A cloud protocol-based remote office system and method
Patent Information
- Application Number
- CN202610940786.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-27
- Publication Date
- 2026-09-25
AI Technical Summary
然而,现有方案大多采用静态权限配置方式,用户在通过身份认证后即可按照预先配置的权限访问数据资源,难以根据用户行为、设备状态、网络环境以及任务阶段等因素的变化实时调整访问权限
(1)本发明通过接收远程办公访问请求并获取用户身份信息、设备信息、网络环境信息、任务信息以及行为信息,构建动态数据图谱,并结合实时更新后的动态数据图谱计算动态风险值,从而生成或调整访问控制决策,使系统能够根据用户状态、设备状态及网络环境变化动态调整访问权限,提高远程办公环境下访问控制的实时性和准确性。
Smart Images

Figure CN122824441A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a remote office system and method based on cloud protocols. Background Technology
[0002] With the development of cloud computing technology and mobile office models, remote work has become an important way for enterprises to collaborate. Existing remote office systems typically achieve remote access through Virtual Private Networks (VPNs), authentication mechanisms, and role-based access control, and utilize transport layer encryption technology to ensure data security during transmission. However, most existing solutions adopt static permission configuration, where users can access data resources according to pre-configured permissions after authentication, making it difficult to adjust access permissions in real time based on changes in user behavior, device status, network environment, and task stage. When terminal device status is abnormal, network environment changes, or user behavior is abnormal, the system may still maintain the original access permissions, leading to the risk of data leakage.
[0003] Therefore, how to build a remote office system that can combine dynamic risk perception to achieve real-time adjustment of access permissions, continuous protection of data objects, support dynamic contraction of decryption permissions, and have full-process audit traceability capabilities has become a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0004] In order to solve the technical problems existing in the background art, in a first aspect, the present invention provides a remote office system based on a cloud protocol, including: a data receiving module for receiving remote office access requests; The request analysis module is used to analyze received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The graph construction module is used to construct data graphs based on acquired user information, device information, network environment information, accessed application information, task information, target data objects, and behavioral information. The map dynamic update module is used to perform real-time dynamic detection of the data map and update the data map in real-time based on the detection results. The risk decision engine is used to calculate dynamic risk values in real time based on the data map that is updated in real time, and to generate or readjust access decisions based on the calculated risk values. The data capsule generation module encrypts the target data object to generate ciphertext and generates a data capsule based on access decisions. The data capsule includes ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash. The dynamic key management module is used to obtain data keys from the key management service based on the key identifier in the data capsule, and to perform fragmentation processing on the data keys to generate multiple key fragments; at the same time, it performs control operations on the key fragments according to access decisions; wherein, the control operations include distribution, combination, freezing or destruction; Zero-trust access gateway is used to segment and encrypt the transmission of data capsules based on access decisions; The audit tracing module is used to record access events to the data capsule and form hash chain audit evidence.
[0005] Furthermore, the map dynamic update module includes: The event sensing unit is used to sense changes in user behavior, terminal status, network environment, and task stage based on user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The relationship mapping unit is used to map perceived changes in user behavior, terminal status, network environment, and task stage to corresponding nodes and relationship edges in the data graph, so as to dynamically update node attribute information and relationship edge information. The weight adjustment unit is used to dynamically adjust the node weights and relation edge weights based on perceived changes in user behavior, terminal status, network environment, and task stage.
[0006] Furthermore, the risk decision engine includes: The real-time risk calculation unit is used to calculate dynamic risk values based on data graphs; The risk prediction unit is used to generate the risk evolution status corresponding to the remote office access request based on the data map, and generate risk warning information based on the risk evolution status. The access policy adjustment unit is used to generate or readjust access decisions based on dynamic risk values and risk warning information. The anomaly feedback integration unit is used to correct the dynamic risk value of the dynamically updated data map in real time.
[0007] Furthermore, the data capsule generation module includes: The ciphertext generation unit is used to encrypt the target data object to generate ciphertext. The policy metadata generation unit is used to generate policy metadata based on access decisions. The policy metadata includes task phase information, user role information, allowed operation set, access permissions, and dynamic risk thresholds. The key identifier generation unit is used to assign a unique identifier to the data key and establish the correspondence between the identifier and the target data object; The dynamic watermark generation unit is used to generate dynamic watermarks based on user information, device information, and task information. The audit hash generation unit is used to generate audit hash values based on the target data object, policy metadata, and dynamic watermark. The capsule encapsulation unit is used to encapsulate ciphertext, policy metadata, key identifiers, dynamic watermarks, and audit hashes into data capsules according to a preset format. Capsule description units are used to generate capsule descriptors that represent the structural and attribute information of data capsules, enabling data capsules to have self-descriptive capabilities.
