Data sharing method and device, equipment, medium and program product

By generating and sending a policy link and signing the policy file with a signing key, the permissions for data sharing are restricted, thus solving the security risks of data sharing in existing technologies and improving the security and efficiency of data sharing.

CN121750356APending Publication Date: 2026-03-27BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-06
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing data sharing solutions pose security risks such as information leakage and resource abuse, especially when access permissions are publicly visible, allowing all users to access files or data.

Method used

By obtaining the policy file, a policy link is generated based on the policy file and the signing key, and then sent to the authorized party to execute the access operation corresponding to the policy file. The policy file is signed using the signing key to limit the attribute information and operation permissions of the data to be shared.

Benefits of technology

It improves the security of data sharing, solves the problems of information leakage and resource abuse, and ensures the confidentiality and security of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750356A_ABST
    Figure CN121750356A_ABST
Patent Text Reader

Abstract

The invention relates to a data sharing method and device, equipment, a medium and a program product. The data sharing method comprises the following steps: acquiring a strategy file, and generating a strategy link based on the strategy file and a signature key; the strategy file comprises attribute information of to-be-shared data and operation authority of the to-be-shared data; and sending the policy link to an authorized party corresponding to the policy file, so that the authorized party executes an access operation corresponding to the policy file based on the policy link. According to the embodiment of the invention, the to-be-shared data and the corresponding operation authority can be limited by setting the policy file, and meanwhile, the access operation is more convenient. According to the technical scheme, the strategy link is generated in the mode that the strategy file is signed through the signature key, when the authorized party executes the corresponding data access operation through the strategy link, the signature needs to be verified through the key, the problems of information leakage and resource abuse in the data sharing process are solved, and then the safety of data sharing is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data processing technology, and in particular to a data sharing method, apparatus, device, medium, and program product. Background Technology

[0002] Currently, there are three common data sharing schemes: the first is a single-link sharing scheme, where the client calculates a signature and provides downloads of a single file or data within its expiration period; the second is to set up an access control list (ACL) for the bucket on the server side to enable downloading and uploading of a single file or data; and the third is to set up access policies for the bucket on the server side to provide more operational sharing options for files or data.

[0003] However, the first sharing method presents security risks such as information leakage and resource abuse because users who obtain the link can download the file even after the expiration period. The second and third sharing methods both require publicly accessible access to enable file or data sharing, meaning all users can access publicly visible files and data, also posing security risks of information leakage and resource abuse. Therefore, ensuring file and data security has become a pressing technical problem that needs to be solved. Summary of the Invention

[0004] To address the aforementioned technical problems, this disclosure provides a data sharing method, apparatus, device, medium, and program product.

[0005] A first aspect of this disclosure provides a data sharing method, including: Obtain the policy file and generate a policy link based on the policy file and the signing key; the policy file includes the attribute information of the data to be shared and the operation permissions of the data to be shared. Send the policy link to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link.

[0006] A second aspect of this disclosure provides a data sharing apparatus, including: The policy link generation module is used to obtain the policy file and generate a policy link based on the policy file and the signing key; the policy file includes the attribute information of the data to be shared and the operation permissions of the data to be shared; The data sharing module is used to send policy links to the authorized parties corresponding to the policy files, so that the authorized parties can perform access operations corresponding to the policy files based on the policy links.

[0007] A third aspect of this disclosure provides an electronic device, including: processor; Memory, used to store executable instructions; The processor is used to read executable instructions from memory and execute the executable instructions to implement the data sharing method provided in the first aspect above.

[0008] A fourth aspect of this disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the data sharing method provided in the first aspect.

[0009] A fifth aspect of this disclosure provides a computer program product comprising a computer program or instructions that, when executed by a processor, implement the data sharing method of the first aspect described above.

