Data management method, electronic device, readable medium and program product
By collaboratively setting access policies among multiple management parties, the problem of high-privilege employees controlling files in mobile office environments was solved, effectively protecting data security.
Patent Information
- Application Number
- CN202411381353.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2026-03-31
AI Technical Summary
Existing data management solutions cannot effectively control employees with high access levels in mobile office scenarios to send or access protected files, leading to the risk of data asset leakage.
Protection is achieved through access policies set by multiple controllers. When an access object modifies one of the policies, it still needs to obtain policy verification from other controllers to ensure data security. This includes the first device receiving and modifying the access policy, replacing it with the third access policy, and then sending it to the second device with modification permissions. The second device then performs verification.
It enables effective control over employees with higher access levels in enterprise mobile office scenarios when sending or accessing protected files, reducing the risk of data leakage and ensuring data security.
Smart Images

Figure CN121765739A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data management technology, and more specifically to a data management method, electronic device, readable medium, and program product. Background Technology
[0002] In some data management scenarios, such as enterprise mobile office scenarios, managers of enterprises (including companies / units) and the issuers of documents all want to use encryption, access control and other means to protect data assets such as documents in circulation and after circulation, so as to control the secure circulation and secure access of data assets such as documents.
[0003] refer to Figure 1 In the data management scenario shown, user A sets permissions for a file to be sent via computer 10. Taking a Word document as an example, these permissions may include the user who can perform specific operations on the Word document (e.g., the account logged into the Word application) and the specific operations performed on the document (e.g., opening, copying, or modifying any part of the current Word document), hereinafter referred to as the access policy. Figure 1 Access strategy a0 in the middle.
[0004] Then, after receiving the document sent by computer 10, computer 20, based on the access policy a0 carried in the document, first verifies whether user B is a user who can perform the specified operations on the document. For example, it verifies whether the login account for the Word document installed on computer 20 is the account specified in access policy a0. After successful verification, computer 20 can continue to perform the specified operations on the document, such as opening, copying, or modifying any part of the Word document.
[0005] However, in the aforementioned enterprise mobile office scenario, if an employee with a higher level of access within the company / organization (i.e., the aforementioned manager) wishes to grant the aforementioned computer 10 the necessary permissions to send Word documents or to control the access permissions of the recipient of the Word document, such as computer 20, to open, copy, and modify the received Word document, the current data management solution cannot provide such support. This may result in a security risk that some of the company / organization's data assets may be leaked by employees. Summary of the Invention
[0006] This application provides a data management method, electronic device, readable medium, and program product that supports access to objects under the protection of multiple control policies set by various management parties. Therefore, it can support the needs of employees with higher access levels in enterprise mobile office scenarios to control the outgoing or accessed files such as protected Word documents by other employees. Furthermore, even if the accessed object modifies the access policy set by one management party, it still needs to obtain the access policies set by other management parties for operation permission verification. This ensures the data security of the accessed object and reduces the security of the accessed object continuing to operate on the accessed object after successful verification.
[0007] Specifically, in a first aspect, this application provides a data management method, comprising: a first device receiving an accessed object and determining that the accessed object has a corresponding first access policy and a second access policy, wherein the first access policy is set by a first management party, the second access policy is set by a second management party, the first device has the right to modify the first access policy, and the first device does not have the right to modify the second access policy; the first device accesses the accessed object based on the first access policy and the second access policy; the first device modifies the first access policy to a third access policy, and replaces the first access policy corresponding to the accessed object with the third access policy; the first device sends the accessed object to a second device, wherein the second device has the right to modify the third access policy, and the second device does not have the right to modify the second access policy.
[0008] For example, the first device mentioned above, as the device receiving the accessed object, can be the accessed object, or the receiving device, such as computer 20 mentioned below. The accessed object can be, for example, a Word document or other file protected by an access policy or encryption. Based on this, when the first device performs an access operation on the accessed object, it can first determine the first access policy and the second access policy related to the access policy carried by the received Word document or other file. It can be understood that the access policy of the accessed object, such as the Word document, can be set by the sending device, such as computer 10 mentioned below, based on access policies set by multiple management parties, such as the first access policy and the second access policy mentioned above. The first access policy can be, for example, a private policy mentioned below, and the second access policy can be, for example, a public policy mentioned below.
[0009] Thus, the data management method provided in the first aspect above can support accessed objects being protected by access policies set by multiple controllers while under the aforementioned access policies. Therefore, it can support the needs of employees with higher access levels in enterprise mobile office scenarios to control the outgoing or accessed protected Word documents and other files by other employees. Furthermore, even if the accessed object modifies the access policy set by one controller, it still needs to obtain access policies set by other controllers for operation permission verification. This ensures the data security of the accessed object and reduces the security of the accessed object continuing to operate on the accessed object after successful verification.
[0010] In one possible implementation of the first aspect above, the second controller includes the cloud. After the first device receives the accessed object, the method further includes: the first device obtaining the fourth access policy and the second access policy corresponding to the accessed object from the cloud, wherein the fourth access policy is the access policy modified by the first controller to the first access policy; and the first device accesses the accessed object based on the first access policy and the second access policy.
[0011] For example, after the accessed object arrives at the access target (e.g., the first device mentioned above), the first controller can still modify the access policy (e.g., the first access policy) and synchronize the modified access policy (e.g., the fourth access policy mentioned above) to the accessed object (e.g., the first device) via the cloud so that it takes effect in a timely manner. This allows the first controller, acting as the sending device, to still protect the accessed object by modifying the access policy after sending documents such as Word documents.
[0012] In one possible implementation of the first aspect above, the first device accesses the accessed object based on a first access strategy and a second access strategy, including: accessing the accessed object based on either the first or second access strategy when the first and second access strategies are the same; and determining a fifth access strategy for the accessed object based on either the first or second access strategy when the first and second access strategies are different, wherein the fifth access strategy includes the intersection of the first and second access strategies and a strategy portion of the first or second access strategy that is different from the intersection.
[0013] In other words, multiple controllers can set the same or different access policies. When all controllers set the same access policy, such as the first and second access policies mentioned above, the access target, such as the first device mentioned above, can access the object to be accessed, such as a Word document, based on the access policy set by one of the controllers, such as the first or second access policy. When all controllers set different access policies, such as the first and second access policies mentioned above, the access target, such as the first device mentioned above, can access the object to be accessed, such as a Word document, based on the intersection of the access policies set by the controllers, and the relevant policies in one of the controllers' access policies other than the aforementioned intersection—that is, the part of the first or second access policy that differs from the intersection.
[0014] In this way, a mechanism can be provided to resolve conflicts between access policies set by multiple controllers, such as when operation permissions restricted by different access policies conflict. This ensures that access policies set by each controller are effectively executed, thereby stably protecting the data security of the accessed objects.
[0015] In one possible implementation of the first aspect described above, the first execution priority corresponding to the first access strategy is higher than the second execution priority corresponding to the second access strategy.
[0016] In one possible implementation of the first aspect above, determining a fifth access strategy for the accessed object based on the first access strategy and the second access strategy includes: determining the fifth access strategy based on the fact that the second execution priority is higher than the first execution priority, including the intersection of the first access strategy and the second access strategy, and the strategy part of the second access strategy that is different from the intersection.
[0017] In one possible implementation of the first aspect described above, the first authority level of the first controller is lower than the second authority level of the second controller.
[0018] In other words, when different access policies are set by different controllers, the execution priority of the corresponding access policy can be determined according to the corresponding permission level of each controller. Then, the access policy used when accessing the accessed object (such as the fifth access policy mentioned above) can be determined. This can include the intersection of the first access policy and the second access policy, and the part of the access policy with higher execution priority that is different from the intersection.
[0019] In this way, it can accommodate the permission levels of multiple control parties and meet the data security management needs of each control party for the accessed objects. This is beneficial to protecting the data assets of companies or units with higher permission levels and providing support solutions for strengthening the security management of enterprise data assets in enterprise mobile office scenarios.
[0020] In one possible implementation of the first aspect above, modifying the first access strategy to a third access strategy includes: modifying at least one of the constraints set in the first access strategy regarding the identity of the access object, the attributes of the access object, and the access object's operation permissions on the accessed object, to obtain the third access strategy; wherein the access object includes the first device.
[0021] In one possible implementation of the first aspect above, the method further includes: the first device detecting that a first constraint set in the third access policy conflicts with a second constraint set in the second access policy; the first device modifying the third access policy to the first access policy.
[0022] For example, if the access policy modified by the accessed object (i.e., the first device) in response to a user operation (i.e., the third access policy) conflicts with the second access policy, which has a higher priority, the accessed object can refuse the user operation, either by not modifying the first access policy or by changing the modified third access policy back to the first access policy. This helps ensure the data security of the accessed object.
[0023] In one possible implementation of the first aspect above, the access object attributes include device attributes, and the device attributes include one or more of the following: a spatial attribute for indicating the operating space type currently logged in by the access object; a network attribute for identifying the network currently accessed by the access object; a location attribute for identifying the location of the access object; a tracing attribute for querying the history of the accessed object being sent, accessed, or modified; and a time attribute for limiting the expiration time of the permission or control period for accessing the accessed object based on the first access policy and the second access policy.
[0024] In one possible implementation of the first aspect above, accessing object attributes and the access object's operation permissions on the accessed object include one or more of the following: opening the accessed object and accessing the content and file attributes of the accessed object; copying the content and file attributes of the accessed object; and changing the content and file attributes of the accessed object.
[0025] For example, the above file attributes may include one or more of the following: author, editor, security classification, department, etc.
[0026] In one possible implementation of the first aspect above, the second controller has management authority over the first controller, and the management authority includes any one of the following: the second controller includes a device management service that has management authority over the devices corresponding to the first controller; the second controller includes an account management service that has management authority over the accounts logged in by the first controller.
[0027] In one possible implementation of the first aspect above, the second control party includes the cloud, and the first device accesses the accessed object based on the first access policy and the second access policy, including: the first device sending a request to the cloud to obtain the second access policy; and the first device accessing the accessed object based on the second access policy and the first access policy received from the cloud.
[0028] For example, the first access policy mentioned above can be a private policy, and the first controller for setting this private policy can be the sending device of a file such as a Word document. The second access policy mentioned above can be a public policy, and the second controller for setting this public policy can be the cloud. This cloud can have device management services with management permissions for the sending device, or it can have management permissions for the accounts logged in on the sending device, such as enterprise accounts.
