Data flow control apparatus and method, storage medium, and computer program product
By introducing policy control network elements into the DSSN architecture, data usage policies are determined and deployed based on data demand information, which solves the problems of low computational efficiency and insufficient security in DSSN technology and realizes reliable and controllable data flow.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-03-26
AI Technical Summary
Existing DSSN technology suffers from low computational efficiency, high cost, and insufficient security in data transactions, making it difficult to promote on a large scale.
In the DSSN architecture, a policy control network element is introduced to determine the data usage policy based on data demand information, and the usage policy is deployed on the data circulation network element to restrict data usage and improve security.
By restricting data usage strategies, the security of data circulation is improved, the problems of low computing efficiency and high cost are solved, and a trustworthy and controllable data circulation is achieved.
Smart Images

Figure CN2025122309_26032026_PF_FP_ABST
Abstract
Description
Data flow control apparatus, method, storage medium and computer program product
[0001] Cross-reference to related applications
[0002] The present application is based on and claims priority to Chinese patent application No. 202411322321.3, filed on September 20, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0003] The present application relates to the technical field of data security, and in particular to a data flow control apparatus, method, storage medium and computer program product. BACKGROUND
[0004] In related technologies, when data transactions are performed, Data Switching Service Networks (DSSN) technology is usually used. However, the DSSN technology mainly implements data transactions, delivery and other services based on privacy computing. However, the data flow mode based on privacy computing has low computing efficiency and high cost. If a data out-of-domain flow mode is used, the security of the data is low. SUMMARY
[0005] Therefore, the present application aims to provide a data flow control apparatus, method, storage medium and computer program product.
[0006] The technical solution of the present application is implemented as follows:
[0007] In a first aspect, the present application provides a data flow control apparatus, which comprises a policy control network element.
[0008] The policy control network element is configured to determine a data usage policy corresponding to first data according to data requirement information of the first data, and deploy the data usage policy on a data flow network element corresponding to the first data, so that the data flow network element uses the first data based on the data usage policy. The data requirement information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, and commodity data requirement information of the data demander.
[0009] In a second aspect, the present application provides a data flow control method applied to a data flow control apparatus, which comprises a policy control network element. The method comprises the following steps.
[0010] The policy control network element determines a data usage policy corresponding to the first data according to data demand information of the first data, wherein the data demand information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, commodity data demand information of the data demander;
[0011] The data usage policy is deployed on a data circulation network element corresponding to the first data, so that the data circulation network element uses the first data based on the data usage policy.
[0012] In a third aspect, the present application provides a storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the data circulation control method.
[0013] In a fourth aspect, the present application provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the data circulation control method.
[0014] The present application provides a data circulation control device, method, storage medium and computer program product. The device comprises a policy control network element. The policy control network element is configured to determine a data usage policy corresponding to the first data according to data demand information of the first data, and deploy the data usage policy on a data circulation network element corresponding to the first data, so that the data circulation network element uses the first data based on the data usage policy. The data demand information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, commodity data demand information of the data demander. According to the above embodiment, the policy control network element first determines the data usage policy corresponding to the data demand information according to the data demand information, and deploys the corresponding data usage policy on the data circulation network element during the first data flow process. After the deployment is completed, the use of the first data will be based on the corresponding data usage policy. Since the use of the first data is limited by the data usage policy, when the data circulation network element uses the first data based on the data usage policy, the first data is protected by the use of the data usage policy, thereby improving the security of the first data. BRIEF DESCRIPTION OF DRAWINGS
[0015] FIG. 1 is a technical architecture diagram of a DSSN data circulation control;
[0016] FIG. 2 is a structural schematic diagram of a data circulation control device according to an embodiment of the present application;
[0017] FIG. 3 is a structural schematic diagram of a data circulation control device according to an embodiment of the present application;
[0018] FIG. 4 is a component schematic diagram of a policy control network element according to an embodiment of the present application;
[0019] FIG. 5 is an example diagram of a point-to-point data flow mode provided by an embodiment of the present application;
[0020] FIG. 6 is an example diagram of a data flow mode through a third party provided by an embodiment of the present application;
[0021] FIG. 7 is a flow diagram of a data flow control method provided by an embodiment of the present application;
[0022] FIG. 8 is a flow diagram of a data flow control method provided by an embodiment of the present application;
[0023] FIG. 9 is an example diagram of a data flow control method provided by an embodiment of the present application. DETAILED DESCRIPTION
[0024] In order to be able to more fully understand the features and technical content of the embodiments of the present application, the technical solutions of the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. The accompanying drawings are only used for reference and are not intended to limit the embodiments of the present application.
[0025] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meanings as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0026] In the following description, "some embodiments" are described, which describe a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. It should also be noted that the terms "first / second / third" used in the embodiments of the present application are only used to distinguish similar objects, and do not represent a specific order of the objects. It can be understood that "first / second / third" can be interchanged in a specific order or sequence as allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0027] In order to further improve transaction flow efficiency, create a safe and reliable flow environment, enrich data security products and cultivate data security services, China Mobile innovatively proposes a DSSN solution for the next generation data flow market, which connects multiple data providers / needs / transaction providers and other subjects by creating a cross-domain, cross-industry, and cross-subject "data logistics network", and provides "data logistics" services for data products.
[0028] As shown in FIG. 1, a technical architecture diagram of DSSN data flow control is shown, which mainly includes the following parts in FIG. 1:
[0029] A data sharing platform (DSP) provides services such as data access management, data trusted delivery, private network scheduling, reliable transmission, security control, and open supervision.
[0030] A DSSN private network is a data sharing virtual private network based on network facilities in the related art, which guarantees the security and quality of service of data transmission.
[0031] A data service node (DSN) is deployed at a data provider and implements core functions such as data source connection, DSSN private network access, and data security calculation. Different forms of products can be provided according to customer needs.
[0032] A data requirement node (DRN) is deployed at a data demander and implements core functions such as business system connection, DSSN private network access, visual development, and data security calculation. Different forms of products can be provided according to customer needs.