[0008] Furthermore, the dynamic key management module includes: The key acquisition and fragmentation unit is used to acquire the corresponding data key from the key management service according to the key identifier, and to split the data key into multiple key fragments; The key policy parsing and scheduling unit is used to generate a key operation policy based on the access decision, and to perform distribution, combination, freezing or destruction operations on key pieces based on the key operation policy. The key reconstruction unit is used to combine the key pieces to reconstruct the data key under the condition of satisfying preset authorization conditions and threshold conditions, thereby controlling the decryption permission of the data capsule; The key auditing unit is used to record key acquisition, fragmentation, distribution, combination and destruction operations, and generate traceable key operation audit information.
[0009] Furthermore, the zero-trust access gateway includes: The access decision parsing unit is used to parse access decisions to determine the data access permission level, transmission security level, and allowed transmission path; The data capsule segmentation unit is used to segment the data capsule according to a preset segmentation rule to obtain segmented data, wherein the segmented data includes encrypted segments, policy metadata segments, and identification information segments. The dynamic encryption unit is used to perform differentiated encryption processing on each data segment according to the access decision, so as to generate corresponding encrypted segment data; The path selection unit is used to select at least one secure transmission path from multiple preset transmission paths based on the network trust level and device trust status determined by the access decision. The segmented transmission control unit is used to send encrypted segmented data in segments according to the selected transmission path, and to set different transmission priorities and transmission order control strategies for different segments. The reassembly constraint control unit is used at the receiving end to verify the reassembly conditions of segmented data based on access decisions, so as to restrict data capsule reassembly to only when the authorization conditions are met and the integrity verification passes. The transmission audit unit is used to record the data segmentation transmission path, encryption strategy, access decision correspondence and reception reassembly results, and generate zero-trust transmission audit logs.
[0010] Secondly, the present invention provides a remote office data security control method based on a cloud protocol, comprising the following steps: Step 1: Receive remote office access requests and analyze the received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavior information; Step 2: Construct a data graph based on the acquired user information, device information, network environment information, accessed application information, task information, target data objects, and behavioral information; Step 3: Perform real-time dynamic detection on the data map and update the data map in real-time based on the detection results; Step 4: Calculate dynamic risk values in real time based on the dynamically updated data map, and generate or readjust access decisions based on the calculated risk values; Step 5: Encrypt the target data object to generate ciphertext, and generate a data capsule based on the access decision. The data capsule includes ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash. Step Six: Obtain the data key from the key management service based on the key identifier in the data capsule, and perform fragmentation processing on the data key to generate multiple key fragments; at the same time, perform control operations on the key fragments according to the access decision; wherein, the control operations include distribution, combination, freezing or destruction; Step 7: Segment and encrypt the data capsule for transmission based on the access decision; Step 8: Record access events to the data capsule and form hash chain audit evidence.
[0011] Thirdly, the present invention provides a computer-readable storage medium including a stored program that, when the program is running, controls the power equipment where the computer-readable storage medium is located to execute the remote office method based on the cloud protocol described above.
[0012] The beneficial effects of this invention are as follows: (1) This invention receives remote office access requests and obtains user identity information, device information, network environment information, task information and behavior information to construct a dynamic data map. It then calculates dynamic risk values by combining the real-time updated dynamic data map, thereby generating or adjusting access control decisions. This enables the system to dynamically adjust access permissions according to changes in user status, device status and network environment, thereby improving the real-time performance and accuracy of access control in a remote office environment.
[0013] (2) This invention encrypts the target data object and generates a data capsule containing data ciphertext, policy metadata, key identifier, dynamic watermark and audit hash by combining access control decision. This extends access control capabilities from the traditional network boundary to the data object itself, so that the data can remain under control even after leaving the original network environment, thereby achieving continuous data protection and improving data security.
[0014] (3) The present invention obtains the corresponding data key based on the key identifier in the data capsule and performs fragment processing on the data key. By performing distribution, combination, freezing or destruction operations on the key fragments according to access control decisions, the data decryption capability can be dynamically adjusted with the change of access risk. When the access risk increases, access permissions are contracted by freezing or destroying some key fragments, thereby avoiding the data loss of control problem caused by key leakage under the traditional centralized key management model and improving the security and flexibility of key management.