[0029] In a second aspect, this application provides an electronic device, including: one or more processors; one or more memories; the one or more memories storing one or more programs, which, when executed by one or more processors, cause the electronic device to perform the data management method provided by the first aspect and various possible implementations of the first aspect.
[0030] Thirdly, this application provides a computer-readable medium storing instructions that, when executed on a computer, cause the computer to perform the data management method provided by the first aspect and various possible implementations of the first aspect.
[0031] Fourthly, this application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the data management method provided by the first aspect and various possible implementations of the first aspect.
[0032] The beneficial effects of the second to fourth aspects mentioned above can be referred to the relevant descriptions in the first aspect and various possible implementations of the first aspect, which will not be repeated here. Attached Figure Description
[0033] Figure 1 The diagram shown illustrates a data management scenario.
[0034] Figure 2 The diagram shown is a schematic diagram of another data management scenario provided in an embodiment of this application.
[0035] Figure 3 The diagram shown illustrates the interactive process involved in implementing a data management method according to an embodiment of this application.
[0036] Figure 4aThe diagram shown is a schematic representation of a process for setting an access policy for an accessed object according to user instructions, as provided in an embodiment of this application.
[0037] Figure 4b The diagram shown is a file management interface that supports users to perform "encryption protection" operations according to an embodiment of this application.
[0038] Figure 4c The image shown is a schematic diagram of a file management interface that supports user setting of permission ranges according to an embodiment of this application.
[0039] Figure 4d The diagram shown is a file management interface that supports users in setting and managing the expiration time of permissions, according to an embodiment of this application.
[0040] Figure 5 The diagram shown is a flowchart illustrating an operation permission verification process provided in an embodiment of this application.
[0041] Figure 6a The diagram shown is a schematic representation of the data management system to which the data management method provided in this application is applicable.
[0042] Figure 6b The diagram shown is a schematic representation of the composition of a capsule file provided in an embodiment of this application.
[0043] Figure 6c The following is based on Figure 6a The diagram shows the operation permission verification process of the data management system.
[0044] Figure 7a The diagram shown illustrates the implementation principle of an encryption protection phase for setting access policies, as provided in an embodiment of this application.
[0045] Figure 7b The diagram shown is a schematic representation of the implementation principle of controlling the transmission process of an accessed object using an access strategy, according to an embodiment of this application.
[0046] Figure 7c The diagram shown is a schematic representation of the implementation principle of a capsule file opening and access control based on access policy according to an embodiment of this application.
[0047] Figure 8 The figure shown is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application.
[0048] Figure 9 The diagram shown is a hardware structure schematic of another electronic device provided in an embodiment of this application. Detailed Implementation
[0049] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be described in detail below with reference to the accompanying drawings and specific implementation methods.
[0050] It is understood that the terminal device in the embodiments of this application may also be referred to as a terminal, user equipment (UE), mobile station (MS), mobile terminal (MT), or other electronic devices. The terminal device may be a mobile phone, smart TV, wearable device, tablet computer, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, and so on.
[0051] Refer to the above Figure 1 As mentioned earlier, the current data management solution cannot support the needs of employees with higher access levels in enterprise mobile office scenarios to control other employees' access to protected Word documents and other files (i.e., the accessed objects). This may lead to the security risk of some data assets of the company / organization being leaked by employees.
[0052] The access policies mentioned above can be used to control the authentication of the access object (e.g., verifying whether user B is a user who can perform specified operations on the document) and the access object's operation permission verification of the accessed object (e.g., verifying whether user B's specified operations on the document include opening, copying, or changing any part of the current Word document).
[0053] Based on this, the accessed object can be, for example, an electronic device that receives the accessed object (such as...). Figure 1 The identity information (ID) of the accessed object can be the user's identity information of the application installed on the electronic device (such as the Word application running on the computer 20) or the identification information of the electronic device. Figure 1Information such as the account ID used by user B on computer 20 to log in to the Word application, or Figure 1 Information such as the device ID of computer 20. The accessed object can be, for example, a file transferred between computer 10 and computer 20. This file can include the aforementioned Word document, or it can include files that can be opened, copied, or modified by other applications, such as spreadsheet (Excel) files, PowerPoint (PPT) files, etc., without any restrictions.
[0054] Correspondingly, the access permissions of an accessing object to an accessed object may include, for example, opening, copying, or modifying any part of a file such as a Word document. This "any part" may include the content of the Word document, Word options, etc., without limitation. Specifically, opening any part of a file may include opening the accessed object and accessing its content and file attributes. These file attributes may include one or more of the following: author, editor, security classification, department, etc., which may also be described as access permissions in some embodiments of this application. Correspondingly, copying any part of a file may include the content and file attributes of the accessed object. Modifying any part of a file may also include modifying the content and file attributes of the accessed object. Furthermore, the aforementioned operation permissions may also include outbound permissions, without limitation.
[0055] It is understandable that the party setting the above-mentioned operation permissions or access policies, such as those mentioned above... Figure 1 In the scenario shown, user A and computer 10 can be referred to as the controller in this embodiment of the application. In other scenarios, the controller can also be a terminal device that receives files such as Word documents (e.g., the one described above). Figure 1 The computer 20 shown) or the user of the terminal device (e.g., the one mentioned above) Figure 1 The user A shown can be any other electronic device that has management authority over the aforementioned computer 10 or computer 20, etc., without any restrictions.
[0056] To address the aforementioned issues, this application provides a data management method that sets access targets and their operational permissions on accessed objects (e.g., files to be sent) based on access policies set by multiple control parties. Some control parties' access policies allow modification by the access targets, while others prohibit modification. Thus, the accessed object is protected by access policies set by multiple control parties, supporting the needs of employees with higher access levels in enterprise mobile office scenarios to control other employees' access to or sending of protected Word documents and other files. Furthermore, even if an access target modifies the access policy set by one control party, it still needs to obtain access policies set by other control parties for operation permission verification, thereby ensuring the data security of the accessed object and reducing the security of the access target continuing to operate on the accessed object after successful verification.
[0057] It is understandable that multiple management parties may set the same or different access policies.
[0058] In some embodiments, to ensure that the access policy of the accessed object is not modified, the access policies set by all controllers can be made identical. Thus, even if the access policies set by some controllers can be modified (i.e., the accessed object is allowed to modify them), since the access policies set by other controllers are restricted from modification (i.e., the accessed object is not allowed to modify them), the accessed object can ultimately be prevented from modifying the access policy of the accessed object.
[0059] Furthermore, the execution priority of some access policies set by other controllers that are restricted from modification can be higher than that of some access policies set by other controllers that can be modified. For example, refer to Figure 2 In the scenario shown, for a Word document, computer 10, as one of the controllers, can set access policy a0, and cloud 30, as the other controller, can set access policy b0. Before sending the Word document, computer 10 can set the operation permissions for computer 20 on the Word document based on access policy a0 and access policy b0. These operation permissions may include, for example, disallowing computer 20 from sending the Word document. The operation permissions constrained by access policy a0 and access policy b0 can be the same. Access policy a0 can be modified by computer 20, but access policy b0 cannot be modified by computer 20. After receiving the Word document, computer 20 can verify the operation permissions based on access policy a0 carried in the Word document and access policy b0 obtained from cloud 30, and then open the Word document.
[0060] Subsequently, computer 20 can modify access policy a0. For example, if computer 20, acting as the controller, sets permissions to allow the Word document to be sent externally, access policy a0 can be modified to access policy a0' (not shown in the diagram). However, when computer 20 closes and reopens the Word document, because access policy b0 set by cloud 30 cannot be modified by computer 20, and access policy b0 has a higher execution priority, computer 20 can only execute access policy b0 to open the Word document, and cannot execute the modified access policy a0' to send the Word document to computer 20' (not shown in the diagram). In other words, the data management method provided in this application can ultimately restrict... Figure 2 In the scenario shown, computer 20 (i.e., the access object) cannot modify the access policy of the Word document (i.e., the accessed object).
[0061] In other embodiments, considering that different controllers have different control permissions—for example, different employees in a company / organization have different control permissions—different access policies can be set for different controllers. For example, continue to refer to… Figure 2 In the scenario shown, for Word documents, employees with lower access permissions can log in to computer 10 using their accounts and set access policies as the controller (e.g., ...). Figure 2 The access policy shown is a0 (hereinafter referred to as the private policy). Employees with higher management privileges can log in to the cloud 30 using an account (e.g., a corporate account) to set other access policies as another management entity (e.g., ...). Figure 2 Access policy b0 (hereinafter referred to as the public policy) is shown below. Specifically, the public policy can be a general policy that every employee in the company must follow when processing Word documents. For example, when sending a Word document to a device on the company's external network, encryption is required before sending, or documents involving company secrets cannot be opened on external devices or require a password to open. The private policy can include the relevant operation permissions set by an employee A, who acts as the controller, for the Word documents he / she processes. For example, only a designated employee, such as employee B, can open the Word document sent by employee A. The specific restrictions of the private policy and the public policy can be the same or different.
[0062] It is understood that in some embodiments, access policies set by different management parties may conflict. For example, there may be a conflict between the operation permissions restricted by the aforementioned public policy and private policy, or there may be a conflict between the private policies set by different computers 10 acting as different management parties. In this case, the permission levels of different management parties can be determined according to the specific circumstances. For example, the access policy set by the management party with a lower permission level must comply with the access policy set by the management party with a higher permission level.
[0063] For example, employee A1, acting as a controller, has a higher permission level than employee A2, who also acts as a controller. Regarding the private policies set for employee A2 (e.g., ...), Figure 2 The access policy shown (a0) can be modified by employee A1 based on their own permission level, for example, by changing the private policy to... Figure 2 The modified access policy a1 is shown. At this point, access policy a1 can be uploaded to cloud 30 and then distributed to employee B's computer 20 via cloud 30. If employee B wants to open a Word document, they can verify their access based on access policy a1 obtained from cloud 30. If the modified access policy a1 restricts employee B's access to the Word document, employee B will be unable to pass the access permission verification and will not be able to open the Word document. Therefore, in some embodiments, the access policy a1 modified by employee A1 with a higher permission level still needs to follow the aforementioned common policy, for example... Figure 2 The access policy shown is b0. For example, when there is a conflict between the modified access policy a1 and access policy b0, employee B's computer 20, which is the access target, can have priority in executing the operation permissions corresponding to access policy b0.
