File management and control method and system based on data leakage prevention service, cloud and storage medium
By generating encrypted credentials and verifying permissions, the file management method solves the problem of low file management efficiency in the DLP mechanism, achieves high efficiency and data security in the whole process control, locates abnormal accounts, and improves the visual management of file operations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 深圳开鸿数字产业发展有限公司
- Filing Date
- 2025-12-10
- Publication Date
- 2026-05-12
AI Technical Summary
Existing document management methods based on DLP mechanisms suffer from problems such as business process obstruction and high false alarm rates, resulting in low efficiency in the overall document management process.
By obtaining the configuration information of the target file, encryption credentials and file encryption keys are generated. User access requests are received for permission verification. Bluetooth scanning information documents are scanned in real time to locate abnormal accounts and optimize the file access process, thus achieving full-process file control.
It improves the efficiency of end-to-end file management, enhances data security and visual management, locates file operation environment information, and reduces misjudgments and abnormal access.
Smart Images

Figure CN122020698A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data monitoring technology, and in particular to a file management method, system, cloud platform, and computer-readable storage medium based on data leakage prevention services. Background Technology
[0002] Data Loss Prevention (DLP) is a data loss prevention solution provided by the system. Data owners can configure permissions for confidential files based on account authentication, allowing them to have read-only, edit, and owner permissions. Confidential files are then stored in encrypted form. On devices that support the DLP mechanism, authentication and authorization can be carried out through end-to-end cloud coordination to obtain the ability to access and modify the data.
[0003] However, existing file management methods based on DLP mechanisms can lead to business interruptions. For example, strict monitoring may misjudge normal operations (such as employees sending work files via private email), causing business processes to be blocked. Furthermore, some enterprises are forced to only enable monitoring mode due to high false alarm rates, which weakens the protection effect.
[0004] Therefore, existing technologies still need to be improved and developed. Summary of the Invention
[0005] The main objective of this invention is to provide a file management method, system, cloud platform, and computer-readable storage medium based on data leakage prevention services. This invention aims to address the problem that in the prior art, monitoring the file flow process may be hindered by business processes, resulting in low efficiency in the full-process management of files.
[0006] To achieve the above objectives, the present invention provides a file management method based on data loss prevention services, the file management method based on data loss prevention services comprising the following steps: Obtain the configuration information of the target file, obtain multiple file encryption keys based on the configuration information, generate corresponding encryption credentials based on the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file; Receive an access request from a querying user, verify the querying user's permissions based on the access request, and if the verification is successful, decrypt the anti-leakage service file based on the querying user's account information and generate an access log file; The constructed Bluetooth scanning information document is scanned in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. Based on the Bluetooth scanning information document, multiple abnormal accounts are identified, the access process of each abnormal account to the target file is located, and the anti-leakage service file is optimized.
[0007] Optionally, the file management method based on data leakage prevention service, wherein obtaining the configuration information of the target file, obtaining multiple file encryption keys according to the configuration information, generating corresponding encryption credentials according to the multiple public key encryption keys, and packaging all the encryption credentials and all the file encryption keys to obtain the leakage prevention service file, specifically includes: Obtain the configuration information of the target file, determine the access type of the target file based on the configuration information, and add multiple file encryption keys to the configuration information based on the access type; Based on the number of file encryption keys, generate a corresponding number of public key encryption keys, and generate a corresponding encryption credential based on each of the public key encryption keys; For each access type, each encryption credential and each file encryption key are packaged to obtain a corresponding anti-leakage service sub-file. Each anti-leakage service sub-file is then integrated to obtain the anti-leakage service file for the target file.
[0008] Optionally, in the file management method based on data leakage prevention service, the access request includes one or more of the following: a file creation request, a file editing request, a file query request, or a file copy request; The process of receiving an access request from a querying user, verifying the user's permissions based on the access request, and if the verification is successful, decrypting the anti-leakage service file based on the user's account information and generating an access log file specifically includes: Receive the file creation request, file editing request, file query request, or file copy request from the querying user, obtain the permission level of the querying user, and perform permission level verification; If the verification result of the level verification is passed, the account information of the querying user is received, and the encrypted credentials of multiple anti-leakage service sub-files are decrypted according to multiple decryption keys in the account information. If the encryption credentials of a certain anti-leakage service sub-file are successfully decrypted, then the access record information of the current access is added to the corresponding anti-leakage service sub-file. Generate an access log file based on all the updated leak prevention service subfiles.
