described in any embodiment of this application.
[0014] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of the methods described in any embodiment of this application.
[0015] The aforementioned data leakage prevention methods employ two key strategies. First, real-time watermarks are generated that are tied to user access levels. The watermark content is strongly correlated with the user's identity, allowing for direct identification of the source of leakage when a document is compromised, facilitating accountability. Second, by dividing the file into a background layer and a content layer, with the background layer serving as the underlying framework, the watermark consistently covers the document's display area and remains separate from the content layer, preventing text from obscuring it. The watermark is embedded within the background layer framework, rather than simply overlaid on the content surface, reducing the likelihood of tampering or erasure and ensuring its continuous visibility throughout the document viewing process. Furthermore, front-end streaming rendering controls the display of the target file, and dynamic control of the content layer's loading range, combined with access permissions, further reduces the exposure of sensitive information. Attached Figure Description
[0016] Figure 1 This is a flowchart illustrating a data leakage prevention method according to an exemplary embodiment; Figure 2 This is a flowchart illustrating a data leakage prevention method implemented in an electronic device according to an exemplary embodiment; Figure 3 This is a structural block diagram of a data leakage prevention device according to an exemplary embodiment; Figure 4 This is an internal structural diagram of an electronic device according to an exemplary embodiment. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0018] The terms "first," "second," and "third" used in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first," "second," or "third" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus.
[0019] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0020] In some embodiments, the data leakage prevention method provided in this application can be applied to electronic devices or cloud servers. The electronic device can be any mobile terminal or fixed terminal. The terminal can be a device that provides voice and / or data connectivity to the user. For example, the terminal can be an IoT terminal, such as a sensor device, a mobile phone or so-called "cellular" phone, and a computer with an IoT terminal; for example, it can be a fixed, portable, pocket-sized, handheld, or computer-embedded device. The cloud server can be any virtualized computing resource or physical server cluster. The server can be a platform that provides on-demand, scalable computing, storage, networking, and application services to the user.
[0021] In some embodiments, such as Figure 1 As shown, a data leakage prevention method is provided, which includes the following steps: S101, in response to a request to view the target file, the operation permissions of the accessing user are determined based on the login information of the accessing user; wherein, the operation permissions include preview permissions and / or editing permissions.
[0022] In this embodiment of the application, the target file may include, but is not limited to, at least one of CAD (Computer-Aided Design), office documents, PDF (Portable Document Format), code files, and compressed files.
[0023] In this embodiment, the input form for the viewing request may include, but is not limited to, text input, voice input, and key input. For example, a user can input a viewing request for a target file by clicking on the editing controls of the target file in the file viewing interface.
[0024] In this embodiment of the application, the login information may include, but is not limited to, at least one of the following: username / email / mobile phone number, dynamic verification code, biometric information, digital certificate, and security questions.
[0025] In this embodiment, the operation permissions may further include temporary users and fixed users. Temporary users refer to users with short-term, limited access permissions; fixed users refer to users who perform routine business operations, and the permission level is determined based on their job responsibilities.
[0026] S102, Based on the login information and the operation permissions, generate a real-time watermark that matches the access user's permission level; In some embodiments, generating a real-time watermark that matches the access user's permission level based on the login information and the operation permissions includes: Based on the login information, a real-time watermark containing the identity identifier of the accessing user and an invisible digital fingerprint is generated; The watermark density of the real-time watermark is determined based on the operation permissions.
[0027] In this embodiment of the application, the identity identifier may include, but is not limited to, at least one of the following: username, user ID, national ID number, and telephone number.
[0028] In one embodiment, login information includes a user ID. The electronic device generates a real-time watermark based on the user ID, containing a visible username / employee ID and an invisible digital fingerprint. Each real-time watermark corresponds one-to-one with the accessing user. The watermark density dynamically adjusts according to the access level; for example, the watermark can be sparser for ordinary employees, while for management employees, due to their higher access levels and access to more and more important sensitive data, the watermark density is higher, thus increasing the difficulty of unauthorized copying or screenshotting.
