Data circulation method, apparatus and system
By generating and executing flow and usage strategies during data circulation, the problem of secure data flow between any two data entities is solved, data usage behavior is controlled, data abuse and leakage are avoided, and circulation performance is improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-09-03
- Publication Date
- 2026-05-15
AI Technical Summary
How to design connectors to ensure the secure flow of data between any two data entities and minimize the occurrence of data misuse and leakage.
By generating and executing flow and usage strategies during the data flow process, it is ensured that data is transmitted and used in accordance with the strategies. This includes setting up management, control, and interface modules on storage and computing devices respectively to control the flow and usage of data.
It enables the control of data users' behavior, ensures data security during the circulation process, avoids data abuse and leakage, and does not require changes to the original usage behavior of the application, thus improving the performance of data circulation.
Smart Images

Figure CN2024116660_15052026_PF_FP_ABST
Abstract
Description
A data circulation method, apparatus and system
[0001] This application claims priority to Chinese Patent Application No. 202311190481.2, filed on September 14, 2023, with the Chinese National Intellectual Property Administration, entitled “A Data Circulation Method, Apparatus and System”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of computer technology, and in particular to a data circulation method, apparatus and system. Background Technology
[0003] The International Data Spaces Association (IDSA) is the most influential international organization in the field of global data circulation, aiming to establish an open, secure, and trustworthy data space. To address data security issues during circulation and effectively restrict data use, IDSA has proposed a connector-based data circulation control system. IDSA states that once any data entity connects to a connector, it can access the data of another data entity through communication between multiple connectors. This constructs a blueprint for secure data circulation, aiming to ensure data flow while protecting the data sovereignty of data owners.
[0004] However, how to design connectors that can ensure the secure flow of data between any two data entities and minimize the occurrence of data misuse and leakage during the flow process is an urgent problem to be solved.
[0005] Summary of the Invention
[0006] To address the aforementioned technical problems, this application provides a data circulation method, apparatus, and system, thereby ensuring the secure circulation of data between any two data entities and preventing issues such as data misuse and data leakage during the circulation process.
[0007] In a first aspect, a data circulation method is provided, comprising: a first storage device acquiring source data from a storage device, generating first data based on the source data, subsequently acquiring a first circulation strategy and a first usage strategy for the first data, and, upon determining that the first data conforms to the first circulation strategy, sending the first data and the first usage strategy to a second storage device. Upon receiving the first data and the first usage strategy from the first storage device, the second storage device, while executing the first usage strategy on the first data, sends the first data and the first usage strategy to a second computing device to control the use of the first data by applications on the second computing device. The first usage strategy is a strategy instructing the second storage device to use the first data; the storage device belongs to a first user; the second storage device and the second computing device belong to a second connection system; the second storage device and the second computing device are used to process the first data according to the instructions of the requesting device; that is, the second connection system is used to process the first data according to the instructions of the requesting device; the requesting device for the first data belongs to the second user; and the storage device and the requesting device for the first data are different devices.
[0008] The above scheme has the following advantages:
[0009] Firstly, the process of the first data flowing from the data owner to the data user includes various stages of data flow, such as creating the first data, determining the first usage strategy, and transmitting the first data. The first storage device only sends the first data when it determines that the first data conforms to the first flow strategy, and instructs the second storage device to use the first data through the first usage strategy. Therefore, it is possible to control the behavior of the data user, thereby ensuring the security of the first data in the flow process and avoiding problems such as data abuse and data leakage.
[0010] Secondly, compared to directly sending the first data to the requesting device, which makes it impossible to control the use of the first data within that device, this technical solution uses a second storage device capable of executing a first usage strategy to process the first data according to the instructions of the requesting device. This ensures that the second computing device's access to, acquisition of, and use of the first data are always constrained by the first usage strategy, thus enabling secure control over the user's behavior and guaranteeing the security of the first data during its circulation. Therefore, the above solution is a practical and feasible solution for implementing the connector-based data circulation management system proposed by IDSA.
[0011] Third, secure transmission of the first data can be achieved using two storage devices. This allows applications on the second computing device to directly access the first data within the same connected system when needed, without altering their existing usage behavior. This facilitates application deployment by data users, eliminating the need for significant adjustments to applications to access the first data and thus improving the performance of the first data across multiple applications.
[0012] In some possible implementations, before the first storage device sends the first data and the first usage policy to the second storage device if it determines that the first data conforms to the first circulation policy, the method further includes: the first storage device receiving a first usage request for requesting the first data, and sending the first data and the first usage policy to the second storage device if it determines that the first usage request and the first data conform to the first circulation policy.
[0013] In the above scheme, the first flow strategy is used to verify the rationality of the data user's first use request, and the first flow strategy is used to check the compliance of the first data, which can control the flow process of the first data and thus ensure the security of the first data in the circulation process.
[0014] In some possible implementations, the above method further includes: the first storage device receiving second data and a second usage policy of the second data sent by the third storage device, and sending the second data and the second usage policy to the first computing device to control the use of the second data by applications on the first computing device when the second usage policy is executed on the second data.
[0015] In the above scheme, the first storage device also supports controlling the first computing device's access to, acquisition of, and use of the second data when executing the second usage policy, thus enabling security control over the behavior of data users and ensuring the security of the second data during circulation.
[0016] In some possible implementations, the first circulation strategy mentioned above includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first storage device and the second storage device. The asset information is generated by the first storage device and includes one or more of the type, size, format, purpose, and availability time of the first data.
[0017] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0018] Secondly, a data circulation method is provided, comprising: a first computing device acquiring source data from a storage device, generating first data based on the source data, subsequently acquiring a first circulation strategy and a first usage strategy for the first data, and, if the first data conforms to the first circulation strategy, sending the first data and the first usage strategy to a second computing device. Upon receiving the first data and the first usage strategy from the first computing device, the second computing device uses the first data while executing the first usage strategy. The first usage strategy instructs the second computing device to use the first data. The first computing device processes the first data according to the instructions of the storage device (belonging to a first user), and the second computing device processes the first data according to the instructions of the device requesting the first data (belonging to a second user). The storage device and the device requesting the first data are different devices.
[0019] The above scheme has the following advantages:
[0020] Firstly, the process of the first data flowing from the data owner to the data user includes various stages of data flow such as creating the first data, transmitting the first data, and using the first data. The first computing device only sends the first data when it determines that the first data conforms to the first flow strategy, and the second computing device can only use the first data when it executes the first usage strategy. Therefore, it is possible to control the behavior of data users, thereby ensuring the security of the first data in the flow process and avoiding problems such as data abuse and data leakage.
[0021] Secondly, compared to directly sending the first data to the requesting device, which makes it impossible to control the use of the first data within that device, this technical solution uses a second computing device capable of executing a first usage strategy to process the first data according to the instructions of the requesting device. This ensures that access to, acquisition of, and use of the first data are always conducted under the constraints of the first usage strategy, thus enabling secure control over the user's behavior and guaranteeing the security of the first data during its circulation. Therefore, the above solution is a practical and feasible solution for implementing the connector-based data circulation management system proposed by IDSA.
[0022] In some possible implementations, before the first computing device sends the first data and the first usage strategy to the second computing device if it determines that the first data conforms to the first flow strategy, the method further includes: the first computing device receiving a first usage request sent by the second computing device for requesting the first data, and sending the first data and the first usage strategy to the second computing device if it determines that the first usage request and the first data conform to the first flow strategy.
[0023] In the above scheme, the first flow strategy is used to verify the rationality of the data user's first use request, and the first flow strategy is used to check the compliance of the first data, which can control the flow process of the first data and thus ensure the security of the first data in the circulation process.
[0024] In some possible implementations, the above method further includes: the first computing device receiving a first usage record of the first data from the second computing device, and determining whether the second computing device's use of the first data conforms to a first usage strategy based on the first usage record, wherein the first usage record is a record of the second computing device's use of the first data.
[0025] In the above scheme, by monitoring the usage behavior of the first data through the first usage record, the behavior of data users can be controlled, thereby ensuring the security of the first data during the circulation process.
[0026] In some possible implementations, the second computing device executes a first usage policy on the first data, generates a first usage record, and uploads the first usage record to the first computing device within the second secure computing environment, thereby controlling the application's use of the first data on the second computing device. The first usage record is a record of the second computing device's use of the first data. The second secure computing environment is a secure, isolated environment used to protect the security of the second computing device, the execution process of the first usage policy, and the usage process of the first data. This can be achieved by closing the application's data input and output interfaces when the application on the second computing device uses the first data, or by deploying a trusted execution environment in the second computing device, or by deploying a virtual machine or container in the second computing device.
[0027] In the above scheme, the second computing device executes the first usage policy on the first data in the second secure computing environment. This ensures that the first data is always used in the second secure computing environment, preventing data leakage, and also ensures that the execution of the first usage policy is not interfered with. Furthermore, generating a first usage record in the second secure computing environment ensures that the first usage record cannot be tampered with, thus ensuring the security and trustworthiness of the first usage record.
[0028] In some possible implementations, the method further includes: the first computing device receiving second data and a second usage policy for the second data sent by the third computing device, and executing the second usage policy on the second data to control the use of the second data by applications on the first computing device. The first computing device is used to process the second data according to the instructions of the device requesting the second data, and the device requesting the second data and the storage device are different devices, or the device requesting the second data and the storage device are the same device.
[0029] In the above scheme, the first computing device also supports executing a second usage policy on the second data to control the use of the second data by applications on the first computing device, thereby enabling secure control over the behavior of data users and ensuring the security of the second data during its circulation.
[0030] In some possible implementations, the first computing device executes a second usage policy on the second data, generates a second usage record, and uploads the second usage record to a third computing device within a first secure computing environment, thereby controlling the use of the second data by applications on the first computing device. The second usage record is a record of the first computing device's use of the second data. The first secure computing environment is a secure, isolated environment used to protect the security of the first computing device, the security of the execution process of the second usage policy, and the security of the use of the second data. This can be achieved by closing the application's data input and output interfaces when the application on the first computing device uses the second data, or by deploying a trusted execution environment in the first computing device, or by deploying a virtual machine or container in the first computing device.
[0031] In the above scheme, the first computing device executes the second usage policy on the second data in the first secure computing environment. This ensures that the second data is always used within the first secure computing environment, preventing data leakage, and also ensures that the execution of the second usage policy is not interfered with. Furthermore, generating the second usage record in the first secure computing environment guarantees that the second usage record cannot be tampered with, ensuring its security and trustworthiness.
[0032] In some possible implementations, the first circulation strategy mentioned above includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first storage device and the second storage device. The asset information is generated by the first storage device and includes one or more of the type, size, format, purpose, and availability time of the first data.
