File access method and apparatus, file access permission determination method and apparatus, and related devices
By applying file tag policy information and encryption key protection mechanism in file access requests, the problem that the existing technology is difficult to effectively defend against multiple data attacks is solved, and efficient file data protection and security control are achieved.
Patent Information
- Application Number
- PCT/CN2024/099581
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-16
- Filing Date
- 2024-06-17
- Publication Date
- 2025-05-22
AI Technical Summary
The prior art is difficult to effectively identify and respond to various attack methods when defending against data attacks, resulting in the failure to meet data security requirements.
By applying file tag policy information in file access requests, permission policy information is generated to control access rights, and using encryption keys to protect files, reducing the security risks brought about by private key leakage.
It realizes data protection with file granularity, improves the security of file access, reduces the risk of file tampering and leaking, and enhances file integrity and confidentiality protection.
Smart Images

Figure CN2024099581_22052025_PF_FP_ABST
Abstract
Description
File access method, file access permission determination method, device and related equipment
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 16, 2023, with application number 202311534765.9 and invention name “File access method, file access permission determination method, device and related equipment”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of data security technology, and in particular to a file access method, a file access permission determination method, an apparatus, and related equipment. Background Art
[0003] During data usage, malicious attacks such as leakage, tampering, and ransomware often occur, posing security risks. Certain security measures are needed to protect data and prevent it from being attacked.
[0004] Currently, attack detection is often used to promptly detect and handle attacks and improve data security. However, due to the wide variety of attacks, it is difficult to detect them all through detection, and the effectiveness of attack defense is insufficient to meet data security requirements.
[0005] Summary of the Invention
[0006] This application provides a file access method and a file access permission determination method, which are intended to implement file-level data protection when a user accesses a file. In addition, this application also provides corresponding apparatus, computing equipment, computer-readable storage medium, and computer program product.
[0007] In a first aspect, the present application provides a file access method. The method is applied to a first device. The first device obtains a file access request for a target file, triggered by a requesting object. The file access request includes access operation information, which describes the access operation that the requesting object needs to perform on the target file. The requesting object is the user requesting access to the target file. The requesting object is the system user of the operating system program of the first device, or the application user of the application program. The first device obtains permission policy information for the requesting object. The permission policy information is determined based on the file tag policy information of the target file and the file access request, and indicates the permissions that the requesting object has for operating the target file. The file tag policy information corresponds to the file tag of the target file and describes the control policy for access operations on the target file. The file tag includes tags of one or more security dimensions. The file tag is set by the administrator of the target file or generated based on the file attributes of the target file. The first device performs access control on the requesting object's access to the target file according to the permission policy information. Based on the file tag, data protection can be implemented at a file-level, improving the security of file access. File-centric data security protection can, to a certain extent, reduce security issues such as file tampering and leakage, and improve the protection of file integrity and confidentiality.
[0008] In a possible implementation, the first device generates the permission policy information of the request object according to the file tag policy information of the target file and the file access request of the request object.
[0009] In one possible implementation, the second device generates permission policy information for the request object. The first device sends a permission request for the target file to the second device. The permission request includes the file label policy information of the target file, access operation information, and the public key of the request object. The file label policy information of the target file is encrypted by the public key of the target file. The first device obtains the permission information fed back by the second device. The permission information includes a first ciphertext. The first ciphertext includes a ciphertext obtained by encrypting the permission policy information of the request object using the public key of the request object. The permission policy information of the request object is obtained by the second device using the private key of the target file, the file label policy information of the target file, and the access operation information. The first device decrypts the first ciphertext using the private key of the request object to obtain the permission policy information of the request object. The second device decrypts the file label policy information of the target file using the private key of the target file and determines the permission policy information. The first device does not need to have the private key of the target file, thereby reducing the security issue of the file label policy information being tampered with after the private key of the target file possessed by the first device is leaked, improving the security level of the file label policy information, and thereby improving the security level of the target file. Furthermore, the file tag policy information and permission policy information exchanged between the first device and the second device are both encrypted information, thereby reducing the risk of information leakage during the interaction between the first device and the second device.
[0010] In one possible implementation, the target file is encrypted using a file encryption key. The file encryption key is encapsulated in the file tag policy information of the target file. The permission information obtained by the first device also includes a second ciphertext obtained by encrypting the file encryption key using the public key of the requesting object. Before executing access control on the requesting object's access to the target file in accordance with the permission policy information of the requesting object, if it is determined based on the permission policy information that the requesting object has access rights, the first device decrypts the target file using the file encryption key. The file encryption key is obtained by the first device decrypting the second ciphertext using the private key of the requesting object. Encrypting each file in this way improves the security of the file. Using a key unique to a file can also effectively reduce the security threat to multiple files caused by key leakage due to encryption using a unified key.
[0011] In one possible implementation, the first device further obtains the file tag of the target file and generates file tag policy information for the target file based on the file tag and the tag policy template. Thus, the file tag policy information can be automatically generated based on the file tag of the target file and the tag policy template.
[0012] In one possible implementation, the tag policy template is obtained from the second device.
[0013] In one possible implementation, the user who sets the file tag policy information can also customize and update the file tag policy information. The first device obtains the customized tag policy information for the target file and uses the customized tag policy information to update the file tag policy information for the target file. This enables customized adjustment of the file tag policy information, improves the flexibility of configuring file tag policy information, and facilitates configuring file tag policy information that meets file protection requirements.
[0014] In a possible implementation, the first device is a host.
[0015] In a possible implementation, the method is applied to the application layer of the first device, or to the system layer of the first device, or to the application layer and the system layer of the first device.
[0016] In one possible implementation, the first device is a storage device. A requesting object triggers a file access request via a third device connected to the first device. The first device receives the file access request for a target file, triggered by the requesting object, sent by the third device. The file access request is encapsulated by the third device using a security protocol. The first device decapsulates the file access request using the security protocol. In this way, the security protocol can be used to protect the security of the file access request, thereby improving file security.
[0017] In one possible implementation, the first device generates feedback file information based on the permission policy information of the request object and the access operation information of the request object, and sends the feedback file information encapsulated using a security protocol to the third device. The security protocol is used to improve the security of information transmitted between the first device and the third device.
[0018] In a possible implementation, the method is applied to a system layer of a first device, and the application is a preset security application.
[0019] In a second aspect, the present application provides a method for determining file access rights. The method is applied to a second device. The second device obtains a permission request for a target file sent by the first device. The permission request includes file label policy information of the target file, access operation information, and the public key of the requesting object. The file label policy information is encrypted by the public key of the target file and is used to describe the control policy for the access operation on the target file. The file label policy information corresponds to the file label of the target file. The file label is set by the administrator of the target file or generated based on the file attributes of the target file. The file label includes labels of one or more security dimensions. The requesting object is the system user of the operating system program of the first device, or the application user of the application program. The second device uses the private key of the target file to decrypt the file label policy information, and determines the permission policy information of the requesting object based on the file label policy information and access operation information of the target file. The permission policy information is used to describe the permission policy of the requesting object for the access operation of the target file. The second device uses the public key of the requesting object to encrypt the permission policy information of the requesting object to obtain a first ciphertext, and sends the permission information including the first ciphertext to the first device. The second device uses the target file's private key to decrypt the target file's file tag policy information and determine the permissions policy information. This prevents the first device from possessing the target file's private key, reduces security issues arising from the leakage of the target file's private key held by the first device, improves the security of the file tag policy information, and thereby improves the security of the target file. Furthermore, both the file tag policy information and permissions policy information exchanged between the first and second devices are encrypted, improving the security of the information during the interaction between the first and second devices and reducing the risk of information leakage during the interaction between the first and second devices.
[0020] In one possible implementation, the target file is encrypted using a file encryption key. The file encryption key is encapsulated in the file tag policy information of the target file. The second device also uses the public key of the requesting object to encrypt the file encryption key to obtain a second ciphertext. The permission information sent by the second device to the first device also includes the second ciphertext. The second device sends the encrypted file encryption key to the first device, so that the first device can decrypt the target file based on the file encryption key and control access to the requesting object. The use of a key unique to the target file can also effectively avoid security threats to multiple files caused by key leakage caused by encryption using a unified key, thereby improving the data security of the target file.