[0010] The technical solution provided in this disclosure has the following advantages compared with the prior art: The data sharing method, apparatus, device, medium, and program product provided in this disclosure can acquire a policy file, which includes attribute information and operation permissions for the data to be shared. After acquiring the policy file, a policy link is generated based on the policy file and a signature key. The policy link is then sent to the authorized party corresponding to the policy file, enabling the authorized party to perform access operations corresponding to the policy file based on the policy link. Therefore, by setting a policy file to restrict the data to be shared and its corresponding operation permissions, and by generating a policy link by signing the policy file with a signature key, the authorized party needs to verify the signature with the key when performing corresponding data access operations through the policy link. This solves the problems of information leakage and resource abuse in the data sharing process, thereby improving the security of data sharing. Attached Figure Description

[0011] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0012] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a data sharing method provided in an embodiment of this disclosure; Figure 2 This is a schematic diagram of an application scenario provided by an embodiment of this disclosure; Figure 3 This is a flowchart of another data sharing method provided in this disclosure embodiment; Figure 4 This is a schematic diagram of the structure of a data sharing device provided in an embodiment of this disclosure; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0014] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0015] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0016] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0017] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0018] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0019] Typically, data sharing is conducted using three methods: single-link sharing, server-side ACL sharing (setting buckets as ACLs), and server-side access policy sharing (setting buckets as access policies). However, all three methods pose security risks such as information leakage and resource abuse during data sharing. To address this issue, this disclosure provides a data sharing method, which will be described below with reference to specific embodiments.

[0020] Figure 1 This is a flowchart illustrating a data sharing method provided in an embodiment of this disclosure. The method can be executed by a data sharing device, which can be implemented in software and / or hardware. The data sharing device can be configured in an electronic device, such as a server or terminal, where the terminal specifically includes a mobile phone, computer, or tablet computer. Furthermore, this method can be applied to… Figure 2 The application scenario shown includes a client 10, an authorized party 20, and a server 30. It is understood that the data sharing method provided in this embodiment can also be applied to other scenarios.

[0021] like Figure 2 As shown, client 10 can be understood as the terminal corresponding to the user who is sharing files or data. Client 10 can upload files or data to server 30 before sharing files or data, and server 30 will manage the files or data.

[0022] The authorized party 20 can be understood as a user client that is authorized by the client 10 to access files or data shared by the client 10.

[0023] The server 30 can be used to manage the files uploaded by the client 10, and at the same time, interact with the authorized party 20.

[0024] Specifically, when sharing files or data, client 10 can send a request to server 30 based on a pre-agreed signing key (such as username, password, etc.), whereby the request includes the conditions corresponding to the policy file. After receiving the request, the server signs the request and returns the signed policy file. The client generates a policy link based on the policy file. Client 10 sends the policy link to authorized party 20. After receiving the policy link, authorized party 20 interacts with server 30 based on the policy link to execute the access operation corresponding to the policy file. In response to the access operation of authorized party 20, server 30 verifies the signature and access permissions. If the verification passes, it returns a response result to authorized party 20; if the verification fails, it returns a verification failure result to authorized party 20.

[0025] The following is combined with Figure 2The application scenarios shown are for Figure 1 The data sharing methods shown are introduced, for example, Figure 2 Client 10 in the system can execute this method. For example... Figure 1 As shown, the data sharing method provided in this embodiment includes the following steps.

[0026] S110. Obtain the policy file and generate a policy link based on the policy file and the signature key.

[0027] In this embodiment of the disclosure, the policy file may include attribute information of the data to be shared and operation permissions for the data to be shared. It may also include an expiration time.

[0028] In this embodiment of the disclosure, the attribute information of the data to be shared may include the identifier of the bucket corresponding to the data to be shared, and the file name information corresponding to the data to be shared. The bucket identifier may include at least one of the following: bucket name, bucket unique identifier, etc.; the file name information may include at least one of the following: file name, file name prefix, file path prefix, etc.

[0029] Operation permissions for data to be shared can be understood as the operation permissions granted to the authorized party, such as read, view, and download operations.

[0030] The expiration time can be understood as the effective end date of the authorized party's permission to operate on the shared data. After the expiration time, the authorized party will no longer be able to perform the access operations corresponding to the data to be shared.