[0009] Optionally, in the file management method based on data leakage prevention service, the leakage prevention service sub-file includes: header information, public key certificate, authorization information, file content, and historical access records; The public key certificate includes: access type and randomly generated key data.
[0010] Optionally, in the file management method based on data loss prevention service, the step of decrypting the encryption credentials of multiple loss prevention service sub-files according to multiple decryption keys in the account information specifically includes: Read the header information of multiple loss prevention service sub-files, verify each header information, and obtain the data segment information of each loss prevention service sub-file; By obtaining the access type of each of the anti-leakage service sub-files, the permission level corresponding to each of the anti-leakage service sub-files is obtained, and each permission level and each corresponding data segment information are added to the encrypted file entity; For each encrypted file entity, a corresponding file link is recreated in the user space file system, and the file link is decrypted using each of the decryption keys.
[0011] Optionally, in the file management method based on data leakage prevention service, the access record information includes: access request, operation time, current file level, querying user, account information, current device identifier, Bluetooth scanning information of the current environment, Wi-Fi information of the current environment, and current coordinates; The step of real-time scanning of the constructed Bluetooth scanning information document, and if the access process of the querying user is not recorded in the Bluetooth scanning information document, then adding the access record file to the Bluetooth scanning information document, specifically includes: The existing Bluetooth scanning information document is scanned in real time to determine whether the current access record is saved in the Bluetooth scanning information document. If the Bluetooth scanning information for the current environment is not found, it is determined that the Bluetooth scanning information document does not save the current access record, and the access record file of the current access record is added to the Bluetooth scanning information document.
[0012] Optionally, the file management method based on data leakage prevention service, wherein identifying multiple abnormal accounts based on the Bluetooth scanning information document, locating the access process of each abnormal account to the target file, and optimizing the leakage prevention service file specifically includes: All access processes are obtained based on the Bluetooth scanning information document. If the anti-leakage service sub-file corresponding to a certain access process does not match the permission level of the querying user, the querying user is determined to be an abnormal account. Extract the abnormal access process corresponding to the abnormal leakage prevention service sub-file, and locate the operating environment information of the abnormal access process based on all the abnormal leakage prevention service sub-files; The encryption credentials of each of the abnormal anti-leakage service sub-files are updated to obtain the corresponding optimized anti-leakage service sub-files, which are then integrated into the current anti-leakage service file.
[0013] Furthermore, to achieve the above objectives, the present invention also provides a file management system based on data leakage prevention services, wherein the file management system based on data leakage prevention services includes: The file building module is used to obtain the configuration information of the target file, obtain multiple file encryption keys according to the configuration information, generate corresponding encryption credentials according to the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file. The access log module is used to receive access requests from querying users, verify the permissions of the querying users based on the access requests, and if the verification is successful, decrypt the anti-leakage service file based on the querying user's account information and generate an access log file. The Bluetooth scanning module is used to scan the constructed Bluetooth scanning information document in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. The optimization module is used to identify multiple abnormal accounts based on the Bluetooth scanning information document, locate the access process of each abnormal account to the target file, and optimize the anti-leakage service file.
[0014] Furthermore, to achieve the above objectives, the present invention also provides a cloud platform, wherein the cloud platform includes: a memory, a processor, and a file management program based on a data leakage prevention service stored on the memory and executable on the processor, wherein when the file management program based on the data leakage prevention service is executed by the processor, it implements the steps of the file management method based on the data leakage prevention service as described above.
[0015] In addition, to achieve the above objectives, the present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a file management program based on a data leakage prevention service, and the file management program based on the data leakage prevention service, when executed by a processor, implements the steps of the file management method based on the data leakage prevention service as described above.