[0021] In a possible implementation, the second device further provides the first device with a label policy template. In response to obtaining the label policy template acquisition request sent by the first device, the second device sends the label policy template to the first device.
[0022] In a possible implementation, the second device is a server or a management device.
[0023] In a third aspect, the present application provides a file access device, which is applied to a first device, and the device includes: an acquisition module, used to obtain a file access request for a target file triggered by a request object, the file access request includes access operation information, and the access operation information is used to describe the access operation that the request object needs to perform on the target file; the request object is a system user of the operating system program of the first device, or an application user of the application program; a processing module, used to obtain permission policy information of the request object, the permission policy information is determined based on the file tag policy information of the target file and the file access request; the file tag policy information corresponds to the file tag of the target file, the file tag policy information is used to describe the control policy for the access operation on the target file, and the permission policy information is used to indicate the permission of the request object to operate the target file; the file tag includes one or more security dimension tags, and the file tag is set by the manager of the target file or generated based on the file attributes of the target file; a control module, used to perform access control on the request object's access to the target file according to the permission policy information.
[0024] In a possible implementation, the processing module is specifically configured to generate permission policy information of the request object according to the file tag policy information of the target file and the file access request of the request object.
[0025] In one possible implementation, the processing module is specifically used to send a permission request for a target file to a second device, where the permission request includes file label policy information of the target file, access operation information, and a public key of the requesting object, and the file label policy information of the target file is encrypted by the public key of the target file; obtaining permission information fed back by the second device, where the permission information includes a first ciphertext, and the first ciphertext includes a ciphertext obtained by encrypting the permission policy information of the requesting object using the public key of the requesting object, and the permission policy information of the requesting object is obtained by the second device using the private key of the target file, the file label policy information of the target file, and the access operation information; decrypting the first ciphertext using the private key of the requesting object to obtain the permission policy information of the requesting object.
[0026] In one possible implementation, the target file is encrypted using a file encryption key, which is encapsulated in the file tag policy information of the target file. The permission information also includes a second ciphertext obtained by encrypting the file encryption key using the public key of the requesting object. The processing module is also used to decrypt the target file using the file encryption key if it is determined that the requesting object has access rights based on the permission policy information. The file encryption key is obtained by decrypting the second ciphertext using the private key of the requesting object.
[0027] In a possible implementation, the acquisition module is further configured to acquire a file tag of a target file; and the generation module is configured to generate file tag policy information of the target file based on the file tag and the tag policy template.
[0028] In one possible implementation, the tag policy template is obtained from the second device.
[0029] In a possible implementation, the acquisition module is further configured to acquire custom label policy information for the target file; and the generation module is further configured to update the file label policy information of the target file using the custom label policy information.
[0030] In a possible implementation, the first device is a host.
[0031] In a possible implementation, the apparatus is applied to an application layer of the first device.
[0032] In a possible implementation, the apparatus is applied to a system layer of the first device.
[0033] In a possible implementation, the application is a preset security application.
[0034] In one possible implementation, the first device is a storage device, and the acquisition module is specifically used to obtain a file access request for a target file triggered by a request object and sent by a third device, and the file access request is encapsulated by the third device using a security protocol; and the file access request is unpacked using the security protocol.
[0035] In a possible implementation, the control module is specifically configured to generate feedback file information according to permission policy information of the request object and access operation information of the request object, and send the feedback file information encapsulated by a security protocol to the third device.
[0036] In a fourth aspect, the present application provides a device for determining file access rights, which is applied to a second device and includes: an acquisition module for obtaining a permission request for a target file sent by a first device, the permission request including file label policy information of the target file, access operation information and a public key of the requesting object, the file label policy information is encrypted by the public key of the target file, the file label policy information corresponds to the file label of the target file, the file label policy information is used to describe the control policy for the access operation on the target file, the file label includes one or more security dimension labels, the file label is set by the administrator of the target file or generated based on the file attributes of the target file, the requesting object is the system user of the operating system program of the first device, or the application user of the application program; a decryption module for decrypting the file label policy information using the private key of the target file; a determination module for determining the permission policy information of the requesting object based on the file label policy information and access operation information of the target file, the permission policy information is used to describe the permission policy of the requesting object for the access operation on the target file; an encryption module for encrypting the permission policy information of the requesting object using the public key of the requesting object to obtain a first ciphertext; a sending module for sending permission information to the first device, the permission information including the first ciphertext.
[0037] In one possible implementation, the target file is encrypted using a file encryption key, which is encapsulated in the file tag policy information of the target file. The encryption module is also used to encrypt the file encryption key using the public key of the request object to obtain a second ciphertext, and the permission information also includes the second ciphertext.
[0038] In a possible implementation, the sending module is further configured to send the label policy template to the first device in response to obtaining the label policy template acquisition request sent by the first device.
[0039] In a possible implementation, the second device is a server or a management device.
[0040] In a fifth aspect, the present application provides a computing device cluster, which includes at least one computing device, each computing device including a processor and a memory; the memory is used to store instructions, and when the computing device cluster is running, the processor in each computing device executes the instructions stored in the memory, so that the computing device cluster executes the file access method in the above-mentioned first aspect or any possible implementation of the first aspect, or executes the file access permission determination method in the above-mentioned second aspect or any possible implementation of the second aspect. It should be noted that the memory can be integrated into the processor or can be independent of the processor. Each computing device may also include a bus. The processor is connected to the memory via a bus. The memory may include a readable memory and a random access memory.
[0041] In a sixth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computing device cluster (the computing device cluster includes at least one computing device), the computing device cluster executes the file access method in the above-mentioned first aspect or any possible implementation of the first aspect, or executes the file access permission determination method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0042] In the seventh aspect, the present application provides a computer program product comprising instructions, which, when run on a computing device cluster (the computing device cluster includes at least one computing device), enables the computing device cluster to execute the file access method in the above-mentioned first aspect or any possible implementation of the first aspect, or execute the file access permission determination method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0043] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] FIG1a is a schematic diagram of a scenario provided by an embodiment of the present application;
[0045] FIG1b is a schematic diagram of another scenario provided by an embodiment of the present application;
[0046] FIG1c is a schematic diagram of interaction between a first device and a second device provided in an embodiment of the present application;
[0047] FIG2a is a schematic diagram of another scenario provided in an embodiment of the present application;
[0048] FIG2b is a schematic diagram of another scenario provided in an embodiment of the present application;
[0049] FIG2c is a schematic diagram of another interaction between a first device and a second device provided in an embodiment of the present application;
[0050] FIG3a is a schematic diagram of a scenario provided in an embodiment of the present application;
[0051] FIG3 b is a schematic diagram of another scenario provided by an embodiment of the present application;
[0052] FIG3c is a schematic diagram of another interaction between a first device and a second device provided in an embodiment of the present application;
[0053] FIG4a is a schematic diagram of another scenario provided in an embodiment of the present application;
[0054] FIG4b is a schematic diagram of another scenario provided in an embodiment of the present application;
[0055] FIG4c is a schematic diagram of another interaction between a first device and a second device provided in an embodiment of the present application;
[0056] FIG5 is a flow chart of a file access method provided in an embodiment of the present application;
[0057] FIG6 is a flow chart of another file access method provided in an embodiment of the present application;
[0058] FIG7 is a schematic diagram of a process for generating file tag policy information for a target file according to an embodiment of the present application;
[0059] FIG8 is a schematic diagram of a file tagging strategy provided by an embodiment of the present application;
[0060] FIG9 is a schematic diagram of another process for generating file tag strategy information for a target file according to an embodiment of the present application;
[0061] FIG10 is a schematic structural diagram of a file access device provided in an embodiment of the present application;
[0062] FIG11 is a schematic diagram of the structure of a device for determining file access rights provided in an embodiment of the present application;
[0063] FIG12 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0064] FIG13 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0065] FIG14 is a schematic diagram of the structure of another computing device cluster provided in an embodiment of the present application. DETAILED DESCRIPTION
[0066] The following will describe the solutions in the embodiments provided in this application in conjunction with the drawings in this application.
