Access control method and related apparatus

By configuring access policies and performing permission verification during data transmission, the problems of data security and privacy in cross-domain data sharing are solved, and the secure flow and use of data between devices is achieved.

WO2025194853A1PCT designated stage Publication Date: 2025-09-25HUAWEI TECH CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/136415
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-22
Filing Date
2024-12-03
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

How to ensure data security and privacy during cross-domain, distributed data sharing and use, especially to prevent data leakage and virus infection during efficient flow between multiple regions and multiple centers.

Method used

By configuring access policies during data transmission, storage nodes verify the requester's permissions and perform access control according to the policies during data transmission and use, ensuring that data is only transferred and used between authorized devices.

Benefits of technology

It implements access control during data transmission, expands the scope of access control, improves data security and confidentiality, and supports the secure flow of data between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024136415_25092025_PF_FP_ABST
    Figure CN2024136415_25092025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose an access control method and a related apparatus. The access control method comprises: a first storage node receives target data and an access policy corresponding to the target data from a first compute node, the access policy being used for indicating permission to access the target data; the first storage node receives an access request from a second compute node, the access request being used for accessing the target data; on the basis of the access policy, the first storage node verifies whether the second compute node has permission to access the target data; and, when the second compute node has permission to access the target data, the first storage node sends the target data and the access policy to the second compute node, so that the second compute node accesses the target data according to the access policy. Thus, access control of the target data during transmission is achieved, access control of the target data during use is also achieved, the range of access control of the target data is expanded, and data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Access control method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on March 22, 2024, with application number 202410338370.X and application name “A method for access control and related devices”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to an access control method and related devices. Background Art

[0003] Data storage security and data transfer play a crucial role in today's digital society. With the increasing circulation of data elements, enterprises and data centers need to achieve cross-domain, distributed data sharing and utilization to improve efficiency, innovate business models, and meet regulatory compliance requirements. Ensuring data security and privacy during transmission, as well as efficient data transfer across multiple locations and centers, is a crucial issue.

[0004] Security sandbox technology is an isolated operating environment. It creates a virtual space completely isolated from the real system environment, allowing browsers, applications, and other potentially risky code to run within it. Programs running within the sandbox have their read and write operations, network access, and other behaviors strictly restricted and monitored. Even if these programs engage in malicious behavior or exploit vulnerabilities, they will not cause actual damage to the host system's data and resources, effectively preventing data leaks and virus infections.

[0005] Due to the isolation mechanism of the security sandbox, all operations performed by users on data within the sandbox (such as reading, modifying or deleting) are limited to the security sandbox. Therefore, users cannot directly transfer these data flows to the real system environment outside the security sandbox. Users can only access and operate data within this environment. Summary of the Invention

[0006] The present application provides an access control method and related devices for improving data security.

[0007] In the first aspect, the present application provides an access control method. A first computing node produces target data and configures an access policy corresponding to the target data, which indicates the authority to access the target data. Then, the first computing node passes the target data and the access policy of the target data to the first storage node, and the first storage node stores these data. In an embodiment of the present application, the access policy of the target data indicates that the target data can only be provided to devices (such as computing nodes or storage nodes) that have permission to access the target data, and after these devices receive the target data, they should also follow the authority indicated by the access policy to use the target data.

[0008] Next, if the second computing node needs to access the target data, the second computing node can send an access request to the first storage node, and the access request is used to access the target data. After receiving the access request, the first storage node determines that the second computing node requests access to the target data. From the above, it can be seen that the first storage node saves the target data and the access policy of the target data, and the access policy indicates the authority to access the target data. The first storage node then verifies whether the second computing node has the authority to access the target data indicated by the access policy based on the access policy of the target data. If the second computing node has the authority to access the target data, the first storage node sends the target data and the access policy of the target data to the second computing node.

[0009] After the second computing node receives the target data and the access policy for the target data, the access policy is used to indicate the permissions for the second computing node to access the target data. The second computing node can only access the target data according to the permissions indicated by the access policy. After receiving the target data, the second computing node cannot perform any access operations on the target data beyond the permissions authorized by the access policy, thereby further strengthening the security and confidentiality of the target data.

[0010] In this application, when a second computing node requests access to target data, the first storage node verifies the second computing node's permission to access the target data based on the target data's access policy. After the target data is transferred to the second computing node, the second computing node should also access the target data according to the permission indicated by the access policy. This achieves access control of the target data during transfer and during use, expanding the scope of access control over the target data and improving data security.

[0011] On the other hand, as can be seen above, within the security sandbox's isolation mechanism, data within the security sandbox cannot flow into the real system environment outside the security sandbox; users can only access and manipulate data within the security sandbox environment. Compared to the security sandbox's isolation mechanism, the access control method of this application supports access control during data transfer and access control during data use, thereby ensuring data security while also enabling secure data transfer between devices.

[0012] On the other hand, the access policy of the target data flows together with the target data to each data storage node and computing node, so that during the flow of the target data, different devices (data storage nodes and computing nodes) can implement the access control process of the target data according to the same access policy, thereby improving the efficiency of access control.

[0013] Based on the first aspect, in an optional implementation, the first storage node is remote storage for the first computing node and the second computing node. The first storage node can store data from each computing node (including the first computing node and the second computing node), and can also provide the data stored by the first storage node to each computing node (including the first computing node and the second computing node). Therefore, after generating the target data and the access policy for the target data, the first computing node sends the target data and the access policy for the target data to the first storage node, and the first storage node saves the target data, the target data, and the access policy for the target data.

[0014] Based on the first aspect, in an optional implementation, the remote storage (Remote Storage) of the first computing node is a second storage node, and the second storage node is responsible for storing and managing the data produced by the first computing node. After the first computing node produces the target data and the access policy for the target data, it sends the target data and the access policy for the target data to the second storage node, and the second storage node saves the target data and the access policy for the target data. If the remote storage of the second computing node is the first storage node, the second computing node cannot directly access the target data through the second storage node. Therefore, after the first computing node sends the target data and the access policy for the target data to the second storage node, the second storage node sends the target data and the access policy for the target data to the first storage node, and the first storage node saves the received target data and the access policy for the target data. Then, the second computing node can request access to the target data from the first storage node.