[0015] (4) The present invention utilizes a zero-trust access gateway to perform segmented encrypted transmission of data capsules based on access control decisions, enabling different data segments to be transmitted and reassembled under controlled conditions. Even if some transmitted data is intercepted, it is difficult to recover the complete data content, thereby improving the security and reliability of the data transmission process.
[0016] (5) By recording data capsule access events, key operation events and data transmission events, and forming hash chain audit evidence, this invention enables full-process tracking of data access, permission changes and data flow, improves the auditability and traceability of the system, and provides reliable support for data security management in remote office environments. Attached Figure Description
[0017] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.
[0018] Figure 1 This is a flowchart of the remote office method based on cloud protocol of the present invention. Detailed Implementation
[0019] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0020] It should be noted that the following detailed description is illustrative and intended to provide further explanation of the invention. Unless otherwise specified, each technical and scientific term used in these embodiments has the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0021] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0022] In this invention, terms such as "upper," "lower," "left," "right," "front," "back," "vertical," "horizontal," "side," and "bottom" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. These terms are used only to facilitate the description of the structural relationships of the various components or elements of this invention and do not specifically refer to any component or element in this invention. They should not be construed as limiting the invention.
[0023] In this invention, terms such as "fixed connection," "connected," and "linked" should be interpreted broadly, indicating a fixed connection, an integral connection, or a detachable connection; a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can determine the specific meaning of these terms in this invention based on the specific circumstances, and they should not be construed as limitations on the invention.
[0024] Example 1: like Figure 1 As shown, the present invention provides a remote office method based on a cloud protocol, comprising: S1: Receive remote work access requests; S2: Analyze the received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavior information; S3: Construct a data graph based on the acquired user information, device information, network environment information, access application information, task information, target data objects, and behavioral information; S3-1: Generate initial map nodes.
[0025] User nodes, device nodes, network nodes, application nodes, task nodes, data object nodes, and behavior event nodes are generated based on the acquired user information, device information, network environment information, accessed application information, task information, target data object, and behavior information, respectively.
[0026] Among them, the user node represents the entity that initiates the access request; the device node represents the terminal used by the user; the network node represents the network environment accessed by the terminal; the application node represents the cloud-based collaborative office application being accessed; the task node represents the current remote office task; the data object node represents the file, form, record, or business data being accessed; and the behavior event node represents the operations performed by the user, such as viewing, editing, downloading, sharing, and approving.
[0027] S3-2: Extract node attributes from the acquired user information, device information, network environment information, access application information, task information, target data object and behavior information, and write the corresponding node attributes to each node.
[0028] For user nodes, node attributes should include at least user identifier, department, position, role, identity credibility, authentication strength, and historical abnormal behavior information; For device nodes, node attributes must include at least the device identifier, operating system version, patch status, endpoint protection status, disk encryption status, and device trustworthiness. For network nodes, node attributes should include at least IP address, network type, geographical location, proxy status, egress risk, and network risk parameters; For application nodes, node attributes should at least include application type, application level, interface permissions, and call frequency; For a task node, the node attributes should at least include the task number, task stage, participating roles, approval relationship, task confidentiality level, and task validity period; For behavior event nodes, the node attributes should include at least the behavior type, behavior time, behavior frequency, anomaly probability, and behavior risk level.
[0029] S3-3: Establish the relationship edges between nodes based on the access context.
[0030] Specifically, the following steps are included: Establish a usage relationship edge between the user node and the device node to indicate that the user initiates access using a certain terminal device.
[0031] An access relationship edge is established between the device node and the network node to indicate that the terminal device accesses the cloud collaborative system through a certain network environment.
[0032] An access relationship edge is established between the user node and the application node to represent a user accessing a certain application system.
[0033] An execution relationship edge is established between the user node and the task node to indicate that the user participates in or executes a remote office task.
[0034] Establish containment edges between task nodes and data object nodes to indicate that the task involves target data objects.
[0035] Establish processing relationship edges between application nodes and data object nodes to represent the application system reading, editing, calling, or transmitting data objects.
[0036] An action initiation relationship edge is established between the user node and the action event node, and an action relationship edge is established between the action event node and the data object node, which are used to indicate that the user has performed a specific operation on the target data object.