[0033] The implementation of the above DSSN technical solution is mainly based on privacy calculation to realize data transaction and delivery services. However, due to the low calculation efficiency and high cost of data flow based on privacy calculation, it is difficult to popularize and promote in a large range, which restricts the improvement of the activity of the data transaction market.
[0034] To solve the above problems, the embodiment of the present application proposes a method of adding support for non-privacy calculation data flow on the basis of the original privacy calculation technology architecture of DSSN. Since privacy calculation is based on data domain design for core data security, in the non-privacy calculation mode, how to provide a trusted and controllable data domain flow transaction and delivery scheme is of great significance to the security of data transaction flow.
[0035] The technical solution of the embodiment of the present application is as follows:
[0036] The embodiment of the present application provides a data flow control device 1 as shown in FIG. 2, which comprises a policy control network element 10. The policy control network element 10 is configured to determine a data use policy corresponding to first data according to data requirement information of the first data, and deploy the data use policy on a data flow network element corresponding to the first data, so that the data flow network element uses the first data based on the data use policy. The data requirement information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, and commodity data requirement information of the data demander.
[0037] In the embodiments of the present application, the data flow network element can include the first network element and the second network element, or the data flow network element can include the second network element and the third network element.
[0038] It should be noted that the specific network element included in the data flow network element needs to be determined according to the data flow mode.
[0039] In the embodiments of the present application, the first network element can be a data provider, the second network element can be a data demander, and the third network element can be a data processing lake network element (which can be abbreviated as DCP).
[0040] In the embodiments of the present application, the first data can be data encapsulated for certain commodity related data, such as data of a certain commodity encapsulated and displayed on a shopping website. The first data can also be other data, which is not specifically limited in the embodiments of the present application.
[0041] In the embodiments of the present application, the data demand information can be commodity demand information (also referred to as commodity data demand information), such as what commodity needs to be purchased, or can be a cooperation agreement reached between a data provider and a data demander specified in a work order. The work order can be understood as a commodity order, the data provider can also be a supplier node, and the data demander can also be a demander node, or can be other data demand information, which is not specifically limited in the embodiments of the present application.
[0042] In the embodiments of the present application, the policy control network element determines the data usage policy corresponding to the first data according to the data demand information of the first data, which can be implemented through the following process:
[0043] 1. The data demander / data provider logs in the data flow system through the authentication and authorization network element.
[0044] 2. The data demander browses a commodity data directory through a data exchange platform (DEP) and selects commodity data from the commodity data directory. The commodity data directory in the DEP is data set published by the data provider through the DEP. The DEP notifies the data provider of the commodity data demand information of the data demander.
[0045] 3. The data provider and the data demander negotiate the data usage policy of the commodity data online through the policy control network element, wherein the data usage policy can include usage conditions, usage manners, prices, and the like.
[0046] For example, the usage conditions can be under which connection, under which application, under which security level, and the like; the usage manners can be usage time, usage times, and the like.
[0047] In the embodiment of the present application, after the policy control network element determines the data usage policy of the first data according to the data requirement information in the negotiation process between the data demand side and the data provision side, the data usage policy is configured and deployed in the data provision side and the data demand side, or in the data demand side and the DCP network element. In this way, the data demand side can use the first data provided by the data provision side according to the data usage policy.
[0048] In the embodiment of the present application, to complete the use of the first data by the data flow network element based on the data usage policy, after the policy control network element configures and deploys the determined data usage policy, the policy control network element needs to notify the DEP of the determined data usage policy, which includes price information and the like, and the DEP saves the determined data usage policy and notifies the DSP.
[0049] It should be noted that the data usage policy determined after the negotiation between the data provision side and the data demand side is the same data usage policy adopted by the data provision side and the data demand side.
[0050] In an embodiment of the present application, the data flow control device further comprises a fourth network element, which is configured to schedule the first network element and the second network element to perform authentication connection related configuration, or schedule the first network element, the second network element and the third network element to perform authentication connection related configuration.
[0051] In the embodiment of the present application, the fourth network element is the DSP.
[0052] In the embodiment of the present application, further, the DSP performs scheduling configuration of the related data flow network element according to the data usage policy notified by the DEP, and after the scheduling configuration is completed, the data demand side uses the first data provided by the data provision side.
[0053] In the embodiment of the present application, the data usage policy can further include a data flow mode, and the data flow mode includes a point-to-point flow mode and a data flow mode through a third party.
[0054] In the embodiment of the present application, if the data flow mode is the point-to-point flow mode, when the DSP performs scheduling configuration of the data flow network element according to the data usage policy, two-party authentication is required, and the DSP will configure authentication protocols, connection information and the like of the two network elements (such as the data demand side and the data provision side).
[0055] In the embodiment of the present application, if the data flow mode is the data flow mode through a third party, when the DSP performs scheduling configuration of the data flow network element according to the data usage policy, three-party mutual authentication is required, and the DSP will configure authentication protocols, connection information, authorization information and the like of the DCP network element, the data demand side and the data provision side.
[0056] It should be noted that the authentication protocol, connection information, etc. can be a connection such as Transport Layer Security (TLS).
[0057] In an embodiment of the present application, if the data flow mode is a point-to-point data flow mode, the data flow network element includes a first network element and a second network element; the second network element is configured to receive the data usage policy sent by the first network element, and based on the data usage policy, use the first data in the first network element when the data usage policy is confirmed.
[0058] In an embodiment of the present application, the first network element can be a data provider, and the second network element can be a data demander.
[0059] In an embodiment of the present application, the first data is stored in the data provider.
[0060] In an embodiment of the present application, the data provider notifies the configuration information of the data usage policy that has been configured by the policy control network element, i.e. the data usage policy has taken effect in the data provider, and then sends the effective data usage policy to the data demander through the policy control network element, and notifies the data demander to confirm the effective data usage policy.
[0061] In an embodiment of the present application, the data demander receives the data usage policy sent by the first network element through the policy control network element, and confirms the data usage policy. The specific confirmation method can be to compare whether the data usage policy sent by the data provider and the data usage policy configured by the data provider are the same.