[0015] Based on the first aspect, in an optional implementation, a data access control device is deployed on the second computing node, and through the data access control device, the second computing node accesses the target data according to the authority indicated by the access policy.

[0016] Based on the first aspect, in an optional implementation, the data access control device can be a hardware card inserted into the second computing node, such as a smart network card or a data processing unit (DPU), or it can be a software module installed and run by the second computing node, or it can be a gateway or independent server connected to the second computing node.

[0017] Based on the first aspect, in an optional embodiment, a data control client is deployed in the second computing node. The data control client is a client used in conjunction with the above-mentioned data access control device, and the data control client provides a user with a communication interface for data interaction with the data access control device. The user accesses the target data stored in the above-mentioned data access control device through the data control client deployed in the second computing node. The data access control device then provides the target data to the data control client in the second computing node according to the permissions indicated by the access policy, so that when the user accesses the target data, the target data will never flow to the storage space outside the data access control device, thereby preventing the target data from being stolen and reducing the risk of data leakage.

[0018] Based on the first aspect, in an optional implementation, the data access control may encrypt the target data before providing the target data to the data control client in the second computing node, and then provide the encrypted target data to the data control client, so that the user is always invisible to the original target data, thereby ensuring the confidentiality of the target data.

[0019] Based on the first aspect, in an optional implementation, the data control client needs to first undergo identity authentication by the data access control device. Only after the data access control device confirms that the identity of the data control client is legal can the data control client interact with the data access control device, thereby preventing unauthorized clients from illegally accessing target data and improving data security.

[0020] Based on the first aspect, in an optional embodiment, the data access control device is configured to receive, store, and manage target data and access policies. Therefore, the second computing node receives the target data and the access policy for the target data through the data access control device, and the data access control device of the second computing node stores the target data and the access policy for the target data. This eliminates the need to store the target data and the access policy for the target data on a disk or in memory on the second computing node, thereby reducing the risk of data leakage.

[0021] Based on the first aspect, in an optional implementation, the access policy is used to indicate at least one of the number of accesses, access time, and access identity to the target data. That is, the access policy includes but is not limited to one or a combination of multiple restrictions among the number of accesses, access time, and access identity, thereby improving the flexibility and management efficiency of the data access control process. It should be understood that the above "number of accesses, access time, and access identity" is only a possible exemplary description of the access policy and does not constitute a substantive limitation on the content of the access policy. In actual applications, in addition to "number of accesses, access time, and access identity," the access policy can also be used to indicate other restrictions, which are not limited in the embodiments of the present application.

[0022] Based on the first aspect, in one optional embodiment, the target data access policy is used to indicate the access time of the target data. By limiting the access time of the data, illegal or unauthorized access attempts can be prevented during unauthorized time periods, reducing the risk of data leakage, tampering, or destruction, and improving data security.

[0023] Based on the first aspect, in an optional implementation, after the first storage node receives the access request from the second computing node, it determines the timestamp of the access request, and the timestamp of the access request indicates the time when the second computing node requests access to the target data. In actual applications, the timestamp of the access request can be the time when the first storage node receives the access request, or it can be the message timestamp carried in the access request when the second computing node sends the access request, which is not limited here. If the timestamp of the access request matches the access time of the target data indicated by the access policy, the first storage node determines that the second computing node has the right to access the target data; if the timestamp of the access request does not match the access time of the target data indicated by the access policy, the first storage node determines that the second computing node does not have the right to access the target data.

[0024] Based on the first aspect, in an optional implementation, the access policy for the target data is used to indicate an access time for the target data. After receiving the target data and the access policy for the target data, the second computing node can only access the target data during the access time indicated by the access policy. If the current time exceeds the access time indicated by the access policy, i.e., the current time does not match the access time indicated by the access policy, the second computing node deletes the target data, thereby preventing subsequent data leakage of the target data. Furthermore, deleting unavailable target data helps free up storage space and improve storage resource utilization.

[0025] Based on the first aspect, in an optional implementation, the first storage node may transfer the target data and access policy for the target data it stores to a third storage node. Specifically, the first storage node receives a migration instruction for the target data, which instructs the target data to be migrated to the third storage node. The first storage node then sends the target data and the access policy corresponding to the target data to the third storage node, so that the third storage node can continue to implement access control over the target data using the access policy, thereby ensuring the security of the transfer of the target data.

[0026] Based on the first aspect, in an optional implementation, before the first storage node sends the target data and the access policy corresponding to the target data to the third storage node, it should also verify whether the third storage node has the authority to access the target data. If the verification is successful, that is, it is confirmed that the third storage node has the authority to access the target data, the first storage node sends the target data and the access policy corresponding to the target data to the third storage node. Among them, the "access" exemplified in the embodiments of the present application includes but is not limited to operations such as reading, modifying, updating, saving or transaction transfer of the target data (for example, the third storage node transfers the target data to the fourth storage node).

[0027] In a second aspect, the present application provides an access control method. The method includes:

[0028] The second computing node sends an access request to the first storage node, where the access request is used to access target data;

[0029] The second computing node receives the target data and the access policy of the target data from the first storage node;

[0030] The second computing node accesses the target data according to the authority indicated by the access policy.

[0031] Based on the second aspect, in an optional implementation, the second computing node accesses the target data according to the permission indicated by the access policy, including:

[0032] Through the data access control device, the second computing node accesses the target data according to the authority indicated by the access policy.

[0033] Based on the second aspect, in an optional implementation manner, the data access control device is a hardware card located in the second computing node.

[0034] Based on the second aspect, in an optional implementation, the second computing node accesses the target data according to the authority indicated by the access policy through the data access control device, including:

[0035] The data access control device receives the target data and access policy sent by the first storage node;

[0036] The data access control device provides the target data to the data control client in the second computing node according to the authority indicated by the access policy. The data control client is a client run by the second node for accessing the target data.

[0037] Based on the second aspect, in an optional implementation, the data access control device provides target data to the data control client in the second computing node, including:

[0038] The data access control device encrypts the target data and provides the encrypted target data to the data control client.

