Data management method, device and equipment and computer storage medium

By copying and locking the data to be downloaded in the cloud server, and approving its download only after verifying its security, the problem of cloud server data leakage is solved, and the security and standardization of data storage are achieved.

CN121935929APending Publication Date: 2026-04-28TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2024-10-25
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Inadequate data management and security measures in cloud servers lead to a high probability of data leakage, allowing users to freely download data to storage areas outside the cloud server.

Method used

When responding to an operation to download data in the cloud server, the data is copied to a temporary storage area and a lock flag is set. The distribution of the target data is detected through a preset security dataset. After obtaining the approval result, the lock flag is removed and the data is downloaded.

Benefits of technology

It improves the security of cloud server data storage, prevents data leakage, ensures that download operations are completed after approval, and enhances the standardization and security of data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121935929A_ABST
    Figure CN121935929A_ABST
Patent Text Reader

Abstract

The invention provides a data management method, device and equipment and a computer storage medium, which are applied to the field of computers and are used for improving the security of data storage in a cloud server and reducing the probability of occurrence of a data leakage problem. The method is applied to a cloud server, and at least comprises the following steps: in response to a downloading operation, copying to-be-downloaded data in the cloud server to obtain corresponding target data; after storing the target data in the temporary storage area, setting a locking identifier representing the shielding operation instruction for the target data; detecting the target data based on a preset security data set to obtain a detection result representing the distribution condition of each security data in the target data; the security data set comprises at least one kind of security data limited to be downloaded; and when an examination and approval result representing that examination and approval pass is obtained based on the detection result, removing the locking identifier, and sending the target data to a target address in a data storage area outside the cloud server indicated by the downloading operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and specifically to a data management method, apparatus and device, and computer storage medium. Background Technology

[0002] With the continuous development of computer technology, cloud computing technology has become increasingly popular. When performing computer-related tasks, most organizations are gradually using cloud servers instead of physical machines as the primary means of operation. A physical machine refers to an actual computer device with physical hardware, including components such as processors, memory, hard drives, motherboards, and power supplies. A cloud server, on the other hand, is a virtualized computing resource provided through cloud computing technology; essentially, it is a virtual machine instance created by virtualization software on a physical machine.

[0003] Generally, when an organization uses cloud servers as its primary operational tool, it partitions the cloud server resources and allocates these resources to various users within the organization. In this way, each user, after receiving the corresponding cloud server resources, can perform data processing and storage operations within those resources.

[0004] However, current technologies do not provide adequate measures for data management and security protection on cloud servers. Specifically, when users process data on their own cloud server resources, they can freely download various data from those resources to other data storage areas outside the cloud server (such as physical machines like mobile phones and personal computers, or other cloud servers or cloud databases). This results in low data security and a high probability of data leakage stored on cloud servers.

[0005] Therefore, there is an urgent need for a new data management method to improve the security of data storage in cloud servers and reduce the probability of data leakage. Summary of the Invention

[0006] This application provides a data management method, apparatus, device, and computer storage medium to improve the security of data storage in cloud servers and reduce the probability of data leakage.

[0007] In a first aspect, embodiments of this application provide a data management method applied to a cloud server, comprising:

[0008] In response to a download operation triggered for data to be downloaded in a cloud server, the data to be downloaded is copied, and the resulting target data is saved to a temporary storage area in the cloud server.

[0009] In the temporary storage area, a locking flag is set for the target data; wherein, the locking flag indicates that the operation command is blocked;

[0010] The target data is detected based on a preset security dataset to obtain corresponding detection results; wherein, the security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data in the target data;

[0011] Based on the detection results, obtain the approval result for the download operation;

[0012] When the approval result indicates that the approval is successful, the lock identifier is removed, and the target data is sent to the target address indicated by the download operation; wherein, the target address is: an address in the data storage area outside the cloud server.

[0013] Secondly, embodiments of this application provide a data management apparatus, comprising:

[0014] A response module is used to respond to a download operation triggered for data to be downloaded in a cloud server, copy the data to be downloaded, and save the obtained target data to a temporary storage area in the cloud server; in the temporary storage area, a lock flag is set for the target data; wherein, the lock flag indicates: blocking operation commands;

[0015] The detection module is used to detect the target data based on a preset security dataset and obtain corresponding detection results; wherein, the security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data in the target data;

[0016] An approval module is used to obtain an approval result for the download operation based on the detection results.

[0017] The processing module is used to remove the lock identifier and send the target data to the target address indicated by the download operation when the approval result indicates that the approval has been passed; wherein, the target address is an address in the data storage area outside the cloud server.

[0018] Optionally, when the approval module obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0019] When the detection result indicates that the target data does not contain any of the security data, an approval result indicating that the download operation has been approved is obtained;

[0020] When the detection result indicates that at least one of the security data is distributed in the target data, an approval result indicating that the download operation is not approved is obtained.

[0021] Optionally, if the download operation is triggered by the target user, then when the approval module obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0022] Based on the identity information of the target user, obtain the data download permission corresponding to the target user;

[0023] Based on the detection results, the security level corresponding to the target data is obtained; wherein, the security level is positively correlated with the number of times the target data matches the security data as represented by the detection results;

[0024] When the data download permission matches the security level of the target data, the approval result for the download operation is determined as: Approval passed.

[0025] Optionally, if the download operation is triggered by the target user, then when the approval module obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0026] Based on the identity information of the target object, the target data, and the detection result, the download operation is subjected to a first verification process to obtain a corresponding first verification result;

[0027] The identity information of the target object and the target data are sent to the approval object, so that the approval object performs a second verification process on the download operation based on the identity information and the target data, and returns the obtained second verification result.

[0028] Receive a second verification result from the approval recipient regarding the download operation;

[0029] When both the first verification result and the second verification result indicate that the verification is successful, the approval result for the download operation is determined to be: approval successful.

[0030] Optionally, if the download operation is triggered by the target user, then when the approval module obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0031] The identity information of the target user, the target data, and the detection results are sent to the approval server, so that the approval server can approve the download operation based on the identity information, the target data, and the detection results, and return the obtained approval result.

[0032] Obtain the approval result from the approval server for the download operation.

[0033] Optionally, after obtaining the detection result and before obtaining the approval result, the detection module is further configured to:

[0034] The target data is subjected to a digest acquisition process to obtain a first digest value; the target data uniquely corresponds to the first digest value;

[0035] When the processing module removes the lock identifier and sends the target data to the target address indicated by the download operation, it is specifically used for:

[0036] The target data is subjected to the digest acquisition process to obtain a second digest value;

[0037] When the second digest value is the same as the first digest value, the lock identifier is removed, and the target data is sent to the target address indicated by the download operation.

[0038] Optionally, the download operation is remotely triggered by the target user on the cloud server based on a remote desktop control protocol, targeting the data to be downloaded.

[0039] Thirdly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0040] Fourthly, embodiments of this application provide a computer device, including:

[0041] Memory, used to store program instructions;

[0042] A processor is configured to invoke program instructions stored in the memory and execute the method described in the first aspect according to the obtained program instructions.

[0043] Fifthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions for causing a computer to perform the method described in the first aspect.