[0062] In an embodiment of the present application, after the data demander confirms the data usage policy sent by the data provider, the data demander and the data provider perform point-to-point data transmission and use according to the determined data usage policy, i.e. the data demander can use the data in the data provider according to the determined data usage policy.
[0063] It should be noted that the data in the embodiments of the present application is not limited to files, structured data joint calculation, etc. Specifically, it can be selected according to actual conditions, and is not specifically limited in the embodiments of the present application.
[0064] In an embodiment of the present application, after the data demander confirms the data usage policy sent by the data provider, the confirmed data usage policy will be monitored through the deployment of the data provider and the data demander for the use of the data in the data provider (such as through a control type client, operating system interception, hardware, etc. security method).
[0065] In the embodiment of the present application, before the data demander uses the first data of the data provider, the data provider performs the initialization processing of desensitization, watermarking, anonymization, etc. on the first data, and the first data can be used out of the domain with the corresponding data use policy.
[0066] In an embodiment of the present application, the data flow network element includes a first network element and a second network element; and the policy control network element is further configured to perform the data processing corresponding to the use restriction information on the first data based on the use restriction information determined by the first network element and the second network element in advance for the first data.
[0067] In the embodiment of the present application, the data processing can include time limit restriction, time length restriction, read-after-burn, risk chain breaking prevention, etc.
[0068] In the embodiment of the present application, the use restriction information can be determined by the first network element and the second network element in the data use policy negotiation process, that is, the use restriction information can be determined by negotiation.
[0069] In the embodiment of the present application, the policy control network element performs the corresponding limitation on the first data according to the negotiation result, specifically, the read-after-burn, risk chain breaking prevention, etc. can be performed according to the use restriction information negotiated in advance after the data use policy is executed.
[0070] In an embodiment of the present application, if the data flow mode is the data flow mode through a third party, the data flow network element includes a second network element and a third network element; at this time, the data flow control device further includes: a first network element storing the first data; wherein the first network element is configured to send the first data and the data use policy to the third network element; the third network element is configured to receive the data use policy and the first data sent by the first network element; and control the second network element to use the first data in the third network element based on the data use policy.
[0071] In the embodiment of the present application, the second network element is a data demander.
[0072] In the embodiment of the present application, the third network element is a DCP.
[0073] In the embodiment of the present application, before the data provider sends the first data and the data use policy to the DCP, the following operations can be performed first:
[0074] The data provider selects the DCP allocated by the DSP to perform the corresponding processing (such as the initialization operation processing of desensitization, watermarking, anonymization, etc.) on the first data.
[0075] In the embodiment of the present application, after the first data is processed by the initialization operation, the processed first data is transmitted to the assigned DCP, so that the first data can be used out of the domain according to the data usage policy.
[0076] In the embodiment of the present application, after the data provider transmits the processed first data and the data usage policy to the DCP, the DCP receives the processed first data and the data usage policy transmitted by the data provider, and further selects a container / software / Trusted Execution Environment (TEE) with a corresponding security level according to the data usage policy to process and store (such as in memory / file / hardware) the data usage policy and the first data.
[0077] In the embodiment of the present application, the DCP informs the data requester of the use of the first data and informs the data requester to confirm the corresponding data usage policy and usage restriction information.
[0078] In the embodiment of the present application, after the data requester confirms the data usage policy and the usage restriction information, the data requester uses the data (such as file browsing and data joint calculation) through the DCP, and the DCP controls and safeguards the first data based on the data usage policy.
[0079] In an embodiment of the present application, the policy control network element is further configured to monitor the execution result of the data usage policy executed by the third network element, and perform a disconnection process on the first network element and the third network element in the case of an abnormal execution result.
[0080] In the embodiment of the present application, the policy control network element monitors the use of the data usage policy by the DCP, and if an abnormal execution result (or a risk) is found in the process of monitoring the data usage policy by the DCP, the policy control network element performs a disconnection process on the data requester and the DCP, and the like.
[0081] In an embodiment of the present application, the policy control network element is further configured to receive the first execution log transmitted by the first network element and the second execution log transmitted by the second network element in the case of completion of the use of the first data, and determine whether the related execution behavior of the data usage policy is abnormal based on the first execution log and the second execution log, and report the abnormal behavior in the case of an abnormal related execution behavior.
[0082] In the embodiments of the present application, after the data flow is completed, the policy control network element receives the first execution log and the second execution log of the data usage policy uploaded by the data demander and the data provider respectively, and the first execution log and the second execution log include, but are not limited to, the software and hardware environment configuration before and after the first data usage, the authentication certificate authentication information, the data usage policy execution flow flag, and the like.
[0083] In the embodiments of the present application, the policy control network element evaluates whether the execution of the data usage policy conforms to the pre-configuration according to the first execution log and the second execution log. If the alarm information appears, it indicates that the pre-configuration is not met.
[0084] In the embodiments of the present application, the policy control network element further generates an evaluation report according to the evaluation result to inform the DEP data demander and the data provider of the specific execution of the data usage policy.
[0085] In an embodiment of the present application, if the data demander and the data provider negotiate to download the data flow software through the application store (the full name in English can be expressed as Application Store, or APP Store for short) to control the data usage policy, the data demander / data provider also needs to download the related application (APP for short in English) according to the negotiation to configure and use the tool, such as data binning and encryption, and the data provider needs to download the related authorized APP to perform the corresponding data processing.
[0086] It should be noted that this process is performed only when the APP is specified for data processing in the negotiation process between the data demander and the data provider.
[0087] It can be understood that the data flow control device provided in the embodiments of the present application first determines the data usage policy corresponding to the data demand information according to the data demand information through the policy control network element, and deploys the corresponding data usage policy on the data flow network element in the first data flow process. After the deployment is completed, the first data usage is performed according to the corresponding data usage policy. Since the first data usage is limited by the data usage policy, when the data flow network element uses the first data based on the data usage policy, the first data is protected by the usage limitation of the data usage policy, and the security of the first data is improved.