[0067] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate and are merely used to describe the manner in which objects with the same attributes are described in the embodiments of this application.
[0068] Data is a valuable asset, containing crucial personal and corporate information. When using data, it's crucial to protect it from attacks to avoid data leaks, tampering, or unavailability. Currently, attack detection algorithms are typically built at the network, host, and storage levels. These algorithms are used to promptly detect and address attacks, maintaining data security. However, these algorithms are limited in the scope of attack detection and can only identify currently known attacks. They struggle to detect unknown attacks, presenting security risks. Furthermore, detection algorithms can be subject to errors, potentially impacting the normal operation of data-processing services. Using detection algorithms to detect attacks fails to meet data security requirements.
[0069] Based on this, an embodiment of the present application provides a file access method applied to a first device. The first device obtains a file access request including access operation information for a target file triggered by a request object. The first device obtains permission policy information of the request object. The permission policy information of the request object is determined based on the file tag policy information of the target file and the file access request of the request object. The file tag policy information corresponds to the file tag of the target file. The file tag policy information is used to describe the control policy for the access operation on the target file. The first device performs access control on the request object's access to the target file according to the permission policy information. The use of file tag policy information can achieve security protection for data with file granularity. In this way, data-centric security protection is achieved, which can reduce the security risks of tampering, leakage and extortion faced by files to a certain extent. In addition, the file tag can be configured based on the security protection requirements of the file, thereby achieving flexible configuration of file tag policy information to meet the security requirements of different files.
[0070] The embodiments of the present application do not limit the deployment of the file access method and the file access permission determination method. As some examples, referring to Figures 1a to 4c, the embodiments of the present application provide four application scenario diagrams.
[0071] As an example, referring to FIG1a , the file access method provided in an embodiment of the present application can be applied to a tag policy client or a tag policy software development kit (SDK), and deployed in an application of the first device, that is, deployed in the application layer of the first device. The first device is, for example, a host. The request object requesting access to the target file can be an application user of the application of the first device, or a system user of the operating system program of the first device. The scenario shown in FIG1a can be, for example, a scenario in which the application has an independent user system. The application layer of the first device implements control over access to files by the application user of the application of the first device or the system user of the operating system program.
[0072] In one possible implementation, the application layer of the first device includes a tag policy client or a tag policy software development kit, which obtains a file access request for a target file triggered by a request object, generates permission policy information of the request object based on the file tag policy information of the target file and the file access request of the request object, and performs access control on the request object's access to the target file according to the permission policy information.
[0073] In another possible implementation, as shown in FIG1b, the first device interacts with the second device to implement access control to the target file. An embodiment of the present application provides a method for determining file access rights. The method for determining file access rights can be applied to a tag policy service, or a tag policy management component, and deployed on a second device. The second device is, for example, a server. Referring to FIG1c, this figure is a schematic diagram of the interaction between a first device and a second device provided in an embodiment of the present application. The application layer of the first device includes a tag policy client or a tag policy software development kit, including an initialization module, a file tag generation module, a file tag policy information generation module, an access request processing module, and an access operation control module. The tag policy service of the second device, or the tag policy management component, includes an initialization module and a permission information determination module. The initialization module of the first device interacts with the initialization module of the second device to implement initialization authentication, that is, identity authentication and certificate issuance. The file tag generation module of the first device is used to generate a file tag based on user triggering, or automatically generate a file tag, and send a tag policy template acquisition request to the second device to obtain the tag policy template fed back by the second device. The file tag policy information generation module of the first device generates file tag policy information for the target file based on the file tag and the tag policy template. The access request processing module of the first device is configured to send a permission request to the permission information determination module of the second device based on the acquired file access request triggered by the request object. The permission information determination module of the second device parses the file tag policy information based on the permission request, determines the permission policy information of the request object, and sends permission information including the permission policy information of the request object encrypted using the public key of the request object to the first device. The access operation control module of the first device is configured to control access operations of the request object based on the permission policy information of the request object included in the permission information.
[0074] As another example, referring to FIG2a , the file access method provided in the embodiment of the present application can be applied to a tag kernel module and deployed in the operating system program (OS) of the first device, that is, deployed in the system layer of the first device. The first device is, for example, a host. Among them, the request object requesting access to the target file can be the system user of the operating system program of the first device, or the application user of the application. The scenario shown in FIG2a is, for example, a scenario in which the application and the OS have a unified user system, or the user system of the application can be synchronized to the user system of the OS, or the application does not have an independent user system. The system layer of the first device implements control over access to files by the application user of the application or the system user of the operating system program.
[0075] In one possible implementation, the system layer of the first device includes a tag kernel module that obtains a file access request for a target file triggered by a request object, generates permission policy information of the request object based on the file tag policy information of the target file and the file access request of the request object, and performs access control on the request object's access to the target file according to the permission policy information.
[0076] In another possible implementation, as shown in Figure 2b, the first device interacts with the second device to implement access control on the target file. The file access permission determination method provided in the embodiment of the present application can be applied to a tag policy service, or a tag policy management component, deployed on the second device. The second device is, for example, a server. Referring to Figure 2c, this figure is a schematic diagram of another interaction between a first device and a second device provided in an embodiment of the present application. The system layer of the first device includes a tag policy client or a tag policy software development kit, including an initialization module, a file tag generation module, a file tag policy information generation module, an access request processing module, and an access operation control module. The tag policy service of the second device, or the tag policy management component, includes an initialization module and a permission information determination module. The interaction process between the first device and the second device is similar to the example corresponding to Figure 1c above, and will not be repeated here.
[0077] As another example, referring to FIG3a , the file access method provided in the embodiment of the present application can be applied to the tag kernel module, and the tag policy client or the tag policy SDK, and deployed in the OS and application of the first device, that is, deployed in the system layer and application layer of the first device. The first device is, for example, a host. Among them, the request object requesting access to the target file can be the system user of the operating system program of the first device, or the application user of the application. The scenario shown in FIG3a is, for example, a business scenario with high security requirements. The system layer and the application layer of the first device collaborate to implement control over access to files by the application user of the application, or the system user of the operating system program.
[0078] In one possible implementation, the tag kernel module of the first device, and the tag policy client or tag policy SDK obtain a file access request for a target file triggered by a request object, generate permission policy information of the request object based on the file tag policy information of the target file and the file access request of the request object, and perform access control on the request object's access to the target file according to the permission policy information.
[0079] In another possible implementation, as shown in FIG3b , the first device interacts with the second device to implement access control for the target file. The file access permission determination method provided in the embodiment of the present application can be applied to a tag policy service, or a tag policy management component, deployed on the second device. The second device is, for example, a server.
[0080] Refer to Figure 3c, which is a schematic diagram of another interaction between a first device and a second device provided in an embodiment of the present application. The system layer and application layer of the first device include a tag policy client or a tag policy software development kit, including an initialization module, a file tag generation module, a file tag policy information generation module, an access request processing module, and an access operation control module. The tag policy service of the second device, or the tag policy management component, includes an initialization module and a permission information determination module. The interaction process between the first device and the second device is similar to the example corresponding to Figure 1c above, and will not be repeated here.
[0081] As another example, referring to FIG4a , the scenario shown in FIG4a is applicable to a storage scenario. The file access method provided in an embodiment of the present application can be applied to a tag kernel module and deployed in a first device. The first device is, for example, a storage device. The first device is also connected to a third device. The third device is, for example, a production host. The requesting object requesting access to the target file accesses the target file stored on the first device through the third device. The first device and the third device communicate via a security protocol. The first device also includes a security protocol server. The third device includes a security protocol client. The security protocol server and the security protocol client are used to encapsulate or unpack the transmission information using a security protocol to achieve communication between the first device and the third device. In this way, the requesting object can complete the access operation to the target file stored on the first device on the third device.
[0082] In one possible implementation, the tag kernel module of the first device obtains a file access request for a target file triggered by a request object, generates permission policy information of the request object based on the file tag policy information of the target file and the file access request of the request object, and performs access control on the request object's access to the target file according to the permission policy information.