[0044] The beneficial effects of this application are as follows:

[0045] This solution proposes corresponding detection and approval operations for the process of downloading data from the cloud server. When a download operation is triggered in response to data to be downloaded from the cloud server, the data to be downloaded is copied to obtain the target data, saved to a temporary storage area, and then a lock flag is set to block operation commands on the target data. This prevents inconsistencies between the detected and approved data and the final downloaded data, thus avoiding data leakage. At the same time, since the target data is in the temporary storage area, the data to be downloaded on the cloud server can still be used normally without interfering with the cloud server user's usage process, thereby improving the reliability of the solution implementation.

[0046] When detecting target data, a preset security dataset is used as the detection basis to detect the target data and obtain the distribution of each security data in the target data. Based on the ease of modifying the security dataset, the detection processing of the target data can be flexibly carried out, which improves the timeliness and flexibility of security detection.

[0047] Based on the detection results, the approval result of the target data is determined. When the approval result indicates that the data has passed, the lock flag is removed, and the target data is sent to a target address outside the cloud server specified in the download operation instruction. This ensures that the download operation of the target data is completed after approval, avoiding arbitrary downloads of the target data and improving the security of data storage in the cloud server. Through fixed detection and approval operations, the standardization of data management in the cloud server is improved, and data downloads to the cloud server can be recorded, thereby preventing the possibility of data leakage in advance. Attached Figure Description

[0048] Figure 1 This application scenario illustrates one application scenario of the data management method provided in the embodiments of this application.

[0049] Figure 2 A flowchart illustrating a data management method provided in an embodiment of this application;

[0050] Figure 3 This is a schematic diagram illustrating a download operation interface provided in an embodiment of this application;

[0051] Figure 4 This application provides a logical diagram illustrating the download of data from a cloud server.

[0052] Figure 5 A logical diagram illustrating a method of accessing a cloud server provided in an embodiment of this application;

[0053] Figure 6A logical schematic diagram of a method for obtaining detection results provided in an embodiment of this application;

[0054] Figure 7 A logical schematic diagram of a method for copying target data provided in an embodiment of this application;

[0055] Figure 8 A flowchart illustrating a method for obtaining approval results provided in an embodiment of this application;

[0056] Figure 9 A logical schematic diagram illustrating a method for obtaining the security level of target data provided in an embodiment of this application;

[0057] Figure 10 A schematic diagram illustrating a process for obtaining approval results, provided as an embodiment of this application;

[0058] Figure 11 A logical schematic diagram of a method for obtaining approval results provided in an embodiment of this application;

[0059] Figure 12 A schematic diagram illustrating another process for obtaining approval results provided in this application embodiment;

[0060] Figure 13 A logical schematic diagram of a method for verifying target data provided in an embodiment of this application;

[0061] Figure 14 A flowchart illustrating a data management method provided in an embodiment of this application;

[0062] Figure 15 A logical schematic diagram of a data management method provided in an embodiment of this application;

[0063] Figure 16 A schematic diagram of the structure of a data management device provided in an embodiment of this application;

[0064] Figure 17 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application;

[0065] Figure 18 This is a schematic diagram of the hardware structure of another electronic device in an embodiment of this application. Detailed Implementation

[0066] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0067] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.

[0068] (1) Physical Machine: A physical machine is a physical hardware device that has its own CPU, memory, hard disk, motherboard and other hardware components. A physical machine runs an operating system and usually can only run one operating system at a time, unless a specific hardware virtualization technology is used. The performance of a physical machine is directly limited by its hardware configuration. Resource allocation is fixed and each hardware component is physically present.

[0069] (2) Virtual Machine: A virtual machine is a complete computer system simulated by software. It runs on a physical machine but behaves like an independent computer. Virtual machines use the resources of the physical machine, but through virtualization technology, these resources are partitioned, allowing each virtual machine to have its own independent operating system and applications. Multiple virtual machines can run simultaneously on a single physical machine, each with its own operating system and applications. The performance of a virtual machine is limited by the resources of the physical machine, but performance can be optimized by adjusting the resource allocation of the virtual machine. Resource allocation is flexible and can be dynamically adjusted as needed.

[0070] (3) Cloud server: A cloud server is a virtualized computing resource provided through cloud computing technology, which allows users to store, manage, and process data on servers in remote data centers. Compared with traditional physical servers, cloud servers offer greater flexibility, scalability, and cost-effectiveness. They are essentially virtual machine instances created by virtualization software on physical machines.

[0071] It should be noted that the embodiments of this application involve operations such as data acquisition and downloading, and data detection. When the following embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, when relevant data needs to be obtained, relevant volunteers can be recruited and relevant agreements authorizing the volunteers to authorize data can be signed, and then the data of these volunteers can be used for implementation; or, implementation can be carried out within the authorized scope of the organization, and the following implementation methods can be used to identify internal members; or, the relevant data used in the specific implementation are all simulated data, such as simulated data generated in a virtual scene.

[0072] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0073] The technical concept of the technical solution of the embodiments of this application will be briefly described below.

[0074] With the continuous advancement of computer technology and the increasing prevalence of cloud computing, most organizations are gradually replacing physical servers with cloud servers as the primary means of handling computer-related tasks. For example, when an organization uses cloud servers, it partitions the cloud server resources and allocates these resources to various users within the organization. This allows each user to process and store data within their assigned cloud server resources.

[0075] However, current technologies do not provide adequate measures for data management and security protection on cloud servers. Specifically, when users process data on their own cloud server resources, they can freely download various data from those resources to other data storage areas outside the cloud server (such as physical machines like mobile phones and personal computers, or other cloud servers or cloud databases). This results in low data security and a high probability of data leakage stored on cloud servers.

[0076] In view of this, embodiments of this application provide a data management method to improve the security of data storage in cloud servers and reduce the probability of data leakage. This method is applied to cloud servers and specifically proposes: in response to a download operation triggered for data to be downloaded in the cloud server, the target data is copied to obtain the corresponding target data, then the target data is saved to a temporary storage area, and a locking flag is set for the target data. This locking flag indicates that the operation command is blocked. Thus, when a user starts a download operation for the target data, the user cannot perform any modification operations on the target data, but can still use the data to be downloaded in the cloud server normally. This avoids data leakage caused by inconsistencies between the data requested for download and the final downloaded data.

[0077] Then, the cloud server detects the target data based on a pre-set security dataset and obtains corresponding detection results. The security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data within the target data. Thus, based on the restricted security data indicated in the security dataset, the quantity and distribution of security data present in the target data can be detected, thereby determining the security level of the target data.

[0078] Furthermore, based on the detection result, the approval result for the download operation is obtained. When the approval result indicates that the approval is successful, the lock mark of the target data is removed, and the target data is sent to the target address indicated by the download operation. The target address is an address in the data storage area outside the cloud server.

[0079] In this way, by first locking the target data, and then detecting and approving the target data, when an approval result indicating that the approval has been obtained is obtained, the cloud server can remove the locking flag of the target data, and then send the target data to the target address indicated by the download operation, so that the detected and approved target data can be downloaded completely and securely from the cloud server to the address of the data storage area outside the cloud server.

