Data transmission method, apparatus, and device
By executing the flow attributes and flow policies in the management module between the data storage device and the receiving device, the risk of data leakage during data transmission is solved, and the security and compliance of data transmission are achieved.
Patent Information
- Application Number
- PCT/CN2024/131587
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-27
- Filing Date
- 2024-11-12
- Publication Date
- 2025-06-05
AI Technical Summary
The prior art is difficult to effectively prevent data leakage during data transmission, especially when the data security and confidentiality levels are different.
Through the method performed by the management module between the data storage device and the receiving device, the flow properties of the target data and the receiving device are obtained, and the data is determined according to the flow policy, to ensure that the data has obtained permissions of the receiving device before transmission.
It effectively improves the security of data during transmission, avoids the risk of data leakage, and ensures that data is only accessible on authorized receiving devices.
Smart Images

Figure CN2024131587_05062025_PF_FP_ABST
Abstract
Description
Data transmission method, device and equipment
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 27, 2023, with application number 202311599756.8 and application name “A Data Transmission Method, Device and Equipment”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a data transmission method, apparatus, and device. Background Art
[0004] With the development of network technology, there is an increasing demand for cross-domain sharing or flow of data, such as sharing data between company headquarters and branches, sharing data between companies and partners, and sharing data between corporate management departments and enterprises.
[0005] Due to the varying security and confidentiality levels of data, data must be managed and controlled to prevent data leaks. Currently, data management is implemented based on access control lists (ACLs). The implementation process is as follows: When a user requests to view data on a remote site, the user-side site can access the remote site to obtain the data and the data's ACL, which describes the users allowed to access the data. The user-side site then determines whether the user is allowed to access the data based on the data's ACL. If the user is not allowed to access the data, the user-side site directly rejects the user's request.
[0006] As can be seen from the above implementation, although the user's site can deny the user's request based on the data's ACL, the data has already been transmitted from the remote site to the user's site. If the data is highly secure, there is still a risk of leakage during transmission or after the data reaches the user's site.
[0007] Summary of the Invention
[0008] The embodiments of the present application provide a data transmission method, apparatus, and device for ensuring data security.
[0009] In a first aspect, an embodiment of the present application provides a data transmission method, which can be executed by a device where a management module is located. In this method:
[0010] The device containing the management module can obtain the flow attributes of the target data to be transmitted and the flow attributes of the receiving device. The flow attributes of the target data represent the factors that restrict the target data's transmission, while the flow attributes of the receiving device represent the factors that restrict the receiving device's access to the data. In other words, the target data cannot be transmitted arbitrarily, but is subject to certain factors. Similarly, the receiving device cannot obtain any data, but is subject to certain factors.
[0011] The device where the management module is located can determine whether the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, wherein the flow policy describes the flow attributes of the target data and the conditions that the flow attributes of the receiving device must follow when the receiving device has the authority to obtain the target data.
[0012] Through the above method, if the receiving device needs to receive data, before transmitting the data to the receiving device, the device where the management module is located can determine whether the target data is allowed to be transmitted to the receiving device based on the flow properties of the target data, the flow properties of the receiving device, and the flow policy, thereby effectively ensuring the security of the target data.
[0013] In one possible implementation, the device in which the management module is located may be a data storage device that stores the target data. The data storage device receives a data request from a receiving device, the data request being used to request the target data and carrying a transfer attribute of the receiving device. Upon receiving the data request, the data storage device may determine whether the target data is permitted to be transmitted to the receiving device based on the transfer attribute of the target data, the transfer attribute of the receiving device, and a transfer policy.
[0014] Through the above method, as a data storage device storing target data, the data storage device can independently decide whether to transmit the target data to the receiving device, thereby improving the security of the target data and avoiding data leakage caused by transmitting the target data to the receiving device.
[0015] In a possible implementation, as a data storage device, when acquiring the flow attributes of target data to be transmitted, the data storage device may acquire the flow attributes of the target data from metadata of the target data.
[0016] Through the above method, the flow attributes of the target data are recorded in the metadata of the target data, which makes it easier for the data storage device to obtain the flow attributes of the target data.
[0017] In one possible implementation, a receiving device may send a metadata request to a data storage device. The metadata request may include the streaming data of the receiving device. The metadata request is used to request a metadata set. The metadata set may be a set of metadata consisting of all data that the receiving device is allowed to obtain, or a portion of the metadata of all data that the receiving device is allowed to obtain.
[0018] After receiving the metadata request sent by the receiving device, the data storage device determines a metadata set according to the streaming attribute of the receiving device in response to the metadata request, the metadata set including metadata allowed to be transmitted to the receiving device, and transmits the metadata set to the receiving device.
[0019] Through the above method, when the receiving device requests to obtain a metadata set, the data storage device will transmit the metadata set including the metadata allowed to be transmitted to the receiving device to the receiving device only after determining the metadata allowed to be transmitted to the receiving device, thereby effectively ensuring the security of the metadata.
[0020] In a possible implementation, if the data storage device determines that the target data is allowed to be transmitted to the receiving device, the data storage device may transmit the target data to the receiving device.
[0021] If the data storage device determines that the target data is not allowed to be transmitted to the receiving device, the data storage device may reject the data request and not transmit the target data to the receiving device.
[0022] Through the above method, the data storage device will transmit the target data to the receiving device only when the target data is allowed to be transmitted to the receiving device.
[0023] In a possible implementation, the device where the management module is located may be a device independent of the data storage device. For the sake of convenience, the device independent of the data storage device is referred to as a management device.
[0024] The data storage device may send a first inquiry message to the management device, wherein the first inquiry message is used to inquire whether the target data is allowed to be transmitted to the receiving device. The first inquiry message carries the flow attributes of the target data and the flow attributes of the receiving device.
[0025] The management device can obtain the flow attributes of the target data and the flow attributes of the receiving device from the first query message, and then determine whether the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy.
[0026] Through the above method, before sending the target data to the receiving device, the data storage device will first query the management device to determine whether the target data is allowed to be transmitted to the receiving device, so as to avoid the situation where the receiving device transmits the target data to the receiving device without obtaining the authority to transmit the target data.
[0027] In one possible implementation, the data storage device may send a second query message to the management device, where the second query message is used to query the metadata set, where the metadata set includes metadata allowed to be transmitted to the receiving device, and the second query message carries the flow attributes of the receiving device.
[0028] In response to the second inquiry message, the management device determines a metadata set according to the flow attribute of the receiving device, and transmits the metadata set to the data storage device, or transmits information indicating the metadata set to the data storage device.
[0029] Through the above method, before sending metadata to the receiving device, the data storage device will first query the management device to determine the metadata allowed to be transmitted to the receiving device, so as to ensure the security of the metadata.
[0030] In one possible implementation, when the management device determines that the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, the management device can send a notification message (such as the first notification message mentioned in the embodiment of the present application) to the data storage device. The notification message is used to notify the target data that it is allowed to be transmitted to the receiving device.
[0031] When the management device determines that the target data is not allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, it can notify the data storage device that the target data is not allowed to be transmitted to the receiving device.
[0032] Through the above method, the management device promptly notifies the data storage device whether the target data is allowed to be transmitted to the receiving device.
[0033] In one possible implementation, the device where the management module is located also has a configuration function for flow attributes. The device where the management module is located can configure flow attributes for the receiving device under the user's instructions; configure flow attributes for the target data under the user's instructions, and record the flow attributes of the target data in the metadata of the target data.
[0034] Through the above method, the device where the management module is located configures the flow attributes under the user's instructions to ensure that the flow attributes of the target data and the flow attributes of the receiving device meet the user's needs, and then, whether the target data is allowed to be transmitted to the receiving device meets the user's needs.
[0035] In one possible implementation, when the device where the management module is located configures the flow attributes for the receiving device, it can generate a certificate that records the flow attributes of the receiving device and perform some or all of the following on the certificate: encrypt the certificate using the public key of the receiving device and add signature information to the certificate; wherein the signature information is generated using its own private key.
[0036] After the certificate is generated, the device where the management module is located sends the certificate to the receiving device.
[0037] Through the above method, the device where the management module is located notifies the receiving device of the flow attributes configured for it by issuing a certificate to the receiving device. This method has a high degree of security and prevents the flow attributes of the receiving device from being maliciously tampered with.
[0038] In one possible implementation, the aforementioned description assumes that the flow attributes of the receiving device are carried in the data request, metadata request, first query message, or second query message. In fact, the flow attributes of the receiving device may not be carried in the data request, metadata request, first query message, or second query message, but may be stored in the device where the management module is located. For example, if a user-preconfigured flow attribute set is stored in the device where the management module is located, when the device where the management module is located obtains the flow attributes of the receiving device, it may obtain the flow attributes of the receiving device from the user-preconfigured device flow attribute set, where the device flow attribute set includes the flow attributes configured by the user for at least one device.
[0039] Through the above method, the device where the management module is located can obtain the flow attributes of the receiving device from the device flow attribute set, and can ensure that the flow attributes of the receiving device are true process attributes, thereby preventing the receiving device from requesting target data or metadata with false flow attributes.
[0040] In one possible implementation, the present application does not limit the content indicated by the flow attributes of the target data. The flow data of the target data may indicate the security level of the target data, the business type of the target data, or the security level and business type of the target data.
[0041] This application does not limit the content indicated by the flow attributes of the receiving device. The flow attributes of the receiving device can indicate the security level of the receiving device, the business type of the business undertaken by the receiving device, or the security level of the receiving device and the business type of the business undertaken by the receiving device at the same time.
[0042] Through the above method, the content indicated by the flow attributes of the target data and the flow attributes of the receiving device is more flexible and applicable to different scenarios.
[0043] In a second aspect, an embodiment of the present application further provides a data transmission device, which has the function of implementing the behavior of the device (such as a data storage device or a management device) where the management module in the method example of the first aspect is located. The beneficial effects can be found in the description of the first aspect and will not be repeated here. The functions can be implemented by hardware or by executing corresponding software implementations through hardware. The hardware or software includes one or more modules corresponding to the above functions. The structure of the data transmission device includes a management module.
[0044] The management module can obtain the flow attributes of the target data to be transmitted and the flow attributes of the receiving device. The flow attributes of the target data represent the factors that restrict the target data from being transmitted, and the flow attributes of the receiving device represent the factors that restrict the receiving device from acquiring the data. The management module determines whether the target data is permitted to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy. The flow policy describes the conditions that the flow attributes of the target data and the flow attributes of the receiving device must comply with when the receiving device has permission to acquire the target data.
[0045] In a possible implementation, when the data transmission device has the function of implementing the behavior of the data storage device, the data transmission device further includes a first transmission module.
[0046] The first transmission module receives a data request sent by a receiving device, the data request is used to request to obtain target data, and the data request carries the flow attribute of the receiving device. The management module obtains the flow attribute of the receiving device from the data request.
[0047] In a possible implementation, when the data transmission device has the function of implementing the behavior of the data storage device, the management module obtains the flow attribute of the target data from the metadata of the target data.
[0048] In a possible implementation, the first transmission module may further receive a metadata request sent by the receiving device, where the metadata request carries the flow attribute of the receiving device.
[0049] The management module determines a metadata set in response to the metadata request and according to the flow attribute of the receiving device, where the metadata set includes metadata allowed to be transmitted to the receiving device.
[0050] The first transmission module transmits the metadata set to the receiving device.