[0083] In another possible implementation, as shown in FIG4b, the first device interacts with the second device to implement access control for the target file. The file access permission determination method provided in the embodiment of the present application can be applied to a tag policy service, or a tag policy management component, deployed on the second device. The second device is, for example, a management device for a storage device. Referring to FIG4c, this figure is a schematic diagram of another interaction between the first device and the second device provided in the embodiment of the present application. The first device includes a tag policy client or a tag policy software development kit, including an initialization module, a file tag generation module, a file tag policy information generation module, an access request processing module, and an access operation control module. The first device also includes a security protocol server. The tag policy service, or the tag policy management component, of the second device includes an initialization module and a permission information determination module. The third device A and the third device B include a security protocol client. The interaction process between the first device and the second device is similar to the example corresponding to FIG1c above and will not be repeated here. The security protocol client of the third device A is used to obtain the file tag selected by the user, and encapsulates the file tag using the security protocol and sends it to the first device. The security protocol server of the first device decapsulates the file tag using the security protocol and sends the file tag to the file tag generation module. The security protocol client of third device A is used to obtain the file access request triggered by the request object, encapsulate the file access request using the security protocol, and then send it to the first device. The security protocol server of the first device decapsulates the file access request using the security protocol and sends it to the access request processing module. This enables control of file access by the request object, namely, the application user of the third device's application or the system user of the operating system program.
[0084] It should be noted that the application scenarios shown in the above Figures 1a to 4c are only examples, and the application scenarios of the file access method and the file access permission determination method provided in this application are not limited to the application scenarios shown in Figures 1a to 4c.
[0085] Next, various non-limiting specific implementations of the file access method and the file access permission determination method provided by this application are described in detail.
[0086] 5 , which is a flowchart of a file access method provided by an embodiment of the present application, wherein the method is applied to a first device and includes steps S501 to S503 .
[0087] S501: The first device obtains a file access request for a target file triggered by a request object.
[0088] The requesting object is an object requesting access to a target file stored on the first device through the first device. The present embodiments do not limit the identity of the requesting object. For example, the requesting object is a user. For example, the user is an application user of an application program on the first device, or a system user of an operating system program on the first device. Additionally, for example, the requesting object is a user and a program process. A program process is the process in which the user triggers the file access request.
[0089] It should be noted that in some possible implementations, the user who is the requesting party needs to pass security authentication.
[0090] In one possible implementation, a first device establishes a connection with a second device. During the initialization phase, the first device exchanges user information with the second device to authenticate the user. The authentication process includes identity authentication and the issuance of a certificate by the second device to the first device. During the identity authentication process, the first device sends object information related to file access. In some examples, the first device sends user information of the user logged in to the application, or user information of the user logged in to the operating system of the first device.
[0091] The second device authenticates the object based on the acquired object information and sends the authentication result to the first device. The first device determines the object that has passed security authentication based on the authentication result. If the requesting object is already an authenticated object, the first device can determine whether the requesting object has passed security authentication based on the authentication result. If the requesting object has passed security authentication, the first device processes the file access request for the target file triggered by the requesting object. If the requesting object has not passed security authentication, the first device does not process the file access request for the target file triggered by the requesting object. If the requesting object is an unauthenticated object, such as a user logging in to the first device for the first time, the first device sends the user information of the requesting object to the second device. The second device authenticates the requesting object based on the acquired user information of the requesting object and sends the authentication result of the requesting object to the first device. The first device can determine whether the requesting object has passed security authentication based on the authentication result of the requesting object. If the requesting object has passed security authentication, the first device processes the file access request for the target file triggered by the requesting object. If the requesting object has not passed security authentication, the first device does not process the file access request for the target file triggered by the requesting object.
[0092] In another implementation, taking the application scenarios shown in Figures 2a and 3a as an example, the file access method provided by the embodiment of the present application is applied to the system layer of the first device. That is, the file access method is executed by the operating system program of the first device. The request object can be the application user of the application deployed by the first device. After obtaining the file access request triggered by the application user, the system layer of the first device first verifies whether the application to which the application user belongs is a safe application. For example, based on a pre-established application whitelist. The application whitelist includes information about safe applications. Determine whether the application user is an application user of an application included in the application whitelist. If the application user is an application user of an application included in the application whitelist, the first device processes the file access request for the target file triggered by the application user. If the application user is not an application user of an application included in the application whitelist, the first device does not process the file access request for the target file triggered by the request object. In this way, security authentication of the application to which the application user belongs can be achieved, applications that access files can be restricted, and malicious processing of files by applications, such as deletion of files, can be prevented, thereby improving the security of files.
[0093] The target file stored on the first device is a file that pre-configures file tag policy information. The file tag policy information corresponds to the file tag of the target file. The file tag can be set based on the attributes of the file and the file protection requirements. The file tag policy information is used to describe the control policy for access operations on the target file. The file tag policy information is used to indicate the permission policy that needs to be followed when accessing the target file. The target file is protected by the file tag policy information.
[0094] The embodiment of the present application does not limit the configuration method of the file tag policy information of the target file. In one possible implementation method, it can be directly configured by the owner or manager of the target file. In another possible implementation method, it is edited and generated by the owner or manager of the target file. The embodiment of the present application provides a specific implementation method for generating the file tag policy information of the target file. Please see below for details.
[0095] The file access request includes access operation information. The access operation information includes the object information of the request object and the operation information of the request object requesting to perform an access operation on the target file. As an example, the object information of the request object is, for example, the account information and object type of the request object. For example, the request object is a user, and the account information is the user's account. The object type is, for example, a system user or an application user. Distinguishing different types of request objects facilitates determining the permission policy information of different types of request objects, implementing access control for different types of request objects, and improving the security of data. In some possible implementations, the object information of the request object also includes the process information of the program process that triggers the file access request, such as the process number. The operation information includes, for example, the type of access operation.
[0096] S502: The first device obtains permission policy information of the requested object.
[0097] The permission policy information of the request object is used to indicate the permission of the request object to operate the target file. The permission policy information of the request object is determined based on the file tag policy information of the target file and the file access request of the request object.
[0098] The embodiments of the present application do not limit possible implementation methods for the first device to obtain permission policy information.
[0099] In a possible implementation, the first device generates permission policy information of the request object according to the file tag policy information of the target file and the file access request of the request object.
[0100] Based on the acquired access operation information, the first device determines the permission policy information related to the access operation information from the file tag policy information of the target file, and obtains the permission policy information of the request object. The permission policy information of the request object is used to indicate the permission of the request object to operate the target file.
[0101] As an example, the file label policy information of the target file includes the operations that can be performed on the target file according to different security dimensions. As an example, the file label policy information of the target file includes policy information of four security dimensions: the sensitivity of the file, the access user, the access process, and the business type to which the file belongs. Among them, the policy information of the sensitivity of the file includes encryption protection for top-secret files. The policy information of the access user includes that users of type U1 have all operation permissions, users of type non-U1 are denied access, users of type U2 have read and write permissions, and users of type U3 have print permissions. The policy information of the access process includes that processes of type P1 have all permissions, and processes of type non-P1 are denied access. The policy information of the business type to which the file belongs restricts the sending of files containing financial data to non-financial personnel.
[0102] The access operation information includes that the user type to which the request object belongs is U1 type, and the type of access operation is a read operation. Taking the file label policy information of the above-mentioned target file as an example, the first device determines based on the access operation information and the file label policy information that the request object of type U1 has all operation permissions. The permission policy information of the request object is to have all operation permissions. As another example, the access operation information includes that the user type to which the request object belongs is U3 type, and the type of access operation is a read operation. Taking the file label policy information of the above-mentioned target file as an example, the first device determines based on the access operation information and the file label policy information that the request object of type U3 has the permission for the print operation. The permission policy information of the request object is to have the permission for the print operation.
[0103] In another possible implementation, the first device interacts with the second device to obtain the permission policy information of the request object sent by the second device. Referring to FIG6 , the above S502 specifically includes the following steps:
[0104] S5021: The first device sends a permission request for the target file to the second device, where the permission request includes access operation information, the public key of the request object, and file tag policy information of the target file encrypted by the public key of the target file.
[0105] After receiving the file access request for the target file, the first device sends a permission request for the target file to the second device. The second device can determine the permission information of the requesting party to access the target file based on the file tag policy information and access operation information of the target file.