[0080] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0081] See Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application, such as... Figure 1 As shown, this scenario may include multiple terminal devices 101 and a server 102.

[0082] Terminal device 101 can be any device capable of network communication, such as a mobile phone, laptop, tablet computer (PAD), notebook computer, desktop computer, smart TV, smart in-vehicle device, smart wearable device, e-book reader, etc. Terminal device 101 can be used to obtain download operations triggered by a user targeting target data in a cloud server, and send these download operations to the cloud server. It can also be used to provide the target address to the cloud server. Server 102 is used to respond to download operations targeting target data and to provide data management for the target data. It can be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms, but is not limited to these.

[0083] Both server 102 and terminal device 101 may include one or more processors, memory, and I / O interfaces for interaction. The memory of server 102 and terminal device 101 may also store program instructions required for execution in the data management method provided in this application embodiment. These program instructions, when executed by the processor, can be used to implement the data management method provided in this application embodiment.

[0084] In this embodiment, each terminal device 101 and the server 102 can communicate directly or indirectly through one or more networks 103. The network 103 can be a wired network or a wireless network. For example, the wireless network can be a mobile cellular network or a Wireless-Fidelity (WIFI) network. Of course, it can also be other possible networks, and this embodiment does not limit them.

[0085] It should be noted that, Figure 1 The examples shown are merely illustrative; in reality, the number of terminal devices and servers is unlimited and not specifically limited in this embodiment. The data management method proposed in this embodiment can be performed solely by server 102, or jointly by server and terminal device 101. For example, when performed solely by server, server can respond to a download operation triggered by a user object, copy the data to be downloaded to obtain the target data, save it to a temporary storage area, set a lock flag for the target data, and then detect the target data to obtain the distribution of secure data within it. Based on this detection, an approval result is obtained. When the approval result indicates successful approval, the lock flag is removed, and the target data is sent to the target address indicated by the download operation.

[0086] The data management method provided by the exemplary embodiments of this application will be described below with reference to the accompanying drawings and the application scenarios described above. It should be noted that the application scenarios described above are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.

[0087] See Figure 2 This is a flowchart illustrating a data management method provided in an embodiment of this application; wherein, the executing entity of this method may be such as Figure 1 The server shown.

[0088] like Figure 2 As shown, the specific implementation steps of this method are as follows:

[0089] Step S21: In response to a download operation triggered for the data to be downloaded in the cloud server, copy the data to be downloaded and save the obtained target data to the temporary storage area in the cloud server.

[0090] It should be noted that the cloud server can be the primary entity used by the aforementioned organization to carry out its work. Therefore, after the organization allocates and distributes the cloud server resources to its internal users, these users will perform corresponding data processing operations within the allocated cloud server resources. When a user wishes to download a portion of the processed data as downloadable data from the cloud server to a data storage area outside the cloud server, the user can trigger a download operation for the downloadable data. At this time, the cloud server can respond to the download operation triggered by the user for the target data on the cloud server by setting a lock flag for the target data.

[0091] In one possible implementation, after the user triggers a download operation for the data to be downloaded, the server, in response to the download operation and while copying the data to be downloaded, may also perform one of the following operations to display the corresponding download process to the target object.

[0092] In one approach, the server can use explicit display methods, such as... Figure 3 As shown, when a user triggers a download operation for data to be downloaded, a prompt message is displayed on the user's interface, indicating that the download operation will undergo a detection and approval process. The user is prompted to confirm whether they want to continue the data download. Once the user confirms again, the cloud server can continue executing subsequent steps for the download operation. This approach provides a transparent interface for the user, ensuring process transparency. Furthermore, by using the user's double confirmation, the necessity of downloading the data is guaranteed, avoiding excessive resource consumption that might result from downloading too much data.

[0093] In one approach, the server can employ an implicit download method. When a user triggers a download operation for the data to be downloaded, the subsequent inspection and approval processes for the data to be downloaded are directly performed. This simplifies the data download process for users and improves their user experience. Correspondingly, when a user wants to download data, they can directly trigger the corresponding download operation through the download function provided by the cloud server.

[0094] In related technologies, some cloud servers use the Secure Shell Protocol (SSH) to access the cloud server when downloading data. Through this method, users can directly download data from the cloud server to their local device by using the Send Zmodem (SZ) command, which is part of the cloud server's data transfer protocol. The SZ command is a command-line tool for transferring files in both operating systems. Users can use the SZ command, such as... Figure 4 As shown, data is downloaded directly from the cloud server to the data storage area of ​​the local device running its corresponding cloud server resources.

[0095] Therefore, in one possible implementation, to prevent users from bypassing the approval process for download operations and directly downloading data from the cloud server to their local machine, access operations to the cloud server can be restricted to remote control; in other words, such as... Figure 5 As shown, the user needs to access the cloud server remotely. Specifically, the user triggers a download operation on the cloud server for the data to be downloaded, based on the remote desktop control protocol. Thus, the cloud server resources allocated to the user run directly on the physical machine provided by the organization. Since the physical machine used by the user is no longer the corresponding local device for the cloud server's operation, the user can no longer directly download data to their local storage using the SZ command.

[0096] Specifically, before users can access cloud servers, they can first be assigned corresponding user accounts and server configurations. The configuration of these user accounts includes: the user's account group, which represents the user's target department within the organization; and the configuration information of the Virtual Network Computing (VNC) accounts corresponding to each user account within the account group. After receiving the corresponding account configuration, users can use their assigned accounts to access their corresponding cloud server resources via remote desktop control.

[0097] Furthermore, restrictions can be placed on the Internet Protocol (IP) addresses of users accessing the cloud server and on the IP addresses of the outgoing transmission exits to prevent users from transmitting data to be downloaded over the network, which could result in the data being downloaded to a data storage space outside the cloud server without being detected and approved.

[0098] When the server responds to a download operation triggered for the data to be downloaded, the server can continue to copy the data to be downloaded and save the copied target data to the temporary storage area in the cloud server.

[0099] For example, such as Figure 6 As shown, when a user triggers a download operation for target data, the target data is typically stored in the resources of the cloud server corresponding to the user. Therefore, for the cloud server, there are different resource areas for different users, with each user corresponding to one resource area. When one user triggers a download operation for the target data in its own resource area, the server can copy the target data to the temporary storage area provided by the cloud server. This temporary storage area is used to store target data that various users on the cloud server expect to download but have not yet completed the detection and approval process.

[0100] In this way, even if a download operation is triggered for the data to be downloaded, the user can still make subsequent modifications to the data to be downloaded on the cloud server, thus avoiding any adverse impact on the user's experience.

[0101] After the data to be downloaded is copied to the temporary storage area, the server can directly perform detection and processing on the target data in the temporary storage area when performing detection and approval, thereby obtaining the corresponding detection results. In this way, the data detected by the server is still the data to be downloaded that was triggered by the user object, and it will not adversely affect the user object's data processing operations, thus improving the feasibility of this solution.

[0102] Step S22: In the temporary storage area, set a lock flag for the target data; wherein, the lock flag indicates that the operation command is blocked.