[0016] In this invention, configuration information of a target file is obtained; multiple file encryption keys are obtained based on the configuration information; corresponding encryption credentials are generated based on the multiple public key encryption keys; all encryption credentials and all file encryption keys are packaged to obtain an anti-leakage service file; an access request from a querying user is received; the user's permissions are verified based on the access request; if the verification is successful, the anti-leakage service file is decrypted based on the user's account information, and an access log file is generated; a pre-built Bluetooth scanning information document is scanned in real time; if the access process of the querying user is not recorded in the Bluetooth scanning information document, the access log file is added to the Bluetooth scanning information document; multiple abnormal accounts are identified based on the Bluetooth scanning information document; the access process of each abnormal account to the target file is located; and the anti-leakage service file is optimized. This invention achieves the addition of access records by modifying file header information, thereby improving the efficiency of full-process file management and locating the file's operating environment information. Attached Figure Description
[0017] Figure 1 This is a flowchart of a preferred embodiment of the file management method based on data leakage prevention service of the present invention; Figure 2 This is a flowchart illustrating the specific process of the data leakage prevention service in a preferred embodiment of the file management method based on data leakage prevention service of the present invention. Figure 3 This is a schematic diagram of a file management method based on data loss prevention service according to a preferred embodiment of the present invention. Figure 4 This is a schematic diagram of the operating environment information of a preferred embodiment of the file management method based on data leakage prevention service of the present invention; Figure 5 This is a structural diagram of a preferred embodiment of the file management system based on data leakage prevention service of the present invention; Figure 6 This is a structural diagram of a preferred embodiment of the cloud-based application of the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this invention clearer and more explicit, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0019] The preferred embodiment of the file management method based on data leakage prevention service of the present invention, such as... Figure 1 As shown, the file management method based on data leakage prevention service includes the following steps: To address existing data leakage prevention functions, this invention discloses a comprehensive solution for data leakage prevention services to improve the efficiency of end-to-end file management, wherein, for example... Figure 2 As shown, it includes a DLP permission management component, which is used for the underlying permission management service and is responsible for sandbox application creation and credential management interaction; the DLP management application component is responsible for setting, verifying and intercepting permissions locally; it is the key carrier for ultimately realizing the user-perceptible controlled sharing function; finally, the cloud docking module is responsible for sending the DLP file certificate (i.e., Cert certificate, Public Key Certificate) to the cloud to complete the account-based authentication, certificate generation and decryption functions.
[0020] Step S10: Obtain the configuration information of the target file, obtain multiple file encryption keys based on the configuration information, generate corresponding encryption credentials based on the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file.
[0021] In addition to the aforementioned control measures such as managing file operation permissions, implementing user awareness functions, and cloud-based synchronous authentication, this invention also manages file operation permissions and local file access records.
[0022] Specifically, the configuration information of the target file is obtained; the access type of the target file is determined based on the configuration information; multiple file encryption keys are added to the configuration information according to the access type; a corresponding number of public key encryption keys are generated according to the number of file encryption keys; a corresponding encryption credential is generated according to each public key encryption key; for the access type, each encryption credential and each file encryption key are packaged to obtain a corresponding anti-leakage service sub-file; and each anti-leakage service sub-file is integrated to obtain the anti-leakage service file of the target file.
[0023] In the embodiments disclosed in this invention, such as Figure 2 As shown, on the local end, the owner of the target file sets file permissions through the DLP permission management application. Then, the DLP permission management application sends the configuration information of the target file to the cloud for reception through the DLP permission management service. The cloud then encapsulates the configuration information into a corresponding policy and sends it back to the DLP permission management application through the DLP permission management service. At the same time, the corresponding credentials of the target file are also uploaded.
[0024] It is important to note that other users may have multiple requests to access the target file, such as editing, querying, and copying. Therefore, it is necessary to build multiple levels of permission to allow different users to access the file, improve the management of the target file, prevent the file from being leaked by unauthorized personnel, and enhance data security.
[0025] For the target file, such as Figure 3 As shown, the generated anti-leakage service file includes header information, CERT certificate, authorization-related information, file content, and historical access records. The CERT certificate contains configuration information and randomly generated key data for text encryption, decryption, and verification. When creating the anti-leakage service file, the access information to be recorded is queried and access records are created by calling the access record generation interface. This includes operation type (create, edit, view, copy), operation time, current file level, operation user (local system user), account information, current device unique identifier, current environment Bluetooth information, current environment WiFi information, and current GPS (Global Positioning System) coordinates.