[0088] Based on the above embodiment, the application further provides a data flow control device, which shows the hierarchical deployment planning of the included network elements, that is, the DSSN technical architecture in the related art is updated, the idea of hierarchical design is adopted, and the DSSN business layer, the DSSN core network and the DSSN trusted node are constructed, so that the problems of trusted and safe data out-domain control in the data transaction process can be solved.
[0089] In the embodiment of the application, the data flow control device is shown in FIG. 3, and the network elements included in each layer and the functions of each network element are introduced as follows.
[0090] DSSN business layer: including data transaction, application store, development environment, vocabulary center and the like.
[0091] Among them, data transaction: including data directory, contract negotiation, contract and order, strategy coordination and the like.
[0092] Application store: an important network element for constructing the DSSN ecological system, responsible for introducing data application software, data processing software and data control software of internal and external technology and service providers.
[0093] Development environment: providing open tools and components for DSSN data development for developers / software / application system providers.
[0094] Vocabulary center: a data standard and formatting unit for each field, used for unifying the data exchange standard format in the DSSN ecology.
[0095] DSSN core network layer: based on the DSP network element in the related art, the core control network element authentication and authorization network element, the policy control network element, the charging and settlement, the certificate authority (CA) center and the DCP (data processing lake) and the like are newly added.
[0096] Among them, authentication and authorization: responsible for authenticating and authorizing the network element entity, user entity and data entering the DSSN environment, and interacting with the CA center to perform identity verification.
[0097] Policy control network element: including the functions of policy negotiation before / after / during data use, policy configuration, policy deployment, policy execution, monitoring of use policy and abnormal handling and the like.
[0098] Charging and settlement: performing charging statistics and settlement between cooperation parties according to data contract, order and use condition.
[0099] CA center: a CA system certified by the state / industry, responsible for issuing relevant certificates of network element entity, user entity and data.
[0100] DSP: On the basis of the DSP in the related art, newly added are functions of scheduling, control, etc. of related network elements, engines, etc. for data use control strategies.
[0101] DCP: Responsible for cloud-based data control processing, and performs centralized data and policy use control according to data interaction requirements.
[0102] DSSN trusted node: On the basis of the DSN / DRN node in the related art, i.e. the basis of the privacy computing engine, newly added are functions of scheduling, adaptation, data directory view guidance, etc. of non-privacy computing engines, including non-structured data (such as file processing), structured data (such as joint calculation, query, etc.).
[0103] Among them, the privacy computing engine includes an FL engine, i.e. a federated learning engine, and FL can be expressed in English as Federated Learning.
[0104] MPC engine: i.e. a multi-party secure computing engine, and MPC can be expressed in English as Secure Multi-Party Computation.
[0105] PSI engine: private set intersection engine, and PSI can be expressed in English as Private Set Intersection.
[0106] PIR engine: private information retrieval engine, also known as private information retrieval engine, and PIR can be expressed in English as Private Information Retrieval.
[0107] Based on the above embodiments, in order to implement the technical solutions in the embodiments of the present application, the architecture of the policy control network element shown in FIG. 3 at least needs to design the following six functional modules, and the six functional modules are specifically shown in FIG. 4, wherein, mainly include data policy negotiation module, data policy execution module, data policy management module, data policy monitoring module, data policy deployment module and data policy use evaluation module, the six functional modules will be deployed related functional modules on the platform side or node side, specific according to actual situation to choose. The specific functions of each functional module will be introduced as follows:
[0108] Data policy negotiation module: an entry point for data use strategy, used for creating, managing policy resources, scope, permissions and policy content; this module provides a user visual editing interface / policy template (such as allowing data users to specify operations on data, such as display, print, calculation, etc., or prohibiting the specified operations, etc.); supports functions of user policy contract signing, multi-round negotiation, revision, confirmation, etc.
[0109] Data policy management module: manage related usage restrictions, policy usage period, etc., while instantiating usage restriction policies, evaluating data usage policies, performing related conflict detection and resolution, revocation, etc.; responsible for making authorization decisions to ensure the execution of data usage policies.
[0110] Data policy deployment module: responsible for converting (or translating) the agreed policy into machine-readable code format (such as executable programs, etc.), deploying the policy. In the point-to-point data flow scenario, this module communicates with the node side to realize the node-side deployment of the policy; in the scenario of data flow through intermediaries, this node not only communicates with the node side to realize the node-side deployment of the policy, but also needs to deploy the policy in the DCP.
[0111] Data policy execution module: after the policy is deployed and loaded, it needs to perform corresponding operations according to the policy rules (such as sending an email or writing to a specific log system when using data, performing desensitization processing before data out of domain, and burning after reading, etc.). There are multiple implementation methods for policy execution: through APP software to intercept corresponding data flow for processing / adaptation of operating system related functions (such as limited use times of file system, time limit, etc.) / trusted environment (such as TEE, Trusted Platform Module (TPM), data sandbox, etc. secure environment burn after reading, etc.). When the policy is executed, the decision information of data operation (such as the file is only allowed to be opened 3 times, and each time the file is opened, the decision information is obtained to judge whether the file opening operation can be performed) needs to be obtained from the policy management module before the data operation is performed.
[0112] Data policy monitoring module: the policy monitoring module ensures that data is always used within the authorized range according to the agreement between the two parties (i.e. data demander and data provider), without leaking, tampering, over-limit use, etc. (such as sensitive data cannot be forwarded to nodes without permission, important data cannot be modified by nodes without permission, data must be deleted from memory after a period of time, etc.). Monitoring methods and strategies include but are not limited to the following ways: periodically dynamically monitoring the software list of data usage nodes, the latest information of dynamic attributes of components, and the latest state compliance that can prove the current attributes and used software stack; when over-limit or abnormal data operation occurs (such as not limiting usage at a specific user, specific location, specific purpose, specific event, time interval, number of times, etc. as agreed), take measures such as abnormal disconnection and risk blocking.