[0051] In a possible implementation, the first transmission module sends the target data to the receiving device after the management module determines that the target data is allowed to be transmitted to the receiving device. The first transmission module rejects the data request after the management module determines that the target data is not allowed to be transmitted to the receiving device.
[0052] In a possible implementation, when the data transmission device has the function of implementing the behavior of the management device, the data transmission device further includes a second transmission module.
[0053] The second transmission module receives a first inquiry message sent by the data storage device. The first inquiry message is used to inquire whether the target data is allowed to be transmitted to the receiving device. The first inquiry message carries the flow attributes of the target data and the flow attributes of the receiving device.
[0054] The management module obtains the flow attributes of the target data and the flow attributes of the receiving device from the first query message.
[0055] In one possible implementation, the second transmission module can also receive a second inquiry message sent by the data storage device. The second inquiry message is used to inquire about the metadata set, which includes metadata allowed to be transmitted to the receiving device. The second inquiry message carries the flow attributes of the receiving device.
[0056] The management module determines the metadata set according to the flow attribute of the receiving device in response to the second query message.
[0057] The second transmission module transmits the metadata set to the data storage device.
[0058] In one possible implementation, when the management module determines that the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, the second transmission module sends a notification message to the data storage device, and the notification message is used to notify the target data that it is allowed to be transmitted to the receiving device.
[0059] In one possible implementation, the management module may configure flow attributes for the receiving device under the user's instruction; the management module may also configure flow attributes for the target data under the user's instruction, and record the flow attributes of the target data in the metadata of the target data.
[0060] In one possible implementation, when the management module configures the flow attributes for the receiving device, it generates a certificate that records the flow attributes of the receiving device, and performs some or all of the following on the certificate: encrypts the certificate using the public key of the receiving device and adds signature information to the certificate; wherein the signature information is generated using its own private key; and the management module sends the certificate to the receiving device.
[0061] In one possible implementation, the data request, metadata request, first query message, and second query message may not carry the transfer attributes of the receiving device. In this case, the management module may obtain the transfer attributes of the receiving device from a user-preconfigured device transfer attribute set, which includes the transfer attributes configured by the user for at least one device.
[0062] In one possible implementation, the flow attributes of the target data indicate some or all of the following: the security level of the target data and the service type of the target data. The flow attributes of the receiving device indicate some or all of the following: the security level of the receiving device and the service type of the service undertaken by the receiving device.
[0063] These modules can perform the corresponding functions in the above-mentioned first aspect method example. Please refer to the detailed description in the method example for details, which will not be repeated here.
[0064] In a third aspect, the present application further provides a computing device comprising a processor and a memory, and may also include a communication interface. The processor executes program instructions in the memory to perform the method provided in the first aspect or any possible implementation of the first aspect. The memory is coupled to the processor and stores program instructions and data necessary to determine the data transmission process. The communication interface is configured to communicate with other devices, such as receiving data requests, metadata requests, first query messages, and second query messages.
[0065] In a fourth aspect, the present application provides a computing device system comprising at least one computing device. Each computing device comprises a memory and a processor. The processor of at least one computing device is configured to access code in the memory to execute the method provided in the first aspect or any possible implementation of the first aspect.
[0066] In a fifth aspect, the present application provides a computer-readable storage medium. When the computer-readable storage medium is executed by a computing device, the computing device performs the method provided in the first aspect or any possible implementation of the first aspect. The storage medium stores a program. The storage medium includes, but is not limited to, volatile memory, such as random access memory, and non-volatile memory, such as flash memory, a hard disk drive (HDD), and a solid state drive (SSD).
[0067] In a sixth aspect, the present application provides a computing device program product, comprising computer instructions that, when executed by a computing device, cause the computing device to perform the method provided in the aforementioned first aspect or any possible implementation of the first aspect. The computer program product may be a software installation package, and when the method provided in the aforementioned first aspect or any possible implementation of the first aspect is required, the computer program product may be downloaded and executed on the computing device.
[0068] In a seventh aspect, the present application also provides a computer chip, which is connected to a memory, and is used to read and execute a software program stored in the memory, and to execute the method described in the above-mentioned first aspect and various possible implementation methods of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] FIG1 is a schematic structural diagram of a data transmission system provided by the present application;
[0070] 2A and 2B are schematic diagrams of a deployment of a management module provided by this application;
[0071] 3A and 3B are schematic diagrams of the structure of a data transmission system in an actual scenario provided by this application;
[0072] FIG4 is a schematic diagram of a data transmission method provided by the present application;
[0073] FIG5 is a schematic diagram of a configuration interface of a flow strategy provided by this application;
[0074] FIG6 is a schematic diagram of a data transmission method provided by the present application;
[0075] FIG7 is a schematic structural diagram of a data transmission device provided by the present application;
[0076] 8 and 9 are schematic structural diagrams of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0077] Before describing a data transmission method, apparatus, and device provided in the embodiments of the present application, some concepts involved in the embodiments of the present application are first described.
[0078] (1), file system.
[0079] A file system is a structured data storage and organization method. It uses the concept of "files" to organize data on computing devices. Data used for the same purpose is organized into different file types according to the structure required by different applications. Different suffixes are typically used to denote different file types, and each file is given a memorable name, also known as the "file name." When there are a large number of files, these files are grouped according to a specific method, with each group of files placed in the same directory (or folder). Furthermore, within a directory, there can be subdirectories (called subdirectories or subfolders) in addition to files, forming a tree-like structure. This tree structure has a special name: file system. There are many types of file systems, including FAT / FAT32 / NTFS in Windows and EXT2 / EXT3 / EXT4 / XFS / BtrFS in Linux. To facilitate searching, we start from the root node and work our way down to the file itself, concatenating the names of directories, subdirectories, and files using special characters (e.g., "\" in Windows / DOS and " / " in Unix-like systems). This string of characters is called a file path, such as " / etc / systemd / system.conf" in Linux or "C:\Windows\System32\taskmgr.exe" in Windows. A path uniquely identifies a specific file. For example, D:\data\file.exe in Windows is a file path representing the file.exe file in the data directory on the D partition.
[0080] The file system is built on block devices. The file system not only records the file path, but also records which blocks make up a file and which blocks record directory / subdirectory information.
[0081] It should be noted that the file system is only one possible data storage and organization form, and the embodiments of the present application do not limit the data storage and organization form stored in the data storage device 100. Here, the file system is used as an example of a relatively common data storage and organization form to illustrate the data transmission method provided in the embodiments of the present application. In fact, the data transmission method provided in the embodiments of the present application is also applicable to other data storage and organization forms, such as block-level data storage and organization forms and object-level data storage and organization forms.
[0082] (2) Global file system (GFS).
[0083] GFS is a data sharing system built from multiple data nodes. It unifies the local data stored on each data node to form a global data view, which displays the data stored on each data node. Any data node in GFS can query this data view and access the data displayed within it. Through GFS, any data node can access not only locally stored data but also data stored on other data nodes. Accessing data stored on other data nodes is as simple and efficient as accessing locally stored data.
[0084] GFS can be understood as a logical "file system" that integrates data from multiple data nodes into a single "file system." GFS does not require that the data on each data node be organized as files. For any data node, the data on that data node can be organized as a file system, blocks, or objects.
[0085] In the embodiment of the present application, any data storage device 100 can be added to the global file system as a data node, and multiple data storage devices 100 can share data based on the global file system. In the global file system, any data storage device 100 can view the global data view of the global file system, which displays the data stored in each data storage device 100 added to the global file system. This also provides a basis for one data storage device 100 to access the data or metadata of another data storage device 100.
[0086] (3) Metadata.
[0087] Metadata, also known as intermediary data or relay data, is data about data, mainly information describing data properties, such as the data address, data modification history, data size, data creation date, etc.
[0088] Here, the storage and organization of data in the form of a file system is taken as an example. The metadata involved in the file system includes file metadata, directory metadata, etc.
[0089] File metadata describes the attributes of the data within the file, such as the file name, file path (also known as the file address), data modification history, file size, etc. Directory metadata describes directory attribute information, such as the directory name, directory modification history, directory identification (ID), directory creation time, directory modification time, access time, and group to which the directory belongs.
[0090] (4) Circulation attributes and circulation strategies.
[0091] In this application, flow attributes are configured for data and the data storage device 100. The flow attributes of the data and the flow attributes of the data storage device 100 are the main basis for determining whether the data or the metadata of the data can be transmitted to the data storage device 100. The flow attributes of the data can be stored in the metadata of the data as part of the metadata of the data.
[0092] The data transfer attribute characterizes the factors that restrict data transmission. In the embodiments of the present application, data transmission between various data storage devices 100 is subject to certain restrictions, and the data transfer attribute is used to describe these restrictions. In other words, the data transfer attribute is used to determine whether data can be transferred to the data storage device 100.
[0093] Similarly, the flow attributes of a data storage device 100 represent the factors limiting the data acquisition by the receiving device. In the embodiments of the present application, the data that each data storage device 100 can receive is subject to certain restrictions. For example, data storage device 100A can request any data from other data storage devices 100, but data storage device 100B can only request partial data from data storage device 100A. Data storage device 100 is used to describe the restrictions imposed on the data storage device 100. The flow attributes of the data storage device 100 are required to determine whether data is allowed to be transmitted to the data storage device 100.
[0094] The flow policy describes the flow properties of the data and the conditions that the flow properties of the data storage device 100 must meet when the data or the metadata of the data can be transmitted to the data storage device 100.
[0095] The flow attributes of the data and the flow attributes of the data storage device 100 may not have any practical significance. They are just two types of information that need to be compared when determining whether the data or the metadata of the data can be transmitted to the data storage device 100.
[0096] The representation form of the flow strategy is related to the flow attributes of the data and the representation method of the flow attributes of the data storage device 100. If the flow attributes of the data and the representation method of the flow attributes of the data storage device 100 are different, the representation form of the flow strategy may also be different.
[0097] For example, the flow attribute of data records an identifier set, where the identifier set includes multiple identifiers. The flow attribute of the data storage device 100 may be an identifier configured for the data storage device 100 .
[0098] The transfer policy can be expressed as follows: the identifier of the data storage device 100 belongs to the set of identifiers recorded by the transfer attribute of the data. In other words, when the identifier of the data storage device 100 belongs to the set of identifiers recorded by the transfer attribute of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0099] The transfer policy can also be expressed as follows: the identifier of the data storage device 100 does not belong to the set of identifiers recorded by the transfer attribute of the data. In other words, when the identifier of the data storage device 100 does not belong to the set of identifiers recorded by the transfer attribute of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0100] For another example, data with the same attributes can be assigned the same data flow attributes based on the data's attributes (e.g., the user ID of the data, the data creation date, the business type of the data, etc.). A data storage device 100 can be configured to manage data with the same attributes. The flow attributes of the data storage device 100 are the same as the flow attributes of the data it manages.
[0101] Then, the transfer policy can be expressed as: the transfer attribute of the data storage device 100 is the same as the transfer attribute of the data. In other words, when the transfer attribute of the data storage device 100 is the same as the transfer attribute of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0102] The flow attributes of the data and the flow attributes of the data storage device 100 themselves may also have some special meaning. When the data storage device 100 determines whether the data or the metadata of the data can be transmitted to the data storage device 100, it needs to determine whether it meets the flow strategy based on the flow attributes of the data and the flow attributes of the data storage device 100.