[0029] In this way, the combination of identity identifiers and invisible digital fingerprints achieves dual protection of explicit traceability and implicit anti-counterfeiting. Even if the visible identity identifier is tampered with or obscured, fingerprint information can still be extracted through technical means to verify the authenticity of the content source, solve the loophole of being unable to trace after the watermark is destroyed, and enhance the reliability of traceability.
[0030] S103, the target file is divided into a background layer and a content layer, and the display effect of the target file is controlled based on front-end streaming rendering; wherein, the background layer is used to display a frame containing the real-time watermark; the content layer is used to display the document content.
[0031] In this embodiment, front-end streaming rendering is a technology that transmits page content to the client in chunks. The server generates HTML and sends it step by step, while the client receives and renders it simultaneously, thereby improving page loading speed and user experience.
[0032] In some embodiments, controlling the display effect of the target file based on front-end streaming rendering includes: During the loading of the target file, sensitive words in the document content are de-identified based on the access user's operation permissions. Based on the aforementioned front-end streaming rendering, the background layer is displayed at a first time, and the desensitized content layer is displayed at a second time; wherein the first time is earlier than or equal to the second time.
[0033] In one embodiment, a sensitive word database management module can be set up in the user management interface. Administrators can use this module to upload, edit, and / or delete sensitive words. Electronic devices dynamically adjust the execution logic of the de-identification rules based on the updated sensitive word database. For example, for customer information categories (covering core words such as name, address, and contact number), a full de-identification mode can be configured to ensure that privacy fields are not exposed. For financial data categories (including words such as monetary amounts and account details), hierarchical de-identification based on user permissions is supported: high-privilege users can view partially de-identified information (such as retaining the last four digits of the bank card number), while low-privilege users only see the fully de-identified result (such as replacing the complete amount with "***").
[0034] In one embodiment, the target file is a document file, which is decomposed into independent background and content layers. The background layer carries a customized watermark pattern, while the content layer presents the anonymized document text. Fine-grained control of the overlay effect is achieved through CSS (Cascading Style Sheets) blending modes. This ensures a natural visual integration of the watermark and content layer, maintains clear and legible watermark visibility in printing or screenshot scenarios, and guarantees the proper display of the anonymized information in the content layer, avoiding blurring or watermark distortion due to overlay. In terms of loading logic, the presentation rhythm is optimized using front-end streaming rendering technology. Initially, the background frame with the complete watermark is rendered quickly to build the basic display layer; then, the anonymized text in the content layer is gradually filled in.
[0035] In this way, by loading the framework first and then the content or displaying it synchronously, the occurrence of the content exposure window in traditional rendering is reduced. This avoids the brief exposure of the document content before desensitization due to loading delays, ensuring that users see a complete interface with watermark protection from the moment the document is opened. This not only strengthens the real-time protection of sensitive information, but also improves the user's visual experience and operational perception through a smooth loading rhythm.
[0036] The aforementioned data leakage prevention methods employ two key strategies. First, real-time watermarks are generated that are tied to user access levels. The watermark content is strongly correlated with the user's identity, allowing for direct identification of the source of leakage when a document is compromised, facilitating accountability. Second, by dividing the file into a background layer and a content layer, with the background layer serving as the underlying framework, the watermark consistently covers the document's display area and remains separate from the content layer, preventing text from obscuring it. The watermark is embedded within the background layer framework, rather than simply overlaid on the content surface, reducing the likelihood of tampering or erasure and ensuring its continuous visibility throughout the document viewing process. Furthermore, front-end streaming rendering controls the display of the target file, and dynamic control of the content layer's loading range, combined with access permissions, further reduces the exposure of sensitive information.
[0037] In some embodiments, the login information includes an identity identifier and a dynamic token; determining the access user's operation permissions based on the access user's login information includes: Verify the validity of the dynamic token; if the validity matches the expected result, trigger a user permission query operation. Based on the identity identifier, the operation permissions corresponding to the accessing user are matched.