[0103] It should be noted that after setting a lock flag for the target data, all operations other than the cloud server's detection and approval of the target data will be blocked. This is to prevent the target data from being submitted for approval and then modified by the user, which could lead to inconsistencies between the data detected and approved and the final downloaded data, thus causing data leakage.

[0104] In one possible implementation, after the target data is stored in the temporary storage area, the server can also perform corresponding processing operations on the target data in the temporary storage area to facilitate subsequent detection and approval processing of the target data.

[0105] It should be noted that the temporary storage area contains not only the target data corresponding to the download operation mentioned in the above steps, but also the target data corresponding to multiple download operations triggered by multiple users. Therefore, the server can also perform corresponding processing operations on the data in the temporary storage area.

[0106] Specifically, after the server copies the data to be downloaded to a temporary storage area and obtains the corresponding target data, the server can generate a corresponding file directory tree based on the target data to represent the address directory of the target data in the temporary storage area. In this way, the server can clearly identify the files and other content contained in the target data that need to be checked and approved, and then perform the corresponding check and approval operations on them in sequence.

[0107] Similarly, for each user's download operation triggered each time, the server can perform the above operations on the target data saved in the temporary storage area, thereby ensuring that effective and accurate detection and approval operations can be performed on multiple target data corresponding to multiple users.

[0108] After configuring the appropriate locking flag for the target data, the server can then proceed with the following operations:

[0109] Step S23: Based on the preset security dataset, detect the target data and obtain the corresponding detection results; wherein, the security dataset includes: at least one type of security data that is restricted from download; the detection results represent: the distribution of each type of security data in the target data.

[0110] It should be noted that the security dataset is pre-configured on the server. This collection of security data can be stored as text, tables, etc., and this application does not impose any restrictions on this. The individual security data points within the security dataset can be either automatically generated security data based on general download rules, or security data configured specifically for the cloud server.

[0111] For example, when automatically generating security data based on general download rules, the relevant general download rules can be obtained first. These general download rules can be download rules configured by cloud server developers to restrict the download of core data from the cloud server. Thus, when setting up the security dataset, several sets of restricted download security data can be generated based on these general download rules, and the target data to be downloaded can be detected based on this security data.

[0112] When a security dataset is configured separately for a cloud server, the data in the security dataset can be a number of security data configured according to the organization's own business or work needs. This security data is confidential data within the organization and is restricted from being downloaded from the cloud server. Therefore, this security data can be directly configured in the security dataset.

[0113] On the other hand, for security datasets, the security data contained therein can be dynamically adjusted based on the passage of time or business development. For example, for some security data, a corresponding time decay period can be set; that is, as time progresses, this portion of security data can be gradually removed from the security dataset to remove its download restrictions. Conversely, some security data can be set to have permanent download restrictions.

[0114] Therefore, when detecting target data, in addition to detecting the characters and words contained in the target data, the detection of the trigger time of the download operation can also be added to determine the security data contained in the security dataset.

[0115] Having clarified the contents of the security dataset, the following will introduce how to detect the target data.

[0116] Specifically, the server can use a scanning method to scan the target data and determine whether it contains content that matches the secure data in the secure dataset. For example, such as... Figure 7 As shown, the server can use a text processing tool, namely the awk command, to scan and segment the target data, find the data in the target data that matches the security dataset, and then record the hit status of each security data in the security dataset. This allows the server to obtain the distribution of each security data in the target data and thus obtain the corresponding detection results.

[0117] In this way, by detecting the target data, the server can obtain the distribution of each security data in the security dataset contained in the target data, and obtain the corresponding detection results based on the distribution.

[0118] The above describes how to obtain the detection results for the target data. After obtaining the detection results, the server can continue to perform the following operations:

[0119] Step S24: Based on the detection results, obtain the approval result for the download operation.

[0120] Based on the distribution of various security data points within the target data in the security dataset, the server can obtain the approval result corresponding to the download operation.

[0121] Regarding the specific methods for obtaining the approval results, this application provides several different methods based on the identity information of the target user that triggered the download operation.

[0122] One possible implementation is as follows:

[0123] When the server obtains the approval result for the download operation based on the detection results, the server can perform the following operations according to the meaning represented by the detection results:

[0124] When the detection result indicates that the target data does not contain any secure data, obtain the approval result indicating that the download operation has been approved.

[0125] Once the server checks the target data and ensures that no data from the distributed security dataset is present in the target data, the server can directly obtain the approval result corresponding to the download operation, i.e., the approval is passed. In this way, the server can continue to execute subsequent operations.

[0126] When the detection result indicates that there is at least one safe data in the target data, an approval result indicating that the download operation is not approved is obtained.

[0127] When the server confirms that at least one piece of secure data is distributed in the target data, it can obtain the approval result corresponding to the download operation based on the distribution, i.e., the approval is not approved. In this way, the server can continue to perform the reminder operation or other alarm operation after the approval is not approved.

[0128] The above describes a method where the server obtains approval results directly based on the detection results of the target data. In this way, the server can quickly provide approval results to the user who triggered the download operation based on the detection results, allowing the user to perform subsequent operations in a timely manner and improving the feasibility of implementing this solution.

[0129] In some other possible implementations, the server can also obtain the subsequent approval results based on the identity information of the target user that triggered the download operation.

[0130] First, it should be noted that the server needs to obtain the identity information of the target user. This identity information can be obtained from the cloud server resource pool where the target data is located, or it can be obtained from the account information that triggered the download operation. This application does not impose any restrictions on this.

[0131] Therefore, after obtaining the identity information, the server can obtain the approval result in the following ways:

[0132] In one possible implementation, see Figure 8 This is a flowchart illustrating a method for obtaining approval results provided in an embodiment of this application. Figure 8 As shown, the specific implementation steps of this method are as follows:

[0133] Step S301: Based on the identity information of the target user, obtain the data download permission corresponding to the target user.

[0134] When allocating cloud server resources to users, you can also configure their respective data download permissions. These data download permissions represent the security level of the data that the user can download.

[0135] Therefore, in addition to obtaining download permissions from the target user, the server also needs to perform the following operations:

[0136] Step S302: Based on the detection results, obtain the security level corresponding to the target data; wherein, the security level is positively correlated with the number of safe data hits by the target data as represented by the detection results.

[0137] The detection results characterize the distribution of each security data in the target data. Therefore, the server can obtain the number of security data hits in the target data from this distribution and determine the security level of the target data based on this. The more security data hits in the target data, the higher the security level of the target data.

[0138] Furthermore, when setting up a security dataset, different restriction levels can be configured for different security data. This way, when the server determines the security level of target data, in addition to the number of security data points that match within the target data, the security level of the target data can also be determined based on the restriction levels of the matched security data. For example, such as... Figure 9As shown, assuming the target data contains three security data points: security data 1, security data 2, and security data 3, with security data 1 having a restriction level of 3, security data 2 having a restriction level of 2, and security data 3 having a restriction level of 4, the security level of the target data is determined as follows: First, the distribution of security data within the target data is obtained. Specifically, if the target data contains three security data points with a sum of restriction levels of 9, then, based on preset weights, the security level of the target data is obtained by weighted summing of the number of security data points and the sum of their restriction levels. The specific values ​​of the weights corresponding to the number of security data points and the sum of their restriction levels can be set based on the actual application requirements; this application does not impose any restrictions on this.