[0039] Based on the second aspect, in an optional implementation manner, the data control client is a client that has been authenticated by the data access control device.

[0040] Based on the second aspect, in an optional implementation manner, the target data is stored in a data access control device.

[0041] Based on the second aspect, in an optional implementation, the access policy is used to indicate at least one of the number of accesses to the target data, the access time, and the access identity.

[0042] Based on the second aspect, in an optional implementation, the access policy is used to indicate the access time of the target data.

[0043] Based on the second aspect, in an optional implementation manner, the method further includes:

[0044] If the current time does not match the access time indicated by the access policy, the second computing node deletes the target data.

[0045] In a third aspect, the present application provides a first storage node, the first storage node comprising:

[0046] a transceiver unit, configured to receive target data and an access policy corresponding to the target data from the first computing node, wherein the access policy is used to indicate permission to access the target data;

[0047] The transceiver unit is further configured to receive an access request from the second computing node, the access request being used to access target data;

[0048] a processing unit, configured to verify, according to the access policy, whether the second computing node has permission to access the target data;

[0049] When the second computing node has the authority to access the target data, the transceiver unit is further configured to send the target data and the access policy to the second computing node, so that the second computing node accesses the target data according to the access policy.

[0050] In a fourth aspect, the present application provides a second computing node, the second computing node comprising:

[0051] a transceiver unit, configured to send an access request to the first storage node, where the access request is used to access target data;

[0052] The transceiver unit is further configured to receive target data and an access policy for the target data from the first storage node;

[0053] The processing unit is configured to access target data according to the permissions indicated by the access policy.

[0054] In a fifth aspect, an embodiment of the present application provides a communication device, comprising: a processor, the processor being coupled to a memory, the memory being used to store instructions, and when the instructions are executed by the processor, the device implements the method in the above-mentioned first aspect, or any possible implementation of the first aspect.

[0055] In a sixth aspect, an embodiment of the present application provides a communication device, comprising: a processor, the processor being coupled to a memory, the memory being used to store instructions, and when the instructions are executed by the processor, the device implements the method in the above-mentioned second aspect, or any possible implementation of the second aspect.

[0056] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium having instructions stored thereon, which, when executed, enables a computer to execute the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0057] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium having instructions stored thereon, which, when executed, enables a computer to execute the method in the above-mentioned second aspect or any possible implementation of the second aspect.

[0058] In a ninth aspect, an embodiment of the present application provides a computer program product, which includes a computer program code. When the computer program code runs on a computer, it enables the computer to execute the method of the above-mentioned first aspect or any possible implementation method of the first aspect.

[0059] In a tenth aspect, an embodiment of the present application provides a computer program product, which includes a computer program code. When the computer program code runs on a computer, it enables the computer to execute the method of the above-mentioned second aspect or any possible implementation of the second aspect.

[0060] In the eleventh aspect, an embodiment of the present application provides a chip, comprising: a processor, the processor being coupled to a memory, the memory being used to store instructions, and when the instructions are executed by the processor, the chip implements the method of the above-mentioned first aspect, the second aspect, any possible implementation of the first aspect, or any possible implementation of the second aspect.

[0061] Among them, the technical effects brought about by any implementation method from the second aspect to the eleventh aspect can refer to the technical effects brought about by the implementation method of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0063] FIG1 is a schematic diagram of a possible scenario of security sandbox technology;

[0064] FIG2 is a schematic diagram of a possible, non-limiting system architecture of the access control method in an embodiment of the present application;

[0065] FIG3 is a schematic diagram of a flow chart of an access control method according to an embodiment of the present application;

[0066] FIG4 is a schematic diagram of a process for configuring an access policy for target data by a first computing node in an embodiment of the present application;

[0067] FIG5 is a schematic diagram of a possible scenario of the access control process in an embodiment of the present application;

[0068] FIG6 is a schematic diagram of another possible scenario of the access control process in an embodiment of the present application;

[0069] FIG7 is a schematic structural diagram of a first storage node provided in an embodiment of the present application;

[0070] FIG8 is a schematic diagram of a structure of a second computing node provided in an embodiment of the present application;

[0071] FIG9 is a schematic diagram of a logical structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0072] The embodiments of the present application provide an access control method and related devices for improving data security.

[0073] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. The terms used in the implementation methods of the present application are only used to explain the specific embodiments of the present application and are not intended to limit the embodiments of the present application. It is known to those skilled in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0074] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0075] The terms "first," "second," "third," "fourth," etc. (if any) in the specification and claims of the present application and in the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential sequence. It should be understood that the numbers used in this way are interchangeable where appropriate, so that the embodiments of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products, or apparatus.

[0076] First, possible application scenarios involved in the embodiments of the present application are introduced.

[0077] Data storage security and data transfer play a crucial role in today's digital society. With the increasing circulation of data elements, enterprises and data centers need to achieve cross-domain, distributed data sharing and utilization to improve efficiency, innovate business models, and meet regulatory compliance requirements. Ensuring data security and privacy during transmission, as well as efficient data transfer across multiple locations and centers, is a crucial issue.

[0078] Security sandbox technology is an isolated operating environment. It creates a virtual space completely isolated from the real system environment, allowing browsers, applications, and other potentially risky code to run within it. Programs running within the sandbox have their read and write operations, network access, and other behaviors strictly restricted and monitored. Even if these programs engage in malicious behavior or exploit vulnerabilities, they will not cause actual damage to the host system's data and resources, effectively preventing data leaks and virus infections.

[0079] Please refer to Figure 1, which illustrates a possible scenario for security sandbox technology. As shown in Figure 1, in security sandbox technology, virtualization technology is used to create a closed runtime environment for untrusted files or programs, ensuring the normal functioning of the untrusted files or programs while also providing security protection. In other words, the isolated untrusted files or programs in the sandbox will run using resources within the sandbox, ensuring the security of resources outside the sandbox without affecting the operation of other programs outside the sandbox.

[0080] Due to the isolation mechanism of the security sandbox, all operations performed by users on data within the sandbox (such as reading, modifying or deleting) are limited to the security sandbox. Therefore, users cannot directly transfer these data flows to the real system environment outside the security sandbox. Users can only access and operate data within this environment.