[0026] If the Bluetooth information, WiFi information, and GPS coordinates of the current environment fail to be constructed, it will not affect the creation of the anti-leakage service file (other information will be affected). When the creation of these three types of information fails, there are two configurations to solve this problem: (1) prompt that there is a problem in the environment and needs to be checked. This will not hinder file operation. If the problem of failure to obtain the information is solved, subsequent operations will update this information; (2) for higher-level confidential files, certain information items will be required. If the acquisition fails, the information will be required to be added manually. For problems that do not affect file security, the anti-leakage service file will continue to be created, which effectively improves the management efficiency of the target file. For more advanced confidential files, when important information items are missing, they will be re-acquired or the user will be prompted to add them manually, thereby improving the visibility of access to the target file and improving the security of the target file.
[0027] Step S20: Receive the access request from the querying user, verify the permissions of the querying user according to the access request, and if the verification is successful, decrypt the anti-leakage service file according to the account information of the querying user and generate an access record file.
[0028] The access request includes one or more of the following: file creation request, file editing request, file query request, or file copy request; the anti-leakage service sub-file includes: header information, public key certificate, authorization information, file content, and historical access records; the public key certificate includes: access type and randomly generated key data.
[0029] Specifically, the system receives the user's request to create a file, edit a file, query a file, or copy a file, and obtains the user's permission level, performing a permission level verification. If the verification passes, the system receives the user's account information and decrypts the encryption credentials of multiple leak prevention service sub-files using multiple decryption keys in the account information. If the encryption credentials of a leak prevention service sub-file are successfully decrypted, the system adds the current access record information to the corresponding leak prevention service sub-file. An access record file is generated based on all updated leak prevention service sub-files.
[0030] Specifically, for access requests entered by querying users, the system first determines whether the querying user's account level is sufficient. For example, if the querying user's level is low, they can only query the target file. In this case, the querying user's account information cannot decrypt the anti-leakage service sub-files corresponding to the file creation request, file editing request, and file copy request of the target file, thereby ensuring the security of the target file.
[0031] Further, the header information of multiple loss prevention service sub-files is read, each header information is verified, and the data segment information of each loss prevention service sub-file is obtained; the access type of each loss prevention service sub-file is used to obtain the permission level corresponding to each loss prevention service sub-file, and each permission level and the corresponding data segment information are added to the encrypted file entity; the corresponding file link is recreated in the user space file system according to each encrypted file entity, and the file link is decrypted using each decryption key.
[0032] When the querying user's level is sufficient, the loss prevention service file is decrypted based on the querying user's account information. First, the header information of the loss prevention service file is read to verify the file and obtain the file data segment information. Then, the current user's permissions for the loss prevention service file are calculated through the configuration information of the Cert segment and set in the DLP File object (i.e., the encrypted file entity). Finally, a file link to the loss prevention service file is created. The application opens the file link through the user space file system and decrypts it using the decryption key.
[0033] During the verification process, the encrypted credentials extracted from the file header information are used to obtain the cloud account private key of the current device login (i.e., the query user) account (from which cloud account information is obtained). After verification, if the private key is valid, the document can be decrypted for subsequent operations. If an unauthorized query user opens the file, it will be determined that the current cloud account user is not authorized and the file opening will fail. This achieves dual verification of the target file and further improves the data security of the target file.
[0034] Step S30: Perform real-time scanning on the constructed Bluetooth scanning information document. If the access process of the querying user is not recorded in the Bluetooth scanning information document, add the access record file to the Bluetooth scanning information document.
[0035] Among them, such as Figure 4 As shown, the access record information includes: access request, operation time, current file level, querying user, account information, current device identifier, Bluetooth scan information of the current environment, Wi-Fi information of the current environment, and current coordinates (i.e., GPS).
[0036] Specifically, the constructed Bluetooth scanning information document is scanned in real time to determine whether the current access record is saved in the Bluetooth scanning information document; if the Bluetooth scanning information of the current environment is not found, it is determined that the Bluetooth scanning information document does not save the current access record, and the access record file of the current access record is added to the Bluetooth scanning information document.