[0139] Thus, once the server obtains the data download permissions corresponding to the user and the security level of the target data, it can determine the approval result for the download operation based on these two pieces of information:

[0140] Step S303: When the data download permission matches the security level of the target data, determine the approval result for the download operation as: Approved; otherwise, determine the approval result for the download operation as: Approved.

[0141] Data download permissions represent the security level of the data that the target user can download. Once the server obtains the target user's data download permissions, it can determine the content of the approval result based on the match between the data download permissions and the security level of the target data. For example, if the data download permissions represent a security level of 16 for the data that the target user can download, and the security level of the target data is 14, then the security level of the target data falls within the range that the target user can download. Therefore, the approval result for the download operation triggered for the target user is the approval result indicating that the download has been approved.

[0142] In this way, the server determines the approval result for the download operation based on the security level of the target data and the data download permissions of the target user. The approval process for the download operation can be completed quickly and automatically, which improves the efficiency of obtaining the approval result, reduces the waiting time for the target user to obtain the approval result, and improves the user experience.

[0143] In one possible implementation, the server can obtain the approval result for the download operation of the target data based on its own verification result and the verification result of the approval object.

[0144] Specifically, participate Figure 10 This is a schematic diagram of a process for obtaining approval results provided in an embodiment of this application, such as... Figure 10 As shown, the specific implementation steps of this method are as follows:

[0145] Step S401: Perform a first verification process on the download operation based on the target object's identity information, target data, and detection results to obtain the corresponding first verification result.

[0146] In this step, the server can perform the above... Figure 8 The method shown determines the corresponding first verification result based on the data download permissions corresponding to the identity information and the security level of the target data represented by the detection results corresponding to the target data, so as to represent whether the data download permissions of the target user match the security level of the target data.

[0147] Alternatively, the first verification process can be that the server directly determines, based on the correspondence between the target user's identity information and the security data, whether the security data matched in the target data that triggered the download operation by the target user is downloadable data corresponding to its identity information; if so, the first verification result indicates that the verification passed; if at least one of the matched security data is not downloadable data corresponding to its identity information, the first verification result indicates that the verification failed.

[0148] Step S402: Send the target object's identity information and target data to the approval object, so that the approval object can perform a second verification process on the download operation based on the identity information and target data, and return the obtained second verification result.

[0149] In this step, the server sends the identity information and target data to the approval object, who then performs a second verification process on the download operation and obtains the corresponding second verification result.

[0150] When the server sends identity information and target data to the approval object, it can generate a corresponding approval form based on the identity information and target data, and send it to the approval object in the form of an approval form, so that the approval object can perform approval operations on each received approval form.

[0151] In this step, a third-party approval process is used, where the approval recipient performs a second verification of the download operation. This multi-faceted verification process improves the accuracy and reliability of the approval results obtained for the download operation.

[0152] Step S403: Receive the second verification result from the approval object regarding the download operation.

[0153] Step S404: When both the first verification result and the second verification result indicate that the verification is passed, the approval result for the download operation is determined to be: Approval passed.

[0154] If the first verification result and / or the second verification result indicate that the verification failed, then the approval result for the download operation is determined to be: approval failed.

[0155] Thus, in this method, such as Figure 11 As shown, for a download operation triggered by the target user, a first verification process is required, executed by the server, and a second verification process is required, executed by the approving user. After these two verification processes, the corresponding first verification result and second verification result are obtained, and then the corresponding approval result is obtained. In this way, by verifying the download operation through multiple parties, the approval result of the target user's download operation for the target data is obtained, improving the accuracy and reliability of the approval result.

[0156] In one possible implementation, the server can send the approval process to the approval server so that the approval server can complete the corresponding approval operation.

[0157] Specifically, after obtaining the identity information of the target user, the server can send the target user's identity information, target data, and detection results to the approval server, so that the approval server can approve the download operation based on the identity information, target data, and detection results, and provide feedback on the approval result; then, the server obtains the approval result from the approval server for the download operation.

[0158] For example, the following will use the interaction process between the cloud server and the approval server as an example to illustrate the solution provided in the embodiments of this application.

[0159] See Figure 12 This is an interactive flowchart for obtaining approval results provided in an embodiment of this application, such as... Figure 12 As shown, this method is completed through interaction between the cloud server and the approval server, and its specific implementation steps are as follows:

[0160] Step S501: The cloud server sends the identity information of the target user, the target data, and the detection results to the approval server; correspondingly, the approval server receives the identity information, target data, and detection results from the cloud server.

[0161] Step S502: The approval server approves the download operation based on the identity information, target data, and detection results.

[0162] The approval process conducted by the approval server based on identity information, target data, and detection results can be referenced above. Figure 8 and Figure 10 The procedure is as shown, and will not be elaborated further here.

[0163] Step S503: The approval server sends the obtained approval result to the cloud server; correspondingly, the cloud server receives the approval result from the approval server for the download operation.

[0164] The above describes the approval process for download operations triggered by the approval server for the target user. It should be noted that when the resources allocated to the cloud server are assigned to at least two users, there may be multiple approval results sent by the approval server to the cloud server within a certain time range.

[0165] Therefore, in one possible implementation, when the approval server sends the approval result to the cloud server, it places the approval result in a message queue. The cloud server then processes each approval result one by one according to its own resource availability. This avoids the possibility of the cloud server crashing due to concurrent processing of a large number of approval results.

[0166] In this approach, the approval process is deployed on the approval server, which avoids the approval process from occupying cloud server resources, ensures the resource guarantee for the main business operation of the cloud server, and improves the reliability of the implementation of this solution.

[0167] The above describes several methods for obtaining review results. After the server obtains the corresponding approval result, the following operations can be performed:

[0168] Step S25: When the approval result indicates that the approval is successful, remove the lock icon and send the target data to the target address indicated by the download operation; wherein, the target address is: the address in the data storage area outside the cloud server.

[0169] Once the server confirms that the approval result indicates successful download, it can remove the lock icon from the target data and send the target data to the target address specified in the download operation. In this way, the server completes the operation of downloading the target data from the cloud server to the target address.

[0170] The target address, located outside the cloud server, can be a data storage address on a physical machine, or an address on another cloud server or database. For example, it could be an address within a Cloud Object Storage (COS) system provided by the target user. A cloud object storage system is a cloud-based service that allows users to store and retrieve large amounts of unstructured data over the internet. This data is typically stored as objects, each including file data, metadata, and a unique identifier associated with it. Therefore, after the server sends the target data to the COS system provided by the target user, the target user can download the corresponding target data from that COS system.

[0171] This solution proposes corresponding detection and approval procedures for the process of downloading data from cloud servers.

[0172] When a download operation is triggered in response to data to be downloaded on the cloud server, the data to be downloaded is copied to obtain the target data and saved to a temporary storage area. Then, a lock flag is set on the target data to block operation commands on the target data. This prevents inconsistencies between the data detected and approved and the final downloaded data, which could lead to data leakage. At the same time, since the target data is in the temporary storage area, the data to be downloaded on the cloud server can still be used normally without interfering with the user's experience on the cloud server, thus improving the reliability of this solution.