[0103] For example, the flow attributes of data describe the security level of the data. Similarly, the flow attributes of the data storage device 100 describe the security level of the data storage device 100.
[0104] Then, the transfer policy can be expressed as follows: the transfer attribute of the data storage device 100 is the same as the transfer attribute of the data. In other words, when the security level of the data storage device 100 is consistent with the security level of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0105] Then, the transfer policy can also be expressed as: the transfer attribute of the data storage device 100 is greater than the transfer attribute of the data. In other words, when the security level of the data storage device 100 is greater than the security level of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0106] For example, the flow attributes of data describe the business type of the data. Similarly, the flow attributes of the data storage device 100 describe the business type of data that the data storage device 100 can process (also known as the business type of the business undertaken by the data storage device 100).
[0107] The transfer policy can be expressed as follows: the transfer attribute of the data storage device 100 is the same as the transfer attribute of the data. In other words, when the business type of the data that the data storage device 100 can process is consistent with the business type of the data, the data storage device 100 can obtain the data or the metadata of the data.
[0108] In practical applications, the flow attributes of data can also describe multiple attributes of the data. Similarly, the flow attributes of the data storage device 100 can also describe multiple attributes of the data storage device 100.
[0109] For example, the flow attributes of data describe the business type of data and the security level of data. Similarly, the flow attributes of the data storage device 100 describe the business type of data that the data storage device 100 can process and the security level of the data storage device 100.
[0110] The transfer policy can be expressed as follows: the business type of the data described in the transfer attributes of the data storage device 100 is consistent with the business type of the data, and the security level described in the transfer attributes of the data storage device 100 is greater than the security level of the data. In other words, when the business type of the data that the data storage device 100 can process is consistent with the business type of the data, and the security level of the data storage device 100 is greater than the security level of the requested data, the data storage device 100 can obtain the data or the metadata of the data.
[0111] In this embodiment of the present application, for ease of explanation, the data transfer attributes obtained when determining whether metadata is permitted to be transmitted to the data storage device 100 are the transfer attributes of "the data described by the metadata." In other words, the "data" refers to "the data described by the metadata." In other words, the transfer attributes of the data and the metadata remain consistent.
[0112] It is worth noting that, when determining whether metadata is permitted to be transmitted to the data storage device 100 based on the data's transfer attributes, the data storage device 100's transfer attributes, and the transfer policy, the embodiment of the present application does not configure metadata-specific transfer attributes. Instead, the data's transfer attributes are referred to as "metadata's transfer attributes." In actual applications, when implementing metadata transfer permission management, transfer attributes can also be configured separately for the metadata. Whether metadata is permitted to be transmitted to the data storage device 100 can be determined based on the metadata's transfer attributes, the data storage device 100's transfer attributes, and the transfer policy. The specific determination method is similar to the method for determining whether metadata is permitted to be transmitted to the data storage device 100 based on the data's transfer attributes, the data storage device 100's transfer attributes, and the transfer policy, and will not be further described here.
[0113] As shown in FIG1 , it is a schematic diagram of the architecture of a data transmission system provided in an embodiment of the present application. The system includes a plurality of data storage devices 100 .
[0114] For any data storage device 100, the data storage device 100 stores data and can manage the data stored in itself, such as adding, deleting, searching, modifying and other operations on the data, and adding, deleting, searching, modifying and other operations on the metadata of the data.
[0115] The embodiments of the present application do not limit the data organization format of the data stored in the data storage device 100. For example, the data storage device 100 may organize data in the form of a file system. For another example, the data storage device 100 may organize data in the form of object storage. For another example, the data storage device 100 may organize data in the form of block storage. The data organization format of different data storage devices 100 may be the same or different.
[0116] In this data transmission system, data or metadata can be transmitted between any two data storage devices 100. To ensure the security of the data or metadata, before transmitting data or metadata to another data storage device 100, one data storage device 100 must first determine whether the data or metadata to be transmitted is allowed to be transmitted to the other data storage device 100. Only if the data or metadata to be transmitted is allowed to be transmitted to the other data storage device 100 will the data transmission device transmit the data or metadata to the other data storage device.
[0117] The embodiments of the present application do not limit the specific form of the data storage device 100. The data storage device 100 may be a hardware device, a single computing device, or a cluster of multiple computing devices. The data storage device 100 may be a software device, such as file management software or database management software. When the data storage device 100 is a software device, the aforementioned "data stored in the data storage device 100" refers to the data managed by the data storage device 100.
[0118] The data transmission system includes a management module 200 , which is used to determine whether data or metadata is allowed to be transmitted to a certain data storage device 100 .
[0119] In the embodiment of the present application, the management module 200 has the following management rights: management of data transfer rights and management of data metadata transfer rights.
[0120] The data transfer rights refer to the data storage devices 100 between which the data is allowed to be transferred in the data transmission system. Similarly, the metadata transfer rights refer to the data storage devices 100 between which the metadata is allowed to be transferred in the data transmission system.
[0121] The following describes the management of data transfer permissions and data metadata transfer permissions:
[0122] 1. Management of metadata transfer rights.
[0123] The management module 200 can determine whether the metadata is allowed to be transmitted to the data storage device 100 , or determine to which one or several data storage devices 100 the metadata is allowed to be transmitted.
[0124] There are many ways to implement the management of metadata transfer permissions.
[0125] Method 1: For any data, when the data storage device 100 requests to obtain metadata, the management module 200 can determine whether the data can be transmitted to the data storage device 100 according to the attributes of the metadata itself.
[0126] For example, when the data storage device 100 requests to obtain metadata, the management module 200 may determine, based on information such as the importance level or user level of the data recorded in the metadata, the metadata that can be transmitted to the data storage device 100. For data whose importance level or user level is greater than a threshold, the management module 200 may determine that the metadata is not allowed to be transmitted to the data storage device 100. For data whose importance level or user level is not greater than the threshold, the management module 200 may determine that the metadata is allowed to be transmitted to the data storage device 100.
[0127] In a second approach, the management module 200 determines whether the data can be transmitted to the data storage device 100 according to the properties of the data storage device 100 .
[0128] For example, when the data storage device 100 requests to obtain metadata, the management module 200 can analyze the address of the data storage device 100 (such as the media access control address (MAC) or the internet protocol (IP) address). After determining that the address of the data storage device 100 belongs to a preset address set that allows metadata to be obtained, the management module 200 can determine whether the metadata is allowed to be transmitted to the data storage device 100.
[0129] Method three: the management module 200 determines whether the data can be transmitted to the data storage device 100 according to the attributes of the data storage device 100 and the attributes of the data itself.
[0130] For example, when the data storage device 100 requests metadata, the management module 200 may analyze the address (such as a MAC address or IP address) of the data storage device 100. After determining that the address of the data storage device 100 belongs to a preset set of addresses from which metadata can be obtained, the management module 200 may then determine, based on the attributes of the metadata itself, which metadata can be transmitted to the data storage device 100. If it is determined that the address of the data storage device 100 does not belong to the preset set of addresses from which data can be obtained, the management module 200 may directly determine that metadata cannot be transmitted to the data storage device 100.
[0131] The following describes a specific implementation method of a management module 200 provided in an embodiment of the present application, which determines whether data can be transmitted to the data storage device 100 based on the attributes of the data storage device 100 and the attributes of the data itself:
[0132] In the embodiment of the present application, when the transfer attributes of the data and the transfer attributes of the data storage device 100 requesting metadata satisfy the transfer policy, the metadata of the data is allowed to be transmitted to the data storage device 100 requesting metadata. Otherwise, the metadata of the data is not allowed to be transmitted to the data storage device 100 requesting metadata. In some scenarios, the data storage device 100 requesting metadata for the data may be referred to as a receiving device.
[0133] To put it another way, when determining whether metadata is allowed to be transmitted to a data storage device 100, it is necessary to obtain the flow attributes of the data (the data described by the metadata) and the flow attributes of the data storage device 100. Based on the flow attributes of the data, the flow attributes of the data storage device 100, and the flow policy, it is determined whether the metadata is allowed to be transmitted to the data storage device 100. In some scenarios, the data storage device 100 may need to receive the metadata, and the data storage device 100 can be referred to as a receiving device.
[0134] The management module 200 can obtain the flow attributes of the data and the flow attributes of the data storage device 100, and can determine whether the data is allowed to be transmitted to the data storage device 100 based on the obtained flow attributes.
[0135] 2. Management of data transfer permissions.
[0136] The management module 200 can determine whether data is allowed to be transmitted to the data storage device 100 , or determine to which one or several management modules 200 the data is allowed to be transmitted.
[0137] There are many ways to implement the management of data transfer permissions.
[0138] Method 1: For any data, when the data storage device 100 requests to obtain the data, the management module 200 can determine whether the data is allowed to be transmitted to the data storage device 100 based on the attributes of the data itself. The attributes of the data itself can be recorded in the metadata of the data.
[0139] For example, when the data storage device 100 requests to obtain data, the management module 200 can determine whether the data is allowed to be transmitted to the data storage device 100 based on information such as the importance level or user level of the data recorded in the metadata of the data. For data whose importance level or user level is greater than a threshold, the management module 200 can determine that the data is not allowed to be transmitted to the data storage device 100. For data whose importance level or user level is not greater than the threshold, the management module 200 can determine that the data is allowed to be transmitted to the data storage device 100.
[0140] In a second approach, the management module 200 determines whether the data is allowed to be transmitted to the data storage device 100 according to the attributes of the data storage device 100 .
[0141] For example, when the data storage device 100 requests to obtain data, the management module 200 can analyze the address of the data storage device 100 (such as a MAC address or IP address). After determining that the address of the data storage device 100 belongs to a preset address set that is allowed to obtain data, the management module 200 can determine that the data is allowed to be transmitted to the data storage device 100.
[0142] Method three: the management module 200 determines whether the data can be transmitted to the data storage device 100 according to the attributes of the data storage device 100 and the attributes of the data itself.
[0143] For example, when the data storage device 100 requests to obtain data, the management module 200 may analyze the address (such as a MAC address or IP address) of the data storage device 100. After determining that the address of the data storage device 100 belongs to a preset set of addresses that are allowed to obtain data, the management module 200 may then determine, based on the attributes of the data itself, whether the data can be transmitted to the data storage device 100. If it is determined that the address of the data storage device 100 does not belong to the preset set of addresses that are allowed to obtain data, the management module 200 may directly determine that the data cannot be transmitted to the data storage device 100.
[0144] The following describes a specific implementation method of a management module 200 provided in an embodiment of the present application, which determines whether data can be transmitted to the data storage device 100 based on the attributes of the data storage device 100 and the attributes of the data itself:
[0145] In the embodiment of the present application, when the data transfer attribute and the data storage device 100 requesting to obtain the data transfer attribute satisfy the transfer policy, the data is allowed to be transferred to the data storage device 100 requesting to obtain the data; otherwise, the data is not allowed to be transferred to the data storage device 100 requesting to obtain the data. In some scenarios, the data storage device 100 requesting to obtain the data can be referred to as a receiving device.
[0146] To put it another way, when determining whether certain data is allowed to be transferred to a certain data storage device 100, it is necessary to obtain the flow attributes of the data and the flow attributes of the data storage device 100. Based on the flow attributes of the data, the flow attributes of the data storage device 100, and the flow policy, it is determined whether the data is allowed to be transferred to the data storage device 100. In some scenarios, the data storage device 100 may need to receive the data, and the data storage device 100 can be referred to as a receiving device.