[0038] In some embodiments, when an accessing user initiates a viewing request, they can submit both a static identity identifier (such as a username) and a dynamic token (such as a time-based one-time token TOTP) to form a dual identity verification mechanism. The electronic device first verifies the validity and integrity of the token with the authentication server in real time (ensuring that it has not expired or been tampered with). Once the verification is successful, the RBAC (Role-Based Access Control) permission query process is immediately triggered.
[0039] In one embodiment, the electronic device quickly locates the user's role based on their identity and matches the user's fine-grained operation permissions; for example, the role of a financial manager is bound to the permission to view complete data, while the role of an intern is only associated with the permission to view summaries.
[0040] In this embodiment, dynamic tokens (such as TOTP) are characterized by short-term validity and real-time generation. Their validity verification can solve the security pain point of easy leakage of static identity identifiers (such as usernames). Even if the identity identifier is stolen, the validity of the dynamic token can prevent attackers from using static information for long-term unauthorized access. Furthermore, permission matching is based on a clear identity identifier, which makes it more traceable: when an operational anomaly occurs, the specific user and their permission scope can be directly located through the identity identifier, which facilitates auditing and responsibility determination.
[0041] In some embodiments, the process of desensitizing sensitive words in the document content based on the access user's operation permissions includes: If the operation permissions do not support viewing the sensitive words, a pre-set regular expression desensitization rule library is matched according to the sensitive information type of the sensitive words to obtain the matching regular expression and replacement rule; The sensitive words are replaced based on the regular expression and the replacement rule.
[0042] In some embodiments, the electronic device pre-establishes a rule base based on the type of sensitive information, with each type bound to a corresponding regular expression and replacement rule. For example, the rule for ID card numbers is to retain the first 3 digits and replace the remaining 12 digits with '*'; the rule for financial numbers is to replace them all with '**' when there is no permission.
[0043] In one embodiment, when storing document content, sensitive areas / vocabularies can be pre-processed and marked (e.g., using metadata to mark "financial figures" or "ID numbers"), reducing the need for real-time full-text parsing and computation time. When a user requests to view the document, the marked areas can be directly located, and the corresponding replacement rules can be invoked to replace the sensitive words.
[0044] In one embodiment, if the user does not have permission to access sensitive fields (such as an intern viewing financial figures), the corresponding regular expression and replacement rules can be called to replace the sensitive fields (such as replacing "100,000 yuan" with "*** yuan").
[0045] In this application embodiment, the leakage risk and desensitization requirements of different sensitive information are different. The regular expression desensitization rule library presets exclusive matching logic for each sensitive type to ensure that desensitization does not destroy the necessary identifiability of the information and can block the leakage of sensitive details. In addition, the fast response of regular expression matching is adapted to real-time collaboration scenarios.
[0046] In some embodiments, the method further includes: If the operation permissions allow viewing the sensitive words, the original data corresponding to the document content will be displayed; During the preview of the target file, if an unauthorized operation is received on the original data of the sensitive words, the unauthorized operation is interrupted and an alarm message is output.
[0047] In some embodiments, if the user has permission to access a sensitive field (such as a finance manager viewing financial figures), the desensitization process can be skipped and the original data can be retained.
[0048] In this application embodiment, unauthorized operations may include, but are not limited to, any behavior that may lead to data leakage, such as copying, downloading, taking screenshots, or printing.
[0049] In some embodiments, interrupting the unauthorized operation upon receiving an unauthorized operation on the original data of the sensitive words includes one of the following: When a copy operation for the original data is received, the copy operation is intercepted based on the rewritten kernel interface; When a screenshot operation is received on the original data, a protection mechanism is triggered and the screenshot operation is interrupted.
[0050] For example, the accessing user is a customer service representative, whose corresponding operation permission is to view the customer's complete phone number for communication; when the electronic device receives the customer service representative's operation to copy the complete phone number, it can immediately interrupt the copying operation to prevent customer information from being privately stored and misused.