[0113] The data strategy use evaluation module is responsible for matching and evaluating the consistency (for example, whether the data set field, limited scene, limited number of times, and the like are executed according to the negotiated data use strategy configuration, data use strategy execution monitoring during the flow process, and data use strategy execution log feedback after the flow process ends), and giving a comprehensive strategy use evaluation result, including a strategy evaluation degree, an execution difference, a risk point evaluation, and the like, which are used to provide subsequent billing credentials to the DEP order module. Meanwhile, the strategy use evaluation result is also used as a basis for subsequent iteration and optimization of the strategy execution, management, and the like modules.
[0114] In the embodiments of the present application, an example diagram of a point-to-point data flow mode is also provided, as shown in FIG. 5, and an example diagram of a data flow mode through a third party is provided, as shown in FIG. 6. As can be seen in FIG. 5, each function module included in the strategy control network element is deployed in the corresponding trusted node of the data provider and the data demander, and the data transmission and use is directly performed between the data provider and the data demander. In FIG. 6, the data provider and the data demander need to exchange data through the third party DCP.
[0115] In the embodiments of the present application, a new DSSN technical architecture is provided, which is constructed according to a DSSN business layer, a DSSN core network, and a DSSN trusted node in a hierarchical design manner, to solve the problems of trust and security of data domain control in the data transaction process. The method and process for constructing a trusted data flow for the data provider and the data demander are compatible with the existing privacy calculation architecture, and solve the new strategy of non-privacy calculation data flow, to provide more technical support for data transaction.
[0116] Compared with the related art, the embodiments of the present application have the following technical advantages:
[0117] 1. A new DSSN technical architecture is provided, to realize a three-layer separation mode of data transaction business development, transaction flow control, and transaction data flow, to more flexibly adapt to various scenes and various cipher data flow business types.
[0118] 2. The problem of trust and controllability in the flow transaction process is solved when the data flow is performed between the data demander and the data provider in a non-privacy calculation mode.
[0119] Based on the above embodiments, in another embodiment of the present application, a data flow control method is also provided, as shown in FIG. 7, which is applied to a data flow control device including a strategy control network element. The method can include the following steps:
[0120] S701, determining, by a policy control network element, a data usage policy corresponding to the first data according to data requirement information of the first data, wherein the data requirement information comprises at least one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, commodity data requirement information of the data demander.
[0121] In the embodiment of the present application, the first data can be data encapsulated for certain commodity related data, such as data encapsulated for a certain commodity displayed on a shopping website. The first data can also be other data, which is not specifically limited in the embodiment of the present application.
[0122] In the embodiment of the present application, the data requirement information can be commodity requirement information (also referred to as commodity data requirement information), or a cooperation agreement reached between a data provider and a data demander specified in a work order, wherein the work order can be understood as a commodity order, the data provider can also be a supplier node, the data demander can also be a demander node, or other data requirement information, which is not specifically limited in the embodiment of the present application.
[0123] In the embodiment of the present application, the determination of the data usage policy corresponding to the first data according to the data requirement information of the first data by the policy control network element can be implemented through the following process:
[0124] 1. The data demander / data provider logs in the data flow system through an authentication and authorization network element.
[0125] 2. The data demander selects commodity data from a commodity data directory in the DEP, wherein the commodity data directory in the DEP is data set published by the data provider through the DEP; the DEP notifies the data provider of the commodity data requirement information of the data demander.
[0126] 3. The data provider and the data demander negotiate the data usage policy of the commodity data online through the policy control network element, wherein the data usage policy can include usage conditions, usage methods, prices, etc.
[0127] S702, deploying the data usage policy on a data flow network element corresponding to the first data, so that the data flow network element uses the first data based on the data usage policy.
[0128] In the embodiment of the present application, the data flow network element can include a first network element and a second network element, or a second network element and a third network element.
[0129] It should be noted that the network elements included in the data flow network element need to be determined according to the data flow mode.
[0130] In the embodiment of the present application, the first network element can be a data provider, the second network element can be a data demander, and the third network element can be a data processing lake (which can be abbreviated as DCP).
[0131] In the embodiment of the present application, after the policy control network element determines the data usage policy of the first data, the policy control network element configures and deploys the data usage policy at the data provider and the data demander, or configures and deploys the data usage policy at the data demander and the DCP network element. In this way, the data demander can use the first data provided by the data provider according to the data usage policy.
[0132] It can be understood that the data flow control method provided in the embodiment of the present application first determines the data usage policy corresponding to the data demand information according to the data demand information through the policy control network element, and deploys the corresponding data usage policy on the data flow network element in the first data flow process. After the deployment is completed, the use of the first data will be used according to the corresponding data usage policy. Since the use of the first data is limited by the data usage policy, when the data flow network element uses the first data based on the data usage policy, the use of the first data is limited and protected by the data usage policy, thereby improving the security of the first data.
[0133] In the embodiment of the present application, to complete the use of the first data by the data flow network element based on the data usage policy, the policy control network element needs to notify the DEP of the determined data usage policy including price information and the like after the determined data usage policy is configured and deployed, and the DEP saves the determined data usage policy and notifies the DSP.
[0134] In an embodiment of the present application, the data flow control apparatus further includes a fourth network element, and the fourth network element is configured to schedule the first network element and the second network element to perform authentication connection related configuration, or schedule the first network element, the second network element, and the third network element to perform authentication connection related configuration.
[0135] In the embodiment of the present application, the fourth network element is the DSP.
[0136] In the embodiment of the present application, the DSP is configured to perform scheduling configuration of the related data flow network element according to the data usage policy notified by the DEP. After the scheduling configuration is completed, the data demander uses the first data provided by the data provider.
[0137] In the embodiment of the present application, the data usage policy can further include a data flow mode, and the data flow mode includes a point-to-point flow mode and a data flow mode through a third party.
[0138] In the embodiment of the present application, if the data flow mode is a point-to-point data flow mode, when the DSP configures the data flow element according to the data usage strategy, only two-party authentication is needed, and the DSP is used to configure the authentication protocol, connection information, and the like of the two-party network elements (such as the data demander and the data provider).