[0033] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0034] Thirdly, a data circulation device is provided, which serves as a first storage device, comprising: a first management module, a first control module, and a first docking module. The first management module is used to obtain source data from the storage device and generate first data based on the source data. The first control module is used to obtain a first circulation strategy and a first usage strategy for the first data. The first docking module is used to send the first data and the first usage strategy to a second storage device when it is determined that the first data conforms to the first circulation strategy. The first usage strategy is a strategy that instructs the second storage device to use the first data. The storage device belongs to a first user. The second storage device is used to process the first data according to the instructions of the device that requests the first data. The device that requests the first data belongs to the second user. The storage device and the device that requests the first data are different devices.
[0035] In some possible implementations, the first docking module is specifically used to receive a first usage request for requesting first data, and, if it is determined that the first usage request and the first data conform to the first flow strategy, send the first data and the first usage strategy to the second storage device.
[0036] In some possible implementations, the first docking module described above is also used to receive second data sent by the third storage device and a second usage strategy for the second data;
[0037] The aforementioned first control module is further configured to send the second data and the second usage strategy to the first computing device to control the use of the second data by the first computing device when the second usage strategy is executed on the second data.
[0038] In some possible implementations, the first circulation strategy mentioned above includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first storage device and the second storage device. The asset information is generated by the first management module mentioned above. The asset information includes one or more of the type, size, format, purpose, and availability time of the first data.
[0039] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0040] Fourthly, a data circulation device is provided, which serves as a first computing device, comprising: a second management module, a second control module, and a second docking module. The second management module is used to obtain source data from a storage device and generate first data based on the source data. The second control module is used to obtain a first circulation strategy and a first usage strategy for the first data. The second docking module is used to send the first data and the first usage strategy to the second computing device when it is determined that the first data conforms to the first circulation strategy. The first usage strategy is a strategy that instructs the second computing device to use the first data. The first computing device is used to process the first data according to the instructions of the storage device, which belongs to a first user. The second computing device is used to process the first data according to the instructions of a device that requests the first data, which belongs to a second user. The storage device and the device that requests the first data are different devices.
[0041] In some possible implementations, the aforementioned second docking module is specifically used to receive a first usage request sent by the second computing device for requesting first data, and to send the first data and the first usage strategy to the second computing device if it is determined that the first usage request and the first data conform to the first flow strategy.
[0042] In some possible implementations, the first computing device is further configured to receive a first usage record of the first data from the second computing device, and determine whether the use of the first data by the second computing device conforms to a first usage strategy based on the first usage record, wherein the first usage record is a record of the use of the first data by the second computing device.
[0043] In some possible implementations, the aforementioned second docking module is further configured to receive second data and a second usage strategy for the second data sent by the third computing device, and execute the second usage strategy on the second data to control the use of the second data by the first computing device. The first computing device is configured to process the second data according to the instructions of the device requesting the second data, and the device requesting the second data and the storage device are different devices, or the device requesting the second data and the storage device are the same device.
[0044] In some possible implementations, the first computing device has a first secure computing environment. The second control module is specifically used within this first secure computing environment to execute a second usage policy on the second data, generate a second usage record, and upload the second usage record to a third computing device, thereby controlling the first computing device's use of the second data. The second usage record is a record of the first computing device's use of the second data. The first secure computing environment is a secure, isolated environment used to protect the security of the first computing device, the security of the execution process of the second usage policy, and the security of the use of the second data. This is achieved by closing the data input and data output interfaces when the first computing device uses the second data, or by deploying a trusted execution environment in the first computing device, or by deploying a virtual machine or container in the first computing device.
[0045] In some possible implementations, the first circulation strategy mentioned above includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first computing device and the second computing device. The asset information is generated by the first computing device and includes one or more of the type, size, format, purpose, and availability time of the first data.
[0046] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0047] Fifthly, a data circulation device is provided as a second storage device, comprising: a third docking module and a third control module. The third docking module is used to receive first data and a first usage strategy of the first data sent by a first storage device. The third control module is used to send the first data and the first usage strategy to a second computing device to control the use of the first data by the second computing device when the first usage strategy is executed on the first data. The second storage device and the second computing device belong to a second connection system, which is used to process the first data according to the instructions of the device requesting the first data.
[0048] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0049] In a sixth aspect, a data circulation device is provided as a second computing device, comprising: a fourth docking module and a fourth control module. The fourth docking module is used to receive first data and a first usage strategy of the first data sent by a first computing device; the fourth control module is used to use the first data when executing the first usage strategy. The second computing device is used to process the first data according to instructions from a requesting device, and the first computing device is used to process the first data according to instructions from a storage device. The first data is generated based on source data in the storage device. The storage device belongs to a first user, and the requesting device belongs to a second user; the storage device and the requesting device are different devices.
[0050] In some possible implementations, the second computing device has a second secure computing environment. The fourth control module is specifically used in the second secure computing environment to execute a first usage policy on the first data, generate a first usage record, and upload the first usage record to the first computing device, thereby controlling the use of the first data by applications on the second computing device. The first usage record is a record of the second computing device's use of the first data. The second secure computing environment is a secure, isolated environment used to protect the security of the second computing device, the security of the execution process of the first usage policy, and the security of the use of the first data. This is achieved by closing the data input and data output interfaces when the second computing device uses the first data, or by deploying a trusted execution environment in the second computing device, or by deploying a virtual machine or container in the second computing device.
[0051] In some possible implementations, the aforementioned first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0052] A seventh aspect provides a data circulation system, including a first storage device as described in any of the third aspects, and / or a second storage device as described in any of the fifth aspects.
[0053] Eighthly, a data circulation system is provided, including a first computing device as described in any of the fourth aspects, and / or a second computing device as described in any of the sixth aspects.
[0054] In a ninth aspect, a computing device cluster is provided, including at least one computing device, each computing device including a processor and memory;
[0055] The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any of the second aspects.
[0056] In a tenth aspect, a storage device cluster is provided, including at least one storage device, each storage device including a processor and memory;
[0057] The processor of the at least one storage device is configured to execute instructions stored in the memory of the at least one storage device to cause the cluster of storage devices to perform the method as described in any of the first aspects.
[0058] In an eleventh aspect, a computer program product containing instructions is provided, which, when executed by a cluster of computing devices, cause the cluster of computing devices to perform a method as described in either the first aspect or the second aspect.
[0059] In a twelfth aspect, a computer-readable storage medium is provided, including computer program instructions that, when executed by a cluster of computing devices, perform a method as described in either the first or second aspect. Attached Figure Description
[0060] To more clearly illustrate the technical solutions in the embodiments of this application or the background art, the accompanying drawings used in the embodiments of this application or the background art will be described below.
[0061] Figure 1 is a schematic diagram of a data circulation scenario involved in this application;
[0062] Figure 2 is a structural schematic diagram of a connection system provided in this application;
[0063] Figure 3 is a schematic diagram of the structure of a storage device provided in this application;
[0064] Figure 4 is a schematic diagram of the structure of a computing device provided in this application;
[0065] Figure 5 is a schematic diagram of the structure of a database system provided in this application;
[0066] Figure 6 is a flowchart illustrating a data circulation method provided in this application;
[0067] Figure 7 is a flowchart illustrating another data circulation method provided in this application;
[0068] Figure 8 is a schematic diagram of the structure of a data circulation system provided in this application;
[0069] Figure 9 is a schematic diagram of another data circulation system provided in this application;
[0070] Figure 10 is a schematic diagram of the structure of a computing device cluster provided in this application;
[0071] Figure 11 is a schematic diagram of another computing device cluster provided in this application;
[0072] Figure 12 is a schematic diagram of the structure of a storage device cluster provided in this application;
[0073] Figure 13 is a schematic diagram of another storage device cluster provided in this application. Detailed Implementation
[0074] The embodiments of this application are described below with reference to the accompanying drawings.
[0075] To facilitate understanding of the embodiments of this application, the application scenarios involved in this application will be introduced first.
[0076] Referring to Figure 1, which is a schematic diagram of a data circulation scenario involved in this application, the data circulation scenario involved in this application includes multiple data entities, such as industrial data cloud 12, enterprise cloud 13, data marketplace 14, Internet of Things cloud 15, open data source 16, enterprise equipment (enterprise equipment 171, enterprise equipment 172, enterprise equipment 173...) and personal equipment (personal equipment 181, personal equipment 182, personal equipment 183...), etc.
[0077] These data entities need to exchange data to realize its value. However, IDSA proposes that while ensuring data flow, it is also necessary to protect the data sovereignty of data owners. Therefore, a connection system must be established between data entities, allowing any data entity to access the data of another data entity through communication between multiple connection systems. However, how to design a connection system that guarantees the secure flow of data between any two data entities and minimizes data misuse and leakage during the process is a pressing issue that needs to be addressed.
[0078] To address the aforementioned issues, this application provides a data circulation method, apparatus, and system capable of enabling data circulation between the aforementioned multiple data entities.
[0079] Referring to Figure 2, which is a schematic diagram of a connection system provided in this application, the connection system 20 provided in this application includes: one or more storage devices 21, one or more computing devices 22, and one or more database systems 23.
[0080] In some possible implementations, storage device 21 is used to store unstructured and semi-structured data, including operational data from computing device 22. Storage device 21 can be a server, network attached storage (NAS), cloud storage gateway (CSG), etc. Unstructured data includes documents, text, images, reports, graphics, audio, video, etc. Semi-structured data includes log files, XML documents, JSON documents, emails, HTML documents, etc.
[0081] In some possible implementations, computing device 22 is used to provide computing services or application services. One or more applications, such as application software, algorithms, or function calls, can be deployed on computing device 22. Computing device 22 can be a supercomputer, a network computer (such as a server, workstation, hub, switch, router), an industrial control computer (such as a PC bus industrial computer, programmable logic control system, distributed control system, fieldbus system, CNC system), a personal computer (such as a desktop computer, all-in-one computer, laptop computer, handheld computer, tablet computer), or an embedded processor (such as an embedded microcontroller, embedded microprocessor, embedded digital signal processor, embedded system-on-a-chip), etc.
[0082] In some possible implementations, database system 23 is used to store structured data. Database system 23 may include one or more storage devices. Alternatively, database system 23 may include one or more calculators. The structured data includes tables.
[0083] In some possible implementations, within the connection system 20, the computing device 22 can access unstructured or semi-structured data in the storage device 21, and also access structured data in the database system 23, based on data requests generated by the application. Furthermore, the computing device 22 can process the unstructured or semi-structured data obtained from the storage device 21 to obtain structured data, and then store the structured data in the database system 23. Alternatively, the computing device 22 can process the structured data obtained from the database system 23 to obtain unstructured or semi-structured data, and then store the unstructured or semi-structured data in the storage device 21.