[0037] Since Bluetooth information sometimes needs to be scanned to obtain, and there is a time lag between Bluetooth information acquisition and file access record operations, a Bluetooth scan information document needs to be created locally when the DLP permission management service is online in the background. The document needs to be scanned regularly to scan the current environment's Bluetooth information and update it. This is to ensure that the access records are complete for each time.
[0038] Furthermore, after each query user accesses the target file (or a query user accesses the target file multiple times, i.e., simultaneously performing editing, copying, and other access processes), a corresponding access record will be generated based on the query user's access process. If the Bluetooth information of the current environment is empty, the corresponding Bluetooth information needs to be added from the local Bluetooth scan information document, and the access record will be synchronized to update the Bluetooth scan information document in real time. By synchronizing the access records on the local and remote ends, the access process of the target file can be recorded more comprehensively, improving the visibility of target file management.
[0039] Step S40: Identify multiple abnormal accounts based on the Bluetooth scanning information document, locate the access process of each abnormal account to the target file, and optimize the anti-leakage service file.
[0040] In order to address the possibility of the aforementioned permission verification and decryption process going out of control, this invention also includes a final process for detecting access records to identify abnormal access records and optimize the anti-leakage service file of the target file, thereby further improving the data security of the target file.
[0041] Specifically, all access processes are obtained based on the Bluetooth scanning information document. If the anti-leakage service sub-file corresponding to a certain access process does not match the permission level of the querying user, the querying user is determined to be an abnormal account. Abnormal anti-leakage service sub-files corresponding to all abnormal access processes are extracted, and the operating environment information of the abnormal access process is located based on all the abnormal anti-leakage service sub-files. The encryption credentials of each abnormal anti-leakage service sub-file are updated to obtain the corresponding optimized anti-leakage service sub-file, which is then integrated into the current anti-leakage service file.
[0042] This involves real-time monitoring of every access record. If an anomaly is detected in a record, it must be retrieved and the entire access process analyzed in detail. For example, if a user's permission level is only to query a target file, but an access record exists in the anti-leakage service file showing the user editing that file, this process needs to be analyzed. This includes retrieving the user's actual behavior, the user's operating environment during the action, and information from the anti-leakage service sub-files such as timestamps. An anomaly tag is then added to the user, prompting the cloud to monitor that user and prevent future unauthorized actions.
[0043] Furthermore, for the edited target file, it is necessary to modify it to the version before the query user made the changes, based on the historical access records in the anti-leakage service file of the target file, and modify the encryption credentials in the anti-leakage service file to improve the security of the target file.
[0044] This invention enables the addition of access records by modifying file header information, thereby improving the efficiency of full-process file management and locating the file's operating environment information.
[0045] Furthermore, such as Figure 5 As shown, based on the above-described file management method based on data loss prevention services, the present invention also provides a file management system based on data loss prevention services, wherein the file management system based on data loss prevention services includes: File building module 51 is used to obtain the configuration information of the target file, obtain multiple file encryption keys according to the configuration information, generate corresponding encryption credentials according to the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file. Access logging module 52 is used to receive access requests from querying users, verify the permissions of querying users based on the access requests, and if the verification is successful, decrypt the anti-leakage service file based on the account information of the querying user and generate an access logging file. Bluetooth scanning module 53 is used to scan the constructed Bluetooth scanning information document in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. The optimization module 54 is used to identify multiple abnormal accounts based on the Bluetooth scanning information document, locate the access process of each abnormal account to the target file, and optimize the anti-leakage service file.
[0046] Furthermore, such as Figure 6 As shown, based on the above-mentioned file management method and system based on data leakage prevention service, the present invention also provides a cloud platform, which includes a processor 10, a memory 20 and a display 30. Figure 6 Only a portion of the components shown in the cloud are illustrated; however, it should be understood that implementation of all shown components is not required, and more or fewer components may be implemented instead.