[0037] S4: Perform real-time dynamic detection on the data map and update the data map in real-time based on the detection results; Specifically, the following steps are included: S4-1: Based on user information, device information, network environment information, access application information, task information, target data object and behavior information, perceive changes in user behavior, terminal status, network environment and task stage. S4-2: Map perceived changes in user behavior, terminal status, network environment, and task stage to corresponding nodes and relationship edges in the data graph, dynamically updating node attribute information and relationship edge information, and dynamically adjusting node weights and relationship edge weights. Specifically, the following steps are included: A1: If the user's state changes, update the user node and user node attributes; Specifically, when a change in user authentication strength, consecutive authentication failures, account permission adjustments, or changes in multi-factor authentication results are detected, the data security graph module updates the identity credibility, authentication strength, and permission status attributes of the corresponding user node.
[0038] At this point, user nodes will not be deleted due to reduced identity credibility, but will remain in the graph, and the low credibility state will be used as the basis for subsequent risk calculation, access denial, and audit tracing.
[0039] A2: If the device status changes, update the device node and device node attributes.
[0040] Specifically, when the terminal trust assessment module detects missing device patches, disabled terminal protection programs, changes in disk encryption status, access to external storage devices, or abnormal device geographical location, the data security graph module updates the device trustworthiness, terminal risk level, and device status attributes of the corresponding device node.
[0041] A3: If the network environment changes, update the network nodes, network node attributes, and access relationship edges.
[0042] Specifically, when the network environment awareness module detects that a terminal device switches from a home network to a public wireless network, or detects proxy access, abnormal exits, cross-regional access, or high-risk IP addresses, the data security graph module disables the access relationship edge between the original device node and the original network node, establishes the access relationship edge between the device node and the new network node, and updates the network risk parameters of the new network node.
[0043] A4: If changes occur during the task phase, update the task node, task node attributes, and data object strategy.
[0044] When a collaborative task moves from the drafting stage to the review, approval, or archiving stage, the data security graph module updates the task stage attributes of the task node and simultaneously updates the relationship between the task node and the data object node, the set of allowed operations for the data object node, and the data capsule policy corresponding to the data object.
[0045] For example, the drafting stage allows editing, the approval stage only allows read-only access and signature, and the archiving stage only allows querying and auditing.
[0046] A5: If the behavior changes, a new behavior event node will be added.
[0047] When a user performs operations such as viewing, editing, downloading, sharing, forwarding, printing, or deleting during a session, the data security graph module generates a new behavior event node for each operation and establishes behavior initiation relationship edges between user nodes and behavior event nodes, as well as interaction relationship edges between behavior event nodes and data object nodes.
[0048] As user actions continue to occur, the number of behavioral event nodes continues to increase, thereby recording the temporal sequence and behavioral chain of access behaviors.
[0049] A6: If the lifecycle of a data object changes, update the data object node and its properties.
[0050] When a data object changes from creation state to editing state, from editing state to approval state, from approval state to archive state, or from valid state to invalid state, the data security graph module updates the lifecycle state, sensitivity level, current capsule policy, key state, and audit chain identifier of the data object node.
[0051] For highly sensitive data, when the risk increases, the data object node switches from the original data capsule strategy to a higher-strength data capsule strategy and establishes a new capsule binding relationship.
[0052] S5: Calculate dynamic risk values in real time based on the data map that has been dynamically updated in real time, and generate or readjust access decisions based on the calculated risk values; Specifically, the following steps are included: S5-1: Calculate dynamic risk values based on data maps; The formula for calculating the dynamic risk value is as follows: ; in, For user identity risks, For equipment risks, For network risks, For abnormal behavior risk, For data sensitivity, Risks associated with the mission phase. For application interface risks, weight to These are parameters based on actual needs.
[0053] S5-2: Based on the data map, generate the risk evolution status corresponding to the remote office access request, and generate risk warning information based on the risk evolution status; S5-3: Generate or readjust access decisions based on dynamic risk values and risk warning information; Specifically, it includes the following steps: S5-3-1: Dynamic risk value The decision engine receives input of risk evolution status and risk warning information, and generates a comprehensive risk value through a risk fusion mechanism. The calculation formula is as follows: ; Where E is the risk level parameter corresponding to the risk evolution state, P is the risk level parameter corresponding to the risk warning information, and β and γ are the risk trend correction coefficient and the warning event correction coefficient, respectively, and their values are configured according to the actual security requirements of the system.
[0054] S5-3-2: Based on the comprehensive risk value Generate the corresponding access decision; when When the value is less than 20, a normal access decision is generated, allowing the user to access the target resource and briefly decrypting the data only in the trusted memory area, while maintaining the current session key in a valid state.