[0084] In one specific implementation, when storage device 21 is used to store ciphertext of unstructured data and ciphertext of semi-structured data, and database system 23 is used to store ciphertext of structured data, computing device 22 obtains the ciphertext of unstructured or semi-structured data from storage device 21, decrypts it using a decryption algorithm, processes the decrypted unstructured or semi-structured data to obtain structured data, encrypts the structured data using an encryption algorithm, obtains the ciphertext of the structured data, and stores the ciphertext of the structured data in database system 23. Alternatively, computing device 22 obtains the ciphertext of structured data from database system 23, decrypts it using a decryption algorithm, processes the decrypted structured data to obtain unstructured or semi-structured data, encrypts the unstructured or semi-structured data using an encryption algorithm, obtains the ciphertext of the unstructured or semi-structured data, and stores the ciphertext of the unstructured or semi-structured data in storage device 21. The ciphertext is the string obtained by encrypting the data using an encryption algorithm.
[0085] It should be understood that the sources of the ciphertext of unstructured data, semi-structured data, and structured data mentioned above are merely examples. The ciphertext of unstructured data and semi-structured data can also be obtained by the storage device 21 encrypting the unstructured data and semi-structured data respectively using encryption algorithms, and the ciphertext of structured data can also be obtained by the database system 23 encrypting the structured data using encryption algorithms. Alternatively, the ciphertext of unstructured data, semi-structured data, and structured data can all be obtained by the computing device 22 encrypting the unstructured data, semi-structured data, and structured data respectively using encryption algorithms. This is not intended as a specific limitation.
[0086] In some possible implementations, storage device 21 and database system 23 can also be used to store anonymous data. Specifically, the anonymous data in storage device 21 is obtained by de-identifying unstructured or semi-structured data. The anonymous data in database system 23 is obtained by de-identifying structured data.
[0087] In some possible implementations, since different applications in computing device 22 have different requirements for data types, database system 23 can directly obtain unstructured or semi-structured data from storage device 21, process the unstructured or semi-structured data to obtain structured data, and then provide the structured data to the applications in computing device 22.
[0088] In some possible implementations, storage device 21, computing device 22, and database system 23 can be the same device; therefore, connection system 20 can be a single device. Taking a server as an example, storage device 21 can be server A, computing device 22 can also be server A, and database system 23 can also be server A. That is, server A, as connection system 20, can implement the functions of storage device 21, computing device 22, and database system 23.
[0089] In some possible implementations, the connection system 20 connects to the data entity, thereby processing the data on behalf of the data storage device or the data-demanding device. The data storage device or data-demanding device can be a storage device, a computing device, or a database system. The connection system 20 connecting to the data entity can include at least the following three implementations:
[0090] In one specific implementation, the data entity is deployed on the computing device 22 of the connection system 20, thereby establishing a connection between the connection system 20 and the data entity. This allows the connection system 20 to process data on behalf of the data storage device or the data-demanding device. For example, an industrial data cloud 12, an enterprise cloud 13, a data trading platform 14, an IoT cloud 15, or an open data source 16 can be deployed on the computing device 22. This allows the computing device 22 of the connection system 20 to store data or data description information, and the storage device 21 of the connection system 20 can directly obtain data or data description information from the computing device 22. The data can be unstructured, semi-structured, or structured. The data description information can include the data type, size, format, etc.
[0091] In another specific implementation, the data entity acts as a data storage device external to the connection system 20. The data storage device imports data into the storage device 21 of the connection system 20. Alternatively, the computing device 22 of the connection system 20 accesses data in the data storage device and stores the acquired data in the storage device 21, thereby establishing a connection between the data entity and the connection system 20. This allows the connection system 20 to process data on behalf of the data storage device. For example, enterprise devices 171, 172, and 173 act as data storage devices external to the connection system 20. The computing device 22 can access data in enterprise devices 171, 172, or 173 and store the data obtained from them in the storage device 21, enabling the connection system 20 to process data on behalf of enterprise devices 171, 172, or 173.
[0092] In another specific implementation, the data entity acts as a data-demanding device outside the connection system 20. The data user deploys applications that can use data on the data-demanding device on the computing device 22 of the connection system 20. The applications on the computing device 22 then use the data, ensuring that data is always provided only to applications on the computing device 22, and not to applications outside the connection system 20. If the application generates new data (such as intermediate results or calculation results) during data usage, the computing device 22 imports the new data into the data-demanding device. In summary, this establishes a connection between the data entity and the connection system 20, enabling the connection system 20 to process data on behalf of the data-demanding device. For example, personal devices 181, 182, and 183, as data-demanding devices external to the connection system 20, can deploy applications on personal devices 181, 182, or 183 on computing device 22. The applications on computing device 22 can use the data and then import the intermediate results, calculation results, and other new data generated by the applications into personal devices 181, 182, or 183, so that the connection system 20 can process the data on behalf of personal devices 181, 182, or 183.
[0093] The specific structures of the aforementioned storage device 21, computing device 22, and database system 23 will be described in detail below.
[0094] Referring to Figure 3, which is a schematic diagram of the structure of a storage device provided in this application, the storage device 21 includes a management module 211, a docking module 212, and a control module 213.
[0095] In some possible implementations, the management module 211 is used to store and manage data 2111, data description information 2112, and data asset information 2113. Data 2111 includes unstructured data, semi-structured data, and operational data of the computing device 22. Data description information 2112 includes the type, size, format, etc., of data 2111. Data asset information 2113 includes the type, size, format, purpose, availability time, etc., of data 2111.
[0096] In some possible implementations, the interface module 212 manages all data input to and output from the connection system 20, as well as performs data transfer with the interface module of the storage device of another connection system 20. To achieve this data transfer, the interface module 212 needs to maintain a transport protocol 2121 and usage requirements 2122. The transport protocol 2121 can be Secure Sockets Layer (SSL), Transport Layer Security (TLS), etc. The usage requirements 2122 include the usage time, scope, and method of the data 2111.
[0097] In some possible implementations, the control module 213 obtains a circulation strategy 2131 based on asset information 2113 in the management module 211, and obtains a usage strategy 2132 based on usage requirements 2122 in the interface module 212. The circulation strategy 2131 is used to restrict the circulation process of data 2111. The usage strategy 2132 is used to control the usage process of data 2111.
[0098] In some possible implementations, the control module 213 acquiring the flow strategy 2131 may include at least the following two implementations:
[0099] In one specific implementation, the control module 213 obtains policy resources from the policy management module, and then uses these policy resources to set a flow policy 2131 based on the asset information 2113 in the data. The policy management module stores and manages policy resources. It can be deployed on storage device 21 or on a separate storage or computing device. Specifically, after receiving the asset information 2113 from the management module 211, the control module 213 generates a first policy resource request and sends it to the policy management module, enabling it to access the policy resources within the module. Subsequently, the control module 213 uses the policy resources to set the specific content of the flow policy 2131 based on the asset information 2113 in the data.
[0100] In another specific implementation, the control module 213 sends the asset information 2113 of the data to the strategy management module and obtains the circulation strategy 2131 from the strategy management module. Specifically, the control module 213 sends the asset information 2113 of the data obtained from the management module 211 to the strategy management module. Based on the asset information 2113 of the data, the strategy management module uses strategy resources to set the specific content of the circulation strategy 2131, and then sends the set circulation strategy 2131 to the control module 213.
[0101] The specific content of the aforementioned data flow strategy 2131 is determined by the data owner and may include access content, available time periods, and target users. For example, if the created data includes both confidential and non-confidential data, it is necessary to prevent confidential data from flowing to external systems. That is, confidential data should only be stored in the first data entity or the first connection subsystem and provided only to the data owner. Therefore, the access content can be specified as non-confidential data in the data flow strategy, i.e., confidential data should be set to not be accessible to external users. Alternatively, for data that is periodically opened, the available time periods can be set in the data flow strategy to prevent data from flowing to external systems during unavailable time periods. Or, if the data is only provided to specific users, the target users need to be set in the data flow strategy to prevent data from flowing to unsuitable users.
[0102] It should be understood that the specific content of the above circulation strategy 2131 is merely an example and is not intended as a specific limitation.
[0103] In some possible implementations, corresponding to the way the control module 213 obtains the flow strategy 2131, the way the control module 213 obtains the usage strategy 2132 can also include at least the following two implementations:
[0104] In one specific implementation, the control module 213 obtains policy resources from the policy management module, and then uses the policy resources to set the usage policy 2132 based on the usage requirement 2122. Specifically, after receiving the usage requirement 2122 sent by the interface module 212, the control module 213 generates a second policy resource request and sends the second policy resource request to the policy management module, enabling the control module 213 to access the policy resources in the policy management module. Subsequently, the control module 213 uses the policy resources to set the specific content of the usage policy 2132 based on the usage requirement 2122.
[0105] In another specific implementation, the control module 213 sends the usage request 2122 to the policy management module and obtains the usage policy 2132 from the policy management module. Specifically, the control module 213 sends the usage request 2122 to the policy management module. Based on the usage request 2122, the policy management module uses policy resources to set the specific content of the usage policy 2132, and then sends the set usage policy 2132 back to the control module 213.
[0106] The specific content of the above usage strategy 2132 is determined by the data owner and may include usage time, usage scope, usage method, collection of usage records, etc. For example, (1) usage time: access time, available time period (such as timed opening, deletion upon expiration); (2) usage scope: IP address of the device used; (3) usage method: access method (such as self-destructing after reading), number of times used, forwarding permission (such as not allowing forwarding to outside the connected system, forwarding to outside the connected system cannot be decrypted); (4) collection of usage records: collection method (such as real-time collection, timed collection), access permission (such as not allowing modification), where usage records include usage behavior logs, data management logs, etc.
[0107] It should be understood that the specific content of the above-mentioned strategy 2132 is merely an example and is not intended as a specific limitation.
[0108] In some possible implementations, the aforementioned management module 211, docking module 212, and control module 213 can be implemented by software in storage device 21 or by hardware in storage device 21.
[0109] Referring to Figure 4, which is a schematic diagram of the structure of a computing device provided in this application, the computing device 22 includes a management module 221, a docking module 222, and a control module 223.
[0110] In some possible implementations, the management module 221 is used to store and manage data 2211, data description information 2212, and data asset information 2213. Data 2211 may include unstructured data, semi-structured data, and structured data. The data description information 2212 may include the data type, size, format, etc., of the data 2211. The data asset information 2213 may include the data type, size, format, purpose, availability time, etc., of the data 2211.
[0111] In some possible implementations, the interface module 222 manages all data input to and output from the connection system 20, as well as performs data transmission with the interface module of another computing device in the connection system 20. To achieve this data transmission, the interface module 222 needs to maintain a transmission protocol 2221 and usage requirements 2222. The transmission protocol 2221 can be SSL, TLS, etc. The usage requirements 2222 include the usage time, scope, and method of the data 2211.