[0031] The number of data items to be shared can be one or more. This can be set according to the user's needs and is not limited here.

[0032] In this embodiment of the disclosure, the flexibility of setting the data to be shared and the operation permissions during the data sharing process is improved by setting the attributes, operation permissions and other information of the data to be shared in the policy file.

[0033] In this embodiment of the disclosure, the signature key can be understood as a key pre-agreed upon by the client and the server, such as a user's login name and password.

[0034] A policy link can be understood as a reference identifier that executes a predefined policy. Authorized parties can obtain relevant policy content through this policy link, and the server can verify the permissions and legitimacy of the request based on the policy resolved from the policy link.

[0035] Specifically, when responding to a data sharing operation, the client can parse the data sharing operation, obtain the policy file corresponding to the data sharing operation, generate a request based on the policy file and the signature key, send the request to the server, receive the signed policy file corresponding to the request returned by the server, and generate a policy link based on the signed policy file. The specific implementation of generating the policy link is similar to the existing implementation of generating links, and will not be described in detail here.

[0036] S120. Send the policy link to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link.

[0037] In this disclosed embodiment, the authorized party can be understood as a user authorized by the client to perform corresponding access operations on the data to be shared.

[0038] Access operations can include reading, viewing, and downloading the data to be shared.

[0039] Specifically, after generating the policy link, the client sends the policy link to the authorized party, so that after receiving the policy link, the authorized party can perform the access operation corresponding to the policy file based on the policy link, thereby enabling the client to share the data to be shared to the authorized party.

[0040] In this embodiment, a policy file can be obtained, which includes attribute information and operation permissions for the data to be shared. After obtaining the policy file, a policy link is generated based on the policy file and a signing key. The policy link is then sent to the authorized party corresponding to the policy file, enabling the authorized party to perform access operations corresponding to the policy file based on the policy link. Therefore, by setting a policy file to restrict the data to be shared and its corresponding operation permissions, and by generating a policy link by signing the policy file with a signing key, the authorized party needs to verify the signature with the key when performing corresponding data access operations through the policy link. This solves the problems of information leakage and resource abuse during data sharing, thereby improving the security of data sharing.

[0041] Based on the above embodiments of this disclosure, data sharing can be achieved by signing the policy file, which ensures the security of data sharing while enabling the simultaneous sharing of multiple data sets, thereby improving the efficiency of data sharing.

[0042] In this embodiment of the disclosure, in order to further improve the security of the policy link, the client can encrypt the policy link after generating it, and send the encrypted policy link, i.e., the sharing page link, to the authorized party.

[0043] Specifically, after generating a policy link based on the policy file and signature key, the data sharing method may further include: generating a link extraction code; encrypting the link extraction code and the policy link to obtain a sharing page link. The sharing page link can be accessed by the authorized party during interaction with the server, i.e., during the execution of the data access operation, without the policy link being visible. This solves the problem of the policy link being arbitrarily forwarded, further improving the confidentiality and security of the access operation.

[0044] In this embodiment of the disclosure, the method for generating a link extraction code may specifically include: generating a random string based on a preset random function, and determining the random string as the link extraction code; or, performing a hash calculation on the strategy link to obtain a hash value; and extracting a portion of the string from the hash value as the link extraction code. Other methods for generating the extraction code may also be included, and are not limited thereto.

[0045] Specifically, after obtaining the policy link, the client generates a link extraction code; and encrypts the link extraction code and the policy link according to preset rules to obtain the sharing page link.

[0046] In this embodiment of the disclosure, setting a link extraction code for the policy link increases the difficulty of obtaining the policy link, improves the security of accessing the policy link, and further enhances the security of data sharing.

[0047] In this embodiment of the disclosure, the link extraction code and the policy link are encrypted to obtain the sharing page link. Specifically, this may include: deriving the link extraction code into a target key based on a preset key derivation algorithm; and encrypting the target key and the policy link to obtain the sharing page link.