[0106] The permission request includes the file tag policy information of the target file, the access operation information included in the file access request, and the public key of the request object. The file tag policy information of the target file is encrypted by the public key of the target file.
[0107] The file label policy information of the target file is determined in advance based on the data protection needs of the target file. The file label policy information of the target file is generated by the first device and protected by encryption using the public key of the target file. The first device does not have the private key corresponding to the public key of the target file, which avoids the decryption of the file label policy information of the target file locally on the first device, and prevents the attacker from using the private key of the target file to decrypt and tamper with the file label policy information after the first device is attacked. This can improve the security of the file label policy information, thereby improving the security of the target file.
[0108] The public key of the target file can be a key set in advance by the owner of the target file, or generated based on the information of the owner of the target file. As an example, the public key of the target file is the public key of the organization to which the owner of the target file belongs, such as a company or group, to enable the organization to manage and access the file.
[0109] In addition, the public key of the request object can be a public key preset by the request object. The embodiment of the present application does not limit the generation method of the public key of the request object. As an example, the public key of the request object is generated based on the relevant information of the request object.
[0110] S5022: The second device obtains the permission request for the target file sent by the first device, where the permission request includes access operation information, the public key of the request object, and file tag policy information of the target file encrypted by the first public key.
[0111] S5023: The second device decrypts the file tag policy information using the private key of the target file.
[0112] The private key of the target file is the decryption key of the public key of the target file. The private key of the target file is, for example, a key set in advance by the owner of the target file, or a key generated based on the information of the owner of the target file. As an example, the private key of the target file is, for example, the private key of the organization or institution to which the owner of the target file belongs. This makes it easier for organizations and institutions to manage files in a unified manner. The second device uses the private key of the target file to decrypt the file label policy information generated by the first device. The first device does not have the decryption key, which can avoid the problem of decryption key leakage caused by the attack on the first device, thereby improving the security of the file label policy information and thus improving the security of the target file.
[0113] S5024: The second device determines the permission policy information of the request object based on the file tag policy information and access operation information of the target file.
[0114] The second device obtains file tag policy information and access operation information of the target file based on the obtained permission request for the target file. Based on the access operation information, the second device can determine the permission policy information related to the access operation information from the file tag policy information of the target file, and obtain the permission policy information of the requesting object. The permission policy information of the requesting object is used to indicate the permission that the requesting object has for operating the target file.
[0115] S5025: The second device encrypts the permission policy information of the request object using the public key of the request object to obtain a first ciphertext.
[0116] After determining the permission policy information of the requesting party, the second device encrypts the permission policy information of the requesting party using the public key of the requesting party to obtain a first ciphertext. The encrypted permission policy information of the requesting party is highly secure and can, to a certain extent, prevent malicious access to the permission policy information during the interaction between the second device and the first device.
[0117] S5026: The second device sends permission information including the first ciphertext to the first device.
[0118] S5027: The first device obtains the permission information fed back by the second device.
[0119] S5028: The first device decrypts the first ciphertext using the private key of the requesting object to obtain the permission policy information of the requesting object.
[0120] The embodiments of the present application do not limit the generation method of the public key and the private key of the requesting object. After obtaining the permission information, the first device uses the private key of the requesting object to decrypt the first ciphertext included in the permission information to obtain the permission policy information of the requesting object. The permission policy information of the requesting object indicates the permission that the requesting object has to operate the target file.
[0121] Using the public key of the target file to encrypt the file tag policy information can improve the security of the file tag policy information stored in the first device. The second device decrypts the file tag policy information and analyzes it to obtain the permission policy information, eliminating the need for the first device to decrypt the file tag policy information locally. This can avoid the risk of an attacker using the decryption key obtained from the first device to maliciously tamper with the file tag policy information, thereby improving the security of the file tag policy information and, in turn, the security of the target file.
[0122] S503: The first device performs access control on the request object's access to the target file according to the permission policy information of the request object.
[0123] The first device can determine the permission of the requesting object to access the target file based on the permission policy information of the requesting object. The first device performs access control on the requesting object to the target file according to the permission policy information of the requesting object.
[0124] Based on the relevant content of S501-S503 above, it can be seen that fine-grained file label policy information and permission policy information with files as the granularity can achieve protection for target files, realize data-centric security protection, improve the protection of data integrity and confidentiality, and to a certain extent reduce the security risks of files being tampered with, leaked and extorted.
[0125] In some scenarios, the target file has confidentiality requirements. The confidentiality requirements of the target file can be configured through the file label policy information of the target file. The first device determines that the target file has confidentiality requirements based on the generated file label policy information of the target file. The first device encrypts the target file using a file encryption key. The embodiment of the present application does not limit the generation method of the file encryption key. As an example, the file encryption key is a randomly generated symmetric key. The file encryption key corresponds one-to-one to the file to be encrypted. This can improve the security of each file that needs to be encrypted, and can also ensure the security of other files when the file encryption keys of some files are cracked. In one possible implementation method, the file encryption key is encapsulated in the file label policy information of the target file, and the file label policy information of the target file is encrypted using the public key of the target file to protect the file encryption key and the file label policy information.
[0126] In the implementation method in which the second device determines the permission policy information of the request object, after obtaining the file label policy information encrypted with the public key of the target file, the second device decrypts the file label policy information with the private key of the target file to obtain the file label policy information and the file encryption key. The second device also encrypts the file encryption key with the public key of the request object to obtain a second ciphertext. The second device sends permission information including the first ciphertext and the second ciphertext to the first device. Based on the second ciphertext of the obtained permission information, the first device can decrypt the second ciphertext with the private key of the request object to obtain the file encryption key. If the first device determines that the request object has access rights to the target file based on the permission policy information, the file encryption key obtained by decrypting the second ciphertext is used to decrypt the target file so that the request object can operate on the target file. In this way, further encryption processing of the target file can be achieved, thereby improving the data security of the target file.
[0127] The above is a method for implementing target file access using the file tag policy information of the target file. The following provides a possible specific implementation method for generating the file tag policy information of the target file.
[0128] See FIG7 , which is a flow chart of generating file tag policy information for a target file according to an embodiment of the present application. The method includes S701-S703:
[0129] S701: The first device obtains a file tag of a target file.
[0130] The target file's file tag is a tag set for the target file. File tags include one or more security-related tags. It should be noted that the target file's file tag is determined based on a tag template. A tag template is a pre-set template for configuration file tags. As an example, a tag template includes multiple selectable file tags. The target file's file tag is selected from the tag template.
[0131] The embodiments of the present application do not limit the manner in which the file tag of the target file is generated. In one possible implementation, the generation of the file tag of the target file is triggered by the manager of the target file. The manager of the target file is a user with the authority to manage the target file. The manager of the target file is, for example, the owner of the target file. The user can generate a file tag by selection or input. In another possible implementation, the first device automatically generates a file tag based on the file attributes of the target file. File attributes include, for example, file type, file generation time, and file priority. As an example, the file tag of the target file is automatically generated according to a pre-set tag generation rule and the file attributes of the target file. The tag generation rule includes, for example, a correspondence between file attributes and file tags.
[0132] As an example, see Figure 8, which is a schematic diagram of a file labeling strategy provided in an embodiment of the present application. The label template includes labels of four security dimensions, namely sensitivity labels, user labels, access process labels, and outgoing permission labels. Sensitivity labels include, for example, top secret, confidential, internal, public, and personal. User labels include, for example, U1 type. Access process labels include P1 type. Outgoing permission labels include financial data and sales data.
[0133] Based on the user's selection instruction for the file tag, the file tag is determined from the tags included in the tag template, or the file tag is automatically generated based on the tags included in the tag template. For example, as shown in Figure 8, a top secret tag, a U1 type tag, a P1 type tag, and a financial data tag are selected from the tag template.
[0134] S703: The first device generates file tag policy information of the target file based on the file tag and the tag policy template.
[0135] The tag policy template is a policy template pre-configured by the tag policy management user. The embodiments of this application do not limit the specific content of the tag policy template. As an example, the tag policy template includes policies corresponding to tags in four security dimensions: sensitivity, user, access process, and outbound permissions.