[0051] In one embodiment, electronic devices can rewrite the Chromium kernel's Clipboard API to build a content filtering mechanism at the underlying level of clipboard interaction. This mechanism can intercept and purify content to be copied in real time, blocking the path of sensitive information propagation through the clipboard at its source. Simultaneously, when a user attempts to perform unauthorized operations via the right-click menu, custom watermark data containing identification information can be dynamically injected. If content is leaked, the source of the leak can be accurately traced through the watermark, enhancing risk identification capabilities.
[0052] In this embodiment, by directly displaying the original data to users with permission to view sensitive keywords, the availability of information in authorized scenarios can be guaranteed, reducing communication costs or work errors caused by incomplete information. Furthermore, while authorized users have the right to view the original sensitive data, unauthorized operations are often high-risk points for leakage. Blocking such operations in real time can curb the abuse of permissions at the source.
[0053] In this application embodiment, specific examples are provided below in conjunction with any of the above embodiments: Specific example 1: Figure 2 This is a flowchart illustrating a data leakage prevention method for an electronic device, as an example. Figure 2 As shown, the electronic device includes a front-end, a back-end, and a database. The user requests a document preview from the front-end of the electronic device, and the front-end sends an identity identifier and a user token to the back-end. The back-end verifies the user's permissions based on the identity identifier and the user token and then retrieves the document from the database. The database returns the document data to the back-end. The back-end returns the document data and user permissions to the front-end. The front-end controls the user's actions on the document based on the user permissions.
[0054] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0055] Based on the same inventive concept, this application also provides a data leakage prevention device for implementing the data leakage prevention method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more data leakage prevention device embodiments provided below can be found in the limitations of the data leakage prevention method described above, and will not be repeated here.
[0056] In one embodiment, such as Figure 3 As shown, a data leakage prevention device is provided, the device comprising: The rights confirmation module 10 is used to determine the operation permissions of the accessing user based on the login information of the accessing user in response to a request to view the target file; wherein the operation permissions include preview permissions and / or editing permissions; The generation module 20 is used to generate a real-time watermark that matches the access user's permission level based on the login information and the operation permissions. The display module 30 is used to divide the target file into a background layer and a content layer, and control the display effect of the target file based on front-end streaming rendering; wherein, the background layer is used to display a frame containing the real-time watermark; and the content layer is used to display the document content.
[0057] In one embodiment, the login information includes an identity identifier and a dynamic token; the authorization module 10 is used to perform the following steps: Verify the validity of the dynamic token; if the validity matches the expected result, trigger a user permission query operation. Based on the identity identifier, the operation permissions corresponding to the accessing user are matched.
[0058] In one embodiment, the generation module 20 is configured to perform the following steps: Based on the login information, a real-time watermark containing the identity identifier of the accessing user and an invisible digital fingerprint is generated; The watermark density of the real-time watermark is determined based on the operation permissions.
[0059] In one embodiment, the display module 30 includes: The desensitization unit is used to desensitize sensitive words in the document content based on the access user's operation permissions during the loading process of the target file; The display unit is configured to display the background layer at a first time and the desensitized content layer at a second time based on the front-end streaming rendering; wherein the first time is earlier than or equal to the second time.
[0060] In one embodiment, the desensitization unit is configured to perform the following steps: If the operation permissions do not support viewing the sensitive words, a pre-set regular expression desensitization rule library is matched according to the sensitive information type of the sensitive words to obtain the matching regular expression and replacement rule; The sensitive words are replaced based on the regular expression and the replacement rule.
[0061] In one embodiment, the apparatus further includes: The display module 30 is used to display the original data corresponding to the document content when the operation permission supports viewing the sensitive words; The control module is configured to, during the preview process of the target file, interrupt the unauthorized operation and output an alarm message when an unauthorized operation on the original data of the sensitive words is received.
[0062] In one embodiment, the control module is configured to perform one of the following steps: When a copy operation for the original data is received, the copy operation is intercepted based on the rewritten kernel interface; When a screenshot operation is received on the original data, a protection mechanism is triggered and the screenshot operation is interrupted.