[0048] In the embodiments disclosed herein, the preset key derivation algorithm can be any existing derivation algorithm, and there are no restrictions herein.

[0049] Specifically, after obtaining the link extraction code, the client can derive the code using a preset key derivation algorithm, converting it into a high-strength key, i.e., the target key. Then, based on a preset encryption algorithm, the target key and the policy link are encrypted to obtain the sharing page link. The preset encryption algorithm can be a hash algorithm or other encryption algorithms.

[0050] The process of encrypting the target key and policy link based on a preset encryption algorithm to obtain the sharing page link may include: encrypting the target key and policy link based on a preset hash algorithm to obtain a hash value; and assembling the hash value and policy link to obtain the sharing page link.

[0051] In this embodiment of the disclosure, the security strength of the link extraction code is improved by deriving the link extraction code. Furthermore, the sharing of data to be shared is achieved by generating a sharing page link, which solves the problem of policy links being forwarded arbitrarily and further improves the confidentiality and security of access operations.

[0052] Furthermore, the policy link is sent to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link. Specifically, this may include: sending the sharing page link and the link extraction code to the authorized party, so that the authorized party can obtain the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, and perform the access operation based on the policy link.

[0053] In some embodiments of this disclosure, after generating a sharing page link, the client sends the sharing page link and the corresponding link extraction code to the authorized party. After receiving the sharing page link and the corresponding link extraction code, the authorized party accesses the sharing page link and enters the link extraction code on the sharing page interface corresponding to the sharing page link to obtain the policy link corresponding to the sharing page link, and then performs an access operation based on the policy link.

[0054] In some other embodiments of this disclosure, after generating the sharing page link, the client sends the sharing page link and the target key derived from the link extraction code corresponding to the sharing page link to the authorized party. After receiving the sharing page link and the target key corresponding to the sharing page link, the authorized party accesses the sharing page link and enters the target key on the sharing page interface corresponding to the sharing page link to obtain the policy link corresponding to the sharing page link, and then performs an access operation based on the policy link.

[0055] In this embodiment of the disclosure, the sharing of data to be shared is carried out by generating a sharing page link. During the authorized access to the data to be shared, the user cannot see the policy link, thereby solving the problem of the policy link being obtained by the user and forwarded at will, and further improving the confidentiality and security of the access operation.

[0056] In this embodiment of the disclosure, during the process of the authorized party obtaining the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, if the protocol type corresponding to the policy link does not match the target protocol type corresponding to the sharing page link, the protocol type corresponding to the policy link is switched to the target protocol type; and / or; if the file acquisition method corresponding to the policy link does not match the target file acquisition method corresponding to the sharing page link, the file acquisition method corresponding to the policy link is converted to the target file acquisition method.

[0057] The target protocol type and target file retrieval method are the default or pre-set protocol type and file retrieval method corresponding to the sharing page link. For example, the target protocol type is Hypertext Transfer Protocol Secure (HTTPS); the target file retrieval method can be a file retrieval method that lists stored object information, such as a List Objects v2 request.

[0058] In this embodiment of the disclosure, converting the file retrieval method corresponding to the policy link to the target file retrieval method can be understood as replacing the target parameter in the file retrieval method corresponding to the policy link with the parameter corresponding to the target file retrieval method. For example, the target parameter can be a parameter used to characterize paging variables.

[0059] In this embodiment of the disclosure, automatic adaptation of protocols and interfaces can be achieved by switching protocol types and changing acquisition methods, which improves the adaptability of policy links and allows the sharing page to support more types of policy links.

[0060] Figure 3 This is a flowchart of another data sharing method provided in this disclosure embodiment, such as... Figure 3 As shown, this data sharing method may include the following steps: S310. Obtain the policy file and generate a policy link based on the policy file and the signature key.

[0061] S320. Generate a link extraction code; encrypt the link extraction code and the strategy link to obtain the sharing page link.