[0112] In some possible implementations, control module 223 is used to obtain a circulation strategy 2231 based on asset information 2213 in management module 221, and a usage strategy 2232 based on usage requirements 2222 in interface module 222. The circulation strategy 2231 is used to restrict the circulation process of data 2211. The usage strategy 2232 is used to control the usage process of data 2211. The implementation method of control module 223 obtaining circulation strategy 2231 can refer to the implementation method of control module 213 obtaining circulation strategy 2131 in Figure 3 above, and the implementation method of control module 223 obtaining usage strategy 2232 can refer to the implementation method of control module 213 obtaining usage strategy 2132 in Figure 3 above.
[0113] In some possible implementations, the aforementioned management module 221, docking module 222, and control module 223 can be implemented by software in the computing device 22 or by hardware in the computing device 22.
[0114] Referring to Figure 5, which is a schematic diagram of the structure of a database system provided in this application, the database system 23 includes a management module 231, an interface module 232, and a control module 233.
[0115] In some possible implementations, the management module 231 is used to store and manage data 2311, data description information 2312, and data asset information 2313. Data 2311 may include structured data, and the data description information 2312 may include the type, size, format, etc., of the data 2311. The data asset information 2313 may include the type, size, format, purpose, availability time, etc., of the data 2311.
[0116] In some possible implementations, the interface module 232 manages all data input to and output to the connection system 20, as well as performs data transfer with the interface module of another connection system 20's database system. To achieve this data transfer, the interface module 232 needs to maintain a transmission protocol 2321 and usage requirements 2322. The transmission protocol 2321 can be SSL, TLS, etc. The usage requirements 2322 include the usage time, scope, and method of the data 2311.
[0117] In some possible implementations, control module 233 is used to obtain a circulation strategy 2331 based on asset information 2313 in management module 231, and a usage strategy 2332 based on usage requirements 2322 in interface module 232. The circulation strategy 2331 is used to restrict the circulation process of data 2311. The usage strategy 2332 is used to control the usage process of data 2311. The implementation method of control module 233 obtaining circulation strategy 2331 can refer to the implementation method of control module 213 obtaining circulation strategy 2131 in Figure 3 above, and the implementation method of control module 233 obtaining usage strategy 2332 can refer to the implementation method of control module 213 obtaining usage strategy 2132 in Figure 3 above.
[0118] In some possible implementations, the aforementioned management module 231, interface module 232, and control module 233 can be implemented by software in the database system 23, or by hardware in the database system 23.
[0119] In some possible implementations, connection system 20 (referred to as the first connection system) includes a first storage device, a first computing device, and a first database system. Another connection system 20 (referred to as the second connection system) includes a second storage device, a second computing device, and a second database system. When the first connection system needs to transmit data with the second connection system, data transmission can be achieved either by connecting the first storage device to the second storage device or by connecting the first computing device to the second computing device. Specifically, the first storage device has a first management module, a first docking module, and a first control module; the first computing device has a second management module, a second docking module, and a second control module. The second storage device has a third management module, a third docking module, and a third control module; the second computing device has a fourth management module, a fourth docking module, and a fourth control module. The first and second storage devices can refer to storage device 21 in Figure 3 above. The first and third management modules can refer to management module 211 of storage device 21 in Figure 3 above. The first and third docking modules can refer to docking module 212 of storage device 21 in Figure 3 above. The first and third control modules can refer to control module 213 of storage device 21 in Figure 3 above. The first and second computing devices can refer to computing device 22 in Figure 4 above. The second and fourth management modules can refer to management module 221 of computing device 22 in Figure 4 above. The second and fourth docking modules can refer to docking module 222 of computing device 22 in Figure 4 above. The second and fourth control modules can refer to control module 223 of computing device 22 in Figure 4 above.
[0120] The following describes a data flow method using a first connection system to process the first data according to instructions from the storage device, and a second connection system to process the first data according to instructions from the requesting device. The data transfer between the first and second storage devices serves as an example of data transfer between the two connection systems. Specifically, the storage device for the first data belongs to a first user, and the requesting device for the first data belongs to a second user; the storage device and the requesting device are different devices.
[0121] Referring to Figure 6, Figure 6 is a flowchart illustrating a data flow method provided in this application. As shown in Figure 6, the data flow method provided in this application includes:
[0122] S601: The first storage device establishes a first secure communication channel with the second storage device.
[0123] In some possible implementations, to ensure the confidentiality and privacy of data transmitted between the first storage device and the second storage device, a first secure communication channel is established between the first docking module of the first storage device and the third docking module of the second storage device based on a transmission protocol. The transmission protocol can be transmission protocol 2121 in docking module 212 in Figure 3.
[0124] In one specific implementation, the first docking module and the third docking module determine the communication key based on a four-way handshake using SSL or TLS, thereby establishing a first secure communication channel. This allows the data transmitted between the two modules to be encrypted using the communication key, effectively preventing the first data from being stolen by a third party.
[0125] S602: The first storage device creates first data and asset information of the first data, and obtains the first flow strategy of the first data.
[0126] In some possible implementations, the first management module of the first storage device obtains source data from the storage device, derives description information of the first data based on the source data, and then creates the first data and its asset information based on the description information. The source data is created by the first user. The description information of the first data includes the type, size, and format of the source data, etc. The asset information of the first data includes the type, size, format, purpose, and availability time of the first data, etc. The first storage device can be storage device 21 in Figure 3, the first management module can be management module 211 of storage device 21 in Figure 3, the first data can be data 2111 in management module 211 in Figure 3, the description information of the first data can be the description information 2112 of the data in management module 211 in Figure 3, and the asset information of the first data can be the asset information 2113 of the data in management module 211 in Figure 3.
[0127] In some possible implementations, the way in which the first storage device obtains the first flow strategy can be referred to the way in which the control module 213 obtains the flow strategy 2131 in Figure 3.
[0128] S603: The first storage device publishes asset information for the first data.
[0129] In some possible implementations, the asset information published by the first storage device as the first data can include at least the following two implementations:
[0130] In one specific implementation, the first docking module of the first storage device publishes the asset information of the first data obtained from the first management module to the outside of the first connection system. The first docking module can be docking module 212 of the storage device 21 in Figure 3.
[0131] In another specific implementation, the first docking module of the first storage device uploads the asset information of the first data to the data circulation service system, which then publishes the asset information of the first data to the outside of the first connection system. The data circulation service system can be a system established by an independent third-party organization to provide public services for data circulation, including authenticating user identity, authenticating device identity, providing trusted applications, managing data asset information, managing data keys, managing data transaction processes, auditing and tracing, etc.
[0132] S604: The second storage device sends a first usage request to the first storage device based on the asset information of the first data. Correspondingly, the first storage device receives the first usage request sent by the second storage device.
[0133] The second storage device can be storage device 21 in Figure 3.
[0134] Among some possible implementations, the generation of the first use request can include at least the following two implementations:
[0135] In one specific implementation, after the second storage device receives the asset information of the first data published by the first storage device, the third control module of the second storage device generates a first usage request based on the asset information of the first data and sends the first usage request to the first storage device. The third control module can be the control module 213 of the storage device 21 in Figure 3.
[0136] In another specific implementation, after receiving the asset information of the first data published by the first storage device through an application in the second computing device, the data user generates a first data request using the application. Alternatively, when using the application in the second computing device, the data that the application needs to access is matched with the asset information of the first data published by the first storage device; if the match is successful, a first data request is generated. Subsequently, the second computing device sends the first data request to the second storage device. The first control module of the second storage device converts the first data request into a first usage request and sends the first usage request to the first storage device. The second computing device can be computing device 22 as shown in Figure 4.
[0137] S605: The first storage device determines whether the first usage request and the first data conform to the first flow strategy.
[0138] In some possible implementations, the first usage request includes the identity information of the data user, the identity information of the second storage device, the identity information of the second computing device, the request content, the request usage time, the request usage scope, the request usage method, and so on.
[0139] In some possible implementations, the first storage device determines whether the first usage request conforms to the first flow policy, including:
[0140] (1) Verify identity accuracy. The first flow strategy specifies the user of the first data. The first control module of the first storage device determines whether the identity information of the data user (e.g., certificate, trusted credentials), the identity information of the second storage device (e.g., device certificate), and the identity information of the second computing device (e.g., device certificate) in the first usage request conform to the user's specifications in the first flow strategy. If they conform, it indicates that the data user, the second storage device, and the second computing device are trusted; if they do not conform, it indicates that the first usage request is unreasonable, and the first storage device rejects the first usage request. The first control module can be the control module 213 of the storage device 21 in Figure 3.
[0141] (2) Verify the reasonableness of the request content. The first flow strategy specifies the access content of the first data. The first control module of the first storage device determines whether the request content in the first use request exceeds the access content specified in the first flow strategy. If it does not exceed the specification, the request content is reasonable; if it exceeds the specification, part of the request content is unreasonable, and the first storage device informs the data user of the unreasonable part of the request content. For example, if the first flow strategy specifies that the access content of the first data is non-confidential data, but the request content in the first use request includes both confidential and non-confidential data, then the request content exceeds the specification, and the first storage device informs the data user that "the first use request to obtain confidential data does not comply with the specification."
[0142] (3) Verify whether the request is reasonable. The first flow strategy sets the usage information of the first data. The first control module of the first storage device determines whether the request requirements in the first usage request (such as the requested usage time, the requested usage scope, the requested usage method, etc.) match the usage information set in the first flow strategy. If they match, it indicates that the request is reasonable; if they do not match, it indicates that part of the request is unreasonable. The first storage device then informs the data user of the unreasonable part of the request.
[0143] It should be understood that the specific content of the first verification request mentioned above is merely an example and is not intended as a specific limitation.
[0144] It should be understood that this technical solution can either execute the above step S601 first, and then execute the above operation of the first storage device determining whether the first usage request conforms to the first flow policy; or it can execute the above operation of the first storage device determining whether the first usage request conforms to the first flow policy first, and then execute the above step S601 after the first storage device determines that the first usage request conforms to the first flow policy.
[0145] In some possible implementations, the first storage device determines whether the first data conforms to the first flow strategy, including:
[0146] (1) Verify the type of the first data. The first transfer strategy specifies the types of data that are allowed to be transferred. The first control module of the first storage device determines whether the type of the first data exceeds the data type specification in the first transfer strategy. If it does not exceed the specification, it means that all the contents of the first data can be transferred to the second storage device; if it exceeds the specification, it means that some data in the first data cannot be transferred to the second storage device. The first storage device then informs the data user of the data that cannot be transferred. For example, the first transfer strategy specifies that the allowed data type is non-sensitive data. If the first data contains both sensitive data and non-sensitive data, then the type of the first data exceeds the specification. The first storage device then informs the data user that "the first data cannot be sent because it contains sensitive data".