[0064] Furthermore, after the same management entity sets and sends access policies (including the aforementioned private and public policies) for Word documents (i.e., the accessed objects), it can modify these policies according to actual management needs. The modified access policies can be synchronized to the accessed objects via the cloud, allowing them to verify access permissions when accessing the Word documents. In other words, modified access policies take effect immediately on the accessed object's end, thus enhancing the management entity's control over the accessed objects.
[0065] For example, employee A, as the controller (e.g.) Figure 2 User A) set access policy a0 (private policy) on computer 10, and after setting the access policy for the Word document based on access policy a0 and access policy b0 (public policy), can send the Word document to employee B (e.g., ...). Figure 2 The computer 20 shown is for user B). Afterwards, employee A can continue to use computer 10 to modify the aforementioned access policy a0, for example, changing access policy a0 to access policy a1 (private policy). See also... Figure 2As shown, the modified access policy a1 can be uploaded to cloud 30 and then bound to access policy b0 set by cloud 30 as the controller. When employee B opens the Word document on computer 20, the modified access policy a1 can replace the original access policy a0 in the Word document. Therefore, if computer 20 wants to open the Word document, it needs to verify the modified access policy a1 (private policy) and the access policy b0 (public policy) set by cloud 30.
[0066] In other embodiments, the following scenario is considered: after an accessing object accesses an accessed object, the accessing object modifies part of the access policy (e.g., the aforementioned private policy), but the modified access policy may conflict with another part of the access policy that is not allowed to be modified (e.g., the public policy) in terms of operation permissions. For example, refer to... Figure 2 As shown, after receiving and opening the Word document, computer 20 can respond to user B's operation to modify relevant permissions by modifying the access policy a0 carried by the Word document, for example, changing it to access policy a2 (not shown in the figure). Access policy a2, compared to access policy a0, for example, adds the operation permission that allows user B's computer 20 to send the Word document. At this time, if access policy a2 conflicts with access policy b0 (i.e., the public policy) obtained from the cloud 30, for data security reasons, the execution priority of another set of access policies that cannot be modified can be set higher than the modified access policy. Thus, the conflicting operation permissions can be constrained by the access policies that cannot be modified. For example, when user B uses computer 20 to send the Word document, computer 20 can execute access policy b0 to refuse the sending operation, instead of executing the modified access policy a2.
[0067] In some embodiments, the aforementioned public policy, in addition to restricting operation permissions such as opening, copying, and modifying any part of a Word document, may also include thresholds or ranges set for one or more device attributes of the accessed object. These device attributes may include, but are not limited to, spatial attributes, network attributes, location attributes, traceability attributes, and time attributes. These device attributes can be used to control the scope of operation permissions for the accessed object and the verification of permission validity periods, etc.
[0068] Among them, the spatial attribute can be used to indicate the type of operating space currently logged into by the accessed object, including the terminal device (e.g., ...). Figure 2The operating system (OS) of computer 10 or computer 20 shown provides user-isolated and configured identification information (ID) corresponding to one or more operating spaces, i.e., space IDs, such as workspace (or main space) IDs, entertainment space (or privacy space) IDs, etc. For example, in the workspace, users can edit files and use space-to-space transfer applications (such as Connect). TM WeChat for Business TM Operations such as sending or receiving protected files (e.g., file viewing / editing / compression applications and file transfer applications) can have running permissions within this workspace, as well as access permissions to some local files (including classified files) managed by the file system. Similarly, in the entertainment space, users can watch sports games or play games; correspondingly, some video applications or game applications can have running permissions within this entertainment space.
[0069] It is understandable that when the same terminal device logs into the same account (i.e., the same user), different operating spaces can have different permissions. These permissions may include file access permissions, permissions to run related applications, and permissions to obtain privacy information such as user personal information and location information collected by applications. Furthermore, data in different operating spaces can be isolated from each other. In some embodiments, different operating spaces can also access networks with different security levels. For example, a workspace may allow access to a company's cellular data network or wireless LAN, while an entertainment space may allow access to the user's personal cellular data network or personal hotspot. In some embodiments, the aforementioned space attributes may also include operating spaces provided by different terminal devices, for example... Figure 2 The operating space provided by computer 20 used by user A and the operating space provided by computer 20 used by user B have different space attributes, which will not be elaborated here.
[0070] Network attributes can be used to identify the network currently accessed by an access object, including the corresponding IP addresses or network segments of the company's external network (WAN) and internal network (LAN) isolated by firewalls. In other embodiments, the above network attributes may also include public networks (i.e., public networks) and private networks (i.e., private networks), where a public network refers to a network that can be accessed by the public within its coverage area, and a private network refers to a network that cannot be accessed without authorization. In some scenarios, the aforementioned external network and public network can refer to the same network, and a LAN can also be understood as a type of private network.
[0071] Location attributes can be used to identify the location of an accessed object, including the geographical area or the corresponding latitude and longitude range.
[0072] The traceability attribute can be used to query the history of when an object was sent, accessed, or modified, including indicating whether the corresponding protected file needs to be traced data management records, file open records, and file edit records.
[0073] The time attribute can be used to limit the expiration time of permissions or control measures for accessing objects based on the first and second access policies. This includes setting expiration times for permissions and control measures for specific access objects. The permission expiration time refers to the expiration time of read-only or read-write permissions granted to a specific device or account for a protected file. In other words, it represents the period during which a specified device or account has the right to perform read operations (i.e., open) or read-write operations (i.e., open and / or edit) on the protected file. When this permission expiration time expires, the authorized specified device or account will no longer be able to open and / or edit the protected file. The control expiration time refers to the protection period for security control of the protected file using the aforementioned common policies. When this control expiration time expires, the protected file can be opened and / or edited by any device or account.
[0074] The detailed process of applying the public policy to protect the protected file based on the parameters corresponding to each of the above attributes, including setting the parameter thresholds or ranges for each attribute, and performing attribute verification based on the set parameter thresholds or ranges, can be found in the description below with flowcharts and other related figures, and will not be elaborated here.
[0075] In addition to restricting the operation permissions of opening, copying, and modifying any part of a Word document, the aforementioned private policy may also include setting the control expiration time and permission expiration time for a specified access object, as well as whether the sending device of the accessed object (such as the aforementioned Word document) has unlimited outgoing permissions or outgoing permissions to send the accessed object to a specified device, and may also include whether the accessed object has the permission to continue forwarding the received accessed object, etc., which are not restricted here.
[0076] Based on the above Figure 2 The data management scenario shown is illustrated, and the specific implementation process of the data management method provided in this application is introduced in conjunction with flowcharts and related figures.
[0077] Figure 3 An embodiment of this application illustrates an interactive flow diagram involving the implementation process of a data management method. This interactive flow involves the aforementioned... Figure 2 The interaction between computer 10, computer 20 and cloud 30 in the scene shown.
[0078] In this system, computer 10 can act as one of the controllers setting access policies, and also as a sending device, sending files (i.e., the objects to be accessed) protected by access policies to computer 20, such as the Word document mentioned above. Correspondingly, computer 20 can act as the object of access, and also as a receiving device, receiving the files sent by computer 10 and verifying operation permissions according to the access policies of those files, thereby opening the received files and performing other operations within the scope of the access policies.
[0079] Specifically, such as Figure 3 As shown, the interaction flow includes:
[0080] S301: Computer 10 detects a first user action that instructs the setting of an access policy for the accessed object.
[0081] For example, the first user operation mentioned above may include operations such as the user performing encryption protection and / or setting access permissions for the accessed object, and may also include operations such as the user instructing the sending of the accessed object, etc., without limitation.
[0082] As an example, see reference Figure 4a As shown, User A can right-click on the Word document "X2.doc" displayed on Computer 10 and select "Encrypt Protection" to set an access policy for the document. Computer 10 responds to User A's access policy setting by setting an access policy for the Word document "X2.doc," such as the first access policy described below. This first access policy can include identity information such as account ID or device ID set for "1. Read-only user" and "2. Editing user," where "2. Editing user" refers to a user with only open permissions, and "2. Editing user" refers to a user with the permission to open, copy, and modify any part of the Word document "X2.doc." The first access policy can also include time information such as start and end dates and times set for "3. Permission Expiration Time" and "4. Control Expiration Time." The first access policy can also include space information set for "5. Operating Space," such as space IDs used to mark workspaces, which are not limited here.
[0083] The interface for displaying the Word document "X2.doc" can be found in the following example. Figure 4b The file management interface 410 is shown above. The user operation of right-clicking and selecting "encryption protection" can be referenced. Figure 4b The operation shown ① refers to clicking the "Encryption Protection" option in the menu bar 411 displayed on the computer 10 in response to a user action of clicking the mouse "right-click". In response to operation ①, the computer 10 can display... Figure 4c The file management interface 420 shown can display a pop-up window 421 corresponding to "encryption protection".
[0084] Continue to refer to Figure 4c Users can click the "Specified User" dropdown control 422 corresponding to the "Read-only" permission in the settings pop-up window 421 to set the identity information of "1. Read-only permission user". Alternatively, they can click the "Specified User" dropdown control 423 corresponding to the "Edit" permission in the settings pop-up window 421 to set the identity information of "2. Edit permission user". This identity information, such as the account ID, can be displayed in the settings pop-up window 421 on computer 10 with prompts such as "Please enter your account ID and press Enter, example: XXXXXXXX", which will not be elaborated upon here.
[0085] Users can also Figure 4c Performing operation ② on the file management interface 420 shown, i.e., clicking the "Advanced" control in the settings pop-up window 421, will take you to the relevant interfaces for setting "3. Permission Expiration Time" and "4. Control Expiration Time", for example... Figure 4d The file management interface shown is 430. Continue to refer to [the relevant documentation / reference]. Figure 4d Users can select the checkbox 431 corresponding to "Permission Expiration Time" to set it, for example, setting "Permission Expiration Time" to "2023 / 12 / 31 18:00". Similarly, users can also select the checkbox 432 corresponding to "Control Expiration Time" to set it, which will not be elaborated here.