[0047] In some embodiments, the memory 20 may be an internal storage unit of the cloud, such as a cloud hard drive or memory. In other embodiments, the memory 20 may be an external storage device of the cloud, such as a plug-in hard drive, smart media card (SMC), secure digital card (SD) card, flash card, etc., equipped on the cloud. Further, the memory 20 may include both internal storage units and external storage devices of the cloud. The memory 20 is used to store application software and various types of data installed on the cloud, such as program code installed on the cloud. The memory 20 can also be used to temporarily store data that has been output or will be output. In one embodiment, the memory 20 stores a file management program 40 based on a data leakage prevention service, which can be executed by the processor 10 to implement the file management method based on a data leakage prevention service in this application.
[0048] In some embodiments, the processor 10 may be a central processing unit (CPU), a microprocessor, or other data processing chip, used to run program code stored in the memory 20 or process data, such as executing the file management method based on the data leakage prevention service.
[0049] In some embodiments, the display 30 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen. The display 30 is used to display information on the cloud and to display a visual user interface. Components on the cloud communicate with each other via a system bus.
[0050] In one embodiment, when the processor 10 executes the file management program 40 based on the data leakage prevention service in the memory 20, the following steps are performed: Obtain the configuration information of the target file, obtain multiple file encryption keys based on the configuration information, generate corresponding encryption credentials based on the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file; Receive an access request from a querying user, verify the querying user's permissions based on the access request, and if the verification is successful, decrypt the anti-leakage service file based on the querying user's account information and generate an access log file; The constructed Bluetooth scanning information document is scanned in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. Based on the Bluetooth scanning information document, multiple abnormal accounts are identified, the access process of each abnormal account to the target file is located, and the anti-leakage service file is optimized.
[0051] The process of obtaining configuration information of the target file, obtaining multiple file encryption keys based on the configuration information, generating corresponding encryption credentials based on the multiple public key encryption keys, and packaging all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file specifically includes: Obtain the configuration information of the target file, determine the access type of the target file based on the configuration information, and add multiple file encryption keys to the configuration information based on the access type; Based on the number of file encryption keys, generate a corresponding number of public key encryption keys, and generate a corresponding encryption credential based on each of the public key encryption keys; For each access type, each encryption credential and each file encryption key are packaged to obtain a corresponding anti-leakage service sub-file. Each anti-leakage service sub-file is then integrated to obtain the anti-leakage service file for the target file.
[0052] The access request includes one or more of the following: a file creation request, a file editing request, a file query request, or a file copy request; The process of receiving an access request from a querying user, verifying the user's permissions based on the access request, and if the verification is successful, decrypting the anti-leakage service file based on the user's account information and generating an access log file specifically includes: Receive the file creation request, file editing request, file query request, or file copy request from the querying user, obtain the permission level of the querying user, and perform permission level verification; If the verification result of the level verification is passed, the account information of the querying user is received, and the encrypted credentials of multiple anti-leakage service sub-files are decrypted according to multiple decryption keys in the account information. If the encryption credentials of a certain anti-leakage service sub-file are successfully decrypted, then the access record information of the current access is added to the corresponding anti-leakage service sub-file. Generate an access log file based on all the updated leak prevention service subfiles.
[0053] The leak prevention service sub-file includes: header information, public key certificate, authorization information, file content, and historical access records; The public key certificate includes: access type and randomly generated key data.
[0054] Specifically, the step of decrypting the encrypted credentials of multiple anti-leakage service sub-files based on multiple decryption keys in the account information includes: Read the header information of multiple loss prevention service sub-files, verify each header information, and obtain the data segment information of each loss prevention service sub-file; By obtaining the access type of each of the anti-leakage service sub-files, the permission level corresponding to each of the anti-leakage service sub-files is obtained, and each permission level and each corresponding data segment information are added to the encrypted file entity; For each encrypted file entity, a corresponding file link is recreated in the user space file system, and the file link is decrypted using each of the decryption keys.
[0055] The access record information includes: access request, operation time, current file level, querying user, account information, current device identifier, Bluetooth scan information of the current environment, Wi-Fi information of the current environment, and current coordinates; The step of real-time scanning of the constructed Bluetooth scanning information document, and if the access process of the querying user is not recorded in the Bluetooth scanning information document, then adding the access record file to the Bluetooth scanning information document, specifically includes: The existing Bluetooth scanning information document is scanned in real time to determine whether the current access record is saved in the Bluetooth scanning information document. If the Bluetooth scanning information for the current environment is not found, it is determined that the Bluetooth scanning information document does not save the current access record, and the access record file of the current access record is added to the Bluetooth scanning information document.