[0081] Data security islands are a data protection technology that uses a combination of hardware and software to encrypt data at the memory level, ensuring that data remains encrypted at all times. Even during computation and analysis, the original data cannot be directly read or stolen, achieving the goal of "available but invisible" and "available but not retrievable." Data security islands enable all participants to conduct joint computations and data analysis without disclosing their original data. This allows each participant's data to be securely transferred and processed within their own secure sandbox. Specifically, a trusted server serves as the data security island, and each participant accesses data within the data security island through methods such as remote desktop. Each party can input data into the data security island, perform computations using pre-defined algorithms or models, and share the resulting results. However, each party cannot access the original data of other participants, thus ensuring data security while promoting the mining and utilization of data value.

[0082] However, participants in a data security island can only share the results of joint computing and data analysis, without transferring their original data. Furthermore, data security islands rely on hardware implementation, requiring each participant to use the hardware computing platform provided by the data security island manufacturer, limiting their use cases.

[0083] In view of this, the embodiment of the present application provides an access control method and related devices for improving the security of data. For ease of understanding, first, a possible, non-restrictive system architecture of the access control method in the embodiment of the present application is introduced. Please refer to Figure 2, which is a possible, non-restrictive system architecture schematic diagram of the access control method in the embodiment of the present application. In the system architecture shown in Figure 2, at least one storage node (storage node 1 and storage node 2 as shown in Figure 2) and at least one computing node are included. As shown in Figure 2, the computing node can be an independently deployed device (single-host), or it can also be a device cluster or distributed system composed of multiple devices (Multi-host), or it can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), big data or artificial intelligence platforms, etc., which are not specifically limited here. Among them, the storage node is the remote storage (Remote Storage) of at least one computing node. The data produced by the computing node will be stored in the storage node through the routing network. The storage node determines whether the requester of the data meets the access rights based on the access control method of the embodiment of the present application, and thus transfers the data to the computing nodes with access rights through the routing network. On the other hand, when accessing the data sent by the storage node, the computing node implements the access control method provided by the embodiment of the present application to achieve access control of the data in the computing node.

[0084] Next, the access control method in the embodiment of the present application is introduced. Please refer to Figure 3, which is a flow chart of the access control method in the embodiment of the present application. The access control method in the embodiment of the present application takes the storage node (including but not limited to the first storage node, the second storage node and the third storage node) and the computing node (including but not limited to the first computing node and the second computing node) as the execution subject of the interaction diagram as an example to illustrate the method, but the present application does not limit the execution subject of the interaction diagram. For example, the storage node in Figure 3 can also be a chip, chip system, or processor that supports the storage node to implement the method, or a logical node, logic module or software that can implement all or part of the storage node function; the computing node in Figure 3 can also be a chip, chip system, or processor that supports the computing node to implement the method, or a logical node, logic module or software that can implement all or part of the computing node function. As shown in Figure 3, the communication method in the embodiment of the present application includes but is not limited to steps 101 to 105.

[0085] 101. The first computing node sends target data and an access policy corresponding to the target data to the first storage node.

[0086] The first computing node produces target data and configures an access policy corresponding to the target data, which indicates the permissions for accessing the target data. Then, the first computing node passes the target data and the access policy of the target data to the first storage node, which stores these data. In an embodiment of the present application, the access policy of the target data indicates that the target data can only be provided to devices (such as computing nodes or storage nodes) that have permissions to access the target data, and after these devices receive the target data, they should also follow the permissions indicated by the access policy to use the target data.

[0087] In one possible implementation, the first storage node serves as remote storage for the first computing node and the second computing node. The first storage node can store data from each computing node (including the first computing node and the second computing node), and can also provide the data stored by the first storage node to each computing node (including the first computing node and the second computing node). Therefore, after generating target data and an access policy for the target data, the first computing node sends the target data and the access policy for the target data to the first storage node, which then stores the target data, the target data, and the access policy for the target data.

[0088] In one possible implementation, the remote storage (Remote Storage) of the first computing node is the second storage node, and the second storage node is responsible for storing and managing the data produced by the first computing node. After the first computing node produces the target data and the access policy for the target data, it sends the target data and the access policy for the target data to the second storage node, and the second storage node saves the target data and the access policy for the target data. If the remote storage of the second computing node is the first storage node, the second computing node cannot directly access the target data through the second storage node. Therefore, after the first computing node sends the target data and the access policy for the target data to the second storage node, the second storage node sends the target data and the access policy for the target data to the first storage node, and the first storage node saves the received target data and the access policy for the target data. Then, the second computing node can request access to the target data from the first storage node.

[0089] In practical applications, the first computing node often generates multiple copies of data. The first computing node can configure the same access policy for these different data, or it can configure different access policies for these different data. In other words, in the embodiments of the present application, the access policies for different data can be the same or different. This improves the flexibility and management efficiency of the data access control process.

[0090] For ease of understanding, the following is an exemplary description of the process by which the first computing node configures an access policy for target data in an embodiment of the present application. Please refer to Figure 4, which is a schematic diagram of the process by which the first computing node configures an access policy for target data in an embodiment of the present application. As shown in Figure 4, the process by which the first computing node configures an access policy for target data includes, but is not limited to, steps 1011 through 1014.

[0091] 1011. Each computing node (including the first computing node and the second computing node) is registered with the first storage node so that the first storage node can authenticate and authorize each computing node.

[0092] Specifically, taking the first computing node as an example, the first computing node sends a connection request to the first storage node. This connection request includes, but is not limited to, information such as the first computing node's identifier and Internet Protocol (IP) address. After receiving the connection request, the first storage node authenticates and authorizes the first computing node, completing the registration process. The first storage node can then manage and schedule the first computing node's resources (including data and access policies).

[0093] 1012. The first computing node configures an access policy for the target data.