[0086] In some embodiments, the first user operation of setting the access policy described above may further include setting attribute information such as the "allowed open location" of a file, which can be used to restrict access objects (e.g., as mentioned above). Figure 2 The device attributes of the computer 20 shown, such as the location information corresponding to the "Allowed Open Location" mentioned above, can be used to constrain the location attributes of the accessed object. As mentioned earlier, in addition to the time information and location information mentioned above, this attribute information may also include network information such as the IP address or network segment corresponding to the network attribute, and record information such as the opening record corresponding to the tracing attribute, etc., without any restrictions here.
[0087] S302: Computer 10 determines the first access policy set for the accessed object.
[0088] For example, computer 10 can determine the first access policy set for the accessed object based on the first user operation of setting the access policy described above. The first access policy can be a private policy, such as the one described above. Figure 2In the scenario shown, user A sets access policy a0 for a Word document via computer 10. The constraints of this first access policy on specific operation permissions can be found in the description of the permission scope and validity period of the operation permissions set for the first user operation in S301 above, and will not be repeated here.
[0089] In some embodiments, such as in a mobile office environment, the first access policy described above can be a private policy set by an employee with lower management privileges. In other embodiments, the first access policy described above can be an access policy set by one of the managing parties with other relationships or without relationships, and there are no restrictions on this.
[0090] S303: Computer 10 sends a request to the cloud 30 to obtain the second access policy.
[0091] For example, in response to the first user operation detected above, computer 10 also needs to obtain a second access policy provided by another control provider, such as cloud 30. Based on this, computer 10 can send a request to cloud 30 to obtain the second access policy.
[0092] It is understood that the aforementioned cloud-based 30 can be a high-level controller, such as an account (also known as an enterprise account) or terminal device used by an employee with high control privileges within a company / organization. Correspondingly, the aforementioned second access policy can be an access policy set by a high-level controller. As mentioned earlier, in some embodiments, access policies set by low-level controllers can be configured to comply with access policies set by high-level controllers.
[0093] In some embodiments, such as in enterprise mobile office scenarios, the second access policy can be a public policy set by employees with higher control privileges, such as the one described above. Figure 2 Access strategy b0 in the scenario shown.
[0094] S304: Cloud 30 sends a second access policy to computer 10.
[0095] For example, the cloud 30 may respond to the received access request by returning (i.e. sending) a second access policy, such as a public policy, to the computer 10.
[0096] It is understandable that the second access policy sent from cloud 30 to computer 10 can be the latest or updated access policy set by the corresponding management party. For example, refer to the above. Figure 2 In the scenario shown, if an employee with higher control authority in a company / organization changes the public policy from access policy b0 to access policy b1, then the cloud 30 can send the modified public policy, i.e., access policy b1, to the computer 10.
[0097] S305: Computer 10 sets the access policy of the accessed object according to the first access policy and the second access policy.
[0098] For example, if the first access policy and the second access policy are the same, computer 10 can set either the first access policy or the second access policy as the access policy of the accessed object. If the first access policy and the second access policy are different, the conflicting parts can follow the access policy set by the controller with the higher permission level. For example, the first access policy follows the second access policy, and in this case, the conflicting operation permissions in the second access policy can be set. The parts of the first access policy and the second access policy that do not conflict can be set together as part of the access policy of the accessed object, that is, the access object's operation permissions on the accessed object include both the operation permissions set in the first access policy and the operation permissions set in the second access policy, which will not be elaborated here.
[0099] Refer to the above Figure 4a An object that has an access policy set becomes an access-protected object under that access policy, for example... Figure 4a The Word document "X2'.doc" shown above has an icon that can be displayed in relevant interfaces such as file management interfaces. Figure 4a The image shows a Word document icon with a lock symbol.
[0100] It is understandable that the process of setting the access policy for the accessed object by computer 20 may include the process of combining the access policy determined by the first access policy and the second access policy with metadata to encapsulate data, and finally forming the accessed object protected by the access policy.
[0101] S306: Computer 10 sends the accessed object protected by the access policy to Computer 20.
[0102] For example, after setting an access policy for the accessed object, computer 10 can send the accessed object protected by the access policy to the access object specified by the user, for example... Figure 2 The computer 20 used by user B in the scenario shown.
[0103] In some embodiments, the first user operation described above may include, for example, a user instruction to send an accessed object, which may specify an access device to receive the accessed object. For example, in the above... Figure 2 In the scenario shown, user A can send a Word document to a designated user B on computer 10. Correspondingly, computer 20 used by user B can be the designated recipient of the accessed document.
[0104] S307: Computer 20 detected a second user operation to access the accessed object.
[0105] For example, the second user operation described above may include operations such as opening, copying, modifying, and sending the accessed object, without limitation.
[0106] Refer to the above Figure 2 In the scenario described, for example, user B can operate computer 20 to run the Word application and open the received Word document. Computer 20 can detect this opening operation, which is the second user operation mentioned above. Another example is that user B can perform operations such as copying content from the Word document or changing the username in the Word options on the interface displayed on computer 20 after opening the document. Computer 20 can detect these copying or modification operations. Yet another example is that user B can display the relevant interface of the Word document on computer 20, as described above... Figure 4b On the file management interface 410 shown, to perform an outgoing operation, such as clicking the "Share to" option in the menu bar 411 displayed on the file management interface 410, the computer 20 can detect the outgoing operation of the Word document.
[0107] S308: Computer 20 obtains the first access strategy based on the received accessed object.
[0108] For example, after receiving the accessed object, when responding to the second user operations such as opening, copying, modifying, and sending, computer 20 can first execute the secure file extension to obtain the first access policy carried by the accessed object, such as the aforementioned private policy. If the accessed object is an encrypted file, computer 20 also needs to execute the decryption algorithm through the system's encryption / decryption component to decrypt the file and then obtain the first access policy carried by the encrypted file; this is not limited here.
[0109] S309: Computer 20 sends a request to the cloud 30 to obtain the second access policy.
[0110] For example, when responding to the above-mentioned second user operations such as opening, copying, modifying, and sending, computer 20 can also obtain a second access policy from another controller, such as cloud 30, based on the access policy of the accessed object, including the control policies set by multiple controllers, such as the above-mentioned public policy.
[0111] It can be understood that the accessed object received by computer 20 can be the accessed object protected by the access policy obtained by computer 10 using data encapsulation technology in S305 above, for example... Figure 4aThe document shown is a Word document with a lock icon. When computer 20 executes S308 to obtain the first access policy, it can determine that the access policy of the accessed object includes both the first access policy set by computer 10 and the second access policy obtained from cloud 30. Based on this, computer 20 can continue to execute S309 to request the second access policy from cloud 30.
[0112] S311: Computer 20 performs operation permission verification according to the first access policy and the second access policy.
[0113] For example, after obtaining the first access policy and the second access policy required to access the accessed object, computer 20 can perform operation permission verification according to the first access policy and the second access policy. This operation permission verification process includes both operation permission verification based on the constraints of the first access policy and operation permission verification based on the constraints of the second access policy, which will not be elaborated here. Furthermore, this operation permission verification process can include authentication of the accessed object, verification of the accessed object's device attribute information, and verification of the accessed object's permission scope and validity period for its operation permissions on the accessed object. The order of these verification processes is not limited here. For example, when performing operation permission verification, computer 20 can first authenticate the accessed object, and after successful authentication, verify the accessed object's device attribute information in conjunction with device attributes, and then verify the accessed object's permission scope and validity period. The specific process of operation permission verification will be described in detail below with reference to the relevant accompanying drawings.
[0114] Refer to the above Figure 2 In the scenario shown, the aforementioned authentication of the access object includes, for example, verifying whether the device ID of computer 20 or the account logged into the Word application running on computer 20 matches the relevant information of the access object authorized by the first and second access policies. If they match, the authentication is successful. In some embodiments, computer 20 can also obtain relevant current device attributes according to the attribute verification required by the first or second access policy, such as the space ID of the operating space currently logged into by computer 20, the network IP address currently accessed by computer 20, the current location information and time information of computer 20, etc., and then compare the attribute information corresponding to each device attribute with the threshold or range of relevant attributes defined in the first and second access policies, thereby determining whether the authentication of computer 20 is successful, that is, whether computer 20 has the access identity to the accessed object.
[0115] The scope of the access permissions of the access object to the accessed object may, for example, include the above. Figure 4c or Figure 4dThe examples illustrate "read-only" or "edit" permissions. "Read-only" permission corresponds to the accessing object, such as computer 20, having only the permission to open the accessed object, such as a Word document. "Edit" permission corresponds to computer 20 having the permission to both open and copy or modify any part of the Word document. In other embodiments, the scope of the accessing object's permissions may also include other permissions, such as outbound permissions. For example, this could include verifying whether computer 20 has outbound permissions for the Word document, and whether it is allowed to send the Word document to the company's external network or limited to sending it to other employees within the company's internal network. These are not limited here.
[0116] It is understandable that if there is a conflict between the operation permissions constrained by the first access policy and the second access policy, computer 20 can first determine the access policy that the conflicting operation permissions should follow before performing operation permission verification. For example, the conflicting operation permissions can comply with the access policy set by the higher-level controller. For example, the first access policy can comply with the second access policy. At this time, computer 20 can verify the conflicting operation permissions according to the requirements of the second access policy. For specific conflict resolution methods, please refer to the relevant descriptions above, which will not be elaborated here.
[0117] It is understandable that computer 20 may have the right to modify the first access policy (e.g., private policy) set by computer 10, but may not have the right to modify the second access policy (e.g., public policy) obtained from the cloud 30.
[0118] Based on this, in some embodiments, the implementation process of the data management method provided in this application may further include S312 to S315.
[0119] S312: Computer 20 detected a third user operation instructing the user to change the first access policy to the third access policy.
[0120] For example, the aforementioned third user operation can refer to the first user operation in S301 above, such as operations including user encryption protection and / or setting access permissions for the accessed object, and may also include user instruction to send the accessed object. Unlike S301 above, the executing entity of this third user operation and the first user operation in S301 may not be the same user. The third access policy after modification may be partially or completely different from the first access policy before modification in terms of the identity of the accessed object, the scope of access permissions, and the validity period of permissions.