[0173] When detecting target data, a preset security dataset is used as the detection basis to detect the target data and obtain the distribution of each security data in the target data. Based on the ease of modifying the security dataset, the detection processing of the target data can be flexibly carried out, which improves the timeliness and flexibility of security detection.

[0174] Based on the detection results, the approval result of the target data is determined. When the approval result indicates that the data has passed, the lock flag is removed, and the target data is sent to a target address outside the cloud server specified in the download operation instruction. This ensures that the download operation of the target data is completed after approval, avoiding arbitrary downloads of the target data and improving the security of data storage in the cloud server. Through fixed detection and approval operations, the standardization of data management in the cloud server is improved, and data downloads to the cloud server can be recorded, thereby preventing the possibility of data leakage in advance.

[0175] In one possible implementation, to further ensure that the data processed in the testing and approval process is consistent with the finally downloaded data, such as... Figure 13 As shown, after obtaining the detection results but before obtaining the approval results, the server can also perform the following operations on the target data:

[0176] The target data is processed to obtain a first summary value; wherein, the target data uniquely corresponds to the first summary value.

[0177] In this process, after obtaining the detection result for the target data, the server can then obtain the first digest value corresponding to that target data. When processing the digest for the target data, the server can use different methods. For example, it can use Message Digest Algorithm 5 (MD5), or algorithms from the Secure Hash Algorithm (SHA) family such as SHA-1, SHA-2 (including SHA-256 and SHA-512), and SHA-3, or the Cyclic Redundancy Check (CRC) algorithm to obtain the digest of the target data. The resulting value is then used as the unique first digest value corresponding to the target data.

[0178] Once the server determines that the approval result indicates approval, it can perform the same digest retrieval process on the target data as described above to obtain the corresponding second digest value. This second digest value is then compared with the first digest value to verify whether the target data was tampered with before the approval result was obtained. Only when the second digest value matches the first digest value can the server proceed with the subsequent steps of removing the lock and sending the target data to the target address indicated in the download operation.

[0179] In this way, after detecting the target data, the corresponding first digest value is obtained. Then, after the approval is confirmed, the corresponding second digest value is obtained. Only when the second digest value and the first digest value are the same, that is, the target data before and after approval are the same, is the target data sent to the target address. This ensures that only the approved data can be downloaded, further guaranteeing the security of data downloaded from the cloud server.

[0180] In one possible approach, the server can also compress and encrypt the target data after detection, thereby reducing the storage space occupied by the target data on the server and further preventing the target data from being tampered with.

[0181] Specifically, after the server completes the detection and processing of the target data, the next step is to obtain the approval result. At this time, the target data in the temporary storage area does not require further processing. This is because, to reduce the target data's consumption of cloud server storage resources, the server can compress the target data to obtain compressed target data, thus reducing the utilization of cloud server storage resources. Correspondingly, once the server confirms that the download operation has been approved, the server can decompress the compressed target data again and then send it to the target address.

[0182] Furthermore, after the server compresses the target data, to improve the security of the target data stored on the cloud server, the server can also encrypt the compressed target data. For example, the server can use an encryption algorithm (GNU Privacy Guard, GnuPG) to encrypt the compressed target data, or it can use an encryption toolkit (Open Source SSL, OpenSSL) to encrypt the target data.

[0183] After obtaining the encrypted data corresponding to the target data, the server can perform digest retrieval processing on the encrypted data to obtain the corresponding first digest value.

[0184] Once the server receives the approval result indicating that the approval has been granted, it can first perform digest retrieval processing on the encrypted target data again to obtain the corresponding second digest value. When it is determined that the first digest value is the same as the second digest value, the server determines that the target data has not been modified. Therefore, it can use the corresponding GnuPG or OpenSSL decryption method to decrypt the encrypted target data to obtain the corresponding compressed target data. After decompressing it, it is sent to the target address.

[0185] In this way, the server can further reduce the consumption of cloud server storage resources and improve the security of target data through compression and encryption operations.

[0186] The above describes various possible implementations of the data management method provided in this application. To clarify the data management method provided in this application, the method will be described in its entirety below.

[0187] See Figure 14 This is a flowchart illustrating a data management method provided in an embodiment of this application, as shown below. Figure 14 as well as Figure 15 As shown, this method is jointly implemented by the target user, the cloud server, the approval server, and the approval recipient. The specific implementation steps of this method are as follows:

[0188] Step S61: The target user triggers a download operation on the data to be downloaded in the cloud server.

[0189] For the target user, when they access the cloud server resources allocated to them via remote desktop control through their own physical device, they can trigger the corresponding download operation based on the data to be downloaded displayed on their physical device by the cloud server.

[0190] Step S62: In response to the download operation triggered by the target user, the cloud server copies the data to be downloaded to the temporary storage area of ​​the cloud server.

[0191] Step S63: In the temporary storage area, the cloud server sets a lock flag for the target data copied from the data to be downloaded. This lock flag indicates that the operation command is blocked.

[0192] In this way, when the cloud server responds to the download operation triggered by the target user, it obtains the target data by copying the data to be downloaded, saves it to the temporary storage area, and sets a lock flag for the target data. This ensures that the target user can still perform other processing operations on the data to be downloaded in the cloud server, while also ensuring that the target data submitted for download operation cannot be modified arbitrarily, thus ensuring the security and reliability of the approval data.

[0193] Step S64: The cloud server uses a security dataset to detect the copied target data and obtains the corresponding detection results.

[0194] After the cloud server completes the setting of the lock identifier, it can detect the target data, obtain the distribution of security data in the target data, and thus determine the security level of the target data.

[0195] Step S65: The cloud server performs digest acquisition processing on the detected target data to obtain the corresponding first digest value.

[0196] Step S66: The cloud server sends the target user's identity information, target data, and detection results to the approval server; correspondingly, the approval server receives the target user's identity information, target data, and detection results from the cloud server.

[0197] In this approach, the approval process for download operations is delegated to the approval server, which avoids excessive consumption of cloud server resources, reduces the impact of the approval process on cloud server operation, and improves the reliability of the solution.

[0198] Step S67: The approval server performs the first verification process on the download operation based on the target object's identity information, target data, and detection results, and obtains the corresponding first verification result.

[0199] Step S68: The approval server sends the identity information and target data to the approval object; correspondingly, the approval object receives the identity information and target data of the target object from the approval server.

[0200] In this way, after the approval server sends this information to the approval recipient, the recipient will approve the download operation accordingly. The approval server can use the identity information and target data as an approval form when sending them.

[0201] Step S69: The approval object performs a second verification process on the download operation based on the identity information and target data.

[0202] Step S610: The approval object sends the obtained second verification result to the approval server; correspondingly, the approval server receives the second verification result from the approval object.

[0203] Step S611: The approval server obtains the corresponding approval result based on the first verification result and the second verification result.

[0204] Step S612: The approval server sends the approval result to the cloud server; correspondingly, the cloud server receives the approval result from the approval server.

[0205] Step S613: When the approval result indicates that the approval is approved, the cloud server performs summary acquisition processing on the target data to obtain the corresponding second summary value.