[0094] After the first computing node generates the target data, it configures the access policy corresponding to the target data. The access policy of the target data may include one restriction condition or a combination of multiple restriction conditions, which makes the access control of the data more refined, comprehensive and flexible while achieving the granularity of access control based on data. For example, in actual applications, the computing node and the storage node use the Open Digital Rights Language (ODRL) of the World Wide Web Consortium (W3C) standard as the policy language. Various restriction conditions and the identifiers corresponding to these restriction conditions are stored in the computing node and the first storage node. When configuring the access policy of the target data, the first computing node can indicate the various restriction conditions included in the access policy of the target data by carrying the identifiers corresponding to the restriction conditions in the access policy. After the first storage node receives the access policy, it can determine the restriction conditions corresponding to the identifiers in the access policy based on the identifiers in the access policy.

[0095] 1013. The first computing node sends the target data and the access policy of the target data to the first storage node.

[0096] After generating the target data, the first computing node transmits the target data to the first storage node via the network, and the first storage node stores the data. In addition, the first computing node also sends the access policy of the target data to the first storage node.

[0097] 1014. The first storage node saves the target data and the access policy of the target data.

[0098] After receiving the target data and the access policy corresponding to the target data, the first storage node establishes a binding relationship between the target data and the access policy of the target data and saves the binding relationship so as to query the target data and the access policy of the target data.

[0099] Exemplarily, the first storage node may save the access policy of the target data in the following content format:

[0100] File_Path: storage path of target data;

[0101] File_Name: the file name of the target data;

[0102] P_ID: ID of the restriction condition;

[0103] P_Content: Access policy content.

[0104] 102. The second computing node sends an access request to the first storage node.

[0105] Next, if the second computing node needs to access the target data, it can send an access request to the first storage node. This access request is used to access the target data. Optionally, in actual applications, this access request can include authentication information of the second computing node, including but not limited to an identity identifier, identity token, or IP address, so that the first storage node can authenticate the second computing node based on this identity information.

[0106] 103. The first storage node verifies whether the second computing node has the authority to access the target data based on the access policy of the target data.

[0107] After receiving the access request, the first storage node determines that the second computing node requests access to the target data. As can be seen from the above, the first storage node saves the target data and the access policy of the target data, and the access policy indicates the authority to access the target data. The first storage node then verifies the second computing node based on the access policy of the target data to see whether it has the authority to access the target data as indicated by the access policy. If the second computing node has the authority, step 104 is executed; and for devices that do not have the authority to access the target data (such as the third computing node shown in Figure 3), the first storage node will not send the target data to these devices that do not have the authority. The unnecessary circulation of target data is reduced, thereby reducing the probability of data leakage during the circulation of target data.

[0108] 104. The first storage node sends the target data and the access policy of the target data to the second computing node.

[0109] In the case that the second computing node has the authority to access the target data, the first storage node sends the target data and the access policy of the target data to the second computing node.

[0110] In one possible implementation, an access policy is used to indicate at least one of the number of accesses, access time, and access identity to the target data. Specifically, the access policy includes, but is not limited to, one or a combination of the number of accesses, access time, and access identity, thereby improving flexibility and management efficiency in the data access control process. It should be understood that the aforementioned "number of accesses, access time, and access identity" is merely an exemplary description of a possible access policy and does not constitute a substantive limitation on the content of the access policy. In actual applications, in addition to "number of accesses, access time, and access identity," access policies may also be used to indicate other restrictions, which are not limited in this embodiment of the present application.

[0111] In one possible implementation, the access policy of the target data is used to indicate the access time of the target data. By limiting the access time of the data, illegal or unauthorized access attempts can be prevented during the unauthorized time period, reducing the risk of data leakage, tampering or destruction, and improving the security of the data. In this scenario, after the first storage node receives the access request from the second computing node, it determines the timestamp of the access request, and the timestamp of the access request indicates the time when the second computing node requested access to the target data. In actual applications, the timestamp of the access request can be the time when the first storage node receives the access request, or it can be the message timestamp carried in the access request when the second computing node sends the access request, and the specific details are not limited here. If the timestamp of the access request matches the access time of the target data indicated by the access policy, the first storage node determines that the second computing node has the authority to access the target data; if the timestamp of the access request does not match the access time of the target data indicated by the access policy, the first storage node determines that the second computing node does not have the authority to access the target data.

[0112] Exemplarily, the application scenario of the access policy is introduced by taking the access policy as an example of indicating the access time of the target data. Assuming that the access policy indicates that the access time of the target data is from 9:00 to 12:00 every day, it means that the target data is only allowed to be accessed during the access time indicated by the access policy (9:00 to 12:00 every day). If an access request needs to access the target data at a time other than the access time indicated by the access policy (9:00 to 12:00 every day), the first storage node determines that the access request cannot satisfy the permission to access the target data based on the instruction of the access policy, then the access request for the target data will not be permitted by the first storage node.

[0113] 105. The second computing node accesses the target data according to the authority indicated by the access policy.

[0114] After the second computing node receives the target data and the access policy for the target data, the access policy is used to indicate the permissions for the second computing node to access the target data during the second computing node's time. The second computing node can only access the target data according to the permissions indicated by the access policy. This prevents the second computing node (or other recipients of the target data) from performing any access operations on the target data beyond the permissions authorized by the access policy (e.g., transferring the target data to other third-party devices without permission from the access policy), thereby further strengthening the security and confidentiality of the target data.

[0115] In one possible implementation, the target data's access policy indicates the target data's access time. After receiving the target data and the target data's access policy, the second computing node can access the target data only during the access time indicated by the access policy. If the current time exceeds the access time indicated by the access policy, i.e., if the current time does not match the access time indicated by the access policy, the second computing node deletes the target data, thereby preventing subsequent data leakage. Furthermore, deleting unavailable target data helps free up storage space and improve storage resource utilization.

[0116] Exemplarily, the application scenario of the access policy is introduced by taking the access policy used to indicate the access time of the target data as an example. Assume that the access policy indicates that the access time of the target data is January 1, 2024, which means that the target data is only allowed to be accessed within the access time indicated by the access policy (January 1, 2024). After the second computing node receives the target data and the access policy of the target data sent by the first storage node, it can only access the target data during January 1, 2024. When the time exceeds January 1, 2024 (for example, January 2, 2024), the second computing node deletes the target data.