[0063] Each module in the aforementioned data leakage prevention device can be implemented entirely or partially through software, hardware, or a combination thereof. Each module can be embedded in the processor of the electronic device in hardware form or independent of the processor, or it can be stored in the memory of the electronic device in software form, so that the processor can call and execute the corresponding operations of each module.
[0064] In one embodiment, an electronic device is provided, the internal structure of which can be shown as follows: Figure 4As shown, the electronic device includes a processor, memory, communication interface, display unit, and input device connected via a method bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores operating methods and computer programs. The internal memory provides an environment for the operation of the operating methods and computer programs in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data leakage prevention method. The display screen can be an LCD screen or an e-ink display screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.
[0065] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0066] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0067] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps performed by the processor of the electronic device of any of the above.
[0068] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0069] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, compilable logic units, quantum computing-based data leakage prevention logic units, etc., and are not limited to these.
[0070] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0071] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A data leak prevention method, characterized by, The method includes: In response to a request to view a target file, the access user's operation permissions are determined based on the access user's login information; wherein, the operation permissions include preview permissions and / or editing permissions; Based on the login information and the operation permissions, a real-time watermark matching the access user's permission level is generated; The target file is divided into a background layer and a content layer, and the display effect of the target file is controlled based on front-end streaming rendering; wherein, the background layer is used to display the frame containing the real-time watermark; and the content layer is used to display the document content.
2. The method of claim 1, wherein, The login information includes an identity identifier and a dynamic token; The process of determining the access user's operation permissions based on the access user's login information includes: Verify the validity of the dynamic token; if the validity matches the expected result, trigger a user permission query operation. Based on the identity identifier, the operation permissions corresponding to the accessing user are matched.
3. The method of claim 1, wherein, The step of generating a real-time watermark that matches the access user's permission level based on the login information and the operation permissions includes: Based on the login information, a real-time watermark containing the identity identifier of the accessing user and an invisible digital fingerprint is generated; The watermark density of the real-time watermark is determined based on the operation permissions.
4. The method of claim 1, wherein, The method of controlling the display effect of the target file based on front-end streaming rendering includes: During the loading of the target file, sensitive words in the document content are de-identified based on the access user's operation permissions. Based on the aforementioned front-end streaming rendering, the background layer is displayed at a first time, and the desensitized content layer is displayed at a second time; wherein the first time is earlier than or equal to the second time.
5. The method of claim 4, wherein, The process of desensitizing sensitive words in the document content based on the access user's operation permissions includes: If the operation permissions do not support viewing the sensitive words, a pre-set regular expression desensitization rule library is matched according to the sensitive information type of the sensitive words to obtain the matching regular expression and replacement rule; The sensitive words are replaced based on the regular expression and the replacement rule.
6. The method of claim 5, wherein, The method further includes: If the operation permissions allow viewing the sensitive words, the original data corresponding to the document content will be displayed; During the preview of the target file, if an unauthorized operation is received on the original data of the sensitive words, the unauthorized operation is interrupted and an alarm message is output.
7. The method according to claim 6, characterized in that, The step of interrupting the unauthorized operation when an unauthorized operation on the original data of the sensitive words is received includes one of the following: When a copy operation for the original data is received, the copy operation is intercepted based on the rewritten kernel interface; When a screenshot operation is received on the original data, a protection mechanism is triggered and the screenshot operation is interrupted.
8. A data leakage prevention device, characterized in that, The device includes: The rights confirmation module is used to determine the operation permissions of the accessing user based on the accessing user's login information in response to a request to view the target file; wherein, the operation permissions include preview permissions and / or editing permissions; The generation module is used to generate a real-time watermark that matches the access user's permission level based on the login information and the operation permissions. The display module is used to divide the target file into a background layer and a content layer, and control the display effect of the target file based on front-end streaming rendering; wherein, the background layer is used to display a frame containing the real-time watermark; and the content layer is used to display the document content.
9. An electronic device, characterized in that, The system includes a processor and a memory; wherein the memory is used to store a computer program; and the processor is configured to, when executing the computer program, implement the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it performs the steps of the method according to any one of claims 1 to 7.