[0206] Step S614: When the second digest value is the same as the first digest value, the cloud server removes the lock flag of the target data.

[0207] Step S615: Send the target data to a target address outside the cloud server specified in the download operation instruction.

[0208] Thus, from the moment the target user triggers a download operation for the data to be downloaded, through the above detection and approval process, once the server determines that the approval result is approved, the target data obtained by copying the data to be downloaded can be sent to the target address for the target user.

[0209] Based on the same inventive concept, embodiments of this application provide a data management apparatus capable of implementing the functions corresponding to the aforementioned image generation method. Please refer to... Figure 16 The device 1600 includes a response module 1601, a detection module 1602, an approval module 1603, and a processing module 1604, wherein:

[0210] The response module 1601 is used to respond to a download operation triggered for the data to be downloaded in the cloud server, to copy the data to be downloaded, and to save the obtained target data to a temporary storage area in the cloud server; in the temporary storage area, a lock flag is set for the target data; wherein, the lock flag indicates that the operation command is blocked;

[0211] The detection module 1602 is used to detect target data based on a preset security dataset and obtain corresponding detection results; wherein, the security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data in the target data;

[0212] Approval module 1603 is used to obtain the approval result for the download operation based on the detection result;

[0213] The processing module 1604 is used to remove the lock flag and send the target data to the target address indicated by the download operation when the approval result indicates that the approval has been passed; wherein, the target address is: the address in the data storage area outside the cloud server.

[0214] Optionally, when the approval module 1603 obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0215] When the detection result indicates that the target data does not contain any secure data, obtain the approval result indicating that the download operation has been approved.

[0216] When the detection result indicates that there is at least one safe data in the target data, obtain the approval result indicating that the download operation is not approved.

[0217] Optionally, if the download operation is triggered by the target user, then when the approval module 1603 obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0218] Based on the identity information of the target user, obtain the data download permissions corresponding to the target user.

[0219] Based on the detection results, the security level corresponding to the target data is obtained; whereby the security level is positively correlated with the number of safe data points matched by the target data as represented by the detection results.

[0220] When the data download permission matches the security level of the target data, the approval result for the download operation is determined as: Approval passed.

[0221] Optionally, if the download operation is triggered by the target user, then when the approval module 1603 obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0222] The download operation is first verified based on the target object's identity information, target data, and detection results to obtain the corresponding first verification result.

[0223] The target object's identity information and target data are sent to the approval object, so that the approval object can perform a second verification process on the download operation based on the identity information and target data, and return the obtained second verification result;

[0224] Receive the second verification result from the approval recipient regarding the download operation;

[0225] When both the first and second verification results indicate that the verification is successful, the approval result for the download operation is determined to be: approval successful.

[0226] Optionally, if the download operation is triggered by the target user, then when the approval module 1603 obtains the approval result for the download operation based on the detection result, it is specifically used for:

[0227] The target user's identity information, target data, and detection results are sent to the approval server, so that the approval server can approve the download operation based on the identity information, target data, and detection results, and then return the approval result.

[0228] Retrieve the approval result from the approval server for the download operation.

[0229] Optionally, after obtaining the test results and before obtaining the approval results, the test module 1602 is also used for:

[0230] The target data is processed to obtain a first summary value; each target data uniquely corresponds to a first summary value.

[0231] When processing module 1604 removes the lock identifier and sends the target data to the target address indicated by the download operation, it is specifically used for:

[0232] Perform a digest extraction process on the target data to obtain a second digest value;

[0233] When the second digest value is the same as the first digest value, remove the lock flag and send the target data to the target address indicated by the download operation.

[0234] Optionally, the download operation is remotely triggered by the target user on a cloud server based on a remote desktop control protocol, targeting the data to be downloaded.

[0235] Based on the same inventive concept, embodiments of this application also provide an electronic device. In one possible implementation, the electronic device may be a server, such as... Figure 1 The server 102 is shown. In this embodiment, the electronic device 1700 has the following structure. Figure 17 As shown, it may include at least a memory 1701, a communication module 1703, and at least one processor 1702.

[0236] The memory 1701 is used to store computer programs executed by the processor 1702. The memory 1701 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and programs required to run instant messaging functions, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.

[0237] Memory 1701 may be volatile memory, such as random-access memory (RAM); memory 1701 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 1701 may be any other medium capable of carrying or storing a desired computer program having the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 1701 may be a combination of the above-described memories.

[0238] Processor 1702 may include one or more central processing units (CPUs) or digital processing units, etc. Processor 1702 is used to implement the above-described image generation method when it calls a computer program stored in memory 1701.

[0239] The communication module 1703 is used to communicate with terminal devices and other servers.

[0240] This application embodiment does not limit the specific connection medium between the memory 1701, communication module 1703, and processor 1702. This application embodiment... Figure 17 The memory 1701 and the processor 1702 are connected via a bus 1704, and the bus 1704 is in Figure 17 The diagram uses thick lines to describe the connections between other components; these are for illustrative purposes only and should not be considered limiting. The 1704 bus can be divided into address bus, data bus, control bus, etc. For ease of description, Figure 17 It is described using only a thick line, but does not indicate that there is only one bus or one type of bus.

[0241] The memory 1701 stores a computer storage medium containing computer-executable instructions for implementing the image generation method of this application embodiment. The processor 1702 is used to execute the image generation method described above.

[0242] In another embodiment, the electronic device may also be other electronic devices, such as... Figure 1 The terminal device 101 shown. In this embodiment, the electronic device can be structured as follows. Figure 18 As shown, it includes components such as: communication component 1810, memory 1820, display unit 1830, camera 1840, sensor 1850, audio circuit 1860, Bluetooth module 1870, processor 1880, etc.

[0243] The communication component 1810 is used to communicate with the server. In some embodiments, it may include a Wireless Fidelity (WiFi) module, which is a short-range wireless transmission technology, and the electronic device can send and receive information through the WiFi module.

[0244] The memory 1820 can be used to store software programs and data. The processor 1880 executes various functions of the terminal device 101 and performs data processing by running the software programs or data stored in the memory 1820. The memory 1820 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. The memory 1820 stores an operating system that enables the terminal device 101 to run. In this application, the memory 1820 may store the operating system and various application programs, and may also store a computer program that executes the image generation method of the embodiments of this application.

[0245] The display unit 1830 can also be used to display information input by the object or information provided to the object, as well as a graphical user interface (GUI) for various menus of the terminal device 101. Specifically, the display unit 1830 may include a display screen 1832 disposed on the front of the terminal device 101. The display screen 1832 may be configured as a liquid crystal display, a light-emitting diode, or the like. The display unit 1830 can be used to display the defect detection interface, model training interface, etc., as described in the embodiments of this application.

[0246] The display unit 1830 can also be used to receive input digital or character information and generate signal inputs related to object settings and function control of the terminal device 101. Specifically, the display unit 1830 may include a touch screen 1831 disposed on the front of the terminal device 101, which can collect touch operations on or near the object, such as clicking a button, dragging a scroll bar, etc.