[0121] refer to Figure 2In the scenario shown, user B on computer 20 performs operations such as encrypting and protecting the received Word document again, and / or setting access permissions for the target object, as well as instructing the user to send the Word document. Setting access permissions can be understood as user B modifying the access policy constraints of the Word document through computer 20, specifically changing the access permissions corresponding to the first access policy to the access permissions corresponding to the third access policy. For example, user B can change the "read-only" permission granted to computer 20 in the Word document's access policy to "edit" permission, or change the access policy from granting computer 20 no outbound permission to grant it the right to send the Word document.
[0122] S313: Computer 20 determines whether there is a conflict of operation permissions between the third access policy and the second access policy.
[0123] If the judgment result is yes, that is, there is a conflict of operation permissions, then computer 20 can continue to execute S314 below;
[0124] If the judgment result is negative, that is, there is no conflict of operation permissions, then computer 20 can continue to execute S315 below.
[0125] For example, in response to the aforementioned third user operation, after modifying the first access policy that allows modification of the access policy of the received accessed object, such as a Word document, the computer 20 also needs to determine whether there is a conflict of operation permissions between the modified third access policy and another part of the second access policy that does not allow modification.
[0126] It is understandable that although computer 20, as the object of access, has the right to modify some access policies set by the controller (such as the first access policy), considering the data security of the object being accessed, this modification right may be restricted by another set of access policies that do not allow modification (such as the second access policy). If a conflict exists, the access policy of the object being accessed may refuse computer 20's modification of the first access policy, that is, computer 20 may execute the following S314 and use the second access policy that does not allow modification to verify the operation permission.
[0127] S314: Computer 20 performs operation permission verification according to the second access policy.
[0128] For example, when executing S313 above, if computer 20 determines that there is a conflict in operation permissions between the modified third access policy and the second access policy, it can use the second access policy obtained from cloud 30 to verify the operation permissions of the accessed object, given that the controller corresponding to the second access policy, such as cloud 30, has higher control permissions. That is, in this case, computer 20 can perform operation permission verification only by executing the second access policy without executing the modified third access policy. Referring to the relevant description in S313 above, the specific process of operation permission verification will be described in detail below with reference to the relevant accompanying drawings.
[0129] In other embodiments, when executing S313 above, the computer 20 may also, after determining that there is a conflict of operation permissions between the modified third access policy and the second access policy, reject the third user operation that the user instructed to modify the first access policy, and continue to verify the operation permissions according to the first access policy and the second access policy.
[0130] S315: Verify operation permissions according to the second and third access policies.
[0131] For example, when computer 20 executes S313 above, if it determines that there is no conflict in operation permissions between the modified third access policy and the second access policy, it can apply the modified third access policy and perform operation permission verification according to the second and third access policies. This operation permission verification process includes verification of operation permissions constrained by both the second and third access policies, which will not be elaborated upon here. Referring to the relevant description in S313 above, the specific process of operation permission verification will be described in detail below with reference to the relevant accompanying drawings.
[0132] Thus, based on the execution process of S301 to S315 above, after the accessed object is protected by the access policy, even if some of the access policies set by the controller are modified after the access policy is sent from the sending device, it can still be protected by at least one access policy set by the controller that cannot be modified. This can ensure the data security of the accessed object and reduce the security of the accessed object continuing to operate on the accessed object after the accessed object passes the verification.
[0133] It is understandable that after sending the accessed object protected by the access policy to computer 20, computer 10 can modify the first access policy (e.g., a private policy) according to changes in the data management needs of the accessed object. The modified access policy of computer 10 can be synchronized to computer 20 via cloud 30 to take effect.
[0134] Based on this, in some embodiments, the implementation process of the data management method provided in this application may further include S316 to S322.
[0135] It should be noted that in some embodiments, S312 to S315 and S316 to S322 described below may not be executed. In other embodiments, S316 to S322 may be executed before S312 to S315. This application addresses... Figure 3 The execution order of each step in the implementation process of the data management method shown is not limited.
[0136] S316: Computer 10 detected a fourth user action instructing the user to change the first access policy to the fourth access policy.
[0137] For example, after sending the accessed object with an access policy set, computer 10 can also respond to a user instruction to modify the access policy, such as the fourth user operation described above, changing the first access policy to the fourth access policy. This fourth user operation can be referred to the relevant description of the first user operation in S301 above. (See reference...) Figure 2 In the scenario shown, the fourth user operation can still be an operation performed by user A on the relevant interface of computer 10. After the fourth user operation is modified, the fourth access policy may be partially or completely different from the first access policy before the modification in terms of the identity of the access object, the scope of the operation permissions, and the validity period of the permissions.
[0138] It is understandable that computer 10 can modify the first access policy based on changes in control needs, such as changes in the security level of the accessed object over time, or user A needing to add more or fewer accessed objects based on work requirements, etc., without any restrictions.
[0139] S317: Computer 10 sends the fourth access policy to the cloud 30.
[0140] For example, after receiving a fourth user operation that modifies the access policy for the accessed object, computer 10 can upload the modified fourth access policy to cloud 30, that is, send the fourth access policy to cloud 30.
[0141] S318: The cloud 30 binds the received fourth access policy with the second access policy.
[0142] For example, after receiving the modified fourth access policy sent by the computer 10, the cloud 30 can bind the fourth access policy to the second access policy corresponding to the accessed object based on the constraints of the fourth access policy.
[0143] It is understandable that after binding, when the cloud 30 receives a request from the access object for the second access policy to access the accessed object, it can send the fourth access policy along with the second access policy to the access object, such as computer 20. The bound second and fourth access policies can be sent to the access object as two associated access policies, or they can be merged into a single access policy that covers the operation permissions set by both the second and fourth access policies; no restriction is placed on this.
[0144] S319: Computer 20 detected a fifth user operation that accessed the accessed object.
[0145] For example, the fifth user operation described above may include operations such as opening, copying, modifying, and sending the accessed object, and there are no limitations on this. Specific operation examples can be found in the relevant description of the second user operation in S307 above, and will not be repeated here.
[0146] S320: Computer 20 sends a request to the cloud 30 to obtain the second access policy.
[0147] For example, in response to the fifth user operation described above, computer 20 may request a second access policy from cloud 30 before performing operations such as opening, copying, modifying, or sending the accessed object. At this time, since the modified fourth access policy of computer 10 has not yet taken effect on computer 20, the access policy that computer 20's operation permissions on the accessed object are subject to may also include the first and second access policies described above before the modification.
[0148] S321: Cloud 30 sends the bound second and fourth access policies to computer 20.
[0149] For example, in response to a request from computer 20 for the second access policy, cloud 30 can send the bound second access policy and fourth access policy together to computer 20.
[0150] It is understood that in some embodiments, while sending the bound second and fourth access policies to the computer 20, the cloud 30 may also send a notification or instruction to the computer 20 to activate the fourth access policy, so that the computer 20 uses the fourth access policy to replace the first access policy. In other embodiments, the computer 20's system may also default to setting the fourth access policy obtained from the cloud as the modified access policy of the corresponding first access policy, which is not limited here.
[0151] S322: Computer 20 performs operation permission verification according to the second access policy and the fourth access policy.
[0152] For example, after receiving the second access policy and the modified fourth access policy from the cloud 30, computer 20 can update the access policy for the accessed object, for example, by replacing the first access policy with the received fourth access policy. Thus, before performing the fifth user operation described above to access the accessed object, computer 20 can verify operation permissions based on the second and fourth access policies. Referring to the relevant description in S313 above, the specific process of operation permission verification will be described in detail below with reference to the accompanying drawings.
[0153] Thus, based on the execution process of S301 to S322 above, after the accessed object is protected by an access policy, if the sending device needs to adjust the access policy based on changes in management requirements after the data is sent from the sending device, such as adjusting the identity of the accessed object or the accessed object's operation permissions on the accessed object, the modified access policy can be promptly applied to the accessed object based on the data management method provided in this application, so as to ensure the data security of the accessed object that has been sent and improve the timeliness of data management.
[0154] The following section, with reference to the accompanying diagram, details the operation permission verification process involved in S311, S314, S315, and S322 mentioned above.
[0155] Figure 5 An embodiment of this application illustrates a flowchart of an operation permission verification process. The entity executing this process can be the access object, such as computer 20. In some embodiments, the access object can also be the receiving device of the accessed object (e.g., a Word document).
[0156] like Figure 5 As shown, after the policy-protected "accessed object" is sent to computer 20 or other receiving devices, computer 20 or other devices, acting as access objects, can respond to the user's "open operation" and verify the operation permissions of the "accessed object." The user's "open operation" could, for example, be the user double-clicking a file (i.e., the accessed object) on the relevant interface of the accessed object displayed on computer 20, as described above. Figure 4b The operations shown are double-clicking the Word document "X2.doc" on the file management interface 410, or right-clicking and selecting the "Open" option.
[0157] Continue to refer to Figure 5 Verifying access permissions for the "accessed object" can include "access object authentication", "access object attribute verification", and "permission scope and validity period verification".
[0158] "Access Object Authentication" can include verifying the identity information of the access object, such as the device ID of computer 20 and the application it is running (e.g., the account logged into the Word application). This verification process can confirm the access object's identity to the accessed object according to the access policy. After the verification process is successful, the computer 20 and other devices can continue to perform "Access Object Attribute Verification". If "Access Object Authentication" fails, the verification result of the operation permission verification can be directly determined as a failure, and the accessed object cannot be opened for access.
[0159] "Access Object Attribute Verification" can include the process of obtaining and verifying attribute information related to the device attributes of the access object, such as computer 20. This attribute information, as mentioned above, may include, but is not limited to, spatial attributes, network attributes, location attributes, traceability attributes, and time attributes. Based on this, the access object, such as computer 20, can perform attribute verification on the above-mentioned attribute information according to the access policy. For example, it can verify whether the computer 20's spatial information (e.g., spatial ID) matches any item in the spatial information list in the access policy; verify whether the network information (e.g., IP address) is within the network segment specified in the access policy; verify whether the location information is within the location range defined by the access policy; verify whether the traceability information includes insecure operations performed by computer 20; and verify whether the time information meets the relevant settings such as permission expiration time and control expiration time in the access policy. These details will not be elaborated upon here. This verification process can confirm the security of the access object's logged-in operating space, network access, and location based on the access policy, and confirm the necessity of managing the data security of the accessed object. For example, documents involving company secrets can be verified within a specific time period, and no operation permission verification is required outside of that time period, allowing public access.