[0062] S330. Send the sharing page link and the link extraction code to the authorized party, so that the authorized party can obtain the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, and perform the access operation based on the policy link.

[0063] It should be noted that the specific implementation of steps S310-S330 is similar to the implementation of the relevant steps in the above embodiments of this disclosure, and will not be repeated here.

[0064] In this embodiment of the disclosure, the difficulty of obtaining the policy link is increased by setting a link extraction code for the policy link, and the sharing of the data to be shared is carried out by generating a sharing page link. During the authorized access to the data to be shared, the user cannot see the policy link, thereby solving the problem of the policy link being obtained by the user and forwarded at will, and further improving the confidentiality and security of the access operation.

[0065] Figure 4 This is a schematic diagram of the structure of a data sharing device provided in an embodiment of this disclosure.

[0066] In this embodiment, the data sharing device can be located within an electronic device and is understood as a functional module within the aforementioned electronic device. Specifically, the electronic device can be a server or a terminal, wherein the terminal specifically includes mobile phones, computers, or tablet computers, etc., without limitation.

[0067] like Figure 4 As shown, the data sharing device 400 may include a policy link generation module 410 and a data sharing module 420.

[0068] The policy link generation module 410 can be used to obtain a policy file and generate a policy link based on the policy file and the signature key; the policy file includes the attribute information of the data to be shared and the operation permissions of the data to be shared. The data sharing module 420 can be used to send a policy link to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link.

[0069] In this embodiment, a policy file can be obtained, which includes attribute information and operation permissions for the data to be shared. After obtaining the policy file, a policy link is generated based on the policy file and a signing key. The policy link is then sent to the authorized party corresponding to the policy file, enabling the authorized party to perform access operations corresponding to the policy file based on the policy link. Therefore, by setting a policy file to restrict the data to be shared and its corresponding operation permissions, and by generating a policy link by signing the policy file with a signing key, the authorized party needs to verify the signature with the key when performing corresponding data access operations through the policy link. This solves the problems of information leakage and resource abuse during data sharing, thereby improving the security of data sharing.

[0070] In some embodiments of this disclosure, the attribute information of the data to be shared includes the identifier of the bucket corresponding to the data to be shared, and the file name information corresponding to the data to be shared.

[0071] In some embodiments of this disclosure, the data sharing device 400 may further include a link encryption processing module.

[0072] The link encryption processing module can be used to generate a link extraction code after generating a policy link based on a policy file and a signing key; The link extraction code and policy link are encrypted to obtain the sharing page link.

[0073] In some embodiments of this disclosure, the link encryption processing module can be specifically used to derive the link extraction code into a target key based on a preset key derivation algorithm; The target key and policy link are encrypted to obtain the sharing page link.

[0074] In some embodiments of this disclosure, the data sharing module 420 may be specifically used to send a sharing page link and a link extraction code to the authorized party, so that the authorized party can obtain the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, and perform an access operation based on the policy link.

[0075] In some embodiments of this disclosure, during the process of the authorized party obtaining the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, if the protocol type corresponding to the policy link does not match the target protocol type corresponding to the sharing page link, the protocol type corresponding to the policy link is switched to the target protocol type. and / or; If the file retrieval method corresponding to the strategy link does not match the target file retrieval method corresponding to the share page link, the file retrieval method corresponding to the strategy link will be converted to the target file retrieval method.

[0076] It should be noted that, Figure 4 The data sharing device 400 shown can execute the various steps in the above method embodiments and realize the various processes and effects in the above method embodiments, which will not be elaborated here.

[0077] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure.

[0078] In this embodiment of the disclosure, Figure 5 The electronic devices shown can be servers or terminals, and terminals specifically include mobile phones, computers, or tablets, etc., without limitation.

[0079] like Figure 5 As shown, the electronic device may include a processor 510 and a memory 520 storing computer program instructions.

[0080] Specifically, the processor 510 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this disclosure.