[0247] The touchscreen 1831 can be placed on top of the display screen 1832, or the touchscreen 1831 and the display screen 1832 can be integrated to realize the input and output functions of the physical terminal device 101. After integration, it can be referred to as a touch display screen. In this application, the display unit 1830 can display the application program and the corresponding operation steps.

[0248] Camera 1840 can be used to capture still images, and objects can publish images captured by camera 1840 through an application. There can be one or multiple cameras 1840. An optical image of an object is generated through a lens and projected onto a photosensitive element. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then transmitted to processor 1880 to be converted into a digital image signal.

[0249] The physical terminal device may also include at least one sensor 1850, such as an accelerometer 1851, a proximity sensor 1852, a fingerprint sensor 1853, and a temperature sensor 1854. The terminal device may also be equipped with other sensors such as a gyroscope, barometer, hygrometer, thermometer, infrared sensor, light sensor, and motion sensor.

[0250] Audio circuitry 1860, speaker 1861, and microphone 1862 provide an audio interface between the physical terminal device 101 and the physical terminal device 101. Audio circuitry 1860 converts received audio data into electrical signals, transmits them to speaker 1861, and speaker 1861 converts them into sound signals for output. Physical terminal device 101 may also be equipped with volume buttons for adjusting the volume of the sound signal. On the other hand, microphone 1862 converts collected sound signals into electrical signals, which are then received by audio circuitry 1860, converted into audio data, and output to communication component 1810 for transmission to, for example, another physical terminal device 101, or to memory 1820 for further processing.

[0251] The Bluetooth module 1870 is used to interact with other Bluetooth devices that also have a Bluetooth module via the Bluetooth protocol. For example, a physical terminal device can establish a Bluetooth connection with a wearable electronic device (such as a smartwatch) that also has a Bluetooth module through the Bluetooth module 1870, thereby exchanging data.

[0252] The processor 1880 is the control center of the physical terminal device, connecting various parts of the terminal through various interfaces and lines. It executes software programs stored in the memory 1820 and calls data stored in the memory 1820 to perform various functions and process data of the terminal device. In some embodiments, the processor 1880 may include one or more processing units; the processor 1880 may also integrate an application processor and a baseband processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the baseband processor mainly handles wireless communication. It is understood that the baseband processor may not be integrated into the processor 1880. In this application, the processor 1880 can run the operating system, applications, user interface display and touch response, and the image generation method of this embodiment. Furthermore, the processor 1880 is coupled to the display unit 1830.

[0253] In some possible implementations, various aspects of the image generation method provided in this application can also be implemented in the form of a program product, which includes a computer program that, when the program product is run on an electronic device, causes the electronic device to perform the steps in the image generation method according to the various exemplary embodiments of this application described above.

[0254] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0255] The program product of the embodiments of this application may employ a portable compact disc read-only memory (CD-ROM) and include a computer program, and may run on an electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with a command execution system, apparatus, or device.

[0256] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a readable computer program. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with a command execution system, apparatus, or device.

[0257] Computer programs contained on readable media may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0258] Computer programs for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The computer program can execute entirely on the user's electronic device, partially on the user's electronic device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).

[0259] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0260] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0261] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0262] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0263] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0264] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0265] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A data management method, characterized in that, Applied to cloud servers, the method includes: In response to a download operation triggered for data to be downloaded in a cloud server, the data to be downloaded is copied, and the resulting target data is saved to a temporary storage area in the cloud server. In the temporary storage area, a locking flag is set for the target data; wherein, the locking flag indicates that the operation command is blocked; The target data is detected based on a preset security dataset to obtain corresponding detection results; wherein, the security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data in the target data; Based on the detection results, obtain the approval result for the download operation; When the approval result indicates that the approval is successful, the lock identifier is removed, and the target data is sent to the target address indicated by the download operation; wherein, the target address is: an address in the data storage area outside the cloud server.

2. The method as described in claim 1, characterized in that, The step of obtaining the approval result for the download operation based on the detection result includes: When the detection result indicates that the target data does not contain any of the security data, an approval result indicating that the download operation has been approved is obtained; When the detection result indicates that at least one of the security data is distributed in the target data, an approval result indicating that the download operation is not approved is obtained.

3. The method as described in claim 1, characterized in that, If the download operation is triggered by the target user, then obtaining the approval result for the download operation based on the detection result includes: Based on the identity information of the target user, obtain the data download permission corresponding to the target user; Based on the detection results, the security level corresponding to the target data is obtained; wherein, the security level is positively correlated with the number of times the target data matches the security data as represented by the detection results; When the data download permission matches the security level of the target data, the approval result for the download operation is determined as: Approval passed.

4. The method as described in claim 1, characterized in that, If the download operation is triggered by the target user, then obtaining the approval result for the download operation based on the detection result includes: Based on the identity information of the target object, the target data, and the detection result, the download operation is subjected to a first verification process to obtain a corresponding first verification result; The identity information of the target object and the target data are sent to the approval object, so that the approval object performs a second verification process on the download operation based on the identity information and the target data, and returns the obtained second verification result. Receive a second verification result from the approval recipient regarding the download operation; When both the first verification result and the second verification result indicate that the verification is successful, the approval result for the download operation is determined to be: approval successful.

5. The method as described in claim 1, characterized in that, If the download operation is triggered by the target user, then obtaining the approval result for the download operation based on the detection result includes: The identity information of the target user, the target data, and the detection results are sent to the approval server, so that the approval server can approve the download operation based on the identity information, the target data, and the detection results, and return the obtained approval result. Obtain the approval result from the approval server for the download operation.

6. The method according to any one of claims 1-5, characterized in that, After obtaining the test result and before obtaining the approval result, the method further includes: The target data is subjected to a digest acquisition process to obtain a first digest value; the target data uniquely corresponds to the first digest value; The step of sending the target data to the target address indicated by the download operation includes: The target data is subjected to the digest acquisition process to obtain a second digest value; When the second digest value is the same as the first digest value, the lock identifier is removed, and the target data is sent to the target address indicated by the download operation.

7. The method according to any one of claims 1-5, characterized in that, The download operation is remotely triggered by the target user on the cloud server based on the remote desktop control protocol, targeting the data to be downloaded.

8. A data management method, characterized in that, Applied to cloud servers, the method includes: A response module is used to respond to a download operation triggered for data to be downloaded in a cloud server, copy the data to be downloaded, and save the obtained target data to a temporary storage area in the cloud server; in the temporary storage area, a lock flag is set for the target data; wherein, the lock flag indicates: blocking operation commands; The detection module is used to detect the target data based on a preset security dataset and obtain corresponding detection results; wherein, the security dataset includes at least one type of security data that is restricted from download, and the detection results characterize the distribution of each type of security data in the target data; An approval module is used to obtain an approval result for the download operation based on the detection results. The processing module is used to remove the lock identifier and send the target data to the target address indicated by the download operation when the approval result indicates that the approval has been passed; wherein, the target address is an address in the data storage area outside the cloud server.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method as described in any one of claims 1-7.

10. A computer device, characterized in that, include: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the method as described in any one of claims 1-7 according to the obtained program instructions.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing a computer to perform the method as described in any one of claims 1-7.