[0160] In some embodiments, the permission expiration time, control expiration time, etc. corresponding to the above time information may be the relevant time set in the second access policy (e.g., public policy), which may be different from the permission expiration time, control expiration time, etc. involved in "permission validity period" in "permission scope and permission validity period verification" below.
[0161] It's understandable that for verification results where "access object attribute verification" passes, computer 20 can continue to perform "permission scope and validity period verification." For verification results where "access object attribute verification" fails, the operation permission verification result is directly determined to be failed, and the accessed object cannot be opened for access. The difference lies in the fact that when "access object attribute verification" passes, computer 20 (i.e., the accessed object) is allowed to execute the maximum permission range restricted by the access policy; that is, computer 20 can fully execute all operation permissions within the scope of the access policy constraints. Conversely, when "access object attribute verification" fails, computer 20 (i.e., the accessed object) can have some operation permissions restricted. For example, if the location attribute verification result fails, indicating that computer 20's location is not secure, computer 20's "editing permission" for the accessed object (e.g., a Word document) can be restricted to "read-only" permission.
[0162] The "Permission Scope" in "Permission Scope and Validity Verification" can be the range of operation permissions jointly determined by the first access policy (e.g., private policy) and the second access policy (e.g., public policy). For example, this range can be the union of the operation permissions limited by the private policy and the public policy; for instance, the union of "read-only" permission and "edit permission" results in "read-only" permission. The "Permission Validity" in "Permission Scope and Validity Verification" can be the relevant time set in the first access policy (e.g., private policy). (Refer to the above.) Figure 2 In the scenario shown, the "permission validity period" can be the permission expiration time and control expiration time displayed in the access policy a0 set by user A through computer 10.
[0163] It is understood that the specific implementation of the data management method provided in this application may rely on the ability to execute the above-mentioned... Figure 3 The data management system related to the process shown can consist of terminal devices and a cloud platform. The terminal devices can be, for example, those described above. Figure 2 Computers 10 and 20 in the scenario shown can be connected to the cloud, for example, as described above. Figure 2 The cloud 30 in the scenario shown may include an account management server, a device management server, and other servers that can provide corresponding services.
[0164] As an example, Figure 6a According to an embodiment of this application, a schematic diagram of the composition of a data management system to which a data management method is applicable is shown.
[0165] like Figure 6a As shown, the data management system may include a cloud platform and terminal devices. The terminal devices can communicate and interact with relevant cloud services deployed in the cloud to implement the data management method provided in this application.
[0166] Specifically, the aforementioned cloud, such as the one described above Figure 2 The cloud 30 in the scenario shown can deploy cloud services related to the data management method provided in this application, such as account management service 310, device management service 320, and policy management service 330.
[0167] Among them, the account management service 310 can be used to manage account information logged in on various terminal devices, such as Huawei. TM The account includes the username, password, and real-name information of the user. In this embodiment, the account management service 310 can also be used to manage accounts logged in on specific applications installed and running on various terminal devices, such as accounts logged in to the aforementioned Word application. The account information managed by the account management service 310 may include account information used by employees with high privilege levels, or account information used by employees with low privilege levels; no limitation is made here. The device management service 320 can be used to manage device information for various terminal devices, including device IDs and other information for each terminal device.
[0168] It is understood that the account information managed by the account management service 310 and the device information managed by the device management service 320 can be provided to the policy management service 330 for setting access policies, such as setting the aforementioned second access policy.
[0169] The policy management service 330 is used to manage the access policies set by various control parties, including adding, deleting, and modifying access policies. These access policies may include a first access policy set by the aforementioned terminal device, such as computer 10, which can be uploaded to the cloud 30. This first access policy may also include access policies modified by computer 10 or computer 20 and uploaded to the cloud 30. Furthermore, it may include a second access policy set by the cloud 30, as well as access policies set and uploaded to the cloud 30 by other control parties; no restrictions are placed on this. It can be understood that the process of the policy management service 330 managing access policies may specifically involve adding, deleting, and modifying the access object's identity, the access object's operational permissions on the accessed object (such as the scope of permissions), and the permission expiration time set by each control party.
[0170] Referring again to the data management system shown in Figure 6, the operating system applied to the terminal device can adopt a layered architecture. This layered architecture divides the operating system into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the operating system is divided into four layers, from top to bottom: the application layer 410, the application framework layer 420, the system service layer 430, and the kernel layer 440. In other embodiments, the operating system may also be divided into other numbers of layers; this is not a limitation.
[0171] The application layer 410 may include a series of applications such as system applications or third-party applications. In this embodiment, the applications in the application layer 410 may include file processing applications, space transfer applications, and applications such as video, music, novels, and games. The file processing applications may include the aforementioned Word application, as well as Excel and PowerPoint applications, used to open files of supported types, i.e., the accessed objects. The space transfer application may include, for example, a file transfer application like Changlian. TM WeChat for Business TM This is used to transfer accessed objects, such as Word documents, Excel files, and PowerPoint files. In some embodiments, the space transfer application may also include cloud storage, etc., without limitation.
[0172] The application framework layer 420 provides a multi-language framework for the application layer, including an capability framework, a user interface (UI) framework, and a user program framework (not shown in the figure). The application framework layer 420 may also include some predefined functions (not shown in the figure) for the application layer 410 to call.
[0173] The system service layer 430 is the core of the operating system. The system service layer provides services to applications in the application layer through the application framework layer.
[0174] The operating system's application framework layer 420 and system service layer 430 may include a set of basic system capabilities subsystems, a set of basic software service subsystems, and a set of enhanced software service subsystems. The basic system capabilities subsystems provide foundational capabilities for the application layer 410 to run, schedule, and migrate applications on multiple devices based on this operating system. The security subsystem 230 included in this basic capabilities subsystem provides various security services to the operating system. The basic software service subsystems provide common, general-purpose software services. The enhanced software service subsystems provide differentiated, enhanced software services tailored to different devices; these will not be elaborated upon here.
[0175] In this embodiment, the security subsystem 230 may include a data management component 231. This data management component 231 executes a secure file extension program, which encapsulates the plaintext file or data content (hereinafter referred to as metadata) requiring access policies with the corresponding access policies. This encapsulates the metadata and the access policies to form a more secure accessed object, also known as a secure file, such as a Word document protected by the aforementioned access policies. Given that the metadata and the access policies protecting the metadata in this secure file resemble a capsule, in some embodiments, the secure file may also be referred to as a data security capsule or capsule file. (See reference...) Figure 6b The capsule file 600 is shown. In some embodiments, the capsule file 600 may also include a key as a shell for the access policy, protecting the access policy and metadata, without limitation.
[0176] Correspondingly, the aforementioned secure file extension program can also be called a data security capsule extension program or capsule extension program, etc. The security component that executes the secure file extension program can be called the aforementioned data management component 231, without any limitation.
[0177] In some embodiments, for files that need to be sent encrypted, the final secure file may also encapsulate a corresponding key. This key can act as a shell for the secure file, protecting the access policies (e.g., private policies) carried by the secure file. Thus, when the secure file is opened on computer 20, the private policy carried by the secure file can be decrypted to obtain it, and the public policy can be retrieved from the cloud 30. Verification can then be performed based on the private and public policies.
[0178] Based on this, the aforementioned data management component 231 may include a file encryption / decryption module 231a, an access control module 231b, a data tagging module 231c, a tracing module 231d, and a permission management module 231e, etc. In other embodiments, the data management component 231 included in the operating system of the terminal device, or a security component performing the same function as the data management component, may include more than Figure 6a The application does not limit the number of software structures shown or the number of software structures shown.
[0179] The file encryption / decryption module 231a can encrypt specified metadata (metadata, i.e., the accessed object) by executing an encryption algorithm when the user specifies an encryption protection operation. The key used in this encryption process can be input by user A of the sending device, such as computer 10, or stored in the local security chip. Furthermore, the file encryption / decryption module 231a can also execute a decryption algorithm to decrypt a specified file (encrypted file, i.e., the accessed object protected by the key and access policy) when the user performs a decryption access operation. The key used in this decryption process can be input by user B of the receiving device, such as computer 20, or stored in the local security chip. It can be understood that after the data management component 231 encrypts the accessed object (i.e., metadata) with the access policy set by the file encryption / decryption module 231a, it encapsulates the key, access policy, and metadata into the aforementioned... Figure 6b The example capsule file is then sent or transmitted.
[0180] The access control module 231b can be used to determine, based on the decryption result of the encrypted file by the file encryption / decryption module 231a, which access policies set by the control parties are included in the access policy of the accessed object when a user performs an open operation on the accessed object (e.g., an encrypted file) protected by the access policy, and to obtain the access policies set by each control party required for data access to the accessed object, such as the first access policy, the second access policy, etc., and then execute each access policy to perform access control on the accessed object.
[0181] In some embodiments, the access control module 231b is further configured to obtain, in real time, attribute information related to the device attributes of the terminal device according to the access policy, including the aforementioned spatial information, network information, location information, traceability information, time information, etc., for use in performing the aforementioned "access object attribute verification" according to the access policy, which will not be elaborated here.
[0182] The data tagging module 231c is used to add data tags to metadata that requires encryption and access policy protection. A data tag is an identifier that attaches metadata information (such as file security level, author or file owner, editing time, word count, page count, etc.) to a data element. It provides key information about the metadata, such as data type, source, modification history, quality, and content. Metadata with added data tags provides the original data for the tracing module 231d to generate tracing information. Based on this, the data tagging module 231c can also be used to identify data tags in the metadata after the accessed object has been successfully accessed, providing the tracing module 231d with information such as data type, source, modification history, quality, and content for tracing analysis.
[0183] The traceability module 231d can be used to perform traceability analysis on the data type, source, modification history, quality, and content of the accessed object to understand whether there are any security risks during the transmission and access process. For accessed objects with security risks, the terminal device can remind the user to pay attention or remind the user to set stricter access policies to protect the accessed object.
[0184] The permission management module 231e can be used to add, delete, or modify the identity information and operation permission information of the access object according to the access policy set by the user. It can also be used to manage the file outgoing permissions of the sending device itself. The permission management module 231e can also be used to add, delete, or modify the operation permission information it has when it is an access object, according to the received access policy.