[0055] When 20≤ When the threshold is less than 40, an enhanced audit access decision is generated. While allowing users to access the target resource, the user's operation process is enhanced with logging, dynamic digital watermarks are added to exported files, and the frequency and number of batch downloads are limited.
[0056] When 40≤ When the threshold is less than 60, a degraded access decision is generated, downgrading the user's access permissions from read and write permissions to read-only permissions, de-identifying sensitive data, and prohibiting copying, printing, and batch export operations, while also restricting calls to highly sensitive application interfaces.
[0057] When 60≤ When the threshold is <80, a temporary blocking decision is generated, suspending the current session connection, freezing the corresponding key fragment, and initiating a re-authentication request to the user; after the user successfully re-authenticates, the current risk is reassessed to determine whether to restore access permissions.
[0058] when When the value is greater than or equal to 80, an access denial decision is generated, the current session token is revoked, access permissions are revoked, the decryption key in the cache is destroyed, an alarm message is sent to the security management center, and the current access log, behavior record and related evidence data are saved for subsequent audit and evidence collection.
[0059] During user access, the access decision engine continuously monitors changes in dynamic risk values and the evolution of risk status. When a change in dynamic risk value exceeds a preset threshold, or when new risk warning information is received, an access decision reassessment mechanism is triggered to re-evaluate the overall risk value. It performs real-time updates and regenerates access decisions.
[0060] If the updated comprehensive risk value Higher than the current overall risk value If so, a permission reduction strategy will be implemented, including lowering access permission levels, shortening session validity periods, freezing some key fragments, limiting application interface call frequency, and increasing security audit levels; if the updated comprehensive risk value Below the current overall risk value If the status remains stable over multiple consecutive monitoring periods, then an access control recovery strategy will be implemented, including restoring access permissions at each level, unfreezing the key, restoring the ability to call interfaces, and reducing the intensity of auditing.
[0061] S5-3-3: The generated access decision results are sent to the access control module, key management module, and data protection module for execution, so as to realize dynamic adaptive control of remote office access behavior, thereby improving system business continuity and access reliability while ensuring data security.
[0062] S5-4: Anomaly Feedback Integration Unit, used to correct the dynamic risk value of the dynamically updated data map in real time.
[0063] S6: Encrypt the target data object to generate ciphertext, and generate a data capsule based on the access decision. The data capsule includes the ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash.
[0064] Specifically, the following steps are included: S6-1: Encrypt the target data object to generate ciphertext; S6-2: Generate policy metadata based on access decisions. The policy metadata includes task phase information, user role information, allowed operation set, access permissions, and dynamic risk thresholds. S6-3: Assign a unique identifier to the data key and establish the correspondence between the identifier and the target data object; S6-4: Generate dynamic watermarks based on user information, device information, and task information; S6-5: Generate an audit hash value based on the target data object, policy metadata, and dynamic watermark; S6-6: Encapsulate the ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash into a data capsule according to a preset format; The preset format includes: field structure and order information for storing ciphertext, policy metadata, key identifiers and dynamic watermarks. The fields are arranged in a fixed order and their boundaries are identified by encapsulation identifiers or length prefixes to form a parsable and self-describing data capsule.
[0065] S6-7: Generate capsule descriptors that represent the structural and attribute information of the data capsule, enabling the data capsule to have self-describing capabilities.
[0066] S7: Used to obtain a data key from the key management service based on the key identifier in the data capsule, and to perform fragmentation processing on the data key to generate multiple key fragments; at the same time, to perform control operations on the key fragments according to the access decision; wherein, the control operations include distribution, combination, freezing or destruction; Specifically, the following steps are included: S7-1: Obtain the corresponding data key from the key management service according to the key identifier, and split the data key into multiple key fragments; S7-2: Generate a key operation policy based on the access decision, and perform distribution, combination, freezing or destruction operations on the key pieces based on the key operation policy; S7-3: Under the condition of satisfying the preset authorization conditions and threshold conditions, the key pieces are combined to reconstruct the data key, thereby controlling the decryption permission of the data capsule; Among them, preset authorization conditions refer to the conditions under which decryption is allowed only when a user, task, or environment meets specific access permission requirements, specifically including: User identity requirements: Visitor identity must be verified (e.g., role, department, job level, etc.).
[0067] Task or stage condition: The current operation belongs to an allowed data access task stage or task flow.
[0068] Access control decision condition: The risk value calculated by the risk decision engine is lower than the preset threshold.
[0069] Equipment and network conditions: The device and network status of the access request source comply with security policies (such as trusted terminals, VPN connections, geographical location restrictions, etc.).