[0147] (2) Verify the estimated transmission time of the first data. The first transfer strategy specifies the available time period for the first data. The first control module of the first storage device determines whether the estimated transmission time of the first data exceeds the specified available time period in the first transfer strategy. If it does not exceed the specified period, it indicates that the first data can be transmitted to the second storage device within the estimated transmission time. If it exceeds the specified period, it indicates that the first data cannot be transmitted to the second storage device within the estimated transmission time. In this case, the first storage device refuses to send the first data to the second storage device and informs the data user.
[0148] It should be understood that the specific content of the above-mentioned verification of the first data is merely an example and is not intended as a specific limitation.
[0149] In summary, the first flow strategy can verify the first usage request and the first data, thereby controlling the first storage device to send the first data.
[0150] In some possible implementations, in addition to the first storage device needing to determine whether the first data conforms to the first flow strategy after receiving the first usage request, the first storage device also needs to determine whether the data conforms to the data flow strategy before transmitting the data to the second storage device each time, in order to avoid data leakage during the flow process.
[0151] S606: First usage strategy for the first storage device to acquire first data.
[0152] In some possible implementations, the first usage strategy is obtained based on usage requirements. Specifically, after establishing the first secure communication channel in step S601 above, the first connection system and the second connection system can respectively utilize the first docking module and the third docking module to negotiate the usage requirements of the first data through the first secure communication channel. Subsequently, the first control module of the first storage device obtains the first usage strategy based on the usage requirements. The usage requirements can be usage requirement 2122 in docking module 212 in Figure 3, and the implementation method of the first control module obtaining the first usage strategy can refer to the implementation method of control module 213 obtaining usage strategy 2132 in Figure 3. For the sake of brevity, it will not be elaborated further here.
[0153] In some possible implementations, the first transfer strategy can be obtained through step S602 above, or it can be obtained based on the transfer requirement. Specifically, after establishing the first secure communication channel in step S601 above, the first connection system and the second connection system can respectively utilize the first docking module and the third docking module to negotiate the transfer requirement of the first data through the first secure communication channel. Subsequently, the first control module of the first storage device obtains the first transfer strategy based on the transfer requirement. The process of the first control module obtaining the first transfer strategy based on the transfer requirement is as follows: after receiving the transfer requirement sent by the first docking module, the first control module sets the first transfer strategy based on the transfer requirement using the policy resources in the policy management module. Alternatively, the first control module sends the received transfer requirement to the policy management module, and the policy management module sets the first transfer strategy based on the transfer requirement using the policy resources, and then sends the set first transfer strategy back to the first control module.
[0154] S607: Upon determining that the first usage request and the first data conform to the first flow policy, the first storage device sends the first data and the first usage policy to the second storage device through the first secure communication channel. Correspondingly, the second storage device receives the first data and the first usage policy sent by the first storage device through the first secure communication channel.
[0155] In some possible implementations, the first storage device sending the first data and the first usage policy to the second storage device through a first secure communication channel may include at least the following four implementations:
[0156] In one specific implementation, within the first storage device, a first interface module obtains first data from a first management module and a first usage policy from a first control module. It then binds the first data and the first usage policy (for example, by including the first usage policy in the metadata of the first data, or by including a link to the first usage policy in the first data so that accessing the first data requires accessing the first usage policy, etc.). This establishes a mutual association between the first data and the first usage policy. The bound first data and the first usage policy are then sent to a third interface module of the second storage device via a first secure communication channel. Specifically, the first interface module of the first storage device can either send the first data first, then the first usage policy; or send the first usage policy first, then the first data; or send the first data and the first usage policy together.
[0157] In another specific implementation, inside the first storage device, the first control module obtains the first data from the first management module, binds the first data with the first usage policy, and then sends the bound first data and the first usage policy to the first docking module, which then sends them to the third docking module through the first secure communication channel.
[0158] In another specific implementation, inside the first storage device, the first control module obtains the first data from the first management module, encapsulates the first data and the first usage policy into a new data packet, and then sends the new data packet to the first docking module, which then sends it to the third docking module through the first secure communication channel.
[0159] In another specific implementation, inside the first storage device, the first control module obtains the first data from the first management module, encrypts the first data and the first usage policy, encapsulates the encrypted first data and the first usage policy into a new data packet, and then sends the new data packet to the first docking module, which then sends it to the third docking module through the first secure communication channel.
[0160] It should be understood that the above method of binding or encapsulating the first data and the first usage strategy is merely an example and is not intended as a specific limitation.
[0161] In some possible implementations, within the second storage device, the third docking module stores the received first data and the first usage policy in the third management module.
[0162] S608: The second storage device sends the first data and the first usage policy to the second computing device when executing the first usage policy on the first data. Accordingly, the second computing device receives the first data and the first usage policy sent by the second storage device.
[0163] In some possible implementations, a data user generates a first data request when using an application on the second computing device, corresponding to the first data request generated in step S603 above. Subsequently, the second computing device sends the first data request to the second storage device. Upon receiving the first data request, the third control module of the second storage device executes a first usage policy obtained from the third management module. This controls the second computing device's access to the first data in the third management module. Specifically, if the first usage policy is encapsulated, it is first decapsulated before execution. For example, if the first usage policy specifies the number of times the first data can be accessed, the third control module records the number of times the second computing device accesses the first data. When the number of times the second computing device accesses the first data exceeds the specified number of accesses, the third control module prohibits the second computing device from accessing the data. Alternatively, if the first usage policy specifies a reading period for the first data, the third control module records the reading time of the first data by the second computing device. When the second computing device continues to read the first data outside the specified reading period, the third control module prohibits the second computing device from reading the data. In summary, the third control module can control the second computing device's acquisition behavior of the first data by executing the first usage strategy on the first data, that is, it can control the second computing device's use of the first data, thereby effectively ensuring the security of the first data during use.
[0164] It should be understood that the sending object of the second storage device in step S608 above is merely an example and is not intended as a specific limitation. For example, the second storage device may also send the first data and the first usage policy to the second database system when the first data is used in accordance with the first usage policy. The second database system may be database system 23 in Figure 5.
[0165] S609: The second computing device uses the first data while executing the first usage strategy.
[0166] In some possible implementations, the fourth control module of the second computing device executes the first usage policy sent by the second storage device, thereby controlling the usage behavior of applications in the second computing device on the first data, such as applications accessing, calculating, copying, and forwarding the first data. In other words, it can control the second computing device's use of the first data. For example, if the first usage policy specifies the available time period for the first data, the fourth control module records the application's usage time of the first data. When the application continues to use the first data for calculation outside the specified available time period, the fourth control module deletes the first data from the application. In summary, by executing the first usage policy, the fourth control module can control the usage behavior of applications in the second computing device on the first data, thereby effectively ensuring the security of the first data during use. The aforementioned fourth control module can be the control module 223 of the computing device 22 in Figure 4.
[0167] In one specific implementation, new data generated during the application's use of the first data must also conform to the specific content of the first usage policy. That is, any new data generated by the second computing device's processing of the first data will be bound to the first usage policy. For example, if the first usage policy specifies the IP address of the device using the first data, then the new data can only be used on the specified device.
[0168] In some possible implementations, the computing devices connected to the system have a secure computing environment, which is a secure, isolated environment used to protect the security of the computing devices. Therefore, if the first computing device has a first secure computing environment and the second computing device has a second secure computing environment, then the fourth control module of the second computing device can execute the first usage policy within the second secure computing environment, controlling the application's access to, computation of, copying of, and forwarding of the first data. This allows the second secure computing environment to protect the security of both the execution of the first usage policy and the use of the first data.
[0169] Among some possible implementations, the second secure computing environment can include at least the following three implementations:
[0170] In one specific implementation, the fourth control module of the second computing device intercepts and manages the data input and data output interfaces of applications on the second computing device, thereby providing a second secure computing environment. Specifically, when the second computing device has an operating system, during the application's use of the first data, the fourth control module instructs the operating system to close the data input and data output interfaces of the second computing device. This also closes the application's external data input and data output interfaces, preventing the first data from flowing outside the application, or even outside the second computing device. Alternatively, the fourth control module changes the application's settings so that the application closes its data input and data output interfaces during the use of the first data, thus preventing the first data from flowing outside the application.
[0171] In another specific implementation, a trusted execution environment (TEE) is deployed in the second computing device to provide a second secure computing environment. Specifically, the fourth control module and the applications on the second computing device both run in the trusted execution environment, ensuring that the processing of the first data by the fourth control module and the use of the first data by the applications are both implemented within the feasible execution environment. The TEE can be SGX (software guard extensions), SEV (secure encrypted virtualization), Trust Zone, etc.
[0172] In another specific implementation, a virtual machine or container is installed on the second computing device to provide a second secure computing environment. Specifically, the fourth control module and the applications on the second computing device are both run in virtual machines or containers, providing an isolated environment for the fourth control module to process the first data and for the applications to use the first data.
[0173] It should be understood that the above-described implementation of the second secure computing environment is merely an example. Different second secure computing environments can be provided for the second computing device according to different security requirements, combined with different software or hardware. This is not intended as a specific limitation.
[0174] In some possible implementations, if the first data obtained from the second storage device is ciphertext, the fourth control module decrypts the ciphertext and provides the decrypted first data to the application. After the use of the first data is completed, the fourth control module encrypts the first data and any new data generated during the use process to form ciphertext, and then sends the ciphertext to the second storage device or the second database system for storage, thereby ensuring that the first data exists in ciphertext format outside of the use process.
[0175] It should be understood that the first usage policy executed by the second computing device and the first data provided to the application in step S609 above, originating from the second storage device, are merely examples and are not intended as specific limitations. The first usage policy executed by the second computing device and the first data provided to the application may also originate from the second database system. Furthermore, the first usage policy may arrive at the second computing device either before or together with the first data in the second database system. The first data and the first usage policy in the second database system originate from the second storage device.
[0176] S610: The second computing device generates a first usage record of the first data and reports the first usage record to the first computing device.
[0177] In some possible implementations, the fourth control module of the second computing device generates a first usage record (such as an action log, management log, etc.) for the first data, thereby recording the second computing device's use of the first data, including the acquisition behavior of the first data in the second storage device and the application's usage behavior of the first data. Subsequently, the second computing device reports the first usage record to the first computing device, allowing the data owner to determine whether the second computing device's use of the first data conforms to the first usage policy and / or the first usage request, thus enabling real-time monitoring of the first data usage and timely anomaly response. The reporting of the first usage record by the second computing device to the first computing device can include at least the following two implementations:
[0178] In one specific implementation, the second computing device can directly send the first usage record to the first computing device. The first computing device can then store the received first usage record in a first storage device, the first computing device, or a first database system. The first database system can be database system 23 as shown in Figure 5.