[0056] Specifically, the step of identifying multiple abnormal accounts based on the Bluetooth scanning information document, locating the access process of each abnormal account to the target file, and optimizing the anti-leakage service file includes: All access processes are obtained based on the Bluetooth scanning information document. If the anti-leakage service sub-file corresponding to a certain access process does not match the permission level of the querying user, the querying user is determined to be an abnormal account. Extract the abnormal access process corresponding to the abnormal leakage prevention service sub-file, and locate the operating environment information of the abnormal access process based on all the abnormal leakage prevention service sub-files; The encryption credentials of each of the abnormal anti-leakage service sub-files are updated to obtain the corresponding optimized anti-leakage service sub-files, which are then integrated into the current anti-leakage service file.
[0057] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a file management program based on a data loss prevention service, and the file management program based on a data loss prevention service, when executed by a processor, implements the steps of the file management method based on a data loss prevention service as described above.
[0058] In summary, this invention provides a file management method and related equipment based on a data leakage prevention service. The method includes: obtaining configuration information of a target file; obtaining multiple file encryption keys based on the configuration information; generating corresponding encryption credentials based on the multiple public key encryption keys; packaging all the encryption credentials and all the file encryption keys to obtain a leakage prevention service file; receiving an access request from a querying user; verifying the querying user's permissions based on the access request; if the verification is successful, decrypting the leakage prevention service file based on the querying user's account information and generating an access record file; performing real-time scanning on a constructed Bluetooth scanning information document; if the Bluetooth scanning information document does not record the querying user's access process, adding the access record file to the Bluetooth scanning information document; identifying multiple abnormal accounts based on the Bluetooth scanning information document; locating the access process of each abnormal account to the target file; and optimizing the leakage prevention service file. This invention achieves improved efficiency in full-process file management by adding access records through modification of file header information and locates the file's operating environment information.
[0059] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or cloud that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or cloud. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or cloud that includes that element.
[0060] Of course, those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware (such as a processor, controller, etc.). The program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The computer-readable storage medium can be a memory, magnetic disk, optical disk, etc.
[0061] It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A file management method based on data leakage prevention services, characterized in that, The file management method based on data loss prevention services includes: Obtain the configuration information of the target file, obtain multiple file encryption keys based on the configuration information, generate corresponding encryption credentials based on the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file; Receive an access request from a querying user, verify the querying user's permissions based on the access request, and if the verification is successful, decrypt the anti-leakage service file based on the querying user's account information and generate an access log file; The constructed Bluetooth scanning information document is scanned in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. Based on the Bluetooth scanning information document, multiple abnormal accounts are identified, the access process of each abnormal account to the target file is located, and the anti-leakage service file is optimized.
2. The file management method based on data leakage prevention service according to claim 1, characterized in that, The process involves obtaining configuration information for the target file, acquiring multiple file encryption keys based on the configuration information, generating corresponding encryption credentials based on the multiple public key encryption keys, and packaging all the encryption credentials and all the file encryption keys together to obtain a data leakage prevention service file, specifically including: Obtain the configuration information of the target file, determine the access type of the target file based on the configuration information, and add multiple file encryption keys to the configuration information based on the access type; Based on the number of file encryption keys, generate a corresponding number of public key encryption keys, and generate a corresponding encryption credential based on each of the public key encryption keys; For each access type, each encryption credential and each file encryption key are packaged to obtain a corresponding anti-leakage service sub-file. Each anti-leakage service sub-file is then integrated to obtain the anti-leakage service file for the target file.
3. The file management method based on data leakage prevention service according to claim 2, characterized in that, The access request includes one or more of the following: a file creation request, a file editing request, a file query request, or a file copy request; The process of receiving an access request from a querying user, verifying the user's permissions based on the access request, and if the verification is successful, decrypting the anti-leakage service file based on the user's account information and generating an access log file specifically includes: Receive the file creation request, file editing request, file query request, or file copy request from the querying user, obtain the permission level of the querying user, and perform permission level verification; If the verification result of the level verification is passed, the account information of the querying user is received, and the encrypted credentials of multiple anti-leakage service sub-files are decrypted according to multiple decryption keys in the account information. If the encryption credentials of a certain anti-leakage service sub-file are successfully decrypted, then the access record information of the current access is added to the corresponding anti-leakage service sub-file. Generate an access log file based on all the updated leak prevention service subfiles.