[0136] A tag policy template corresponds to a tag template and includes tag policy information corresponding to each tag included in the tag template.
[0137] Taking Figure 8 as an example, the label policy template includes label policy information of four security dimensions, including label policy information corresponding to each label included in the label template. Sensitivity policy information includes: 1. Encryption for top secret or confidential files; 2. No encryption for public files; 3. Top secret files are denied printing and copying; 4. Only the user to whom they belong has permission to use personal files. User policy information includes: 1. U1 type users have all permissions; 2. For top secret and confidential files, other types of users are denied access; for public files, all types of users have all permissions. Access process policy information includes: 1. P1 type processes have all permissions; 2. For top secret or confidential files, other processes are denied access; for public files, all types of processes have all permissions. Outbound permission policy information includes: 1. Financial data can only be sent internally by financial personnel; 2. Public data does not restrict outbound permissions.
[0138] The first device obtains the tag policy information of the file tag of the target file from the tag policy template, integrates the tag policy information of the file tags, and obtains the file tag policy information of the target file.
[0139] As an example, the file tag of the target file is matched with the tag template included in the tag policy template, and the file tag policy information of the tag template consistent with the file tag of the target file is used as the file tag policy information corresponding to the file tag of the target file.
[0140] As shown in Figure 8, the first device can determine the file label policy information corresponding to the file label of the target file from the label policy template, that is, the file label policy information of the target file, including: 1. Sensitivity policy information: top secret file encryption; 2. Access user policy information: U1 type users have all permissions, and other types of users are denied access; 3. Access process policy information: P1 type processes have all permissions, and other processes are denied access; 4. Outbound permission policy information: limit outbound transmission to non-financial personnel.
[0141] After obtaining the file label policy information of the target file, the first device can encapsulate the file content of the target file, the file label of the target file, and the file label policy information of the target file into a protected file. The embodiment of the present application does not limit the implementation method of encapsulating the file. As an example, the file content of the target file, the file label of the target file, and the file label policy information of the target file are encapsulated into one file. As another example, the file content of the target file, the file label of the target file, and the file label policy information of the target file are respectively encapsulated into three interrelated files. The file label policy information of the target file can be encrypted by the first public key.
[0142] Based on the above steps S701 and S703, it can be seen that file tags and file tag policy information can be flexibly configured to meet the data security requirements of the target file, achieving fine-grained security protection for files and meeting the security requirements of different files and file access for different object types. Furthermore, configuring file tag policy information using file tags and tag policy templates can improve the efficiency of configuring file tag policy information.
[0143] The embodiment of the present application does not limit the source of the tag policy template.
[0144] In one possible implementation, the tag policy template is pre-configured in the first device.
[0145] In another possible implementation, the tag policy template is obtained by the first device from the second device. Referring to FIG7 , the method may further include S7021 to S7023.
[0146] S7021: The first device sends a label policy template acquisition request to the second device.
[0147] The tag policy template acquisition request is used to obtain the tag policy template. The tag policy template is a policy template pre-configured by the tag policy management user. The embodiments of the present application do not limit the specific content included in the tag policy template. As an example, the tag policy template includes policies corresponding to tags of four security dimensions: sensitivity, access user, access process, and outbound permission.
[0148] S7022: In response to obtaining the label policy template acquisition request sent by the first device, the second device sends the label policy template to the first device.
[0149] The second device stores the tag policy template.
[0150] S7023: The first device obtains the label policy template sent by the second device.
[0151] Furthermore, based on the file tag policy information generated based on the tag policy template, the file tag policy information can also be customized and adjusted.
[0152] 9, which is a flow chart of another method for generating file tag policy information for a target file according to an embodiment of the present application. The method is applied to a first device and a second device, and in addition to S701-S703 above, further includes S704 and S705.
[0153] S704: The first device obtains custom tag policy information for the target file.
[0154] In one possible implementation, the first device displays an editing control for editing file label policy information. The user can input custom label policy information for the target file through the editing control. The custom label policy information includes, for example, added additional label policy information. As an example, taking the file label policy information of the target file shown in Figure 8 as an example, the additional label policy information includes newly added access user policy information: U2 type users have read permission and write permission, U3 type users have read permission, write permission and print permission, P2 type processes have read-only permission, and P3 type processes have read permission and write permission. The custom label policy information also includes, for example, revised label policy information. The revised label policy information includes the label policy information that needs to be modified for the file label policy information of the target file, as well as the revised label policy information.
[0155] S705: The first device updates the file tag policy information of the target file using the custom tag policy information.
[0156] In this way, the target file can be flexibly adjusted based on the rapid configuration of the file label policy information of the target file, so that the generated file label policy information of the target file is more in line with the data security requirements of the target file.
[0157] In addition, in a storage scenario, as shown in FIG4a , the first device is a storage device. The storage device is connected to a third device. The third device is, for example, a production host. The production host is a host connected to the storage device and capable of accessing data stored in the storage device. The storage device and the production host interact via a security protocol. The embodiments of the present application do not limit the type of security protocol. As an example, the security protocol is a Network Attached Storage (NAS) protocol or an Object Storage Service (OBS) protocol.
[0158] In one possible implementation, a requesting party accesses a file using a third device connected to a first device. The requesting party triggers a file access request for a target file on the third device. The third device encapsulates the file access request using a security protocol. The third device sends the encapsulated file access request to the first device. The first device decapsulates the obtained file access request using the security protocol.
[0159] Furthermore, when executing access control on the target file accessed by the requesting party according to the permission policy information of the requesting party, the first device generates feedback file information according to the permission policy information of the requesting party and the access operation information of the requesting party. The first device sends the feedback file information, encapsulated using the security protocol, to the third device. The third device, upon receiving the feedback file information, decapsulates the feedback file information using the security protocol.
[0160] By encapsulating and decapsulating information exchanged between the first device and the third device using a security protocol, the security of the interaction between the first device and the third device can be improved, and security requirements for accessing files can be met.
[0161] During the process of configuring file tag policy information for a target file on a storage device, the generation of a file tag for the target file can be triggered by a user of a third device or automatically by the third device. The third device encapsulates the file tag of the target file using a security protocol and sends the encapsulated file tag of the target file to the first device. The first device obtains the file tag of the target file encapsulated using the security protocol.
[0162] The first device decapsulates the file tag of the encapsulated target file using the security protocol to obtain the file tag of the target file.
[0163] The present application further provides a file access device 1000, which is applied to a first device, as shown in FIG10 , and includes:
[0164] an acquisition module, configured to acquire a file access request for a target file triggered by a requesting object, the file access request including access operation information describing an access operation that the requesting object needs to perform on the target file; the requesting object being a system user of an operating system program of the first device, or an application user of an application program;
[0165] a processing module configured to obtain permission policy information of the request object, the permission policy information being determined based on file tag policy information of the target file and the file access request; the file tag policy information corresponding to the file tag of the target file, the file tag policy information being used to describe a control policy for access operations on the target file, and the permission policy information being used to indicate the permission of the request object to operate the target file; the file tag including one or more security dimension tags, and the file tag being set by the administrator of the target file or generated based on the file attributes of the target file;
[0166] A control module is used to perform access control on the request object's access to the target file according to the permission policy information.
[0167] In a possible implementation, the processing module is specifically configured to generate permission policy information of the request object according to the file tag policy information of the target file and the file access request of the request object.
[0168] In one possible implementation, the processing module is specifically used to send a permission request for the target file to the second device, the permission request including the file label policy information of the target file, the access operation information and the public key of the request object, and the file label policy information of the target file is encrypted by the public key of the target file; obtain the permission information fed back by the second device, the permission information including a first ciphertext, the first ciphertext including the ciphertext obtained by encrypting the permission policy information of the request object using the public key of the request object, and the permission policy information of the request object is obtained by the second device using the private key of the target file, the file label policy information of the target file and the access operation information; decrypt the first ciphertext using the private key of the request object to obtain the permission policy information of the request object.
[0169] In one possible implementation, the target file is encrypted using a file encryption key, which is encapsulated in the file tag policy information of the target file. The permission information also includes a second ciphertext obtained by encrypting the file encryption key using the public key of the request object. The processing module is also used to decrypt the target file using the file encryption key if it is determined that the request object has access rights based on the permission policy information. The file encryption key is obtained by decrypting the second ciphertext using the private key of the request object.