[0185] Kernel layer 440 is the layer between hardware and software. The operating system's kernel layer 440 may include: kernel subsystem 441 and driver subsystem 442.
[0186] The kernel subsystem, given that operating systems can employ a multi-kernel design, supports the selection of a suitable OS kernel for different resource-constrained devices. The kernel abstract layer (KAL) on the kernel subsystem 441 provides basic kernel capabilities to upper layers by shielding the differences between multiple kernels, including positioning systems, security chips, file systems, and network systems.
[0187] The positioning system provides positioning capabilities, enabling it to provide real-time location information to the attribute management component 231c of the security subsystem 230. The security chip provides security capabilities, such as key management, to support the file encryption / decryption module 231a in encrypting / decrypting metadata. The security chip provides a trusted execution environment (TEE) for the upper layer, within which the security subsystem 230, or data management component 231, can run. Applications in the application layer 410, such as file processing and spatial data transfer applications, can also run within the TEE to enhance the security of processes such as setting access policies for accessed objects and accessing them according to those policies.
[0188] The Driver Framework (HDF) of the Driver Subsystem 442 is the foundation for the open distributed system hardware ecosystem, providing unified peripheral access capabilities and a framework for driver development and management. The kernel layer includes at least display drivers, camera drivers, audio drivers, and sensor drivers.
[0189] It is understood that the form of the aforementioned data management component 231 is not limited to the security component in the aforementioned security subsystem 230; for example, it could also be an Android component that can be installed on any operating system. TM (Android TM An application package (APK) can also be called a data management device or a data capsule device, etc., without any restrictions.
[0190] Based on the above Figure 6a The operating system shown is applied to the terminal device, which can execute... Figure 6c The operation permission verification process is shown. The terminal device can be a sending device, such as the computer 10 mentioned above.
[0191] refer to Figure 6c In cases where the accessed object is metadata, the metadata (such as Word documents) is transferred via file exchange applications like Changlian. TM WeChat for Business TM When the file is sent to a personal space, the file transfer application can call the data management component to first determine whether encryption is required, then execute the security extension to set an access policy for the metadata as a layer of protection, and set a key for the metadata that needs to be encrypted as another layer of protection, and finally form a capsule file which is then sent out by the file transfer application.
[0192] When the accessed object is a capsule file (such as a Word document), the capsule file is transferred via a file transfer application such as Changlian. TM WeChat for Business TM When the capsule file is sent to a personal space, since the capsule file has already been created, the file transfer application can call the data management component to first determine whether the access policy of the capsule file allows it to be sent out. If it allows it to be sent out, then the capsule file will be sent out.
[0193] Based on the above Figure 6a The data management system shown below, with reference to the accompanying drawings, will be used to introduce the implementation principles of the different data management stages involved in the data management method provided in this application.
[0194] Figure 7a An embodiment of this application illustrates a schematic diagram of the implementation principle of an encryption protection phase for setting access policies.
[0195] like Figure 7aAs shown, the sending device, such as computer 10, can respond to a user operation (refer to the first user operation in S301 above) and perform a process of setting access policies for metadata (e.g., files such as Word documents, i.e., the accessed object). This process can invoke the system's data management component 231. In some embodiments, this process may further include providing the data management component 231 with a user-set key for encrypting metadata.
[0196] In response to a call, the data management component 231 can obtain relevant account information from the account management service 310 in the cloud 30, such as the login account of the relevant application running on the computer 10 (e.g., the Word application) and the account information corresponding to the access object set by the corresponding access policy. The account information obtained by the data management component 231 can be added to the corresponding access policy as the basis for account-based authentication.
[0197] During the process of setting access policies, the data management component 231 can also execute a secure file extension. This process can trigger the computer 10 to request the second access policy from the policy management service 330 in the cloud 30 and to request space attributes from the device management service 320 in the cloud 30. These space attributes include attribute information corresponding to each workspace authorized by the second access policy, such as space IDs. The permissions authorized by the second access policy can include outbound permissions and / or access permissions. This attribute information can, for example, include attribute information of workspaces corresponding to employees with corresponding permission levels within a company / unit. These space attributes can be used to set configuration information related to space attributes in the access policy for metadata, such as pre-setting some space IDs that are allowed to access metadata as configuration information. In response to the request from the data management component 231, the cloud 30 can return the space attributes and the second access policy to the computer 10.
[0198] After obtaining all the information needed to set the access policy, the data management component 231 can execute the secure file extension program to add the metadata, access policy, and key to form a capsule file. The structure of this capsule file is as described above. Figure 6b As shown, the capsule file can be securely opened, copied, and its data content modified after decryption and operation permission verification according to the access policy.
[0199] Figure 7b An embodiment of this application illustrates a schematic diagram of the implementation principle of using access policies to control the transmission process of accessed objects.
[0200] like Figure 7bAs shown, accessed objects protected by access policies, such as the capsule file mentioned above, can be sent through a data transmission channel established between a sending device, such as computer 10, and a receiving device, such as computer 20. This sending process can also be completed based on a data transmission channel established between space-sharing applications installed on computer 10 and computer 20. These space-sharing applications can establish a data transmission channel through corresponding application servers.
[0201] In this embodiment, the sending process can trigger the data management component 231 to execute a secure file extension program, send a second access policy to the cloud 30, and execute the relevant settings regarding outgoing permissions in the second access policy and the first access policy carried in the capsule file. Specifically, the data management component 231 can first determine whether the second access policy includes a policy prohibiting outgoing access. If the determination is yes, the outgoing access of the capsule file can be directly prohibited, for example, prohibiting the capsule file from being sent to the computer 20. Conversely, if the determination is no, the data management component 231 can continue to determine whether the first access policy includes a policy prohibiting outgoing access, and then decide whether to prohibit the outgoing access of the capsule file. It can be understood that, considering the needs of data asset management, the permission level of the controller corresponding to the second access policy can be higher than the permission level of the controller corresponding to the first access policy. Therefore, when neither the second access policy nor the second access policy includes a policy prohibiting outgoing access, that is, when the results of the above two determinations are both no, the computer 10 can outgoing the capsule file. In this way, the data transmission security of metadata and capsule files (i.e., the accessed objects) can be effectively controlled.
[0202] Figure 7c The present application provides an embodiment illustrating the implementation principle of a process for controlling the opening and access of capsule files based on access policies.
[0203] like Figure 7c As shown, after receiving the capsule file (i.e., the accessed object protected by the policy), the receiving device, such as computer 20, can respond to the user's open operation (refer to the second user operation in S307 above) to decapsulate the capsule file. That is, it unpacks the capsule file based on data encapsulation technology to obtain the access policy that controls access to metadata in the capsule file. In some other embodiments, the decapsulation process may also include the process of decrypting the capsule file using a key, which will not be elaborated here.
[0204] Continue to refer to Figure 7cAfter the capsule file is unsealed, the data management component 231 of computer 20 can execute the secure file extension program to first obtain the first access policy carried by the capsule file, that is, the access policy set by computer 10 as one of the controllers. As mentioned earlier, the Trusted Execution Environment (TEE) provided by the security chip of computer 20 can provide trusted attributes for the process of data management component 231 executing the secure file extension program. At this time, computer 20 can first perform account authentication with the account management service 310 of cloud 30 according to the first access policy carried by the capsule file. Alternatively, computer 20 can also decrypt the capsule file by entering the decryption key, obtain the first access policy carried by the capsule file, and then perform account authentication. For example, verifying whether the account logged in by the application that opened the capsule file on computer 20 (such as the account logged in by the Word application) is the account corresponding to the access object specified in the first access policy.
[0205] Continue to refer to Figure 7c The access policy carried by the capsule file on computer 20 also includes a second access policy, which can also be obtained from the cloud 30. Therefore, after the aforementioned account authentication is successful, computer 20 can perform verification according to the access policy (including the first and second access policies). This verification process can include the aforementioned identity verification, attribute verification, and operation permission verification, etc., as detailed in S311 above. Figure 5 The process and related descriptions are not elaborated here. After successful verification according to the access policy, computer 20 can open the corresponding application and the file (i.e., the accessed object). Conversely, if the verification according to the access policy fails, computer 20 will fail to open the file. In this case, computer 20 can display a prompt interface indicating that opening failed to user B, or indicate that user B does not have permission to open the file, etc., which will not be elaborated here.
[0206] Figure 8 A schematic diagram of the hardware structure of an electronic device is shown according to an embodiment of this application. This electronic device can be the aforementioned computer 10, or the aforementioned computer 20, or other terminal devices. In other embodiments, it can also be a tablet computer or a foldable screen phone, etc., and no limitation is made herein.
[0207] Electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, antenna 1, antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identity module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor, a gyroscope sensor, an accelerometer sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, etc.
[0208] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0209] Processor 110 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.
[0210] The controller can generate operation control signals based on the instruction opcode and timing signals to complete the control of instruction fetching and execution.
[0211] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the aforementioned memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0212] In this embodiment, the processor 110 of computer 10 or computer 20 can generate operation control signals based on the aforementioned controller to perform the above-mentioned tasks. Figure 3 , Figure 5 , Figure 6c and Figures 7a to 7c The control of instruction fetching and execution for each part of the process or procedure shown is used to implement the relevant content executed by computer 10 or computer 20 or data management component 231, thereby realizing the data management method provided in this application. Specific implementation processes can be found in the above process or procedure diagrams and related descriptions, and will not be elaborated upon here.
[0213] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM card interface, and / or a universal serial bus (USB) interface, etc.
[0214] USB interface 130 is an interface that conforms to the USB standard specification, specifically it can be a Mini USB interface, Micro USB interface, USB Type C interface, etc.
[0215] It is understood that the interface connection relationships between the modules illustrated in the embodiments of this application are merely illustrative and do not constitute a structural limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.
[0216] The charging management module 140 receives charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 receives charging input from the wired charger via a USB interface 130. In some wireless charging embodiments, the charging management module 140 receives wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also supply power to the electronic device via the power management module 141. The power management module 141 connects to the battery 142, and the charging management module 140 connects to the processor 110.
[0217] The wireless communication function of electronic device 100 can be realized through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0218] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.
[0219] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc.
[0220] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc.
[0221] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, so that electronic device 100 can communicate with networks and other devices through wireless communication technology.