4. The file management method based on data leakage prevention service according to claim 3, characterized in that, The leak prevention service sub-file includes: header information, public key certificate, authorization information, file content, and historical access records; The public key certificate includes: access type and randomly generated key data.
5. The file management method based on data leakage prevention service according to claim 4, characterized in that, The step of decrypting the encrypted credentials of multiple loss prevention service sub-files based on multiple decryption keys in the account information specifically includes: Read the header information of multiple loss prevention service sub-files, verify each header information, and obtain the data segment information of each loss prevention service sub-file; By obtaining the access type of each of the anti-leakage service sub-files, the permission level corresponding to each of the anti-leakage service sub-files is obtained, and each permission level and each corresponding data segment information are added to the encrypted file entity; For each encrypted file entity, a corresponding file link is recreated in the user space file system, and the file link is decrypted using each of the decryption keys.
6. The file management method based on data leakage prevention service according to claim 3, characterized in that, The access record information includes: access request, operation time, current file level, querying user, account information, current device identifier, Bluetooth scan information of the current environment, Wi-Fi information of the current environment, and current coordinates; The step of real-time scanning of the constructed Bluetooth scanning information document, and if the access process of the querying user is not recorded in the Bluetooth scanning information document, then adding the access record file to the Bluetooth scanning information document, specifically includes: The existing Bluetooth scanning information document is scanned in real time to determine whether the current access record is saved in the Bluetooth scanning information document. If the Bluetooth scanning information for the current environment is not found, it is determined that the Bluetooth scanning information document does not save the current access record, and the access record file of the current access record is added to the Bluetooth scanning information document.
7. The file management method based on data leakage prevention service according to claim 1, characterized in that, The step of identifying multiple abnormal accounts based on the Bluetooth scanning information document, locating the access process of each abnormal account to the target file, and optimizing the anti-leakage service file specifically includes: All access processes are obtained based on the Bluetooth scanning information document. If the anti-leakage service sub-file corresponding to a certain access process does not match the permission level of the querying user, the querying user is determined to be an abnormal account. Extract the abnormal access process corresponding to the abnormal leakage prevention service sub-file, and locate the operating environment information of the abnormal access process based on all the abnormal leakage prevention service sub-files; The encryption credentials of each of the abnormal anti-leakage service sub-files are updated to obtain the corresponding optimized anti-leakage service sub-files, which are then integrated into the current anti-leakage service file.
8. A file management system based on data leakage prevention services, characterized in that, The file management system based on data loss prevention service is applied to the file management method based on data loss prevention service as described in any one of claims 1-7, wherein the file management system based on data loss prevention service includes: The file building module is used to obtain the configuration information of the target file, obtain multiple file encryption keys according to the configuration information, generate corresponding encryption credentials according to the multiple public key encryption keys, and package all the encryption credentials and all the file encryption keys to obtain the anti-leakage service file. The access log module is used to receive access requests from querying users, verify the permissions of the querying users based on the access requests, and if the verification is successful, decrypt the anti-leakage service file based on the querying user's account information and generate an access log file. The Bluetooth scanning module is used to scan the constructed Bluetooth scanning information document in real time. If the access process of the querying user is not recorded in the Bluetooth scanning information document, the access record file is added to the Bluetooth scanning information document. The optimization module is used to identify multiple abnormal accounts based on the Bluetooth scanning information document, locate the access process of each abnormal account to the target file, and optimize the anti-leakage service file.
9. A cloud platform, characterized in that, The cloud includes: a memory, a processor, and a file management program based on a data loss prevention service stored on the memory and executable on the processor. When the file management program based on the data loss prevention service is executed by the processor, it implements the steps of the file management method based on a data loss prevention service as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a file management program based on a data loss prevention service, which, when executed by a processor, implements the steps of the file management method based on a data loss prevention service as described in any one of claims 1-7.