[0070] Threshold conditions refer to the cryptographic requirements for reconstructing the data key from a key slice, usually expressed as threshold cryptography, and specifically include: Minimum number of key fragments: The key can only be reconstructed when the number of fragments reaches or exceeds a preset threshold (t-of-n).
[0071] Key fragment source restriction: Key fragments used in reconstruction must come from legitimate distribution paths (to prevent unauthorized fragment acquisition and reconstruction).
[0072] Key status check: The key chip has not been frozen, revoked, or destroyed.
[0073] S7-4: Record key acquisition, fragmentation, distribution, combination and destruction operations, and generate traceable key operation audit information.
[0074] S8: Segment and encrypt the data capsule according to the access decision; Specifically, the following steps are included: S8-1: Analyze access decisions to determine data access permission levels, transmission security levels, and permitted transmission paths; S8-2: Segment the data capsule according to the preset segmentation rules to obtain segmented data, wherein the segmented data includes encrypted segments, policy metadata segments, and identification information segments; S8-3: Based on the access decision, perform differentiated encryption processing on each data segment to generate corresponding encrypted segment data; S8-4: Based on the network trust level and device trust status determined by the access decision, select at least one secure transmission path from multiple preset transmission paths; S8-5: Send encrypted segmented data in segments according to the selected transmission path, and set different transmission priorities and transmission order control strategies for different segments; S8-6: At the receiving end, the conditions for reassembling segmented data are verified based on the access decision to restrict data capsule reassembly to only when the authorization conditions and integrity verification are met; S8-7: Record the data segmentation transmission path, encryption strategy, access decision correspondence and reception reassembly results, and generate a zero-trust transmission audit log.
[0075] S9: Record access events to the data capsule and form hash chain audit evidence.
[0076] Example 2: This example provides a remote office system based on a cloud protocol, including: The data receiving module is used to receive remote office access requests; The request analysis module is used to analyze received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The graph construction module is used to construct data graphs based on acquired user information, device information, network environment information, accessed application information, task information, target data objects, and behavioral information. The map dynamic update module is used to perform real-time dynamic detection of the data map and update the data map in real-time based on the detection results. The map dynamic update module includes: The event sensing unit is used to sense changes in user behavior, terminal status, network environment, and task stage based on user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The relationship mapping unit is used to map perceived changes in user behavior, terminal status, network environment, and task stage to corresponding nodes and relationship edges in the data graph, so as to dynamically update node attribute information and relationship edge information. The weight adjustment unit is used to dynamically adjust the node weights and relation edge weights based on perceived changes in user behavior, terminal status, network environment, and task stage.
[0077] The risk decision engine is used to calculate dynamic risk values in real time based on the data map that is updated in real time, and to generate or readjust access decisions based on the calculated risk values. The risk decision engine includes: The real-time risk calculation unit is used to calculate dynamic risk values based on data graphs; The risk prediction unit is used to generate the risk evolution status corresponding to the remote office access request based on the data map, and generate risk warning information based on the risk evolution status. The access policy adjustment unit is used to generate or readjust access decisions based on dynamic risk values and risk warning information. The anomaly feedback integration unit is used to correct the dynamic risk value of the dynamically updated data map in real time.
[0078] The data capsule generation module encrypts the target data object to generate ciphertext and generates a data capsule based on access decisions. The data capsule includes ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash. The data capsule generation module includes: The ciphertext generation unit is used to encrypt the target data object to generate ciphertext. The policy metadata generation unit is used to generate policy metadata based on access decisions. The policy metadata includes task phase information, user role information, allowed operation set, access permissions, and dynamic risk thresholds. The key identifier generation unit is used to assign a unique identifier to the data key and establish the correspondence between the identifier and the target data object; The dynamic watermark generation unit is used to generate dynamic watermarks based on user information, device information, and task information. The audit hash generation unit is used to generate audit hash values based on the target data object, policy metadata, and dynamic watermark. The capsule encapsulation unit is used to encapsulate ciphertext, policy metadata, key identifiers, dynamic watermarks, and audit hashes into data capsules according to a preset format. Capsule description units are used to generate capsule descriptors that represent the structural and attribute information of data capsules, enabling data capsules to have self-descriptive capabilities.