[0222] Electronic device 100 implements display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0223] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Mini-LED, a Micro-LED, a Micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, electronic device 100 may include one or N displays 194, where N is a positive integer greater than 1.
[0224] The electronic device 100 can perform shooting functions through an ISP, a camera 193, a video codec, a GPU, a display 194, and an application processor. The ISP is used to process data fed back from the camera 193. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0225] Camera 193 is used to capture still images or videos. An object passes through the lens to generate an optical image that is projected onto a photosensitive element. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP (Internet Service Provider) for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP (Digital Signal Processor) for processing. The DSP converts the digital image signal into image signals in standard formats such as RGB and YUV. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0226] The external storage interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external storage interface 120 to perform data storage functions. For example, music, video, and other files can be saved on the external memory card.
[0227] Internal memory 121 can be used to store computer executable program code, including instructions. Internal memory 121 may include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of electronic device 100 (such as audio data, phonebook, etc.). In addition, internal memory 121 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc. Processor 110 executes various functional applications and data processing of electronic device 100 by running instructions stored in internal memory 121 and / or instructions stored in memory disposed in the processor.
[0228] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0229] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. Electronic device 100 can receive button input and generate key signal inputs related to user settings and function control of electronic device 100.
[0230] Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, different vibration feedback effects can correspond to touch operations performed on different applications (such as taking photos, playing audio, etc.). Motor 191 can also correspond to different vibration feedback effects for touch operations performed on different areas of the display screen 194. Different application scenarios (such as time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customized.
[0231] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0232] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to make contact with and separate from the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 simultaneously. The types of these multiple cards can be the same or different. The SIM card interface 195 is also compatible with different types of SIM cards. The SIM card interface 195 is also compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to realize functions such as calls and data communication. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.
[0233] This application also provides an electronic device 200 for implementing the data management methods provided in the above embodiments. The electronic device 200 may include the server running on the cloud 30. In some embodiments, the electronic device 200 may also include the computer 10 and computer 20, without limitation.
[0234] like Figure 9 As shown, the electronic device 200 includes a bus 1102, a processor 1104, a memory 1106, and a communication interface 1108. The processor 1104, the memory 1106, and the communication interface 1108 communicate with each other via the bus 1102. The electronic device 200 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the electronic device 200.
[0235] Bus 1102 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 9 The bus 1104 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 1104 may include a path for transmitting information between various components of the electronic device 200 (e.g., memory 1106, processor 1104, communication interface 1108).
[0236] The processor 1104 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0237] The memory 1106 may include volatile memory, such as random access memory (RAM). The processor 1104 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0238] The memory 1106 stores executable program code, and the processor 1104 executes the executable program code to implement the relevant functions of the account management service 310, device management server 320, and policy management service 330 of the aforementioned cloud 30, thereby realizing the data management method provided in this application. That is, the memory 1106 stores instructions for executing the data management method.
[0239] Alternatively, the memory 1106 stores executable code, which the processor 1104 executes to implement the relevant functions of the data management component 231 in the aforementioned computers 10 and 20, thereby realizing the data management method. That is, the memory 1106 stores instructions for executing the data management method.
[0240] The communication interface 1108 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the electronic device 200 and other devices or communication networks.
[0241] This application also provides a computer program product for implementing the data management methods provided in the above embodiments.
[0242] Various embodiments of the mechanisms disclosed in this application can be implemented in hardware, software, firmware, or combinations of these implementation methods. Embodiments of this application can be implemented as computer program modules or module code executable on a programmable system, the programmable system including at least one processor, a storage system (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device.
[0243] Computer program modules or module code can be applied to input instructions to perform the functions described in this application and generate output information. The output information can be applied to one or more output devices in a known manner. For the purposes of this application, the processing system includes any system having a processor such as, for example, a digital signal processor (DSP), a microcontroller, an application-specific integrated circuit (ASIC), or a microprocessor.
[0244] Module code can be implemented using a high-level modular language or an object-oriented programming language to communicate with the processing system. Assembly language or machine language can also be used to implement module code when needed. In fact, the mechanisms described in this application are not limited to any particular programming language. In either case, the language can be a compiled language or an interpreted language.
[0245] In some cases, the disclosed embodiments may be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments may also be implemented as instructions carried or stored thereon on one or more temporary or non-temporary machine-readable (e.g., computer-readable) storage media, which may be read and executed by one or more processors. For example, the instructions may be distributed via a network or through other computer-readable media. Therefore, machine-readable media may include any mechanism for storing or transmitting information in a machine-readable (e.g., computer-readable) form, including but not limited to floppy disks, optical disks, optical discs, magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic cards or optical cards, flash memory, or tangible machine-readable storage for transmitting information (e.g., carrier waves, infrared signals, digital signals, etc.) using the Internet in the form of electrical, optical, acoustic, or other forms of propagated signals. Therefore, machine-readable media include any type of machine-readable medium suitable for storing or transmitting electronic instructions or information in a machine-readable (e.g., computer-readable) form.
[0246] In this specification, the reference to "an embodiment" or "an embodiment" means that a specific feature, structure, or characteristic described in connection with the embodiment is included in at least one exemplary implementation or technology disclosed according to an embodiment of this application. The appearance of the phrase "in an embodiment" in various places in the specification does not necessarily refer to the same embodiment.
[0247] The disclosure of embodiments of this application also relates to means for performing operations in text. This means may be specifically constructed for the claimed purpose or may include a general-purpose computer selectively activated or reconfigured by a computer program stored in a computer. Such a computer program may be stored on a computer-readable medium, such as, but not limited to, any type of disk, including floppy disks, optical disks, CD-ROMs, magneto-optical disks, read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic or optical cards, application-specific integrated circuits (ASICs), or any type of medium suitable for storing electronic instructions, and each may be coupled to a computer system bus. Furthermore, the computer mentioned in the specification may include a single processor or may employ an architecture involving multiple processors for increased computing power.
[0248] Furthermore, the language used in this specification has been primarily chosen for readability and instructional purposes and may not have been chosen to depict or limit the disclosed subject matter. Therefore, the embodiments disclosed herein are intended to illustrate, and not limit, the scope of the concepts discussed herein.
Claims
1. A data management method characterized by, The method comprises: A first device receives an accessed object and determines that the accessed object has a first access policy and a second access policy, wherein the first access policy is set by a first controller, the second access policy is set by a second controller, the first device has a modification authority of the first access policy, and the first device does not have a modification authority of the second access policy; The first device accesses the accessed object based on the first access policy and the second access policy; The first device modifies the first access policy into a third access policy, and replaces the first access policy corresponding to the accessed object with the third access policy; The first device sends the accessed object to a second device, wherein the second device has a modification authority of the third access policy, and the second device does not have a modification authority of the second access policy.
2. The method of claim 1, wherein, The second controller comprises a cloud, and After the first device receives the accessed object, the method further comprises: The first device obtains a fourth access policy and the second access policy corresponding to the accessed object from the cloud, wherein the fourth access policy is an access policy modified by the first controller on the first access policy; The first device accesses the accessed object based on the first access policy and the second access policy.
3. The method of claim 1, wherein, The first device accesses the accessed object based on the first access policy and the second access policy, comprising: Corresponding to the first access policy being the same as the second access policy, accessing the accessed object based on the first access policy or the second access policy; Corresponding to the first access policy being different from the second access policy, determining a fifth access policy for the accessed object based on the first access policy and the second access policy, wherein the fifth access policy comprises an intersection of the first access policy and the second access policy, a policy part of the first access policy or the second access policy that is different from the intersection.
4. The method according to any one of claims 1 to 3, characterized in that, The first execution priority corresponding to the first access policy is higher than the second execution priority corresponding to the second access policy.
5. The method of claim 4, wherein, The first device accesses the accessed object based on the first access policy and the second access policy, comprising: Based on the second execution priority being higher than the first execution priority, determining that the fifth access policy comprises the intersection of the first access policy and the second access policy, and a policy part of the second access policy that is different from the intersection.
6. The method of claim 5, wherein, The first controller has a first authority level lower than a second authority level of the second controller.
7. The method according to any one of claims 1 to 6, characterized in that, The first device modifies the first access policy into a third access policy, comprising: Modifying at least one constraint condition set in the first access policy regarding an identity of an access object, an attribute of the access object, and an operation authority of the access object on the accessed object to obtain the third access policy; and The access object comprises the first device.
8. The method of claim 7, wherein, The method further comprises: The first device detects that there is a conflict between a first constraint condition set in the third access policy and a second constraint condition set in the second access policy; The first device modifies the third access policy as the first access policy.
9. The method of claim 8, wherein, The access object attribute comprises a device attribute, and the device attribute comprises one or more of the following: a space attribute for indicating a type of operation space in which the access object is currently logged in; a network attribute for identifying a network to which the access object is currently connected; a location attribute for identifying a location where the access object is located; a trace attribute for querying a history record of the accessed object being sent, accessed or modified; a time attribute for limiting a permission expiration time or a control expiration time of accessing the accessed object based on the first access policy and the second access policy.
10. The method of claim 8, wherein, The access object attribute and the operation permission of the access object to the accessed object comprise one or more of the following: opening the accessed object and accessing content and file attributes of the accessed object; copying content and file attributes of the accessed object; changing content and file attributes of the accessed object.
11. The method of any one of claims 1-10, the second controller has a management permission to the first controller, and the management permission comprises any one of the following: the second controller comprises a device management service having a management permission to a device corresponding to the first controller; the second controller comprises an account management service having a management permission to an account logged in by the first controller.
12. The method of any one of claims 1-10, the second controller comprises a cloud, and the first device accesses the accessed object based on the first access policy and the second access policy comprises: the first device sends a request for obtaining the second access policy to the cloud; the first device accesses the accessed object based on the second access policy received from the cloud and the first access policy.
13. An electronic device, comprising: comprise: one or more processors; one or more memories, the one or more memories storing one or more programs, when the one or more programs are executed by the one or more processors, causing the electronic device to perform the data management method of any one of claims 1-12.
14. A computer readable medium characterized by instructions stored on the readable medium, when executed on a computer, cause the computer to perform the data management method of any one of claims 1-12.
15. A computer program product, characterised in that, comprise computer programs / instructions, when executed by a processor, implement the data management method of any one of claims 1-12.