[0179] In another specific implementation, the second computing device can upload the first usage record to the data circulation service system, and the first computing device can download the first usage record from the data circulation service system. Furthermore, the first computing device can also perform auditing, risk identification, and source tracing analysis of the data user's usage behavior based on the first usage record in the data circulation service system. Here, the data circulation service system is the same as the data circulation service system in step S602 above.
[0180] In some possible implementations, the second computing device has a second secure computing environment, and the fourth control module generates the first usage record in the second secure computing environment, thereby ensuring that the first usage record cannot be tampered with and ensuring the security and trustworthiness of the first usage record.
[0181] It should be understood that, in the above embodiments, the data transmission between the first storage device and the second storage device is merely an example of data transmission between the first connection system and the second connection system, and is not intended to be a specific limitation. For example, data transmission between the first computing device and the second computing device can also be implemented to achieve data transmission between the first connection system and the second connection system.
[0182] If data transmission is implemented between the first computing device and the second computing device, then the operations performed by the first storage device in steps S601, S602, S603, S604, S605, S606, and S607 of the above embodiments will be performed by the first computing device; the operations performed by the first management module of the first storage device will be performed by the second management module of the first computing device; the operations performed by the first docking module of the first storage device will be performed by the second docking module of the first computing device; and the operations performed by the first control module of the first storage device will be performed by the second control module of the first computing device. Correspondingly, the operations performed by the second storage device in steps S603, S605, and S607 of the above embodiments will be performed by the second computing device; the operations performed by the third management module of the second storage device will be performed by the fourth management module of the second computing device; the operations performed by the third docking module of the second storage device will be performed by the fourth docking module of the second computing device; and the operations performed by the third control module of the second storage device will be performed by the fourth control module of the second computing device. After the second computing device receives the first data and the first usage policy sent by the first computing device through the first secure communication channel, it directly uses the first data while executing the first usage policy, that is, it directly executes step S609 in the above embodiment. Therefore, when data is transmitted between the first computing device and the second computing device, step S608 in the above embodiment is not executed.
[0183] It should be understood that data transmission between the first and second database systems can also be achieved by implementing data transmission between the first and second database systems. If data transmission is implemented between the first and second database systems, then in steps S601, S602, S603, S604, S605, S606, and S607 of the above embodiments, the operations performed by the first storage device will be performed by the first database system; the operations performed by the first management module of the first storage device will be performed by the fifth management module of the first database system; the operations performed by the first docking module of the first storage device will be performed by the fifth docking module of the first database system; and the operations performed by the first control module of the first storage device will be performed by the fifth control module of the first database system. Correspondingly, in steps S603, S605, and S607 of the above embodiments, the operations performed by the second storage device will be performed by the second database system; the operations performed by the third management module of the second storage device will be performed by the sixth management module of the second database system; the operations performed by the third docking module of the second storage device will be performed by the sixth docking module of the second database system; and the operations performed by the third control module of the second storage device will be performed by the sixth control module of the second database system. Among them, the first database system and the second database system can refer to the database system 23 in Figure 5 above, the fifth management module and the sixth management module can refer to the management module 231 of the database system 23 in Figure 5 above, the fifth docking module and the sixth docking module can refer to the docking module 232 of the database system 23 in Figure 5 above, and the fifth control module and the sixth control module can refer to the control module 233 of the database system 23 in Figure 5 above.
[0184] In summary, implementing the embodiments of this application has the following advantages:
[0185] Firstly, the internal structure of the connection system and a method for data flow between the two connection systems based on this internal structure are provided. This ensures that the process of first data flowing from the data owner to the data user, including all stages of data flow such as creating first data, publishing asset information, determining a first usage strategy, transmitting first data, storing first data, using first data, and monitoring the use of first data, can be secure and reliable. Therefore, the embodiments of this application provide a practical solution for ensuring the secure flow of first data between any two data entities and avoiding problems such as data abuse and data leakage during the flow process.
[0186] Secondly, compared to directly sending the first data to the requesting device, which makes it impossible to control the use of the first data in the requesting device, this technical solution uses a second storage device that can execute the first usage strategy to process the first data according to the instructions of the requesting device. This ensures that the second computing device's access, acquisition, and use of the first data are always under the constraints of the first usage strategy, thus enabling secure control over the user's behavior and ensuring the security of the first data during its circulation.
[0187] Thirdly, the secure transmission of the first data can be achieved through storage devices based on the two interconnected systems. This allows applications on the second computing device to directly access the first data within the same interconnected system when they need to use it, without needing to change the application's original usage behavior of the first data. This facilitates direct application deployment by data users, eliminating the need for significant adjustments to applications to use the first data, thereby improving the flow performance of the first data across multiple applications.
[0188] Fourthly, using the first flow strategy to verify the rationality of the data user's first use request and to check the compliance of the first data can control the flow process of the first data, thereby ensuring the security of the first data during circulation. Moreover, access to, acquisition, and use of the first data are only supported when the first use strategy is executed, which enables security control over the data user's usage behavior, thereby ensuring the security of the first data during circulation.
[0189] Fifthly, the second computing device executes the first usage policy in the second secure computing environment and provides the first data to the application, which can ensure that the execution process of the first usage policy is not interfered with and can also prevent the leakage of the first data.
[0190] Based on the aforementioned first connection system, second connection system, and data flow method, the following describes a different data flow method. The first connection system is used to process the first data according to the instructions of the storage device, and the second connection system is used to process the first data according to the instructions of the requesting device. Data transmission between the first and second storage devices is used as an example of data transmission between the first and second connection systems. Furthermore, a third connection system is used to process the second data according to the instructions of the storage device, and the first connection system is used to process the second data according to the instructions of the requesting device. Data transmission between the third and first storage devices is used as an example of data transmission between the third and first connection systems. In this method, the requesting device for the second data and the storage device for the first data are different devices, or they are the same device. The third connection system includes a third storage device, a third computing device, and a third database system. The third storage device can refer to storage device 21 in Figure 3, the third computing device can refer to computing device 22 in Figure 4, and the third database system can refer to database system 23 in Figure 5.
[0191] Referring to Figure 7, which is a flowchart illustrating another data flow method provided in this application, the data flow method provided in this application includes:
[0192] S701: The first storage device establishes a first secure communication channel with the second storage device.
[0193] S702: The first storage device creates first data and asset information of the first data, and obtains the first flow strategy of the first data.
[0194] S703: The first storage device publishes asset information for the first data.
[0195] S704: The second storage device sends a first usage request to the first storage device based on the asset information of the first data. Correspondingly, the first storage device receives the first usage request sent by the second storage device.
[0196] S705: The first storage device determines whether the first usage request and the first data conform to the first flow strategy.
[0197] S706: First usage strategy for the first storage device to acquire first data.
[0198] S707: Upon determining that the first usage request and the first data conform to the first flow policy, the first storage device sends the first data and the first usage policy to the second storage device through the first secure communication channel. Correspondingly, the second storage device receives the first data and the first usage policy sent by the first storage device through the first secure communication channel.
[0199] S708: The second storage device sends the first data and the first usage policy to the second computing device when executing the first usage policy on the first data. Accordingly, the second computing device receives the first data and the first usage policy sent by the second storage device.
[0200] S709: The second computing device uses the first data while executing the first usage strategy.
[0201] S710: The second computing device generates a first usage record of the first data and reports the first usage record to the first computing device.
[0202] The execution process of steps S701 to S710 can be referred to the execution process of steps S601 to S610 in Figure 6 above. For the sake of brevity, it will not be elaborated here.
[0203] S711: The third storage device establishes a second secure communication channel with the first storage device.
[0204] S712: The third storage device creates second data and asset information of the second data, and obtains the second flow strategy of the second data.
[0205] S713: The third storage device publishes asset information for the second data.
[0206] S714: The first storage device sends a second usage request to the third storage device based on the asset information of the second data. Accordingly, the third storage device receives the second usage request sent by the first storage device.
[0207] S715: The third storage device determines whether the second usage request and the second data conform to the second flow strategy.
[0208] S716: Second usage strategy for the third storage device to obtain second data.
[0209] S717: Upon determining that the second usage request and the second data conform to the second flow policy, the third storage device sends the second data and the second usage policy to the first storage device through the second secure communication channel. Correspondingly, the first storage device receives the second data and the second usage policy sent by the third storage device through the second secure communication channel.
[0210] S718: The first storage device sends the second data and the second usage policy to the first computing device when executing the second usage policy on the second data. Accordingly, the first computing device receives the second data and the second usage policy sent by the first storage device.
[0211] S719: The first computing device uses the second data while executing the second usage strategy.
[0212] In some possible implementations, the second control module of the second computing device can execute the second usage policy and provide second data to the application within the first secure computing environment. This allows the first secure computing environment to protect the security of both the execution of the second usage policy and the use of the second data. The implementation of the first computing environment can refer to the implementation of the second computing environment in step S609 of Figure 6.
[0213] S720: The first computing device generates a second usage record of the second data and reports the second usage record to the third computing device.
[0214] The execution process of steps S711 to S720 can be referred to the execution process of steps S601 to S610 in Figure 6 above. For the sake of brevity, it will not be elaborated here.
[0215] It should be understood that this technical solution can either execute steps S701 to S710 first, and then execute steps S711 to S720; or execute steps S711 to S720 first, and then execute steps S701 to S710; or execute the steps in steps S701 to S710 and the steps in steps S711 to S720 alternately. For example, execute step S701 first, then step S711, then step S702, then step S712, and so on. Or, execute steps S711, S712, and S713 first, then steps S701, S702, and S703, then steps S714, S715, and S716, then steps S704, S705, and S706, and so on.
[0216] It should be understood that, in the above embodiments, the data transmission between the third storage device and the first storage device is merely an example of data transmission between the third connection system and the first connection system, and is not intended to be a specific limitation. For example, data transmission can also be achieved between the third computing device and the first computing device, or between the third database system and the first database system, thereby realizing data transmission between the third connection system and the first connection system. For the sake of brevity, further details will not be elaborated here.
[0217] Referring to Figure 8, which is a schematic diagram of a data circulation system provided in this application, the data circulation system can be used to implement the aforementioned data circulation method. As shown in Figure 8, the data circulation system 800 includes a first storage device 810 and a second storage device 820. The first storage device 810 includes a first management module 811, a first control module 812, and a first docking module 813. The second storage device 820 includes a third docking module 821 and a third control module 822.
[0218] The first management module 811 is used to obtain source data from the storage device and generate first data based on the source data;
[0219] The first control module 812 is used to acquire the first flow strategy and the first usage strategy of the first data;
[0220] The first docking module 813 is used to send the first data and the first usage strategy to the second storage device 820 when it is determined that the first data conforms to the first flow strategy.