[0117] In the embodiment of the present application, when a second computing node requests access to target data, the first storage node verifies the second computing node's permission to access the target data based on the target data's access policy. After the target data is transferred to the second computing node, the second computing node should also access the target data according to the permission indicated by the access policy. This achieves access control of the target data during transfer and during use, expanding the scope of access control over the target data and improving data security.

[0118] On the other hand, the access policy of the target data flows together with the target data to each data storage node and computing node, so that during the flow of the target data, different devices (data storage nodes and computing nodes) can implement the access control process of the target data according to the same access policy, thereby improving the efficiency of access control.

[0119] On the other hand, as can be seen above, within the security sandbox's isolation mechanism, data within the security sandbox cannot flow into the real system environment outside the security sandbox; users can only access and manipulate data within the security sandbox environment. Compared to the security sandbox's isolation mechanism, the access control method of this application supports access control during data transfer and access control during data use, thereby ensuring data security while also enabling secure data transfer between devices.

[0120] On the other hand, in the data security island mechanism, a trusted server serves as a data security island for storing original data. Users can only access the results obtained after calculation and data analysis of the above original data, that is, users cannot directly access the original data in the data security island. Compared with the data security island mechanism, the access control method of this application supports the flow of original data between various devices, realizing the flow of original data between devices, so that users can access the original data without any modification, preserve the original state of the data, and ensure the integrity and authenticity of the data.

[0121] As can be seen from the above, the target data and the access policy for the target data are stored in the first storage node. The access control method in the embodiment of the present application can support the flow of target data and access policies between different storage nodes. That is, the first storage node can transfer the target data and the access policy for the target data it stores to other storage nodes. In one possible implementation, the first storage node receives a migration instruction for the target data, which instructs the target data to be migrated to a third storage node. The first storage node then sends the target data and the access policy corresponding to the target data to the third storage node, so that the third storage node continues to implement access control to the target data through the access policy, thereby ensuring the security of the flow of target data.

[0122] Specifically, before the first storage node sends the target data and the access policy corresponding to the target data to the third storage node, it should also verify whether the third storage node has the authority to access the target data. If the verification is successful, that is, it is confirmed that the third storage node has the authority to access the target data, the first storage node sends the target data and the access policy corresponding to the target data to the third storage node. Among them, the "access" exemplified in the embodiments of the present application includes but is not limited to operations such as reading, modifying, updating, saving or transaction transfer of target data (for example, the third storage node transfers the target data to the fourth storage node).

[0123] In order to better implement the access control method provided in the embodiment of the present application, optionally, a data access control device is deployed in each computing node (including the second computing node). The data access control device is used to receive, save and manage target data and access policies. Therefore, the second computing node receives the target data and the access policy of the target data through the data access control device, and the data access control device of the second computing node saves the target data and the access policy of the target data. Then, the target data and the access policy of the target data do not need to be saved in the disk or memory of the second computing node, thereby reducing the risk of data leakage. Then, through the data access control device, the second computing node accesses the target data according to the authority indicated by the access policy.

[0124] In one possible implementation, the data access control device can be a hardware card inserted into the second computing node, such as a smart network card or a data processing unit (DPU), or it can be a software module installed and run by the second computing node, or it can be a gateway or independent server connected to the second computing node.

[0125] In one possible implementation, a data control client is deployed in the second computing node. This data control client is used in conjunction with the data access control device and provides a communication interface for users to interact with the data access control device. Users access target data stored in the data access control device through the data control client deployed in the second computing node. The data access control device then provides the target data to the data control client in the second computing node according to the permissions indicated by the access policy. This ensures that during the user's access to the target data, the target data will never be transferred to storage space outside the data access control device, thereby preventing the target data from being stolen and reducing the risk of data leakage.

[0126] Optionally, the data control client needs to undergo identity authentication by the data access control device first. Only after the data access control device confirms that the identity of the data control client is legitimate can the data control client interact with the data access control device.

[0127] Optionally, before providing the target data to the data control client in the second computing node, the data access control can first encrypt the target data, and then provide the encrypted target data to the data control client, so that the user is always invisible to the original target data, thereby ensuring the confidentiality of the target data.

[0128] For ease of understanding, the access control method in the embodiment of the present application is described below with reference to a scenario example. Please refer to Figure 5, which is a schematic diagram of a possible scenario of the access control process in the embodiment of the present application. In the scenario illustrated in Figure 5, the access control process includes steps 201 to 206.

[0129] 201. The first computing node sends the target data and the access policy of the target data to the first storage node.

[0130] In this scenario, both the first and second compute nodes are registered with the first storage node and establish a communication connection with the first storage node. After the first compute node generates target data, it sends the target data and its access policy to the first storage node. When the second compute node needs to access the target data, it sends an access request to the first storage node.

[0131] 202. The data access control device of the second computing node sends an access request for target data to the first storage node.

[0132] The user issues an access operation to the target data from the data control client in the second computing node, which triggers the data access control device in the second computing node to generate an access request to the target data. The data access control device then sends the access request to the first storage node.

[0133] 203. The first storage node verifies whether the second computing node has the authority to access the target data based on the access policy of the target data.

[0134] The first storage node verifies, based on the access policy for the target data, whether the second computing node has the permission to access the target data as indicated by the access policy. If the second computing node has the permission, step 204 is executed. If the second computing node does not have the permission to access the target data as indicated by the access policy, the first storage node does not send the target data to the second computing node.

[0135] Step 203 is similar to the aforementioned step 103. Please refer to the description of the aforementioned step 103 for details, and will not be repeated here.

[0136] 204. The first storage node sends the target data and the access policy of the target data to the second computing node.

[0137] When the second computing node has the authority to access the target data, the first storage node sends the target data and the access policy of the target data to the data access control device of the second computing node, and the data access control device saves the target data and the access policy of the target data.

[0138] 205. The user obtains target data in the data access control device through the data control client.

[0139] As can be seen from the above, the data control client provides a communication interface for users to interact with the data access control device. The user reads the target data from the data access control device through the data control client to access the target data.

[0140] 206. The data access control device continuously detects the usage status of the target data.

[0141] The data access control device continuously detects the usage status of the target data. Thus, when the access policy indicates that the current second computing node has lost access rights to the target data, the data access control device closes the communication interface with the data control client.