[0081] Memory 520 may include a large-capacity storage for information or instructions. For example, and not limitingly, memory 520 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 520 may include removable or non-removable (or fixed) media. Where appropriate, memory 520 may be internal or external to the integrated gateway device. In a particular embodiment, memory 520 is a non-volatile solid-state memory. In a particular embodiment, memory 520 includes read-only memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (Electrically Programmable ROM, EPROM), an electrically erasable programmable PROM (EEPROM), an electrically alterable ROM (EAROM), or flash memory, or a combination of two or more of these.

[0082] The processor 510 performs the steps of the data sharing method provided in the embodiments of this disclosure by reading and executing computer program instructions stored in the memory 520.

[0083] In one example, the electronic device may also include a transceiver 530 and a bus 540. Wherein, as... Figure 5 As shown, the processor 510, memory 520 and transceiver 530 are connected via bus 540 and communicate with each other.

[0084] Bus 540 may include hardware, software, or both. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 540 may include one or more buses.

[0085] This disclosure also provides a computer-readable storage medium that can store a computer program, which, when executed by a processor, enables the processor to implement the data sharing method provided in this disclosure.

[0086] The aforementioned storage medium may include, for example, a memory 520 containing computer program instructions, which can be executed by a processor 510 of an electronic device to complete the data sharing method provided in this embodiment. Optionally, the storage medium may be a non-transitory computer-readable storage medium, such as a ROM, random access memory (RAM), compact disc ROM (CD-ROM), magnetic tape, floppy disk, and optical data storage device.

[0087] This disclosure also provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, they implement the data sharing method provided in this disclosure and can achieve the various processes and effects in the above embodiments of this disclosure, which will not be elaborated here.

[0088] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data sharing method, characterized in that, include: Obtain the policy file, and generate a policy link based on the policy file and the signature key; The policy file includes the attribute information of the data to be shared and the operation permissions for the data to be shared. The policy link is sent to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link.

2. The method according to claim 1, characterized in that, The attribute information of the data to be shared includes the identifier of the bucket corresponding to the data to be shared, and the file name information corresponding to the data to be shared.

3. The method according to claim 1, characterized in that, After generating the policy link based on the policy file and the signing key, the method further includes: Generate a link extraction code; The link extraction code and the strategy link are encrypted to obtain the sharing page link.

4. The method according to claim 3, characterized in that, The step of encrypting the link extraction code and the strategy link to obtain the sharing page link includes: The link extraction code is derived into the target key based on a preset key derivation algorithm; The target key and the policy link are encrypted to obtain the sharing page link.

5. The method according to claim 3, characterized in that, Sending the policy link to the authorized party corresponding to the policy file, so that the authorized party performs the access operation corresponding to the policy file based on the policy link, includes: The sharing page link and the link extraction code are sent to the authorized party, so that the authorized party can obtain the policy link based on the link extraction code on the sharing page corresponding to the sharing page link, and perform the access operation based on the policy link.

6. The method according to claim 5, characterized in that, During the process of the authorized party obtaining the strategy link based on the link extraction code on the sharing page corresponding to the sharing page link, if the protocol type corresponding to the strategy link does not match the target protocol type corresponding to the sharing page link, the protocol type corresponding to the strategy link is switched to the target protocol type. and / or; If the file retrieval method corresponding to the strategy link does not match the target file retrieval method corresponding to the share page link, then the file retrieval method corresponding to the strategy link is converted to the target file retrieval method.

7. A data sharing device, characterized in that, include: The policy link generation module is used to obtain a policy file and generate a policy link based on the policy file and the signature key. The policy file includes the attribute information of the data to be shared and the operation permissions for the data to be shared. The data sharing module is used to send the policy link to the authorized party corresponding to the policy file, so that the authorized party can perform the access operation corresponding to the policy file based on the policy link.

8. An electronic device, characterized in that, include: processor; Memory, used to store executable instructions; The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the data sharing method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, causes the processor to implement the data sharing method described in any one of claims 1-6.

10. A computer program product, the computer program product comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the data sharing method as described in any one of claims 1-6.