[0147] The management module 200 can obtain the flow attributes of the metadata and the flow attributes of the data storage device 100, and can determine whether the data is allowed to be transmitted to the data storage device 100 based on the obtained flow attributes.
[0148] The embodiments of the present application do not limit the deployment method of the management module 200 in the data transmission system. For example, as shown in FIG2A , in the data transmission system, each data storage device 100 is deployed with a management module 200. For any of the data storage devices 100, when another data storage device requests data or metadata from the data storage device 100 (e.g., by sending a data request or metadata request to request data or metadata in the embodiments of the present application), the data storage device 100 can independently determine whether the data or metadata is allowed to be transmitted to the other data storage device.
[0149] For another example, as shown in FIG2B , in the data transmission system, the management module 200 can be deployed independently, that is, the management module 200 can be deployed in the data transmission system as a device independent of the data storage device 100. For ease of description, the device independent of the data storage device 100 is referred to as the management device 300, and the management device 300 includes the management module 200. For any data storage device 100 in the data transmission system, when other data storage devices request the data storage device 100 to obtain data (or metadata) (such as by sending a data request or a metadata request to request to obtain data or metadata in the embodiment of the present application), the data storage device 100 can ask the management device 300 whether the data (or metadata) is allowed to be transmitted to other data storage devices 100 (such as by sending a first inquiry message or a second inquiry message to inquire whether the target data or metadata is allowed to be transmitted to other data storage devices in the embodiment of the present application). The management device 300 obtains the flow attributes of the data (or the flow attributes of the metadata) and the flow attributes of the data storage device 100, and can determine whether the data (or metadata) is allowed to be transmitted to other data storage devices based on the obtained flow attributes, and notify the data storage device 100 that the data is allowed to be transmitted to other data storage devices, notify the data storage device 100 that the data is not allowed to be transmitted to other data storage devices, or transmit a metadata set to the other data storage device, where the metadata set includes metadata that is allowed to be transmitted to other data storage devices.
[0150] Regardless of whether the management module 200 is deployed in the data storage device 100 or the management device 300 , in addition to having the function of managing the flow rights of data and metadata, the management module 200 can also configure flow attributes for data and / or the data storage device 100 .
[0151] Configuration 1: Configure flow properties for data.
[0152] The management module 200 provides a user-friendly interface for configuring data flow attributes. For ease of explanation, this interface is referred to as the first configuration interface. Users can use this first configuration interface to configure data flow attributes. The management module 200 obtains user-configured data flow attributes through this first configuration interface and records the data flow attributes in the data's metadata.
[0153] For example, when the various data storage devices 100 in the data transmission system form a global file system, the management module 200 can display the global data view of the global file system to the user through the first configuration interface. By viewing the global data view, the user can configure the flow attributes for part or all of the data displayed in the global data view. Taking the data stored in a certain data storage device 100 as an example of file system organization and storage, the user can view the tree structure of the files and directories in the file system through the global data view, and the user can configure the flow attributes for the files or directories in the file system starting from the root directory. The management module 200 obtains the flow attributes configured by the user for the file or directory through the first configuration interface, records the flow attributes of the file in the metadata of the file, and records the flow attributes of the directory in the metadata of the directory.
[0154] Configuration 2: Configure the flow attributes for the data storage device 100.
[0155] The management module 200 provides a user-friendly interface for configuring the transfer properties of the data storage device 100. For ease of explanation, this interface for configuring the transfer properties of the data storage device 100 is referred to as a second configuration interface. Through this second configuration interface, the user can configure the transfer properties for the data storage device 100. The management module 200 obtains the transfer properties configured by the user for the data storage device 100 through this second configuration interface.
[0156] For example, when the data storage devices 100 in the data transmission system form a global file system, the management module 200 can display the data storage devices 100 that have been added to the global file system to the user through the second configuration interface. The user can configure transfer attributes for some or all of the data storage devices 100 that have been added to the global file system, and the management module 200 obtains the transfer attributes configured by the user for the data storage devices 100 through the second configuration interface.
[0157] For another example, the management module 200 can display to the user, through the second configuration interface, the various data storage devices 100 connected to the management module 200. The user can configure transfer attributes for some or all of the data storage devices 100 connected to the management module 200, and the management module 200 obtains the transfer attributes configured by the user for the data storage devices 100 through the second configuration interface.
[0158] For another example, the management module 200 may not display the data storage device 100 through the second configuration interface, but the user may transmit the address (or identifier) of the data storage device 100 for which the flow attributes need to be configured and the flow attributes configured for it to the management module 200 through the second configuration interface. The address of the data storage device 100 is the information required for the management module 200 to establish a connection with the data storage device 100. The identifier of the data storage device 100 is the information that can be recognized by the management module 200 and uniquely identifies the data storage device 100. After the management module 200 obtains the flow attributes configured by the user for the data storage device 100 through the second configuration interface, the management module 200 transmits the flow attributes of the data storage device 100 to the data storage device 100 based on the address of the data storage device 100.
[0159] After obtaining the transfer attributes configured by the user for the data storage device 100, the management module 200 may perform some or all of the following operations:
[0160] Operation 1: The management module 200 transmits the transfer attributes configured by the user to the data storage device 100.
[0161] After the management module 200 obtains the flow attributes configured by the user for the data storage device 100 through the second configuration interface, it can transmit the flow attributes configured by the user to the data storage device 100 so that the data storage device 100 can obtain and save the flow attributes of the data storage device 100 in a timely manner.
[0162] Operation 2: The management module 200 saves the flow attribute of the data storage device 100 .
[0163] The management module 200 may store a device flow attribute set, which records the flow attributes of each data storage device 100 in the data transmission system. After the management module 200 obtains the flow attributes configured by the user for the data storage device 100 through the second configuration interface, the flow data of the data storage device 100 may be recorded in the device flow attribute set. The embodiment of the present application does not limit the manner in which the flow attributes of each data storage device 100 are recorded in the device flow attribute set. For example, the device flow attribute set may identify the data storage device 100 by the address of the data storage device 100, that is, what is recorded in the device flow attribute set is the mapping relationship between the flow attributes of each data storage device 100 and its address information. The address of the data storage device 100 may be the MAC address or IP address of the data storage device 100. For another example, the device flow attribute set may identify the data storage device 100 by the identifier of the data storage device 100, that is, what is recorded in the device flow attribute set is the mapping relationship between the flow attributes of each data storage device 100 and its identifier.
[0164] It should be noted that in some scenarios, the user only informs the management module 200 of the flow attributes configured for the data storage device 100 through the second configuration interface. The data storage device 100 has already obtained the user-configured flow attributes through other means. Therefore, in such scenarios, the management module 200 does not need to transmit the flow attributes to the data storage device 100, and the management module 200 can only perform operation 2. In some scenarios, when the data storage device 100 initiates a data request or metadata request, it will carry the flow attributes of the data storage device 100, which means that the management module 200 can relatively easily obtain the flow attributes of the data storage device 100. In such scenarios, when the management module 200 obtains the user-configured flow attributes for it through the second configuration interface, it can only perform operation 1 and not perform operation 2.
[0165] In the above description, only the example of the management module 200 configuring the flow attributes for the data storage device 100 under the user's instructions is used for explanation. This configuration method is only one possible configuration method. The embodiment of the present application does not limit the management module 200 to configuring the flow attributes for the data storage device 100. For example, the management module 200 can obtain the topological relationship between the various data storage devices 100 in the data transmission system. The topological relationship indicates the subordinate relationship between the various data storage devices 100. The management module 200 has a certain learning ability. Through the learning of the topological relationship, it determines the data storage device 100 at the upper layer, the data storage device 100 at the middle layer, and the data storage device 100 at the lower layer, and then spontaneously configures the flow attributes for each data storage device 100 in the data transmission system based on this.
[0166] In the embodiment of the present application, the first configuration interface and the second configuration interface are used to represent a certain function provided by the management module 200 to the user. The embodiment of the present application does not limit the specific presentation form of the first configuration interface and the second configuration interface. For example, the first configuration interface and the second configuration interface can be presented to the user in the form of a visual interface. For another example, the first configuration interface and the second configuration interface can be provided to the user in the form of a pre-set command, and the user can complete the configuration of the flow properties of the data or data storage device 100 by sending the pre-set command to the management device.
[0167] The specific form of the management module 200 is not limited in the embodiments of the present application. The management module 200 can be hardware, such as a single computing device, or a processor or computing circuit logic within a computing device. The management module 200 can also be a software module, such as data management software running on a computing device, or a computing instance such as a container or virtual machine running on the computing device.
[0168] The following introduces two examples of applying the data transmission system architecture shown in Figure 1 to actual scenarios.
[0169] Example 1: Bank data distribution scenario.
[0170] The bank's management system includes a data center that manages the data of each branch, and a site for each branch (a site can be a single computing device or a cluster of computing devices). Each branch site is used to manage branch data. Each branch site has access to its own data, but not to data from other branches.
[0171] FIG3A is a schematic diagram of a data transmission system structure for a bank data distribution scenario according to an embodiment of the present application. In the data transmission system, three branch sites are exemplarily shown, labeled Site A, Site B, and Site C. Correspondingly, the three branches are labeled Branch A, Branch B, and Branch C.
[0172] Site A can only obtain data from Branch A from the data center, Site B can only obtain data from Branch B from the data center, and Site C can only obtain data from Branch C from the data center.
[0173] The data center can configure the same flow attributes for the data of site A and branch A, the data center can configure the same flow attributes for the data of site B and branch B, and the data center can configure the same flow attributes for the data of site C and branch C. The flow attributes of site A, site B, and site C are completely different.
[0174] The flow policy stored in the data center is to allow the site to obtain the branch data when the flow attributes of the site and the branch data requested by the site are the same.
[0175] Example 2: Data protection scenario in a data center.
[0176] Data centers typically store large amounts of data, which needs to be protected according to security levels to prevent data leaks. Data centers can transfer data to and from other data centers, and can also transfer stored data to other data centers. However, not all data can be transferred to other data centers during this process. Therefore, to protect data, data centers can set security levels for other data centers. The higher the security level, the more secure the other data center is, and the more data it can access.
[0177] As shown in Figure 3B, it is a schematic diagram of the structure of a data transmission system in a data protection scenario of a data center provided in an embodiment of the present application. In this data transmission system, three edge data centers are exemplarily displayed, and the three edge data centers are respectively marked as edge data center A, edge data center B, and edge data center C.
[0178] The data center can configure security levels for edge data center A, edge data center B, and edge data center C respectively. Among them, the security level of edge data center A is 10, the highest security level; the security level of edge data center B is 8; and the security level of edge data center CB is 2, the lowest security level.
[0179] Data centers record the security level of stored data in the metadata, which is equivalent to the security level of the metadata. The data center's stored transfer policy stipulates that edge data centers can only access data or metadata with a security level lower than that of the edge data center. In this example, the security level is a specific manifestation of the transfer attribute.
[0180] That is, edge data center A can obtain data or metadata with a security level less than 10. Edge data center B can obtain data or metadata with a security level less than 8. Edge data center C can obtain data or metadata with a security level less than 2.
[0181] When any edge data center requests data or metadata from a data center, it can carry the security level of the edge data center in the request. After receiving the edge data center, the data center determines the security level of the edge data center and the security level of the requested data or metadata. When the security level of the edge data center and the security level of the requested data or metadata meet the flow policy, the requested data or metadata is transmitted to the edge data center.