[0139] In the embodiment of the present application, if the data flow mode is a third-party data flow mode, when the DSP configures the data flow element according to the data usage strategy, three-party mutual authentication is needed, and the DSP is used to configure the authentication protocol, connection information, and authorization information of the DCP network element, the data demander, and the data provider.
[0140] In an embodiment of the present application, if the data flow mode is a point-to-point data flow mode, the data flow element includes a first network element and a second network element; the second network element receives the data usage strategy sent by the first network element, and in the case that the second network element confirms the data usage strategy, the first data in the first network element is used based on the data usage strategy.
[0141] In the embodiment of the present application, the second network element receives the data usage strategy sent by the first network element, which can be implemented in the following manner:
[0142] The data provider first notifies the configuration information of the data usage strategy configured by the policy control network element, that is, the data usage strategy has taken effect in the data provider, and then sends the effective data usage strategy to the data demander through the policy control network element, and notifies the data demander to confirm the effective data usage strategy.
[0143] In the embodiment of the present application, when the data demander receives the data usage strategy sent by the data provider through the policy control network element, the data usage strategy is confirmed. The specific confirmation manner can be whether the data usage strategy sent by the data provider is the same as the data usage strategy configured by the data demander.
[0144] In the embodiment of the present application, after the data demander confirms the data usage strategy sent by the data provider, the data demander and the data provider perform point-to-point data transmission and usage according to the determined data usage strategy, that is, the data demander uses the data in the data provider according to the determined data usage strategy.
[0145] It should be noted that the data in the embodiment of the present application is not limited to files, structured data joint calculation, and the like, and can be selected according to actual conditions, which is not specifically limited in the embodiment of the present application.
[0146] In the embodiment of the present application, after the data demander confirms the data usage policy sent by the data provider, the confirmed data usage policy will be used to monitor the data usage in the first network element (such as through a control type client, operating system interception, hardware, and other security methods) through the deployment of the data provider and the data demander.
[0147] In the embodiment of the present application, before the data demander uses the first data in the data provider, the first data needs to be initialized by the data provider through desensitization, watermarking, anonymization, and the like, and then the first data can be used out of the domain with the corresponding data usage policy.
[0148] In an embodiment of the present application, the data flow network element includes a first network element and a second network element; based on the usage restriction information determined by the first network element and the second network element in advance for the first data, the policy control network element performs data processing corresponding to the usage restriction information on the first data.
[0149] In the embodiment of the present application, the data processing can include time limit restriction, time length restriction, read-after-burn, risk chain breaking prevention, and the like.
[0150] In the embodiment of the present application, the usage restriction information can be determined by the first network element and the second network element in the data usage policy negotiation process, that is, the usage restriction information can be determined through negotiation of the two.
[0151] In the embodiment of the present application, the policy control network element performs corresponding limitation on the first data according to the negotiation result, specifically, after the data usage policy is executed, the read-after-burn, risk chain breaking prevention, and the like are performed according to the pre-negotiated usage restriction information.
[0152] In an embodiment of the present application, if the data flow mode is a third-party data flow mode, the data flow network element includes a second network element and a third network element; at this time, the data flow control apparatus further includes: a first network element storing the first data; the first network element sends the first data and the data usage policy to the third network element; the third network element receives the data usage policy and the first data sent by the first network element; and based on the data usage policy, the third network element controls the second network element to use the first data in the third network element.
[0153] In the embodiment of the present application, the second network element is a data demander.
[0154] In the embodiment of the present application, the third network element is a DCP.
[0155] In the embodiment of the present application, before the data provider sends the first data and the data usage policy to the DCP, the following operations can be performed first:
[0156] The data provider selects the DCP assigned by the DSP, and performs corresponding processing on the first data (such as performing initialization operation processing such as desensitization, watermarking, anonymization, etc. on the first data).
[0157] In the embodiments of the present application, after the initialization operation processing on the first data, the processed first data is transmitted to the assigned DCP by the data provider, so that the first data can be used out of the domain according to the data usage policy.
[0158] In the embodiments of the present application, after the data provider sends the processed first data and the data usage policy to the DCP, the DCP receives the processed first data and the data usage policy sent by the data provider, and further selects a container / software / TEE of a corresponding security level according to the data usage policy to process and store (such as in memory, files, hardware, etc.) the data usage policy and the first data.
[0159] In the embodiments of the present application, the DCP notifies the data demander of the use of the first data, and notifies the confirmation of the corresponding data usage policy and usage restriction information.
[0160] In the embodiments of the present application, after the data demander confirms the data usage policy and the usage restriction information, the data demander uses the data (such as file browsing, data joint calculation, etc.) through the DCP, and the DCP controls and safeguards the first data based on the data usage policy.
[0161] In an embodiment of the present application, the policy control network element can also monitor the execution result of the data usage policy on the third network element; in the case of an abnormal execution result, the first network element and the third network element are disconnected.
[0162] In the embodiments of the present application, the policy control network element monitors the use of the data usage policy by the DCP, and if an abnormal execution result (or a risk) is found during the monitoring of the data usage policy by the policy control network element on the DCP, the policy control network element disconnects the data demander and the DCP, etc.
[0163] In an embodiment of the present application, in the case of using the first data, the policy control network element receives the first execution log sent by the first network element and the second execution log sent by the second network element; based on the first execution log and the second execution log, it is determined whether the related execution behavior of the data usage policy is abnormal, and in the case of an abnormal related execution behavior, the abnormal behavior is reported.
[0164] In the embodiments of the present application, whether through the point-to-point data flow mode or through the third-party data flow mode, after the data flow is completed, the policy control network element receives the first execution log and the second execution log of the data use policy uploaded by the data demand side and the data providing side respectively, and the first execution log and the second execution log include but are not limited to the software and hardware environment configuration before and after the first data use, the authentication certificate authentication information, the data use policy execution process flag, etc.
[0165] In the embodiments of the present application, the policy control network element evaluates whether the execution of the data use policy conforms to the pre-configuration according to the first execution log and the second execution log, for example, if the alarm information appears, it indicates that it does not conform to the pre-configuration. The policy control network element further issues an evaluation report according to the evaluation result, and notifies the DEP data demand side and the data providing side of the specific execution of the data use policy.