[0170] In a possible implementation, the acquisition module is further configured to acquire a file tag of the target file;
[0171] A generating module is used to generate file tag policy information of the target file based on the file tag and the tag policy template.
[0172] In a possible implementation, the tag policy template is obtained from the second device.
[0173] In a possible implementation, the acquisition module is further configured to acquire custom tag policy information for the target file;
[0174] The generating module is further configured to update the file label policy information of the target file using the custom label policy information.
[0175] In a possible implementation, the first device is a host.
[0176] In a possible implementation manner, the apparatus is applied to an application layer of the first device.
[0177] In a possible implementation manner, the apparatus is applied to a system layer of the first device.
[0178] In a possible implementation, the application is a preset security application.
[0179] In one possible implementation, the first device is a storage device, and the acquisition module is specifically used to obtain a file access request for a target file triggered by a request object and sent by a third device, wherein the file access request is encapsulated by the third device using a security protocol; and the file access request is unsealed using the security protocol.
[0180] In a possible implementation, the control module is specifically configured to generate feedback file information according to the permission policy information of the request object and the access operation information of the request object, and send the feedback file information encapsulated using a security protocol to the third device.
[0181] The acquisition module, processing module, and control module can all be implemented in software or hardware. For example, the implementation of the acquisition module will be described below using the acquisition module as an example. Similarly, the implementation of the processing module and control module can refer to the implementation of the acquisition module.
[0182] As an example of a software functional unit, the module acquisition module may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the acquisition module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Typically, a region may include multiple AZs.
[0183] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.
[0184] As an example of a hardware functional unit, the acquisition module may include at least one computing device, such as a server. Alternatively, the acquisition module may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0185] The multiple computing devices included in the acquisition module can be distributed in the same region or in different regions. The multiple computing devices included in the acquisition module can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the acquisition module can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.
[0186] It should be noted that, in other embodiments, the acquisition module can be used to execute any step in the file access method, the processing module can be used to execute any step in the file access method, and the control module can be used to execute any step in the file access method. The steps that the acquisition module, processing module and control module are responsible for implementing can be specified as needed. The full functions of the file access device are realized by respectively implementing different steps in the file access method through the acquisition module, processing module and control module.
[0187] The present application further provides a device 1100 for determining file access rights, which is applied to a second device. As shown in FIG11 , the device includes:
[0188] an acquisition module, configured to acquire a permission request for the target file sent by the first device, the permission request including file tag policy information of the target file, access operation information, and a public key of a requesting party, the file tag policy information being encrypted by the public key of the target file, the file tag policy information corresponding to the file tag of the target file, the file tag policy information being used to describe a control policy for access operations on the target file, the file tag including tags of one or more security dimensions, the file tag being set by an administrator of the target file or generated based on file attributes of the target file, and the requesting party being a system user of an operating system program of the first device, or an application user of an application program;
[0189] A decryption module, configured to decrypt the file tag policy information using the private key of the target file;
[0190] a determination module, configured to determine permission policy information of a requesting object based on the file tag policy information of the target file and the access operation information, wherein the permission policy information is used to describe the permission policy of the requesting object for the access operation on the target file;
[0191] an encryption module, configured to encrypt the rights policy information of the request object using the public key of the request object to obtain a first ciphertext;
[0192] A sending module is configured to send permission information to the first device, where the permission information includes the first ciphertext.
[0193] In one possible implementation, the target file is encrypted using a file encryption key, and the file encryption key is encapsulated in the file tag policy information of the target file. The encryption module is also used to encrypt the file encryption key using the public key of the request object to obtain a second ciphertext, and the permission information also includes the second ciphertext.
[0194] In a possible implementation, the sending module is further configured to send the label policy template to the first device in response to obtaining the label policy template acquisition request sent by the first device.
[0195] In a possible implementation, the second device is a server or a management device.
[0196] The acquisition module, decryption module, determination module, encryption module, and sending module can all be implemented in software or hardware. For example, the implementation of the acquisition module will be described below using the acquisition module as an example. Similarly, the implementation of the decryption module, determination module, encryption module, and sending module can refer to the implementation of the acquisition module.
[0197] As an example of a software functional unit, the module acquisition module may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the acquisition module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Typically, a region may include multiple AZs.
[0198] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.
[0199] As an example of a hardware functional unit, the acquisition module may include at least one computing device, such as a server. Alternatively, the acquisition module may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0200] The multiple computing devices included in the acquisition module can be distributed in the same region or in different regions. The multiple computing devices included in the acquisition module can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the acquisition module can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.
[0201] It should be noted that, in other embodiments, the acquisition module can be used to execute any step in the file access permission determination method, the decryption module can be used to execute any step in the file access permission determination method, the determination module can be used to execute any step in the file access permission determination method, the encryption module can be used to execute any step in the file access permission determination method, and the sending module can be used to execute any step in the file access permission determination method. The steps that the acquisition module, decryption module, determination module, encryption module and sending module are responsible for implementing can be specified as needed. The full functions of the file access permission determination device are realized by respectively implementing different steps in the file access permission determination method through the acquisition module, decryption module, determination module, encryption module and sending module.
[0202] This application also provides a computing device 1200. As shown in Figure 12, computing device 1200 includes a bus 1202, a processor 1204, a memory 1206, and a communication interface 1208. Processor 1204, memory 1206, and communication interface 1208 communicate with each other via bus 1202. Computing device 1200 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computing device 1200.
[0203] Bus 1202 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG12 shows a single bus line, but this does not imply a single bus or type of bus. Bus 1202 may include a path for transmitting information between various components of computing device 1200 (e.g., memory 1206, processor 1204, and communication interface 1208).
[0204] The processor 1204 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0205] The memory 1206 may include volatile memory, such as random access memory (RAM). The processor 1204 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0206] The memory 1206 stores executable program codes, and the processor 1204 executes the executable program codes to respectively implement the functions of the aforementioned acquisition module, processing module, and control module, thereby implementing the file access method. In other words, the memory 1206 stores instructions for executing the file access method.
[0207] Alternatively, the memory 1206 stores executable code, and the processor 1204 executes the executable code to respectively implement the functions of the aforementioned acquisition module, decryption module, determination module, encryption module, and sending module, thereby implementing the file access method. In other words, the memory 1206 stores instructions for executing the file access permission determination method.
[0208] The communication interface 1208 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1200 and other devices or a communication network.
[0209] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0210] As shown in Figure 13, the computing device cluster includes at least one computing device 1200. The memory 1206 in one or more computing devices 1200 in the computing device cluster may store the same instructions for executing the file access method.
[0211] In some possible implementations, the memory 1206 of one or more computing devices 1200 in the computing device cluster may also store partial instructions for executing the file access method. In other words, the combination of one or more computing devices 1200 can jointly execute the instructions for executing the file access method.
[0212] It should be noted that the memory 1206 in different computing devices 1200 in the computing device cluster can store different instructions, each for executing a portion of the functions of the file access device. In other words, the instructions stored in the memory 1206 in different computing devices 1200 can implement the functions of one or more modules among the acquisition module, the processing module, and the control module.
[0213] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. The network may be a wide area network (WAN) or a local area network (LAN), etc. FIG14 illustrates a possible implementation. As shown in FIG14 , two computing devices 1200A and 1200B are connected via a network. Specifically, the connection to the network is made via a communication interface in each computing device. In this type of possible implementation, the memory 1206 in the computing device 1200A stores instructions for executing the functions of the acquisition module. Simultaneously, the memory 1206 in the computing device 1200B stores instructions for executing the functions of the processing module and the control module.
[0214] The connection method between the computing device clusters shown in Figure 14 can be considered to be that the file access method provided by this application needs to process a large amount of data, so the functions implemented by the processing module and the control module are considered to be handed over to the computing device 1200B for execution.
[0215] It should be understood that the functionality of the computing device 1200A shown in FIG14 may also be implemented by multiple computing devices 1200. Similarly, the functionality of the computing device 1200B may also be implemented by multiple computing devices 1200.