[0142] Please refer to Figure 6, which is a schematic diagram of another possible scenario of the access control process in an embodiment of the present application. In the scenario illustrated in Figure 6, the access control process includes steps 301 to 306.

[0143] 301. The first computing node and the second computing node share data across storage nodes.

[0144] As shown in Figure 6, the first compute node is registered with the second storage node, and the second compute node is registered with the first storage node. In other words, the second storage node serves as the remote storage for the first compute node, and the first storage node serves as the remote storage for the second compute node. After the first compute node generates the target data and the access policy for the target data, it sends the target data and the access policy to the second storage node. Next, in this scenario, the first compute node needs to share the target data with the second compute node.

[0145] 302. User A sends a migration instruction to the second storage node through the first computing node. The migration instruction instructs the second storage node to send target data to the first storage node.

[0146] 303. The second storage node verifies whether the first storage node has the right to access the target data based on the access policy of the target data. If the first storage node has the right to access the target data, the second storage node sends the target data and the access policy of the target data to the first storage node.

[0147] 304. The first storage node sends the target data and the access policy of the target data to the second computing node.

[0148] After receiving the target data and access policy sent by the second storage node, the first storage node verifies, based on the target data access policy, whether the second computing node has the permission to access the target data as indicated by the access policy. If the second computing node has the permission, the first storage node sends the target data and the target data access policy to the second computing node.

[0149] 305. User B obtains target data from the data access control device through the data control client.

[0150] 306. The data access control device continuously detects the usage status of the target data.

[0151] The process from step 305 to step 306 is similar to the process from step 205 to step 206 mentioned above. Please refer to the description of step 205 to step 206 mentioned above for details, and will not be repeated here.

[0152] Accordingly, the embodiment of the present application also provides related devices for implementing the above-mentioned scheme. Specifically, please refer to Figure 7, which is a structural diagram of the first storage node provided in the embodiment of the present application. The first storage node in Figure 7 can be a chip, chip system, or processor used to support the first storage node to implement the method; or, the first storage node can also be a logical node, logical module or software used to implement all or part of the functions of the first storage node. As shown in Figure 7, the first storage node includes:

[0153] The transceiver unit 401 is configured to receive target data and an access policy corresponding to the target data from the first computing node, where the access policy indicates the permission to access the target data;

[0154] The transceiver unit 401 is further configured to receive an access request from a second computing node, the access request being used to access target data;

[0155] Processing unit 402, configured to verify whether the second computing node has permission to access the target data according to the access policy;

[0156] When the second computing node has the authority to access the target data, the transceiver unit 401 is further configured to send the target data and the access policy to the second computing node, so that the second computing node accesses the target data according to the access policy.

[0157] It should be noted that the information interaction, execution process, etc. between the modules / units in the first storage node are based on the same concept as the method embodiment corresponding to Figure 3 in this application. For specific contents, please refer to the description in the method embodiment shown above in this application, and will not be repeated here.

[0158] Please refer to Figure 8, which is a schematic diagram of the structure of a second computing node provided in an embodiment of the present application. The second computing node in Figure 8 can be a chip, chip system, or processor used to support the second computing node to implement the method; or the second computing node can also be a logical node, logical module, or software used to implement all or part of the functions of the second computing node. As shown in Figure 8, the second computing node includes:

[0159] The transceiver unit 501 is configured to send an access request to the first storage node, where the access request is used to access target data;

[0160] The transceiver unit 501 is further configured to receive target data and an access policy for the target data from the first storage node;

[0161] The processing unit 502 is configured to access target data according to the permissions indicated by the access policy.

[0162] It should be noted that the information interaction, execution process, etc. between the modules / units in the second computing node are based on the same concept as the method embodiment corresponding to Figure 3 in this application. For specific contents, please refer to the description in the method embodiment shown above in this application, and will not be repeated here.

[0163] Please refer to Figure 9, which is a schematic diagram of the logical structure of a communication device 60 provided in an embodiment of the present application. The communication device 60 in Figure 9 can be deployed with the first storage node described in the embodiment corresponding to Figure 7 to implement the function implemented by the first storage node in the embodiment corresponding to Figure 3, or the communication device 60 can be deployed with the second computing node described in the embodiment corresponding to Figure 8 to implement the function implemented by the second computing node in the embodiment corresponding to Figure 4. The communication device 60 includes: a memory 601, a processor 602, a communication interface 603 and a bus 604. Among them, the memory 601, the processor 602, and the communication interface 603 realize communication connection with each other through the bus 604.

[0164] The memory 601 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 601 may store programs. When the program stored in the memory 601 is executed by the processor 602, the processor 602 and the communication interface 603 are used to perform steps 101-105 of the above-described access control method embodiment.

[0165] The processor 602 can be a central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), a graphics processing unit (GPU), a digital signal processor (DSP), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or any combination thereof, to execute relevant programs to implement one or more steps 101-105 of the access control method embodiment of the present application. The steps of the data processing method disclosed in the embodiment of the present application can be executed by a compiler and an executor, wherein the compiler and executor can be executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory 601, and the processor 602 reads the information in the memory 601 and, in combination with its hardware, executes one or more steps 101-105 of the access control method embodiment of the present application.

[0166] The communication interface 603 uses a transceiver device such as, but not limited to, a transceiver to implement communication between the communication device 60 and other devices or a communication network.

[0167] Bus 604 provides a pathway for transmitting information between the various components of computer device 60 (e.g., memory 601, processor 602, and communication interface 603). Bus 604 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, control buses, and the like. For ease of illustration, FIG9 shows a single thick line, but this does not imply that there is only one bus or only one type of bus.

[0168] It should be noted that the information interaction, execution process, etc. between the modules / units in the communication device are based on the same concept as the method embodiment corresponding to Figure 3 in this application. For specific contents, please refer to the description in the method embodiment shown above in this application, and will not be repeated here.

[0169] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be executed on a computing device or stored in any available medium. When the computer program product is executed on at least one computing device, the computer program product causes the at least one computing device to execute the method described in the embodiment shown in FIG. 3 .