[0166] In an embodiment of the present application, if the data demand side and the data providing side negotiate to download the data flow software through the APP Store to control the data use policy, the data demand side / data providing side also needs to download the related APP according to the negotiation to configure and use the tool, such as data binning and encryption, and the data providing side needs to download the related authorized APP to perform the corresponding data processing.
[0167] It should be noted that this process is performed only when the APP needs to be specified for data processing in the negotiation process of the data demand side and the data providing side.
[0168] Based on the above embodiments, the embodiments of the present application also provide a whole flowchart of the data flow control method between the network elements, as shown in FIG. 8, which specifically includes the following steps:
[0169] First, the data demand side / data providing side logs in the data flow system through authentication and authorization, specifically including:
[0170] 1. The data demand side logs in the account.
[0171] 2. The authentication and authorization network element performs security authentication, such as CA verification.
[0172] 3. The authentication and authorization network element sends an authentication pass response to the data demand side.
[0173] After the authentication is passed, the following steps are continued to be executed:
[0174] 4. The data demand side browses the commodity data directory through the DEP and selects commodity data. The commodity data directory in the DEP is the data set published by the data providing side through the DEP.
[0175] 5. The DEP notifies the data provider of the commodity data demand information.
[0176] 6. The data consumer and the data provider negotiate the data usage policy of the commodity data online through the policy control network element, wherein the data usage policy includes usage conditions, usage methods, prices, etc., and is confirmed.
[0177] 7. The policy control network element configures and deploys the negotiated data usage policy, and notifies the DEP of the data usage policy, including price information, etc.
[0178] 8. The DEP saves the confirmed data usage policy and notifies the DSP.
[0179] 9. The DSP configures the related data flow network elements according to the data usage policy.
[0180] If it is a point-to-point data flow method, the DSP will configure the authentication protocol, connection information, etc. of the network elements of both parties (i.e. the data consumer and the data provider).
[0181] If the data flow is conducted through a third party, the DSP will configure the authentication protocol, connection information, authorization information, etc. of the DCP network element, the data consumer and the data provider.
[0182] It should be noted that the data flow method is also included in the negotiated data usage policy.
[0183] 9', if the data consumer and the data provider negotiate to control the policy through the APP Store to download the data flow software, the data consumer / data provider downloads the related APP according to the negotiation to configure and use the tool.
[0184] If data binning and encryption are required, the data provider needs to download the related authorized APP to perform the corresponding data processing.
[0185] It should be noted that in 9', the APP specified for data processing and use will only be executed if the APP is required in the data usage policy negotiated in step 6.
[0186] After the related data flow network elements are configured, if it is a point-to-point data flow method, steps 10-14 are executed, as follows:
[0187] 10. The data provider performs initialization processing such as desensitization, watermarking, anonymization, etc. on the first data. In this way, the first data can be allowed to be used out of the domain according to the data usage policy.
[0188] 11、Data Provider notifies the Policy Control Network Element of the configuration information of the data usage policy and the first data, such as the corresponding restriction (such as time limit, time length, read-after-burn, etc.) of the first data by the Policy Control Network Element according to the data usage policy negotiated at the time of signing.
[0189] 12、The Policy Control Network Element notifies the Data Demand Side of the confirmation of the data usage policy, and the confirmed data usage policy will be used for monitoring the data usage through the deployment of the Data Demand Side and the Data Provider.
[0190] Such as through the security mode of control class client, operating system interception, hardware, etc.
[0191] 13、The Data Demand Side and the Data Provider perform point-to-point data (file, structured data joint calculation, etc.) transmission and usage according to the established data usage policy.
[0192] 14、After the execution of the data usage policy, the relevant read-after-burn, risk chain breaking prevention and control operations are performed according to the pre-negotiated usage restriction of the first data.
[0193] If the data flow is performed through a third party, the following 10'-14' are executed, as follows:
[0194] 10'、The Data Provider selects the DCP distributed by the DSP, and transmits the first data to the DCP after corresponding processing (such as desensitization, watermarking, anonymization, etc.) of the first data. In this way, the first data can be allowed to be used out of the domain with the corresponding data usage policy.
[0195] 11'、The DCP selects the container / software / TEE of the corresponding security level to process and store (such as memory / file / hardware) the data usage policy and the first data according to the data usage policy.
[0196] 12'、The DCP notifies the Data Demand Side of the usage of the first data, and notifies the confirmation of the corresponding data usage policy and usage restriction information.
[0197] 13'、After the confirmation of the usage restriction information and the data usage policy by the Data Demand Side, the Data Demand Side uses the first data (such as file browsing, data joint calculation, etc.) through the DCP, and the DCP performs usage control guarantee.
[0198] 14'、The Policy Control Network Element monitors the data usage policy of the DCP, and performs chain breaking operation if a risk is found.
[0199] 15. After the data circulation is completed, both the data requester and the data provider shall upload execution logs of the relevant data usage policies. The execution logs shall include, but are not limited to, the hardware and software environment configurations before and after data usage, certificate authentication information, and data policy execution process markers.
[0200] 16. The policy control network element evaluates whether the execution of the data use policy conforms to the pre-configuration based on the execution log, and issues an evaluation report and notifies the DEP of the relevant execution status.
[0201] Based on the above embodiments, this application also provides an example of a data flow control method, as shown in Figure 9, which can be implemented through the following process:
[0202] 1. The authentication and authorization network elements (including CA center, authentication and authorization, etc.) issue user certificates, node certificates, application certificates, etc. to each participant (such as data requester a, data provider, etc.), node (such as TEE node), and application (such as APP).
[0203] Among them, the CA center's identity CA issues user certificates to ensure that legitimate users establish a secure communication connection with two-way verification. Node certificates are used for secure verification and transmission between trusted nodes, and also provide dynamic trusted identity management for nodes (application components). The identity CA's private key signs the application image file hash to ensure the legitimacy and integrity of the source, and the identity CA needs to verify it during deployment. The application certificate is used for dynamic trusted identity management of application instances. During deployment, the compute nodes will verify the application signing certificate, and the CA center issues identity certificates for the application.