[0182] The data transmission method provided in the embodiments of the present application is described below with the management module 200 being deployed in the data storage device 100 and the management module 200 being deployed independently (ie, deployed in the management device 300).
[0183] 1. The management module 200 is deployed in the data storage device 100:
[0184] The following describes a data transmission method provided by an embodiment of the present application in conjunction with FIG4 . The data transmission method includes three parts: a flow strategy and flow attribute configuration process, specifically referring to steps 400 to 402; a metadata transmission process, specifically referring to steps 403 to 406; and a data transmission process, specifically referring to steps 407 to 410. In the following, to distinguish between different data storage devices 100, data storage device 100A is regarded as a data storage device 100 storing target data, and data storage device 100B is regarded as a data storage device 100 requiring a request for target data or metadata.
[0185] Step 400: The data storage device 100A obtains a transfer strategy.
[0186] There are many ways for the data storage device 100A to obtain the transfer policy. For example, a user can send the transfer policy to the data storage device 100A via a user-side computing device. In another example, a user can directly operate the data storage device 100A and enter the transfer policy into the data storage device 100A. In another example, the transfer policy may be pre-stored in the data managed by the data storage device 100A, and the data storage device 100A can obtain the data from the data.
[0187] The following describes two ways in which a user configures a transfer policy for the data storage device 100A:
[0188] Method 1: The user configures a transfer strategy for the data storage device 100A through commands.
[0189] The data storage device 100A provides a command for configuring the flow policy. The user completes the configuration of the flow policy by typing the command into the data storage device 100A.
[0190] For example, consider the case where the data managed by data storage device 100A exists in the form of a Linux file system. Linux provides the vfs setxattr command, which is used to set extended attributes in the Linux file system. Extended attributes are a type of metadata within files or directories in the Linux file system. In other words, extended attributes can be considered a type of attribute within metadata. Users can use the vfs setxattr command to configure a transfer policy and apply the policy to all files and directories in the Linux file system.
[0191] Method 2: The user configures a transfer policy for the data storage device 100A through the management interface.
[0192] The data storage device 100A can provide a visual management interface for users, and the management interface provides an option for configuring a transfer policy, and users can configure the management policy in the management interface.
[0193] FIG5 is a schematic diagram of a management interface provided in an embodiment of the present application, assuming that the data flow attributes and the security level of the data storage device 100 described by the flow attributes of the data and the security level of the data storage device 100. The management interface provides an option to configure a flow policy, and the user can configure a specific flow policy by entering or selecting the relationship between the flow attributes of the data and the flow attributes of the data storage device 100.
[0194] In the embodiment of the present application, the transfer policy can be changed after it is configured. When the user determines that the transfer policy needs to be changed, the user can use the aforementioned method of configuring the transfer policy to configure the changed transfer policy to the data storage device 100A.
[0195] Step 401: The data storage device 100A configures flow attributes for the data stored in the data storage device 100A. The flow attributes of the data can be stored in the metadata of the data. The flow attributes of different data can be the same or different.
[0196] The data storage device 100A can, under the user's instructions, configure the flow attribute for all data stored in the data storage device 100A; the data storage device 100A can also, under the user's instructions, configure the flow attribute for only part of the data stored in the data storage device 100A. For example, under the user's instructions, the data storage device 100A can configure the flow attribute for only the data with a higher confidentiality level or a higher security level among the data stored in the data storage device 100A, and the data that is not configured with the flow attribute is assumed to be allowed to be transmitted.
[0197] The manner in which the data storage device 100A configures the flow attributes of the data stored in the data storage device 100A under the user's instruction can be referred to the introduction of the management module 200 configuring the flow attributes for the data in the above description, which will not be repeated here.
[0198] Assume that the data stored in the data storage device 100A is organized in the form of a file system, in which files and directories form a tree structure. Under the user's instructions, the data storage device 100A configures flow attributes for the files or directories in the file system starting from the root directory of the file system, and records the flow attributes of the files in the metadata of the files, and records the flow attributes of the directories in the metadata of the directories.
[0199] In this file system, the file or directory configuration flow attributes have the following characteristics:
[0200] Feature 1: Subdirectories and files under a directory can inherit the flow attributes of the directory.
[0201] The subdirectories and files under the directory can have the same transfer attributes as the directory to which they belong. For subdirectories or files that inherit the transfer attributes of the directory, the operation of configuring the transfer attributes can be omitted; that is, when the data storage device 100A queries the transfer attributes of a certain file or a certain subdirectory, if the transfer attributes of the certain file or a certain subdirectory are not recorded in the metadata of the file or subdirectory, the transfer attributes of the directory to which the file or subdirectory belongs can be queried, and the transfer attributes of the directory can be used as the transfer attributes of the file or subdirectory.
[0202] When configuring the transfer attributes of a subdirectory or file that inherits the transfer attributes of a directory, information indicating the inherited transfer attributes of the directory can be added to the metadata of the file or subdirectory. In other words, when the data management subsystem queries the transfer attributes of a file or subdirectory, if the metadata of the file or subdirectory contains this information, the transfer attributes of the directory to which the file or subdirectory belongs can be queried and the transfer attributes of the directory can be used as the transfer attributes of the file or subdirectory.
[0203] Note: Subdirectory is a special kind of "directory" and is a relative concept used when describing the structure of a directory. A subdirectory refers to the next level "directory" included in a directory.
[0204] Feature 2: Subdirectories and files under a directory can overturn the circulation attribute of the directory, that is, they do not inherit the circulation attribute of the directory.
[0205] The subdirectories and files under the directory can have different transfer attributes from the directory they belong to. For subdirectories or files that do not inherit the transfer attribute of the directory, the transfer attribute of the subdirectory or file needs to be added to the metadata of the subdirectory or file.
[0206] Step 402: The data storage device 100A configures a flow attribute for the data storage device 100B, and the data storage device 100B saves the flow attribute configured by the data storage device 100A.
[0207] The following describes a method for configuring transfer attributes for a data storage device 100B in a data storage device 100A according to an embodiment of the present application:
[0208] Step 1: The data storage device 100A obtains the transfer attribute configured by the user for the data storage device 100B through the second configuration interface, and generates a certificate recording the transfer attribute of the data storage device 100B.
[0209] To ensure the security of the data in the certificate, the data storage device 100A may also perform some or all of the following security operations on the certificate:
[0210] Security Operation 1: Encrypt the certificate using the public key of data storage device 100B. The public key of data storage device 100B is publicly available and can be obtained by any data storage device 100. The private key corresponding to the public key is stored internally in data storage device 100B. This example uses an asymmetric encryption algorithm to encrypt the certificate. In fact, the embodiment of the present application does not limit the method used by data storage device 100A to encrypt the certificate.
[0211] Security operation 2: Add signature information to the certificate. The signature information is generated using the private key of the data storage device 100A. The private key of the data storage device 100A is publicly available and can only be obtained by the data storage device A. The public key corresponding to the private key is publicly available.
[0212] Step 2: The data storage device 100A sends the certificate to the data storage device 100B.
[0213] Step 3: The data storage device 100B receives the certificate, verifies the certificate, and saves the flow attribute of the data storage device 100B after the verification is completed.
[0214] Regarding the two security operations mentioned in step 1, the data storage device 100B verifies the certificate as follows:
[0215] For security operation 1, the data storage device 100B decrypts the certificate using the private key of the data storage device 100B. If the decryption is successful, the certificate is verified successfully; otherwise, the verification fails.
[0216] For the second security operation, the data storage device 100B uses the public key of the data storage device 100A to verify the signature information on the certificate. If the verification is successful, the certificate is successfully verified; otherwise, the verification fails.
[0217] Step 4: The data storage device 100B notifies the data storage device 100A that the certificate has been successfully received, and saves the transfer attribute of the data storage device 100B.
[0218] In the embodiment of the present application, it is permitted to change the flow attributes of the data storage device 100B after the flow attributes of the data storage device 100B have been configured. The data storage device 100A can reconfigure the flow attributes for the data storage device 100B under the user's instruction, or the data storage device 100A can reconfigure the flow attributes for the data storage device 100B at the request of the data storage device 100B. When the data storage device 100A changes the flow attributes of the data storage device 100B, it can use the aforementioned method of configuring the flow attributes to configure the changed flow attributes to the data storage device 100B.
[0219] At this point, data storage device 100A has completed acquiring the transfer policy and configuring the transfer attributes. Subsequently, data storage device 100A can determine whether to transfer data or metadata to storage device B based on the transfer policy, the transfer attributes of the data, and the transfer attributes of data storage device 100B.
[0220] It should be noted that the embodiment of the present application does not limit the execution order of steps 400 to 402. In actual applications, the acquisition of the flow strategy and the configuration of the flow attributes can be carried out simultaneously; or the flow attributes of the data storage device 100B and the flow attributes of the data can be configured first, and then the flow strategy can be acquired.
[0221] The data storage device 100B can be deployed closer to the user, and the user (through a computing device on the user side) can directly interact with the data storage device 100B to obtain data from the data storage device 100B or view the attribute information of the data. During the process of the user interacting with the data storage device 100B to request to obtain data or view the attribute information of the data, the data storage device 100B can request to obtain data or metadata from the data storage device 100A.
[0222] Step 403: The data storage device 100B sends a metadata request to the data storage device 100A. The metadata request is used to request a metadata set. Optionally, the metadata request carries the flow attribute of the data storage device 100B.
[0223] In step 403, the metadata set requested by the metadata request may include all metadata accessible to the data storage device 100B, and the transfer attributes of the metadata accessible to the data storage device 100B and the transfer attributes of the data storage device 100 satisfy the transfer policy. The metadata request may carry instruction information indicating that all metadata needs to be requested, or the metadata request may not carry this instruction information. If the instruction information is not carried, it is assumed that the metadata requested by the data storage device 100A is all metadata accessible to the data storage device 100B.
[0224] The metadata set requested by the metadata request may include some metadata from all metadata accessible to the data storage device 100B. The metadata request may carry information indicating the metadata. For example, the metadata requested by the metadata request may be metadata for data of business type "business A," and the metadata request may carry information indicating business A.
[0225] Step 404: The data storage device 100A receives the metadata request and determines a metadata set according to the flow attribute of the data storage device 100B.
[0226] When the metadata request device carries the flow attribute of the data storage device 100B, the data storage device 100A can directly obtain the flow attribute of the data storage device 100B from the metadata request.
[0227] When the metadata requesting device does not carry the transfer attributes of the data storage device 100B, the data storage device 100A stores a device transfer attribute set, which records the transfer attributes of each data storage device 100 in the data transmission system. The data storage device 100A can obtain the transfer attributes of the data storage device 100B from the device transfer attribute set. For example, the device transfer attribute set records the mapping relationship between the transfer attributes of each data storage device 100 and the address of each data storage device 100. The data storage device 100A uses the address of the data storage device 100B carried in the metadata request to query the device transfer attribute set based on the address of the data storage device 100B and obtain the transfer attributes of the data storage device 100B.
[0228] In addition to obtaining the flow attributes of the data storage device 100B, the data storage device 100A also needs to obtain the flow attributes of the data stored in the data storage device 100A, that is, the data storage device 100A obtains the flow attributes of the data from the metadata of the data stored in the data storage device 100A.