[0079] The dynamic key management module is used to obtain data keys from the key management service based on the key identifier in the data capsule, and to perform fragmentation processing on the data keys to generate multiple key fragments; at the same time, it performs control operations on the key fragments according to access decisions; wherein, the control operations include distribution, combination, freezing or destruction; The dynamic key management module includes: The key acquisition and fragmentation unit is used to acquire the corresponding data key from the key management service according to the key identifier, and to split the data key into multiple key fragments; The key policy parsing and scheduling unit is used to generate a key operation policy based on the access decision, and to perform distribution, combination, freezing or destruction operations on key pieces based on the key operation policy. The key reconstruction unit is used to combine the key pieces to reconstruct the data key under the condition of satisfying preset authorization conditions and threshold conditions, thereby controlling the decryption permission of the data capsule; The key auditing unit is used to record key acquisition, fragmentation, distribution, combination and destruction operations, and generate traceable key operation audit information.
[0080] Zero-trust access gateway is used to segment and encrypt the transmission of data capsules based on access decisions; The zero-trust access gateway includes: The access decision parsing unit is used to parse access decisions to determine the data access permission level, transmission security level, and allowed transmission path; The data capsule segmentation unit is used to segment the data capsule according to a preset segmentation rule to obtain segmented data, wherein the segmented data includes encrypted segments, policy metadata segments, and identification information segments. The dynamic encryption unit is used to perform differentiated encryption processing on each data segment according to the access decision, so as to generate corresponding encrypted segment data; The path selection unit is used to select at least one secure transmission path from multiple preset transmission paths based on the network trust level and device trust status determined by the access decision. The segmented transmission control unit is used to send encrypted segmented data in segments according to the selected transmission path, and to set different transmission priorities and transmission order control strategies for different segments. The reassembly constraint control unit is used at the receiving end to verify the reassembly conditions of segmented data based on access decisions, so as to restrict data capsule reassembly to only when the authorization conditions are met and the integrity verification passes. The transmission audit unit is used to record the data segmentation transmission path, encryption strategy, access decision correspondence and reception reassembly results, and generate zero-trust transmission audit logs.
[0081] The audit tracing module is used to record access events to the data capsule and form hash chain audit evidence.
[0082] Example 3: The present invention provides a computer-readable storage medium, which includes a stored program that, when the program is running, controls the power equipment where the computer-readable storage medium is located to execute the remote office method based on the cloud protocol described in Embodiment 1.
[0083] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the terminal embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0084] In the embodiments provided by this invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or units may be electrical, mechanical, or other forms.
[0085] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0086] Additionally, it should be noted that the flowcharts in the accompanying drawings illustrate methods according to embodiments of this disclosure. In the descriptions corresponding to the flowcharts or block diagrams in the drawings, the operations or steps corresponding to different blocks may occur in a different order than disclosed in the description; sometimes, there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the function involved. Each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0087] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A remote office system based on a cloud protocol, characterized in that, include: The data receiving module is used to receive remote office access requests; The request analysis module is used to analyze received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The graph construction module is used to construct data graphs based on acquired user information, device information, network environment information, accessed application information, task information, target data objects, and behavioral information. The map dynamic update module is used to perform real-time dynamic detection of the data map and update the data map in real-time based on the detection results. The risk decision engine is used to calculate dynamic risk values in real time based on the data map that is updated in real time, and to generate or readjust access decisions based on the calculated risk values. The data capsule generation module encrypts the target data object to generate ciphertext and generates a data capsule based on access decisions. The data capsule includes ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash. The dynamic key management module is used to obtain data keys from the key management service based on the key identifier in the data capsule, and to perform fragmentation processing on the data keys to generate multiple key fragments; at the same time, it performs control operations on the key fragments according to access decisions; wherein, the control operations include distribution, combination, freezing or destruction; Zero-trust access gateway is used to segment and encrypt the transmission of data capsules based on access decisions; The audit tracing module is used to record access events to the data capsule and form hash chain audit evidence.
2. The remote office system based on cloud protocol according to claim 1, characterized in that, The map dynamic update module includes: The event sensing unit is used to sense changes in user behavior, terminal status, network environment, and task stage based on user information, device information, network environment information, access application information, task information, target data objects, and behavioral information. The relationship mapping unit is used to map perceived changes in user behavior, terminal status, network environment, and task stage to corresponding nodes and relationship edges in the data graph, so as to dynamically update node attribute information and relationship edge information. The weight adjustment unit is used to dynamically adjust the node weights and relation edge weights based on perceived changes in user behavior, terminal status, network environment, and task stage.