[0204] 2. The data provider confirms the agreed-upon data usage policy control rules and performs specified data operations (through the application APP) on specified data in the specified area (TEE node DCP) for the designated user (data requester a).
[0205] 3. User authentication between the data requester and the data provider. Specifically, when data requester A sends a request to the data provider to use data, the data provider and data requester A conduct mutual authentication. Both parties exchange certificates, negotiate encryption algorithms, and generate session keys, etc. (The data provider verifies the completeness and validity of data requester A's certificate and encrypts random numbers using the data provider's public key. Similarly, data requester A also verifies the completeness and validity of the provided certificate and encrypts random numbers using the data requester's public key).
[0206] 4. The designated APP, node for data operation. Specifically, after the authentication of both parties, the data demander a uses the data of the data provider according to the above control rules to the designated DCP (TEE node) and uses the designated application APP to operate the data.
[0207] 5. Inter-node authentication between data demander and DCP. Specifically, when the data demander and DCP interact, the data demander and DCP need to provide trust proof data for the other party to verify the trustworthiness of the system, including exchanging the following information:
[0208] Software stack measurement: including software stack measurement data metadata (English can be expressed as Metadata) (the list and information of all software in the software stack) and dynamic attribute token (English can be expressed as TOKEN) (i.e. Certificate Data File, DAT) (authorized access TOKEN, used to authorize access to other nodes) of security boot trust root, operating system (Operating System, OS) and application. Among them, the key link is that the data demander and the DCP trusted node request remote proof from each other, and exchange the non-repeated random number value (Number once, Nonce) which is used once, and the nodes generate measurement data, Metadata based on the DAT applied to the CA system and sign, and send to the other party (including data demander a and DCP), and the nodes verify the measurement data and Metadata. After the node authentication, the DCP node checks the application APP software before use.
[0209] 6. Data application APP authentication. Specifically, when the data demander starts the application APP (running in the DCP TEE node), the application APP requests remote authentication from the data provider based on the application certificate issued by the CA, confirms that the application APP runs in the designated trusted node DCP TEE environment and the code has not been tampered with, and checks the application APP and data user in the authorization list according to the data use strategy set by the data provider, and operates the data according to the preset application APP.
[0210] Based on the above embodiments, the embodiments of the present application provide a storage medium having a computer program stored thereon. The computer readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors, and are applied to a data flow control device. The computer program implements the data flow control method as described above. The processor can be at least one of an application specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a CPU, a controller, a microcontroller, or a microprocessor. It can be understood that, for different devices, the electronic device used to implement the functions of the processor can also be other devices, and the embodiments of the present application are not limited specifically.
[0211] Based on the above embodiments, the embodiments of the present application provide a computer program product, which includes a computer program. The computer program can be executed by one or more processors, and is applied to a data flow control device. The computer program implements the data flow control method as described above.
[0212] It should be noted that, in the embodiments of the present application, the terms "comprising", "including", or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article, or device including the element.
[0213] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and the necessary general hardware platform, of course, can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for causing an image display device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present application.
[0214] The above merely describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application.
Claims
1. A data flow traffic control apparatus, the apparatus comprising: A policy control network element; The policy control network element is configured to determine a data usage policy corresponding to the first data according to data requirement information of the first data, and deploy the data usage policy on a data flow network element corresponding to the first data, so that the data flow network element uses the first data based on the data usage policy; wherein the data requirement information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, commodity data requirement information of the data demander. The data flow network element includes a first network element and a second network element; 2. The apparatus of claim 1, wherein, The second network element is configured to receive the data usage policy sent by the first network element, and use the first data in the first network element based on the data usage policy when the data usage policy is confirmed. The data flow network element includes a first network element and a second network element; 3. The apparatus of claim 1, wherein, The policy control network element is further configured to perform data processing corresponding to usage restriction information on the first data based on the usage restriction information determined by the first network element and the second network element in advance for the first data. The data flow network element includes a second network element and a third network element; the device further includes a first network element storing the first data; 4. The apparatus of claim 1, wherein, The first network element is configured to send the first data and the data usage policy to a third network element; The third network element is configured to receive the data usage policy and the first data sent by the first network element, and control the second network element to use the first data in the third network element based on the data usage policy.
5. The device of claim 4, wherein The policy control network element is further configured to monitor the execution result of the data usage policy on the third network element; and perform a disconnection process on the first network element and the third network element when the execution result is abnormal.
6. The device of claim 1, wherein The policy control network element is further configured to receive a first execution log sent by the first network element and a second execution log sent by the second network element when the use of the first data is completed; determine whether the related execution behavior of the data usage policy is abnormal based on the first execution log and the second execution log, and report the abnormal behavior when the related execution behavior is abnormal. The device further includes a fourth network element; 7. The apparatus of claim 1, wherein, The fourth network element is configured to schedule the first network element and the second network element for authentication connection related configuration; Alternatively, the fourth network element is configured to schedule the first network element, the second network element and the third network element for authentication connection related configuration.
8. A data flow control method applied to a data flow control device, the device including a policy control network element, the method comprising: determining, by the policy control network element, a data usage policy corresponding to the first data according to data requirement information of the first data; wherein the data requirement information at least includes one or more of the following: a cooperation agreement reached between a data provider and a data demander specified in a work order, commodity data requirement information of the data demander. deploy the data usage policy on a data flow network element corresponding to the first data, for the data flow network element to use the first data based on the data usage policy.
9. A storage medium having stored thereon a computer program which, when executed by a processor, implements the method of claim 8.
10. A computer program product comprising a computer program which, when executed by a processor, implements the method of claim 8.
Citation Information
Patent Citations
Data processing method, system, equipment and medium for secure and trusted data circulation platform
CN117972151A
Cross-domain data security control method and system
CN118316719A
Data circulation method, device and system and storage medium
CN118536143A
Data circulation control device and method, storage medium and computer program product
CN119316189A
System and method for multiparty secure computing platform
US20220108026A1