[0229] After determining the transfer attributes of data storage device 100B and the data's transfer attributes, data storage device 100A can further determine whether the transfer attributes of data storage device 100B and the data's transfer attributes satisfy the transfer policy. For any piece of metadata, if the transfer attributes of data storage device 100B and the data's transfer attributes satisfy the transfer policy, the metadata is accessible to data storage device 100B. Otherwise, the metadata is not accessible to data storage device 100B.
[0230] Assume that the flow attribute of data describes the security level of the data, and the flow attribute of the data storage device 100B describes the security level of the data storage device 100B.
[0231] When the transfer policy states that the transfer attributes of the data storage device 100 are identical to the transfer attributes of the data, and if the security level of the data storage device 100B is consistent with the security level of the data, then the transfer attributes of the data storage device 100B and the transfer attributes of the data satisfy the transfer policy, and the metadata of the data is metadata that the data storage device 100B is allowed to access. If the security level of the data storage device 100B is inconsistent with the security level of the data, then the transfer attributes of the data storage device 100B and the transfer attributes of the data do not satisfy the transfer policy, and the metadata of the data is not metadata that the data storage device 100B is allowed to access.
[0232] When the flow policy states that the flow attribute of the data storage device 100B is greater than the flow attribute of the data, and if the security level of the data storage device 100B is consistent with the security level of the data, then the flow attribute of the data storage device 100B and the flow attribute of the data do not satisfy the flow policy, and the metadata of the data is not metadata that the data storage device 100B can access. If the security level of the data storage device 100B is lower than the security level of the data, then the flow attribute of the data storage device 100B and the flow attribute of the data do not satisfy the flow policy, and the metadata of the data is not metadata that the data storage device 100B can access. If the security level of the data storage device 100B is greater than the security level of the data, then the flow attribute of the data storage device 100B and the flow attribute of the data satisfy the flow policy, and the metadata of the data is metadata that the data storage device 100B is allowed to access.
[0233] Taking the file system as an example, given the two characteristics of the transfer attributes of files and directories in the file system in step 401, any directory in the file, the files and subdirectories included in the directory may all inherit the transfer attribute of the directory, or may all override the transfer attribute of the directory. In addition, some files and / or subdirectories may inherit the transfer attribute of the directory, while some files and / or subdirectories may override the transfer attribute of the directory.
[0234] For such subdirectories or files that do not inherit the flow attributes of the directory, if the subsequent data storage device 100B requests the metadata of the directory or the files or subdirectories contained in the directory, the data storage device 100A needs to determine whether the flow policy is met based on the flow attributes of the subdirectory or file and the flow attributes of the data storage device 100B, and whether the metadata of the subdirectory or file can be sent to the data storage device 100B.
[0235] For such subdirectories or files that inherit the flow attributes of a directory, if the subsequent data storage device 100B requests the metadata of the directory or the files or subdirectories contained in the directory, the data storage device 100A needs to determine whether the flow policy is satisfied based on the flow attributes of the directory and the flow attributes of the data storage device 100B, and whether the metadata of the subdirectory or file can be sent to the data storage device 100B.
[0236] Step 405: After determining the metadata that is allowed to be accessed by the data storage device 100B, the data storage device 100A feeds back a metadata positive response to the data storage device 100B, where the metadata positive response carries a metadata set.
[0237] When the metadata requested by the metadata request may be all metadata that the data storage device 100B can access, the metadata set includes all metadata that the data storage device 100B can access.
[0238] The metadata requested by the metadata request may be part of all metadata accessible to the data storage device 100B. The metadata set includes part of all metadata accessible to the data storage device 100B.
[0239] The transfer attributes of data storage device 100B and the transfer attributes of the data satisfy the transfer policy, indicating that data storage device 100B has the authority to obtain the data and its metadata. After data storage device 100A transmits the metadata to data storage device 100B via a metadata affirmative response, if the metadata of the data is updated, data storage device 100A can send a metadata update notification message to data storage device 100B. The metadata update notification message is used to indicate that the metadata has been updated. After receiving the metadata update notification message, data storage device 100B can request to obtain the updated metadata by sending a metadata request. If the metadata of the data has been updated, data storage device 100A can also directly send the updated metadata to data storage device 100B.
[0240] Step 406: After determining that there is no metadata that the data storage device 100B is allowed to access, the data storage device 100A feeds back a metadata negative response to the data storage device 100B, where the metadata negative response indicates that the data storage device 100B has no right to obtain the metadata.
[0241] The flow attributes of the data storage device 100B and the flow attributes of the data do not satisfy the flow policy, which means that the data storage device 100B does not have the authority to obtain the metadata, and the metadata will not be transmitted to the data storage device 100B.
[0242] It should be noted that after the metadata is transferred to the data storage device 100B, it can be considered that the data storage device 100B has the authority to process the obtained metadata. If the subsequent flow attributes of the data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, resulting in the flow attributes of the data and the flow attributes of the data storage device 100B no longer meeting the flow policy, the data storage device 100A can reject the metadata request initiated by the subsequent data storage device 100B to request the metadata of the data, that is, notify the data storage device 100B that it has no right to view the metadata. As for the metadata obtained by the data storage device 100B before the flow attributes of the data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, the data storage device 100A can notify the data storage device 100B to delete the obtained metadata, or it can not trace the metadata obtained by the data storage device 100B. If partial or complete changes in the data flow attributes, the flow attributes of the data storage device 100B, and the flow strategy result in the addition of some data allowed to be accessed by the data storage device 100B, the data storage device 100A can transfer the metadata of the added data to the data storage device 100B.
[0243] After the data storage device 100B obtains the metadata, that is, obtains the address information of the data, the data storage device 100B can request the data from the data storage device 100. The address information of the data can be the address of the data, such as the logical block address (LBA) of the data. The address information of the data can also be used to determine the information required for the address of the data, such as the identifier of a file or directory.
[0244] The following describes a method of transmitting data between the data storage device 100B and the data storage device 100A, taking an example in which the data storage device 100B requests the data storage device 100A to obtain target data.
[0245] Step 407: The data storage device 100B sends a data request to the data storage device 100A. The data request is used to request target data. The data request device carries the address information of the target data. Optionally, the data request can also carry the flow attribute of the data storage device 100B.
[0246] When a user interacts with data storage device 100B and requests to obtain target data, if the target data is data stored in data storage device 100A, data storage device 100B needs to obtain the target data from data storage device 100A to display the target data to the user or send it to the user (i.e., the user's computing device). When data storage device 100B obtains the target data from data storage device 100A, step 407 is executed.
[0247] Step 408: The data storage device 100A receives the data request and determines whether the flow attributes of the data storage device 100B and the flow attributes of the target data satisfy the flow policy.
[0248] After receiving the data request, the data storage device 100A needs to obtain the flow attributes of the target data and the flow attributes of the data storage device 100B.
[0249] Regarding the flow attribute of the target data, the data storage device 100A may determine the metadata of the target data according to the address information of the target data, and then obtain the flow attribute of the target data from the metadata of the data.
[0250] Regarding the transfer attributes of the data storage device 100B, if the data request carries the transfer attributes of the data storage device 100B, the data storage device 100A can obtain the transfer attributes of the data storage device 100B from the data request. If the data request does not carry the transfer attributes of the data storage device 100B, the data storage device 100A can obtain the transfer attributes of the data storage device 100B from a stored device transfer attribute set. The method for the data storage device 100A to obtain the transfer attributes of the data storage device 100B from the device transfer attribute set can be found in the above description and will not be repeated here.
[0251] After the data storage device 100A obtains the flow attributes of the target data and the flow attributes of the data storage device 100B, it determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy. The method by which the data storage device 100A determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy is similar to the method by which the data storage device 100A determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy in step 404. For details, please refer to the above description and will not be repeated here.
[0252] Step 409: When the data storage device 100A determines that the flow attributes of the data storage device 100B and the flow attributes of the target data satisfy the flow policy, the data storage device 100A feeds back a data affirmative response to the data storage device 100B, where the data affirmative response carries the target data.
[0253] The flow attributes of the data storage device 100B and the flow attributes of the target data satisfy the flow policy, indicating that the data storage device 100B has the authority to obtain the target data. After the data storage device 100A transmits the target data to the data storage device 100B through a data affirmative response, if the target data is updated, the data storage device 100A can send a data update notification message to the data storage device 100B. The data update notification information is used to indicate that the target data has been updated. After receiving the data update notification message, the data storage device 100B can request to obtain the updated target data by sending a data request, or if the user requests to view the target data again, it can send a data request again to request to obtain the updated target data. If the target data is updated, the data storage device 100A can also directly send the updated data to the data storage device 100B.
[0254] Step 410: When the data storage device 100A determines that the flow attributes of the data storage device 100B and the flow attributes of the target data do not satisfy the flow policy, the data storage device 100A feeds back a data negative response to the data storage device 100B, indicating that it has no right to obtain the target data.
[0255] The transfer attributes of data storage device 100B and the transfer attributes of the target data do not satisfy the transfer policy, indicating that data storage device 100B does not have the authority to obtain the target data, and the target data will not be transmitted to data storage device 100B. After receiving the data negative response, data storage device 100B can notify the user that it does not have the authority to query the target data.
[0256] It should be noted that after the target data is transferred to the data storage device 100B, it can be considered that the data storage device 100B has the authority to process the acquired target data. If the subsequent flow attributes of the target data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, resulting in the flow attributes of the target data and the flow attributes of the data storage device 100B no longer meeting the flow policy, the data storage device 100A can reject the subsequent data request initiated by the data storage device 100B to request the data, that is, notify the data storage device 100B that it has no right to query the target data. As for the target data acquired by the data storage device 100B before the flow attributes of the target data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, the data storage device 100A can notify the data storage device 100B to delete the acquired target data, or it can not trace the target data acquired by the data storage device 100B.
[0257] 2. The management module 200 is deployed independently (the management module 200 is deployed in the management device 300):
[0258] The following describes a data transmission method provided by an embodiment of the present application in conjunction with FIG6 . The data transmission method includes three parts: a flow strategy and flow attribute configuration process, specifically referring to steps 600 to 602; a metadata transmission process, specifically referring to steps 603 to 609; and a data transmission process, specifically referring to steps 610 to 612. In the following, to distinguish between different data storage devices 100, data storage device 100A is regarded as a data storage device 100 storing target data, and data storage device 100B is regarded as a data storage device 100 requiring a request for target data or metadata.
[0259] Step 600: The management device 300 obtains the transfer policy. The management device 300 performs step 600 in a manner similar to the data storage device 100A performs step 400. For details, please refer to the above description and will not be repeated here.
[0260] Step 601: The management device 300 configures transfer attributes for the data stored in the data storage device 100A and saves the transfer attributes of the data. The transfer attributes of different data can be the same or different. The management device 300 performs step 601 in a similar manner to the data storage device 100A performing step 401. For details, please refer to the previous description and will not be repeated here.
[0261] It should be noted that after the management device 300 configures the flow attributes for the data stored in the data storage device 100A, it can transmit the flow attributes of the data to the data storage device 100A, and the data storage device 100A can store the flow attributes of the data in the metadata of the data. The management device 300 may not transmit the flow attributes of the data to the data storage device 100A. The management device 300 may store the flow attributes of the data or store the flow data of the data in the metadata of the data. The metadata containing the flow attributes of the data may be stored in the management device 300.