[0221] The third docking module 821 is used to receive first data and a first usage strategy of the first data sent by the first docking module 813 of the first storage device 810;
[0222] The third control module 822 is used to send the first data and the first usage strategy to the second computing device to control the use of the first data by the second computing device when the first usage strategy is executed on the first data.
[0223] The first usage strategy is a strategy that instructs the second storage device 820 to use the first data. The storage device belongs to the first user, and the second storage device 820 and the second computing device belong to the second connection system. The second storage device 820 and the second computing device are used to process the first data according to the instructions of the first data requesting device. That is, the second connection system is used to process the first data according to the instructions of the first data requesting device. The first data requesting device belongs to the second user, and the storage device and the first data requesting device are different devices.
[0224] In some possible implementations, the first docking module 813 is specifically used to receive a first usage request for requesting first data, and, if it is determined that the first usage request and the first data conform to the first flow strategy, send the first data and the first usage strategy to the second storage device 820.
[0225] In some possible implementations, the first docking module 813 is also used to receive second data sent by the third storage device and a second usage strategy for the second data;
[0226] The first control module 812 is further configured to send the second data and the second usage strategy to the first computing device to control the use of the second data by the first computing device when the second usage strategy is executed on the second data.
[0227] In some possible implementations, the first circulation strategy includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined by negotiation between the first storage device 810 and the second storage device 820. The asset information is generated by the first management module 811 and includes one or more of the type, size, format, purpose, and availability time of the first data.
[0228] In some possible implementations, the first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0229] Referring to Figure 9, which is a schematic diagram of another data circulation system provided in this application, the data circulation system can be used to implement the aforementioned data circulation method. As shown in Figure 9, the data circulation system 900 includes a first computing device 910 and a second computing device 920. The first computing device 910 includes a second management module 911, a second control module 912, and a second docking module 913. The second computing device 920 includes a fourth docking module 921 and a fourth control module 922.
[0230] The second management module 911 is used to obtain source data from the storage device and generate first data based on the source data;
[0231] The second control module 912 is used to acquire the first flow strategy and the first usage strategy of the first data;
[0232] The second docking module 913 is used to send the first data and the first usage strategy to the second computing device 920 when it is determined that the first data conforms to the first flow strategy.
[0233] The fourth docking module 921 is used to receive first data and a first usage strategy of the first data sent by the second docking module 913 of the first computing device 910;
[0234] The fourth control module 922 is used to use the first data when executing the first usage strategy.
[0235] The first usage strategy is a strategy that instructs the second computing device 920 to use the first data. The first computing device 910 is used to process the first data according to the instructions of the storage device, which belongs to the first user. The second computing device 920 is used to process the first data according to the instructions of the device that requests the first data, which belongs to the second user. The storage device and the device that requests the first data are different devices.
[0236] In some possible implementations, the second docking module 913 is specifically used to receive a first usage request sent by the second computing device 920 for requesting first data, and to send the first data and the first usage strategy to the second computing device 920 if it is determined that the first usage request and the first data conform to the first flow strategy.
[0237] In some possible implementations, the second computing device 920 has a second secure computing environment. Specifically, the fourth control module 922 is used within this second secure computing environment to execute a first usage policy on the first data, generate a first usage record, and upload the first usage record to the first computing device 910, thereby controlling the use of the first data by applications on the second computing device 920. The first usage record is a record of the second computing device 920's use of the first data. The second secure computing environment is a secure, isolated environment used to protect the security of the second computing device 920, the security of the execution process of the first usage policy, and the security of the use of the first data. This is achieved by closing the data input and data output interfaces when the second computing device 920 uses the first data, or by deploying a trusted execution environment in the second computing device 920, or by deploying a virtual machine or container in the second computing device 920.
[0238] In some possible implementations, the first computing device 910 is further configured to receive a first usage record of the first data from the second computing device 920, and determine whether the use of the first data by the second computing device 920 conforms to a first usage strategy based on the first usage record, wherein the first usage record is a record of the use of the first data by the second computing device 920.
[0239] In some possible implementations, the second docking module 913 is further configured to receive second data and a second usage strategy for the second data sent by the third computing device, and execute the second usage strategy on the second data to control the use of the second data by the first computing device 910. The first computing device 910 is configured to process the second data according to the instructions of the device requesting the second data, and the device requesting the second data and the storage device are different devices, or the device requesting the second data and the storage device are the same device.
[0240] In some possible implementations, the first computing device 910 has a first secure computing environment. The second control module 912 is specifically used within the first secure computing environment to execute a second usage policy on the second data, generate a second usage record, and upload the second usage record to a third computing device, thereby controlling the first computing device 910's use of the second data. The second usage record is a record of the first computing device 910's use of the second data. The first secure computing environment is a secure, isolated environment used to protect the security of the first computing device 910, the security of the execution process of the second usage policy, and the security of the use of the second data. This is achieved by closing the data input and data output interfaces when the first computing device 910 uses the second data, or by deploying a trusted execution environment in the first computing device 910, or by deploying a virtual machine or container in the first computing device 910.
[0241] In some possible implementations, the first circulation strategy includes one or more of the objects of use and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined by negotiation between the first computing device 910 and the second computing device 920. The asset information is generated by the first computing device 910 and includes one or more of the type, size, format, purpose, and availability time of the first data.
[0242] In some possible implementations, the first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
[0243] Referring to Figure 10, which is a schematic diagram of a computing device cluster provided in this application, the computing device cluster includes at least one computing device. This computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a desktop computer, a laptop computer, or a smartphone, or other terminal device.
[0244] As shown in Figure 10, the computing device cluster includes at least one computing device 1000.
[0245] The computing device 1000 includes a bus 1001, a processor 1002, a memory 1003, and a communication interface 1004. The processor 1002, the memory 1003, and the communication interface 1004 communicate with each other via the bus 1001. It should be understood that this application does not limit the number of processors and memories in the computing device 1000.
[0246] Bus 1001 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, only one line is used in Figure 10, but this does not imply that there is only one bus or one type of bus. Bus 1001 can include pathways for transmitting information between various components of computing device 1000 (e.g., memory 1003, processor 1002, communication interface 1004).
[0247] The processor 1002 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0248] The memory 1003 may include volatile memory, such as random access memory (RAM). The memory 1003 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0249] The memory 1003 stores executable program code, which the processor 1002 executes to implement the functions of the management module 221, the docking module 222, and the control module 223 of the aforementioned computing device 22, thereby realizing the operations implemented by the first computing device, the second computing device, or the third computing device in the aforementioned data flow method. That is, the memory 1003 stores instructions from the first, second, or third computing device for executing the data flow method.
[0250] The communication interface 1004 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 1000 and other devices or communication networks.
[0251] In some possible implementations, the memory 1003 of one or more computing devices 1000 in a computing device cluster may store the same instructions for executing data flow methods.
[0252] In some possible implementations, the memory 1003 of one or more computing devices 1000 in the computing device cluster may also store partial instructions for executing the data flow method. In other words, a combination of one or more computing devices 1000 can jointly execute instructions for executing the data flow method.
[0253] It should be noted that the memory 1003 in different computing devices 1000 within the computing device cluster can store different instructions, which are used to execute some of the functions of the aforementioned computing device 22. That is, the instructions stored in the memory 1003 of different computing devices 1000 can implement the functions of one or more of the aforementioned management module 221, docking module 222, and control module 223.
[0254] Referring to Figure 11, which is a schematic diagram of another computing device cluster structure provided in this application, one or more computing devices in the computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. As shown in Figure 11, two computing devices 1000A and 1000B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this type of possible implementation, the memory 1003 in computing device 1000A stores instructions for executing the functions of the management module 221. Simultaneously, the memory 1003 in computing device 1000B stores instructions for executing the functions of the docking module 222 and the control module 223.
[0255] The connection method between the computing device clusters shown in Figure 11 can be considered as follows: taking into account that the data circulation method provided in this application requires a large amount of data storage, the function implemented by the management module 221 is to be executed by the computing device 1000A.
[0256] It should be understood that the functions of computing device 1000A shown in Figure 11 can also be performed by multiple computing devices 1000. Similarly, the functions of computing device 1000B can also be performed by multiple computing devices 1000.
[0257] This application embodiment also provides another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similarly referred to the connection method of the computing device clusters shown in Figures 10 and 11. The difference is that the memory 1003 of one or more computing devices 1000 in this computing device cluster can store the same instructions for executing data flow methods.
[0258] Referring to Figure 12, which is a schematic diagram of a storage device cluster provided in this application, the storage device cluster includes at least one storage device. This storage device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the storage device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0259] As shown in Figure 12, the storage device cluster includes at least one storage device 1200.
[0260] The storage device 1200 includes a bus 1201, a processor 1202, a memory 1203, and a communication interface 1204. The processor 1202, the memory 1203, and the communication interface 1204 communicate with each other via the bus 1201. It should be understood that this application does not limit the number of processors and memories in the storage device 1200.
[0261] Bus 1201 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, only one line is used in Figure 12, but this does not imply that there is only one bus or one type of bus. Bus 1201 can include pathways for transmitting information between various components of storage device 1200 (e.g., memory 1203, processor 1202, communication interface 1204).
[0262] The processor 1202 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0263] Memory 1203 may include volatile memory, such as random access memory (RAM). Memory 1003 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0264] The memory 1203 stores executable program code, and the processor 1202 executes this executable program code to implement the functions of the management module 211, the docking module 212, and the control module 213 of the aforementioned storage device 21, thereby realizing the operations implemented by the first storage device, the second storage device, or the third storage device in the aforementioned data flow method. That is, the memory 1203 stores instructions for the first storage device, the second storage device, or the third storage device to execute the data flow method.
[0265] The communication interface 1204 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the storage device 1200 and other devices or communication networks.
[0266] In some possible implementations, the memory 1203 of one or more storage devices 1200 in the storage device cluster may store the same instructions for executing data flow methods.
[0267] In some possible implementations, the memory 1203 of one or more storage devices 1200 in the storage device cluster may also store partial instructions for executing the data flow method. In other words, a combination of one or more storage devices 1200 can jointly execute instructions for executing the data flow method.
[0268] It should be noted that the memory 1203 in different storage devices 1200 in the storage device cluster can store different instructions, which are used to execute some of the functions of the aforementioned storage device 21. That is, the instructions stored in the memory 1203 in different storage devices 1200 can realize the functions of one or more of the aforementioned management module 211, docking module 212 and control module 213.