[0216] The present application also provides another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similar to the connection method of the computing device cluster described in Figures 13 and 14. However, the memory 1206 in one or more computing devices 1200 in this computing device cluster can store the same instructions for executing the file access permission determination method.
[0217] In some possible implementations, the memory 1206 of one or more computing devices 1200 in the computing device cluster may also store partial instructions for executing the method for determining file access permissions. In other words, the combination of one or more computing devices 1200 can jointly execute the instructions for executing the method for determining file access permissions.
[0218] It should be noted that the memory 1206 in different computing devices 1200 in the computing device cluster may store different instructions for executing a portion of the file access permission determination function. In other words, the instructions stored in the memory 1206 in different computing devices 1200 may implement the functions of one or more of the acquisition module, decryption module, determination module, encryption module, and sending module.
[0219] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the computer program product causes the at least one computing device to execute a file access method or a file access permission determination method.
[0220] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute a file access method or instruct the computing device to execute a file access permission determination method.
[0221] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A file access method, characterized in that: The method is applied to a first device, and the method includes: Acquire a file access request for a target file triggered by a request object, the file access request including access operation information, the access operation information being used to describe an access operation that the request object needs to perform on the target file; the request object is a system user of an operating system program of the first device, or an application user of an application program; Acquire the permission policy information of the request object, the permission policy information is determined based on the file tag policy information of the target file and the file access request; the file tag policy information corresponds to the file tag of the target file, the file tag policy information is used to describe the control policy for the access operation on the target file, and the permission policy information is used to indicate the permission of the request object to operate the target file; the file tag includes one or more security dimension tags, and the file tag is set by the administrator of the target file or generated based on the file attributes of the target file; Access control of the request object to the target file is performed according to the authority policy information.
2. The method according to claim 1, characterized in that The obtaining the permission policy information of the request object includes: The permission policy information of the request object is generated according to the file tag policy information of the target file and the file access request of the request object.
3. The method according to claim 1, characterized in that The obtaining the permission policy information of the request object includes: Sending a permission request for the target file to the second device, the permission request including the file tag policy information of the target file, the access operation information, and the public key of the request object, wherein the file tag policy information of the target file is encrypted by the public key of the target file; Acquire permission information fed back by the second device, the permission information including a first ciphertext, the first ciphertext including a ciphertext obtained by encrypting permission policy information of the request object using the public key of the request object, the permission policy information of the request object being obtained by the second device using the private key of the target file, the file tag policy information of the target file, and the access operation information; The first ciphertext is decrypted using the private key of the request object to obtain the permission policy information of the request object.
4. The method according to claim 3, characterized in that The target file is encrypted using a file encryption key, the file encryption key is encapsulated in the file tag policy information of the target file, the permission information also includes a second ciphertext obtained by encrypting the file encryption key using the public key of the request object, and before performing access control on the request object accessing the target file according to the permission policy information of the request object, the method also includes: If it is determined based on the permission policy information that the request object has access rights, the target file is decrypted using the file encryption key, where the file encryption key is obtained by decrypting the second ciphertext using the private key of the request object.
5. The method according to claim 1, characterized in that The method further comprises: Get the file tag of the target file; Based on the file tag and the tag policy template, file tag policy information of the target file is generated.
6. The method according to claim 5, characterized in that The tag policy template is obtained from the second device.
7. The method according to claim 5, characterized in that The method further comprises: Obtaining custom tag policy information for the target file; The file label policy information of the target file is updated using the custom label policy information.
8. The method according to claim 1, characterized in that The first device is a host.
9. The method according to claim 8, characterized in that The method is applied to the application layer of the first device.
10. The method according to claim 8 or 9, characterized in that: The method is applied to the system layer of the first device.
11. The method according to claim 10, characterized in that The application is a preset security application.
12. The method according to claim 1, characterized in that The first device is a storage device, and obtaining a file access request for a target file triggered by a request object includes: Acquire a file access request for a target file that is triggered by a request object and sent by a third device, wherein the file access request is encapsulated by the third device using a security protocol; The file access request is unsealed using the security protocol.
13. The method according to claim 12, characterized in that The performing access control on the request object accessing the target file according to the permission policy information includes: Feedback file information is generated according to the permission policy information of the request object and the access operation information of the request object, and the feedback file information encapsulated by using a security protocol is sent to the third device.
14. A method for determining file access rights, characterized in that: The method is applied to a second device, and the method includes: Obtaining a permission request for the target file sent by the first device, the permission request including file label policy information of the target file, access operation information, and a public key of a request object, the file label policy information being encrypted by the public key of the target file, the file label policy information corresponding to a file label of the target file, the file label policy information being used to describe a control policy for access operations on the target file, the file label including labels of one or more security dimensions, the file label being set by an administrator of the target file or generated based on file attributes of the target file, and the request object being a system user of an operating system program of the first device, or an application user of an application program; Decrypting the file tag policy information using the private key of the target file; Determine the permission policy information of the request object based on the file tag policy information of the target file and the access operation information, wherein the permission policy information is used to describe the permission policy of the request object for the access operation of the target file; Encrypting the permission policy information of the request object by using the public key of the request object to obtain a first ciphertext; Sending permission information to the first device, where the permission information includes the first ciphertext.
15. The method according to claim 14, characterized in that The target file is encrypted using a file encryption key, and the file encryption key is encapsulated in file tag policy information of the target file. The method further includes: The file encryption key is encrypted using the public key of the request object to obtain a second ciphertext, and the permission information also includes the second ciphertext.
16. The method according to claim 14, characterized in that The method further comprises: In response to obtaining the label policy template acquisition request sent by the first device, a label policy template is sent to the first device.
17. The method according to any one of claims 14 to 16, characterized in that: The second device is a server or a management device.
18. A file access device, characterized in that: The device is applied to a first device, and includes: an acquisition module, configured to acquire a file access request for a target file triggered by a request object, wherein the file access request includes access operation information, and the access operation information is used to describe the access operation that the request object needs to perform on the target file; the request object is a system user of an operating system program of the first device, or an application user of an application program; A processing module is used to obtain the permission policy information of the request object, the permission policy information is determined based on the file label policy information of the target file and the file access request; the file label policy information corresponds to the file label of the target file, the file label policy information is used to describe the control policy for the access operation on the target file, and the permission policy information is used to indicate the permission of the request object to operate the target file; the file label includes one or more security dimension labels, and the file label is set by the administrator of the target file or generated based on the file attributes of the target file; A control module is used to perform access control on the request object's access to the target file according to the permission policy information.
19. A device for determining file access rights, characterized in that: The device is applied to a second device, and includes: an acquisition module, configured to acquire a permission request for the target file sent by the first device, the permission request including file label policy information of the target file, access operation information, and a public key of a request object, the file label policy information being encrypted by the public key of the target file, the file label policy information corresponding to a file label of the target file, the file label policy information being used to describe a control policy for access operations on the target file, the file label including labels of one or more security dimensions, the file label being set by an administrator of the target file or generated based on a file attribute of the target file, and the request object being a system user of an operating system program of the first device, or an application user of an application program; A decryption module, used to decrypt the file tag policy information using the private key of the target file; A determination module, used to determine the permission policy information of the request object based on the file tag policy information of the target file and the access operation information, wherein the permission policy information is used to describe the permission policy of the request object for the access operation of the target file; An encryption module, used to encrypt the permission policy information of the request object using the public key of the request object to obtain a first ciphertext; A sending module is used to send permission information to the first device, where the permission information includes the first ciphertext.
20. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device so that The computing device cluster executes the method according to any one of claims 1-13, or executes the method according to any one of claims 14-17.
21. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster executes the method described in any one of claims 1 to 13, or executes the method described in any one of claims 14 to 17.
22. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 13, or executes the method according to any one of claims 14 to 17.
Citation Information
Patent Citations
Android privacy data protection method and system based on authority tags
CN104318171A
Method and server for preventing electronic document leakage
CN105512565A
File outgoing management and control system and method in a secure application environment
CN109614812A
IPFS file processing method, node, medium and device
CN111400269A
OBS file access method, system and device, electronic equipment and storage medium
CN115982778A