3. The remote office system based on cloud protocol according to claim 1, characterized in that, The risk decision engine includes: The real-time risk calculation unit is used to calculate dynamic risk values based on data graphs; The risk prediction unit is used to generate the risk evolution status corresponding to the remote office access request based on the data map, and generate risk warning information based on the risk evolution status. The access policy adjustment unit is used to generate or readjust access decisions based on dynamic risk values and risk warning information. The anomaly feedback integration unit is used to correct the dynamic risk value of the dynamically updated data map in real time.
4. The remote office system based on cloud protocol according to claim 1, characterized in that, The data capsule generation module includes: The ciphertext generation unit is used to encrypt the target data object to generate ciphertext. The policy metadata generation unit is used to generate policy metadata based on access decisions. The policy metadata includes task phase information, user role information, allowed operation set, access permissions, and dynamic risk thresholds. The key identifier generation unit is used to assign a unique identifier to the data key and establish the correspondence between the identifier and the target data object; The dynamic watermark generation unit is used to generate dynamic watermarks based on user information, device information, and task information. The audit hash generation unit is used to generate audit hash values based on the target data object, policy metadata, and dynamic watermark. The capsule encapsulation unit is used to encapsulate ciphertext, policy metadata, key identifiers, dynamic watermarks, and audit hashes into data capsules according to a preset format. Capsule description units are used to generate capsule descriptors that represent the structural and attribute information of data capsules, enabling data capsules to have self-descriptive capabilities.
5. The remote office system based on cloud protocol according to claim 1, characterized in that, The dynamic key management module includes: The key acquisition and fragmentation unit is used to acquire the corresponding data key from the key management service according to the key identifier, and to split the data key into multiple key fragments; The key policy parsing and scheduling unit is used to generate a key operation policy based on the access decision, and to perform distribution, combination, freezing or destruction operations on key pieces based on the key operation policy. The key reconstruction unit is used to combine the key pieces to reconstruct the data key under the condition of satisfying preset authorization conditions and threshold conditions, thereby controlling the decryption permission of the data capsule; The key auditing unit is used to record key acquisition, fragmentation, distribution, combination and destruction operations, and generate traceable key operation audit information.
6. The remote office system based on cloud protocol according to claim 1, characterized in that, The zero-trust access gateway includes: The access decision parsing unit is used to parse access decisions to determine the data access permission level, transmission security level, and allowed transmission path; The data capsule segmentation unit is used to segment the data capsule according to a preset segmentation rule to obtain segmented data, wherein the segmented data includes encrypted segments, policy metadata segments, and identification information segments. The dynamic encryption unit is used to perform differentiated encryption processing on each data segment according to the access decision, so as to generate corresponding encrypted segment data; The path selection unit is used to select at least one secure transmission path from multiple preset transmission paths based on the network trust level and device trust status determined by the access decision. The segmented transmission control unit is used to send encrypted segmented data in segments according to the selected transmission path, and to set different transmission priorities and transmission order control strategies for different segments. The reassembly constraint control unit is used at the receiving end to verify the reassembly conditions of segmented data based on access decisions, so as to restrict data capsule reassembly to only when the authorization conditions are met and the integrity verification passes. The transmission audit unit is used to record the data segmentation transmission path, encryption strategy, access decision correspondence and reception reassembly results, and generate zero-trust transmission audit logs.
7. A remote office data security control method based on a cloud protocol, characterized in that, Includes the following steps: Step 1: Receive remote office access requests and analyze the received remote office access requests to obtain user information, device information, network environment information, access application information, task information, target data objects, and behavior information; Step 2: Construct a data graph based on the acquired user information, device information, network environment information, accessed application information, task information, target data objects, and behavioral information; Step 3: Perform real-time dynamic detection on the data map and update the data map in real-time based on the detection results; Step 4: Calculate dynamic risk values in real time based on the dynamically updated data map, and generate or readjust access decisions based on the calculated risk values; Step 5: Encrypt the target data object to generate ciphertext, and generate a data capsule based on the access decision. The data capsule includes ciphertext, policy metadata, key identifier, dynamic watermark, and audit hash. Step Six: Obtain the data key from the key management service based on the key identifier in the data capsule, and perform fragmentation processing on the data key to generate multiple key fragments; at the same time, perform control operations on the key fragments according to the access decision; wherein, the control operations include distribution, combination, freezing or destruction; Step 7: Segment and encrypt the data capsule for transmission based on the access decision; Step 8: Record access events to the data capsule and form hash chain audit evidence.
8. A computer-readable storage medium comprising a stored program, characterized in that, When the program is running, it controls the power equipment containing the computer-readable storage medium to perform the remote office method based on the cloud protocol as described in any one of claims 1 to 6.