[0262] Step 602: Management device 300 configures transfer attributes for data storage device 100B, and data storage device 100B saves the transfer attributes configured by management device 300. The manner in which management device 300 performs step 602 is similar to the manner in which data storage device 100A performs step 402. For details, please refer to the previous description and will not be repeated here.
[0263] It should be noted that the embodiment of the present application does not limit the execution order of steps 600 to 602. In actual applications, the acquisition of the flow strategy and the configuration of the flow attributes can be carried out simultaneously; or the flow attributes of the data storage device 100B and the flow attributes of the data can be configured first, and then the flow strategy can be acquired.
[0264] Step 603: Data storage device 100B sends a metadata request to data storage device 100A. This metadata request is used to request metadata. Optionally, the metadata request includes the transfer attributes of data storage device 100B. Step 603 is executed similarly to step 403. For details, please refer to the previous description and will not be repeated here.
[0265] Step 604: After receiving the metadata request, data storage device 100A sends a second query message to management device 300. The second query message is used to inquire about the metadata set, which includes metadata that is allowed to be transmitted to the receiving device. Optionally, the second query message carries the transfer attribute of data storage device 100B.
[0266] Step 605: The management device 300 receives the second query message and determines a metadata set based on the transfer attributes of the data storage device 100B. The manner in which the management device 300 obtains the transfer attributes of the data storage device 100B and determines the metadata set based on the transfer attributes of the data storage device 100B is similar to the manner in which the data storage device 100A obtains the transfer attributes of the data storage device 100B and determines the metadata set based on the transfer attributes of the data storage device 100B in step 404. For details, please refer to the aforementioned content and will not be repeated here.
[0267] Step 606: After determining the metadata that is allowed to be accessed by the data storage device 100B, the management device 300 feeds back the metadata set to the data storage device 100A.
[0268] When the metadata requested by the metadata request may be all metadata that the data storage device 100B can access, the metadata set includes all metadata that the data storage device 100B can access.
[0269] The metadata requested by the metadata request may be part of all metadata accessible to the data storage device 100B. The metadata set includes part of all metadata accessible to the data storage device 100B.
[0270] Step 607: The data storage device 100A feeds back a metadata positive response to the data storage device 100B, where the metadata positive response carries a metadata set.
[0271] Step 608: After determining that there is no metadata that the data storage device 100B is allowed to access, the management device 300 notifies the data storage device 100A that the data storage device 100B has no right to obtain the metadata.
[0272] Step 609: The data storage device 100A feeds back a metadata negative response to the data storage device 100B, where the metadata negative response indicates that the data storage device 100A has no right to obtain the metadata.
[0273] The flow attributes of the data storage device 100B and the flow attributes of the data do not satisfy the flow policy, which means that the data storage device 100B does not have the authority to obtain the metadata, and the metadata will not be transmitted to the data storage device 100B.
[0274] It should be noted that after metadata is transferred to data storage device 100B, data storage device 100B can be considered to have the authority to process the acquired metadata. If the subsequent data flow attributes, the flow attributes of data storage device 100B, and the flow policy partially or completely change, resulting in the data flow attributes and the flow attributes of data storage device 100B no longer meeting the flow policy, the management device 300 can notify data storage device 100B through data storage device 100A that it is not authorized to view the metadata in subsequent metadata requests initiated by data storage device 100B to request metadata for the data. For metadata acquired by data storage device 100B before the data flow attributes, the flow attributes of data storage device 100B, and the flow policy partially or completely change, the management device 300 can notify data storage device 100B through data storage device 100A to delete the acquired metadata, or it can not trace the metadata acquired by data storage device 100B. If partial or complete changes in the data flow attributes, the flow attributes of the data storage device 100B, and the flow policy result in the addition of some data allowed to be accessed by the data storage device 100B, the management device 300 can transmit the metadata of the added data to the data storage device 100B through the data storage device 100A.
[0275] The following describes a method of transmitting data between the data storage device 100B and the data storage device 100A, taking an example in which the data storage device 100B requests the data storage device 100A to obtain target data.
[0276] Step 610: Data storage device 100B sends a data request to data storage device 100A. This data request is used to request data and carries the address information of the target data. Optionally, the data request may also carry the transfer attribute of data storage device 100B. The execution of step 610 is similar to that of step 407. For details, please refer to the previous description and will not be repeated here.
[0277] Step 611: After receiving the data request, data storage device 100A sends a first query message to management device 300. The first query message is used to inquire whether the target data is allowed to be transferred to data storage device 100B. Optionally, the first query message carries the transfer attributes of the target data and / or the transfer attributes of data storage device 100B.
[0278] If the data storage device 100A stores the flow attributes of the target data, such as after the management device 300 configures the flow attributes for the target data, it can transmit the flow attributes of the target data to the data storage device 100A, and the data storage device 100A can carry the flow data of the target data in the first query message.
[0279] If the data storage device 100A does not store the target data's flow attributes, the first query message may not carry the target data's flow attributes. Instead, the first query message may carry the target data's identification information, such as the file name or directory name, or other information uniquely identifying the target data. Of course, if the data storage device 100A stores the target data's flow attributes, the first query message may not carry the target data's flow attributes. The management device 300 may determine the target data's metadata based on the target data's identification information and then obtain the target data's flow attributes from the stored target data's metadata.
[0280] If the data request carries the transfer attributes of the data storage device 100B, the first inquiry message may carry the transfer attributes of the data storage device 100B. If the data request does not carry the transfer attributes of the data storage device 100B, the first inquiry message may not carry the transfer attributes of the data storage device 100B. The first inquiry message may carry the address or identifier of the data storage device 100B. The address or identifier of the data storage device 100B may be carried in the data request. This allows the management device 300 to subsequently obtain the transfer attributes of the data storage device 100B from the device transfer attribute set based on the address or identifier of the data storage device 100B. Of course, if the data request carries the transfer attributes of the data storage device 100B, the first inquiry message may not carry the transfer attributes of the data storage device 100B. The management device 300 determines the transfer attributes of the data storage device 100B based on the address or identifier of the data storage device 100B.
[0281] Step 612: After receiving the first query message, the management device 300 determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy. The way in which the management device 300 obtains the flow attributes of the target data and the flow attributes of the data storage device 100B and determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy is similar to the way in which the data storage device 100A obtains the flow attributes of the target data and the flow attributes of the data storage device 100B and determines whether the flow attributes of the data storage device 100B and the flow attributes of the data satisfy the flow policy in step 408. The difference is that in step 612, the management device 300 directly obtains the flow attributes of the target data or the flow attributes of the data storage device 100B from the first query message or determines the flow attributes of the target data or the flow attributes of the data storage device 100B based on the information carried in the first query message. That is, the messages processed by the management device 300 and the data storage device 100 are different. For details, please refer to the above description and will not be repeated here.
[0282] Step 613: When the management device 300 determines that the flow attributes of the data storage device 100A and the flow attributes of the target data meet the flow policy, the management device 300 sends a first notification message to the data storage device 100A. The first notification message is used to notify the target data that it is allowed to be transferred to the data storage device 100B.
[0283] Step 614: After receiving the first notification message, the data storage device 100A feeds back a data affirmative response to the data storage device 100B, where the data affirmative response carries the target data.
[0284] The flow attributes of the data storage device 100B and the flow attributes of the target data satisfy the flow policy, indicating that the data storage device 100B has the authority to obtain the target data. After the data storage device 100A transmits the target data to the data storage device 100B through a data affirmative response, if the target data is updated, the data storage device 100A sends a data update notification message to the data storage device 100B. The data update notification message is used to indicate that the target data has been updated. After receiving the data update notification message, the data storage device 100B can request to obtain the updated target data by sending a data request, or if the user requests to view the target data again, it can send a data request again to request to obtain the updated target data. If the data is updated, the data storage device 100A can also directly send the updated data to the data storage device 100B.
[0285] Step 615: When the management device 300 determines that the flow attributes of the data storage device 100A and the flow attributes of the target data do not satisfy the flow policy, the management device 300 sends a second notification message to the data storage device 100A. The second notification message is used to notify that the target data is not allowed to be transferred to the data storage device 100B.
[0286] Step 616: The data storage device 100A feeds back a data negative response to the data storage device 100B, where the data negative response indicates that the data storage device 100A has no right to obtain the target data.
[0287] The transfer attributes of data storage device 100B and the transfer attributes of the target data do not satisfy the transfer policy, indicating that data storage device 100B does not have the authority to obtain the target data, and the target data will not be transmitted to data storage device 100B. After receiving the data negative response, data storage device 100B can notify the user that it does not have the authority to query the target data.
[0288] It should be noted that after the target data is transferred to the data storage device 100B, it can be considered that the data storage device 100B has the authority to process the acquired target data. If the subsequent flow attributes of the target data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, resulting in the flow attributes of the target data and the flow attributes of the data storage device 100B no longer meeting the flow policy, the management device 300 can notify the data storage device 100A that the data storage device 100B has no authority to obtain the target data. The data storage device 100A can reject subsequent data requests initiated by the data storage device 100B to request the data, that is, notify the data storage device 100B that it has no authority to query the target data. As for the target data acquired by the data storage device 100B before the flow attributes of the target data, the flow attributes of the data storage device 100B, and the flow policy partially or completely change, the data storage device 100A can notify the data storage device 100B to delete the acquired target data, or it can not trace the target data acquired by the data storage device 100B.
[0289] Based on the same inventive concept as the method embodiment, the present application also provides a data transmission device for executing the method performed by the data storage device 100B or the management device 300 in the method embodiment described above. As shown in FIG7 , the data transmission device 700 includes a management module 200. When the data transmission device 700 has the function of implementing the behavior of a data storage device, the data transmission device 700 may also include a first transmission module 701. When the data transmission device 700 has the function of implementing the behavior of a management device, the data transmission device 700 may also include a second transmission module 702.
[0290] The management module 200 can obtain the flow attributes of the target data to be transmitted and the flow attributes of the receiving device. The flow attributes of the target data represent the restrictive factors for the target data to be transmitted, and the flow attributes of the receiving device represent the restrictive factors for the receiving device to obtain data.
[0291] The management module 200 can also determine whether the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, wherein the flow policy describes the flow attributes of the target data and the conditions that the flow attributes of the receiving device must follow when the receiving device has the authority to obtain the target data.
[0292] As a possible implementation, the first transmission module 701 receives a data request sent by a receiving device, the data request is used to request to obtain target data, and the data request carries the flow attributes of the receiving device; the management module 200 obtains the flow attributes of the receiving device from the data request.
[0293] As a possible implementation, the management module 200 may obtain the flow attributes of the target data from the metadata of the target data.
[0294] As a possible implementation, the first transmission module 701 may also receive a metadata request sent by the receiving device, where the metadata request carries the flow attribute of the receiving device.
[0295] The management module 200 determines, in response to the metadata request, a metadata set according to the flow attribute of the receiving device, where the metadata set includes metadata that is allowed to be transmitted to the receiving device;
[0296] The first transmission module 701 transmits a metadata set to a receiving device.
[0297] As a possible implementation, the first transmission module 701 sends the target data to the receiving device after the management module 200 determines that the target data is allowed to be transmitted to the receiving device.
[0298] As a possible implementation, the second transmission module 702 receives a first inquiry message sent by the data storage device. The first inquiry message is used to inquire whether the target data is allowed to be transmitted to the receiving device. The first inquiry message carries the flow attributes of the target data and the flow attributes of the receiving device.