[0269] Referring to Figure 13, which is a schematic diagram of another storage device cluster structure provided in this application, one or more storage devices in the storage device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. As shown in Figure 13, two storage devices 1200A and 1200B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each storage device. In this type of possible implementation, the memory 1203 in storage device 1200A stores instructions for executing the functions of the management module 211. Simultaneously, the memory 1203 in storage device 1200B stores instructions for executing the functions of the docking module 212 and the control module 213.
[0270] The connection method between the storage device clusters shown in Figure 13 can be considered as follows: taking into account that the data circulation method provided in this application requires a large amount of data storage, the function implemented by the management module 211 is handed over to the storage device 1200A for execution.
[0271] It should be understood that the function of storage device 1200A shown in Figure 13 can also be performed by multiple storage devices 1200. Similarly, the function of storage device 1200B can also be performed by multiple storage devices 1200.
[0272] This application embodiment also provides another storage device cluster. The connection relationship between the storage devices in this storage device cluster can be similarly referred to the connection method of the storage device cluster described in Figures 12 and 13. The difference is that the memory 1203 in one or more storage devices 1200 in this storage device cluster can store the same instructions for executing data flow methods.
[0273] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform the aforementioned data flow method, or another of the aforementioned data flow methods.
[0274] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform the aforementioned data flow method, or instruct the computing device to perform another of the aforementioned data flow methods.
[0275] It should be understood that in the embodiments of this application, "when," "...when," and "if" all refer to the terminal device or access network device making corresponding processing under certain objective circumstances, and are not time-limited, nor do they require the terminal device or access network device to make a judgment action, nor do they imply any other limitations.
[0276] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A data circulation method, characterized in that, include: The first storage device generates the first data; The first storage device acquires the first flow strategy and the first usage strategy of the first data; When the first storage device determines that the first data conforms to the first flow policy, it sends the first data and the first usage policy to the second storage device, wherein the first usage policy is a policy that instructs the second storage device to use the first data.
2. The method according to claim 1, characterized in that, The first storage device generates first data, including: The first storage device obtains source data from the storage device and generates the first data based on the source data. The storage device belongs to a first user. The second storage device is used to process the first data according to the instructions of the device that requests the first data. The device that requests the first data belongs to a second user. The storage device and the device that requests the first data are different devices.
3. The method according to claim 1 or 2, characterized in that, Before the first storage device sends the first data and the first usage policy to the second storage device if it determines that the first data conforms to the first flow policy, the method further includes: The first storage device receives a first usage request, wherein the first usage request is used to request the first data; The first storage device, upon determining that the first data conforms to the first flow policy, sends the first data and the first usage policy to the second storage device, including: If the first storage device determines that the first usage request and the first data conform to the first flow policy, the first storage device sends the first data and the first usage policy to the second storage device.
4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: The first storage device receives the second data and the second usage strategy of the second data sent by the third storage device; When the first storage device executes the second usage policy on the second data, it sends the second data and the second usage policy to the first computing device to control the use of the second data by the applications on the first computing device.
5. The method according to any one of claims 1 to 4, characterized in that, The first circulation strategy includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first storage device and the second storage device. The asset information is generated by the first storage device and includes one or more of the type, size, format, purpose, and availability time of the first data.
6. The method according to any one of claims 1 to 5, characterized in that, The first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
7. A data circulation method, characterized in that, include: The second storage device receives the first data sent by the first storage device and the first usage strategy of the first data; When the second storage device executes the first usage policy on the first data, it sends the first data and the first usage policy to the second computing device to control the use of the first data by the applications on the second computing device.
8. The method according to claim 7, characterized in that, The second storage device and the second computing device belong to a second connection system, which is used to process the first data according to the instructions of the first data requesting device.
9. The method according to claim 7 or 8, characterized in that, The first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
10. A data circulation method, characterized in that, include: The first computing device generates the first data; The first computing device acquires the first flow strategy and the first usage strategy of the first data; When the first computing device determines that the first data conforms to the first flow strategy, it sends the first data and the first usage strategy to the second computing device, wherein the first usage strategy is a strategy that instructs the second computing device to use the first data.
11. The method according to claim 10, characterized in that, The first computing device generates first data, including: The first computing device obtains source data from the storage device and generates the first data based on the source data. The storage device belongs to a first user. The second computing device is used to process the first data according to the instructions of the device that requests the first data. The device that requests the first data belongs to a second user. The storage device and the device that requests the first data are different devices.
12. The method according to claim 10 or 11, characterized in that, Before the first computing device sends the first data and the first usage strategy to the second computing device if it determines that the first data conforms to the first flow strategy, the method further includes: The first computing device receives a first usage request sent by the second computing device, wherein the first usage request is used to request the first data; The first computing device, upon determining that the first data conforms to the first flow strategy, sends the first data and the first usage strategy to the second computing device, including: When the first computing device determines that the first usage request and the first data conform to the first flow strategy, it sends the first data and the first usage strategy to the second computing device.
13. The method according to any one of claims 10 to 12, characterized in that, The method further includes: The first computing device receives a first usage record of the first data from the second computing device, wherein the first usage record is a record of the second computing device using the first data; The first computing device determines, based on the first usage record, whether the second computing device's use of the first data conforms to the first usage strategy.
14. The method according to any one of claims 10 to 13, characterized in that, The method further includes: The first computing device receives second data and a second usage strategy for the second data sent by the third computing device; The first computing device executes the second usage policy on the second data to control the use of the second data by applications on the first computing device.
15. The method according to claim 14, characterized in that, The first computing device is used to process the second data according to the instructions of the device that requests the second data, wherein the device that requests the second data is a different device from the storage device, or the device that requests the second data is the same device as the storage device.
16. The method according to claim 14 or 15, characterized in that, The first computing device executes the second usage policy on the second data to control the use of the second data by applications on the first computing device, including: The first computing device executes the second usage policy on the second data in a first secure computing environment to control the use of the second data by applications on the first computing device, wherein the first secure computing environment is a secure isolated environment used to protect the security of the first computing device, the security of the execution process of the second usage policy, and the security of the use process of the second data.
17. The method according to claim 16, characterized in that, The method further includes: The first computing device generates a second usage record in the first secure computing environment and uploads the second usage record to the third computing device, wherein the second usage record is a record of the first computing device using the second data.
18. The method according to claim 17, characterized in that, The first secure computing environment is implemented by disabling the data input and data output interfaces of the application when the application on the first computing device uses the second data; or, the first secure computing environment is implemented by deploying a trusted execution environment on the first computing device; or, the first secure computing environment is implemented by deploying a virtual machine or container on the first computing device.
19. The method according to any one of claims 10 to 18, characterized in that, The first circulation strategy includes one or more of the users and access content of the first data. The first circulation strategy is generated based on circulation requirements or asset information of the first data. The circulation requirements are determined through negotiation between the first computing device and the second computing device. The asset information is generated by the first computing device and includes one or more of the type, size, format, purpose, and availability time of the first data.
20. The method according to any one of claims 10 to 19, characterized in that, The first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
21. A data circulation method, characterized in that, include: The second computing device receives first data sent by the first computing device and a first usage strategy for the first data; The second computing device uses the first data while executing the first usage strategy.
22. The method according to claim 21, characterized in that, The second computing device is used to process the first data according to the instructions of the requesting device of the first data. The first computing device is used to process the first data according to the instructions of the storage device. The first data is generated based on the source data in the storage device. The storage device belongs to the first user, and the requesting device belongs to the second user. The storage device and the requesting device are different devices.
23. The method according to claim 21 or 22, characterized in that, The second computing device executes the first usage policy on the first data to control the use of the first data by applications on the second computing device, including: The second computing device executes the first usage policy on the first data in a second secure computing environment to control the use of the first data by applications on the second computing device, wherein the second secure computing environment is a secure isolated environment used to protect the security of the second computing device, the security of the execution process of the first usage policy, and the security of the use process of the first data.
24. The method according to claim 23, characterized in that, The method further includes: The second computing device generates a first usage record in the second secure computing environment and uploads the first usage record to the first device, wherein the first usage record is a record of the second computing device using the first data.
25. The method according to claim 23 or 24, characterized in that, The second secure computing environment is implemented by disabling the data input and data output interfaces of the application when it uses the first data on the second computing device, or by deploying a trusted execution environment on the second computing device, or by deploying a virtual machine or container on the second computing device.
26. The method according to any one of claims 21 to 25, characterized in that, The first usage strategy includes one or more of the following: usage time, usage scope, and usage method of the first data.
27. A data circulation device, characterized in that, Used as a first storage device, it includes a first management module, a first control module, and a first docking module. The first management module is used to generate the first data; The first control module is used to acquire the first flow strategy and the first usage strategy of the first data; The first docking module is configured to send the first data and the first usage strategy to the second storage device when it is determined that the first data conforms to the first flow strategy, wherein the first usage strategy is a strategy that instructs the second storage device to use the first data.
28. A data circulation device, characterized in that, Used as a first computing device, it includes a second management module, a second control module, and a second docking module. The second management module is used to generate the first data; The second control module is used to acquire the first flow strategy and the first usage strategy of the first data; The second interface module is used to send the first data and the first usage strategy to the second computing device when it is determined that the first data conforms to the first flow strategy, wherein the first usage strategy is a strategy that instructs the second computing device to use the first data.
29. A data circulation device, characterized in that, Used as a second storage device, it includes a third docking module and a third control module. The third docking module is used to receive first data sent by the first storage device and a first usage strategy of the first data; The third control module is configured to send the first data and the first usage policy to the second computing device to control the use of the first data by the application on the second computing device when the first usage policy is executed on the first data.
30. A data circulation device, characterized in that, Used as a second computing device, it includes a fourth docking module and a fourth control module. The fourth docking module is used to receive first data sent by the first computing device and a first usage strategy of the first data; The fourth control module is used to use the first data when the first usage strategy is executed.
31. A data circulation system, characterized in that, It includes the first storage device as described in claim 27, and / or the second storage device as described in claim 29.
32. A data circulation system, characterized in that, It includes the first computing device as described in claim 28, and / or the second computing device as described in claim 30.
33. A storage device cluster, characterized in that, It includes at least one storage device, each storage device including a processor and memory; The processor of the at least one storage device is configured to execute instructions stored in the memory of the at least one storage device to cause the cluster of storage devices to perform the method as described in any one of claims 1 to 6, or to perform the method as described in any one of claims 7 to 9.
34. A computing device cluster, characterized in that, It includes at least one computing device, each computing device including a processor and memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any one of claims 10 to 20, or to perform the method as described in any one of claims 21 to 26.
35. A computer program product containing instructions, characterized in that, When the instruction is executed by the computing device cluster, the computing device cluster causes the computing device cluster to perform the method as described in any one of claims 1 to 26.
36. A computer-readable storage medium, characterized in that, Includes computer program instructions, which, when executed by a cluster of computing devices, perform the method as described in any one of claims 1 to 26.