[0170] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-mentioned method for executing the embodiment described in Figure 3.

[0171] The communication device provided in the embodiment of the present application can specifically be a chip, which includes: a processing unit and a communication unit. The processing unit can be, for example, a processor, and the communication unit can be, for example, an input / output interface, a pin, or a circuit. The processing unit can execute computer-executable instructions stored in the storage unit to enable the chip to perform the method described in the embodiment shown in Figure 3 above. Optionally, the storage unit is a storage unit within the chip, such as a register, a cache, etc. The storage unit can also be a storage unit located outside the chip within the wireless access device, such as a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), etc.

[0172] It should be noted that the device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the drawings of the device embodiments provided in the embodiments of the present application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.

[0173] Through the description of the above embodiments, it is clear to those skilled in the art that the embodiments of the present application can be implemented by means of software plus necessary general hardware, and of course can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. In general, all functions performed by computer programs can be easily implemented with corresponding hardware, and the specific hardware structures used to implement the same function can also be various, such as analog circuits, digital circuits, or application-specific circuits, etc. However, for the embodiments of the present application, software program implementation is a better implementation method in most cases. Based on such an understanding, the technical solutions of the embodiments of the present application are essentially or partly contributed to the prior art can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer's floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., including a number of instructions to enable a computer device (which can be a personal computer, training equipment, or network equipment, etc.) to execute the methods described in each embodiment of the present application.

[0174] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.

[0175] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, a computer, a training device or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website, a computer, a training device or a data center. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a training device, a data center, etc. that includes one or more available media integrations. The available medium can be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

Claims

1. A method of access control, characterized in that: include: The first storage node receives target data and an access policy corresponding to the target data from the first computing node, where the access policy is used to indicate permission to access the target data; The first storage node receives an access request from the second computing node, where the access request is used to access the target data; Verifying, by the first storage node, whether the second computing node has permission to access the target data according to the access policy; In the case that the second computing node has the authority to access the target data, the first storage node sends the target data and the access policy to the second computing node, so that the second computing node accesses the target data according to the access policy.

2. The method according to claim 1, characterized in that The first computing node is a production node of the target data.

3. The method according to claim 1 or 2, characterized in that The first storage node receives target data and an access policy corresponding to the target data from the first computing node, and the method includes: The first storage node receives target data and an access policy corresponding to the target data sent by the second storage node, where the target data and the access policy are sent by the first computing node to the second storage node.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: The second computing node accesses the target data according to the authority indicated by the access policy.

5. The method according to claim 4, characterized in that The second computing node accesses the target data according to the permission indicated by the access policy, including: Through the data access control device, the second computing node accesses the target data according to the authority indicated by the access policy.

6. The method according to claim 5, characterized in that The data access control device is a hardware card located in the second computing node.

7. The method according to claim 5 or 6, characterized in that The second computing node accesses the target data according to the authority indicated by the access policy through the data access control device, including: The data access control device receives the target data and the access policy sent by the first storage node; The data access control device provides the target data to the data control client in the second computing node according to the authority indicated by the access policy. The data control client is a client run by the second node for accessing the target data.

8. The method according to claim 7, characterized in that The data access control device provides the target data to the data control client in the second computing node, including: The data access control device encrypts the target data and provides the encrypted target data to the data control client.

9. The method according to claim 7, characterized in that The data control client is a client that has undergone identity authentication by the data access control device.

10. The method according to claim 7, 8 or 9, characterized in that The target data is stored in the data access control device.

11. The method according to any one of claims 1 to 10, characterized in that The access policy is used to indicate at least one of the number of accesses to the target data, the access time, and the access identity.

12. The method according to claim 11, characterized in that The access policy is used to indicate the access time of the target data.

13. The method according to claim 12, characterized in that Verifying, by the first storage node, whether the second computing node has permission to access the target data according to the access policy, includes: The first storage node determines a timestamp of the access request; If the timestamp matches the access time indicated by the access policy, the first storage node determines that the second computing node has the authority to access the target data.

14. The method according to claim 12, characterized in that The method further comprises: If the current time does not match the access time indicated by the access policy, the second computing node deletes the target data.

15. The method according to any one of claims 1 to 14, characterized in that The method further comprises: The first storage node receives a migration instruction for the target data, the migration instruction instructing to migrate the target data to a third storage node; The first storage node sends the target data and an access policy corresponding to the target data to the third storage node.

16. The method according to claim 15, characterized in that The first storage node sending the target data and the access policy corresponding to the target data to the third storage node includes: The first storage node verifies, according to the access policy, whether the third storage node has permission to access the target data; In a case where the second computing node has permission to access the target data, the first storage node sends the target data and an access policy corresponding to the target data to the third storage node.

17. A first storage node, characterized in that: include: a transceiver unit, configured to receive target data and an access policy corresponding to the target data from the first computing node, wherein the access policy is used to indicate permission to access the target data; The transceiver unit is further configured to receive an access request from a second computing node, wherein the access request is used to access the target data; a processing unit, configured to verify, according to the access policy, whether the second computing node has permission to access the target data; In the case where the second computing node has the authority to access the target data, the transceiver unit is further configured to send the target data and the access policy to the second computing node, so that the second computing node accesses the target data according to the access policy.

18. A communication device, characterized in that: comprising a processor coupled to a memory, The memory is used to store instructions; The processor is configured to execute instructions in the memory, so that the communication device performs the method according to any one of claims 1 to 16.

19. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 16 is implemented.

20. A computer program product, characterized in that The computer program product stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the method according to any one of claims 1 to 16 is implemented.

21. A chip, characterized in that: The chip includes a processor coupled to a memory. The memory is used to store instructions; The processor is configured to execute instructions in the memory, so that the chip executes the method according to any one of claims 1 to 16.

Citation Information

Patent Citations

  • Regional medical treatment information system and access authority control method

    CN102790761A

  • General access control method and device

    CN104917761A

  • Security access control framework under distributed cloud environment and access method thereof

    CN105049409A

  • Data sharing method and system, blockchain system, and computing equipment

    CN106992990A

  • Monitoring data access control method, device and equipment and storage medium

    CN111737752A