[0299] The management module 200 obtains the flow attributes of the target data and the flow attributes of the receiving device from the first query message.
[0300] As a possible implementation, the second transmission module 702 receives a second query message sent by the data storage device. The second query message is used to inquire about a metadata set, which includes metadata permitted for transmission to the receiving device. The second query message carries the receiving device's transfer attributes. In response to the second query message, the management module 200 determines the metadata set based on the receiving device's transfer attributes. The second transmission module 702 transmits the metadata set to the data storage device.
[0301] As a possible implementation, when the management module 200 determines that the target data is allowed to be transmitted to the receiving device based on the flow properties of the target data, the flow properties of the receiving device, and the flow policy, the second transmission module 702 sends a notification message to the data storage device, and the notification message is used to notify the target data that it is allowed to be transmitted to the receiving device.
[0302] As a possible implementation, the management module 200 configures flow attributes for the receiving device under the user's instruction; configures flow attributes for the target data under the user's instruction, and records the flow attributes of the target data in the metadata of the target data.
[0303] As a possible implementation method, the management module 200 generates a certificate that records the flow attributes of the receiving device, and performs some or all of the following on the certificate: encrypts the certificate using the public key of the receiving device and adds signature information to the certificate; wherein the signature information is generated using its own private key; the management module 200 sends the certificate to the receiving device.
[0304] As a possible implementation, the management module 200 obtains the flow attributes of the receiving device from a device flow attribute set pre-configured by the user, where the device flow attribute set includes the flow attributes configured by the user for at least one device.
[0305] As a possible implementation method, the flow attributes of the target data indicate part or all of the following: the security level of the target data, the business type of the target data, and the flow attributes of the receiving device indicate part or all of the following: the security level of the receiving device, the business type of the business undertaken by the receiving device.
[0306] The division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0307] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for enabling a terminal device (which can be a personal computer, mobile phone, or network device, etc.) or a processor to execute all or part of the steps of the method of each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc., various media that can store program code.
[0308] The present application further provides a computing device 800 as shown in Figure 8. The computing device 800 includes a bus 801, a processor 802, a communication interface 803, and a memory 804. The processor 802, the memory 804, and the communication interface 803 communicate with each other via the bus 801.
[0309] Among them, the processor 802 can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0310] The memory 804 can be a dynamic random access memory (DRAM). In addition to DRAM, the memory 804 can also be other random access memories, such as static random access memory (SRAM). In addition, the memory 804 can also be a read-only memory (ROM). As for the read-only memory, for example, it can be a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), etc. The memory 804 can also be a flash memory medium (FLASH), a hard disk drive (HDD) or a solid state drive (SSD). The memory 804 stores computer program instructions, and the processor 802 executes the computer program instructions to execute the steps performed by the data storage device 100A in the method described in Figure 4 or the steps performed by the management device 300 in the method described in Figure 8. The memory 804 can also include software modules required for other running processes such as the operating system (such as multiple modules in the data transmission device 700). The operating system can be LINUX TM ,UNIX TM ,WINDOWS TM wait.
[0311] The present application also provides a computing device system, comprising at least one computing device 900 as shown in FIG9 . The computing device 900 comprises a bus 901, a processor 902, a communication interface 903, and a memory 904. The processor 902, the memory 904, and the communication interface 903 communicate with each other via the bus 901. The at least one computing device 900 in the computing device system communicates with each other via a communication path.
[0312] The specific types of the processor 902 and the memory 904 can be found in the relevant description of the processor 802 and the memory 804, which will not be repeated here. The processor 902 executes the computer program instructions stored in the memory 904 to execute part or all of the steps executed by the data storage device 100A in the method described in Figure 4, or the processor 902 executes the computer program instructions stored in the memory 904 to execute part or all of the steps executed by the management device 300 in the method described in Figure 6. The memory may also include software modules required for other running processes such as the operating system. The operating system may be LINUX TM ,UNIX TM ,WINDOWS TM wait.
[0313] At least one computing device 900 in the computing device system establishes communication with each other via a communication network, and any one or multiple modules of the data transmission apparatus 700 are run on each computing device 900 .
[0314] The above embodiments can be implemented in whole or in part through software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, hard disk, tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid state drive (SSD).
[0315] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0316] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0317] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0318] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0319] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A data transmission method, characterized in that: The method comprises: Acquire the flow attribute of the target data to be transmitted and the flow attribute of the receiving device, wherein the flow attribute of the target data represents the restriction factor for the target data to be transmitted, and the flow attribute of the receiving device represents the restriction factor for the receiving device to obtain data; Determine whether the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, wherein the flow policy describes the flow attributes of the target data and the conditions that the flow attributes of the receiving device must comply with when the receiving device has the authority to obtain the target data.
2. The method according to claim 1, characterized in that The obtaining of the flow attribute of the receiving device includes: A data request sent by the receiving device is received, where the data request is used to request to obtain the target data, and the data request carries a flow attribute of the receiving device.
3. The method according to claim 1 or 2, characterized in that The obtaining of the flow attribute of the target data to be transmitted includes: The flow attribute of the target data is obtained from the metadata of the target data.
4. The method according to claim 2 or 3, characterized in that Before receiving the data request sent by the receiving device, the method further includes: receiving a metadata request sent by the receiving device, wherein the metadata request carries a flow attribute of the receiving device; In response to the metadata request, determining the metadata set according to the streaming attribute of the receiving device, the metadata set including metadata allowed to be transmitted to the receiving device; The set of metadata is transmitted to the receiving device.
5. The method according to any one of claims 2 to 3, characterized in that: The method further comprises: After determining that the target data is allowed to be transmitted to the receiving device, the target data is sent to the receiving device.
6. The method according to claim 1, characterized in that The obtaining of the flow attributes of the target data to be transmitted and the flow attributes of the receiving device includes: A first inquiry message sent by a receiving data storage device is used to inquire whether the target data is allowed to be transmitted to the receiving device, and the first inquiry message carries the flow attribute of the target data and the flow attribute of the receiving device.
7. The method according to claim 6, characterized in that Before receiving the first inquiry message sent by the data storage device, the method further includes: receiving a second inquiry message sent by the data storage device, the second inquiry message being used to inquire about a metadata set, the metadata set including metadata allowed to be transmitted to the receiving device, the second inquiry message carrying a flow attribute of the receiving device; In response to the second query message, determining the metadata set according to a flow attribute of the receiving device; The set of metadata is transmitted to the data storage device.
8. The method according to claim 6 or 7, characterized in that In the case where it is determined according to the flow attribute of the target data, the flow attribute of the receiving device, and the flow policy that the target data is allowed to be transmitted to the receiving device, the method further includes: A notification message is sent to the data storage device, where the notification message is used to notify that the target data is allowed to be transmitted to the receiving device.
9. The method according to any one of claims 1 to 8, characterized in that: Before acquiring the flow attribute of the target data to be transmitted and the flow attribute of the receiving device, the method further includes: configuring the streaming attributes for the receiving device under the instruction of the user; Under the instruction of the user, the flow attribute is configured for the target data, and the flow attribute of the target data is recorded in the metadata of the target data.
10. The method according to claim 9, characterized in that The configuring the streaming attribute for the receiving device includes: Generate a certificate recording the transfer attribute of the receiving device, and perform some or all of the following on the certificate: encrypt the certificate using the public key of the receiving device and add signature information to the certificate; wherein the signature information is generated using its own private key; The certificate is sent to the receiving device.
11. The method according to claim 1, characterized in that The acquiring the flow attribute of the receiving device includes: The flow attribute of the receiving device is obtained from a device flow attribute set pre-configured by a user, wherein the device flow attribute set includes the flow attributes configured by the user for at least one device.
12. The method according to any one of claims 1 to 11, characterized in that: The flow attribute of the target data indicates part or all of the following: the security level of the target data and the business type of the target data.
13. The method according to any one of claims 1 to 12, characterized in that: The flow attribute of the receiving device indicates part or all of the following: the security level of the receiving device and the service type of the service undertaken by the receiving device.
14. A data transmission device, characterized in that: The device comprises a management module, The management module is used to obtain the flow attribute of the target data to be transmitted and the flow attribute of the receiving device, wherein the flow attribute of the target data represents the restriction factor for the target data to be transmitted, and the flow attribute of the receiving device represents the restriction factor for the receiving device to obtain data; Determine whether the target data is allowed to be transmitted to the receiving device based on the flow attributes of the target data, the flow attributes of the receiving device, and the flow policy, wherein the flow policy describes the flow attributes of the target data and the conditions that the flow attributes of the receiving device must comply with when the receiving device has the authority to obtain the target data.
15. The device according to claim 14, characterized in that The device also includes a first transmission module, The first transmission module is used to: receive a data request sent by the receiving device, the data request is used to request to obtain the target data, and the data request carries the flow attribute of the receiving device; The management module is used to obtain the flow attribute of the receiving device from the data request.
16. The device according to claim 14 or 15, characterized in that The management module is used to: The flow attribute of the target data is obtained from the metadata of the target data.
17. The device according to claim 15 or 16, characterized in that The first transmission module is further used for: receiving a metadata request sent by the receiving device, wherein the metadata request carries a flow attribute of the receiving device; The management module is further configured to respond to the metadata request and determine the metadata set according to the flow attribute of the receiving device, wherein the metadata set includes metadata allowed to be transmitted to the receiving device; The first transmission module is further used to: transmit the metadata set to the receiving device.
18. The device according to any one of claims 16 to 17, characterized in that: The first transmission module is further configured to send the target data to the receiving device after the management module determines that the target data is allowed to be transmitted to the receiving device.
19. The device according to claim 14, characterized in that The device also includes a second transmission module; The second transmission module is used to: receive a first inquiry message sent by the data storage device, the first inquiry message is used to inquire whether the target data is allowed to be transmitted to the receiving device, and the first inquiry message carries the flow attribute of the target data and the flow attribute of the receiving device; The management module is used to obtain the flow attribute of the target data and the flow attribute of the receiving device from the first inquiry message.
20. The device according to claim 19, characterized in that The second transmission module is further used for: receiving a second inquiry message sent by the data storage device, the second inquiry message being used to inquire about a metadata set, the metadata set including metadata allowed to be transmitted to the receiving device, the second inquiry message carrying a flow attribute of the receiving device; The management module is further configured to determine the metadata set according to the flow attribute of the receiving device in response to the second query message; The second transmission module is further used to transmit the metadata set to the data storage device.
21. The device according to claim 19 or 20, characterized in that In the case where it is determined according to the flow attribute of the target data, the flow attribute of the receiving device, and the flow strategy that the target data is allowed to be transmitted to the receiving device, the second transmission module is further used to: A notification message is sent to the data storage device, where the notification message is used to notify that the target data is allowed to be transmitted to the receiving device.
22. A computing device, characterized in that The computing device comprises a processor and a memory, wherein the processor is configured to call computer program instructions stored in the memory to execute the method according to any one of claims 1 to 13.
Citation Information
Patent Citations
Method and system for guaranteeing security of electronic documents by using electronic document security labels
CN103824031A
Data sending method and device, storage medium and electronic equipment
CN109547406A
Data processing method and device, equipment and medium
CN112417505A
Data access control method and device, equipment and storage medium
CN114218605A
Data access control method and device
CN116089661A