WO2021184264A1 - Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés - Google Patents

Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés Download PDF

Info

Publication number
WO2021184264A1
WO2021184264A1 PCT/CN2020/080051 CN2020080051W WO2021184264A1 WO 2021184264 A1 WO2021184264 A1 WO 2021184264A1 CN 2020080051 W CN2020080051 W CN 2020080051W WO 2021184264 A1 WO2021184264 A1 WO 2021184264A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
storage device
key
data storage
supervision
Prior art date
Application number
PCT/CN2020/080051
Other languages
English (en)
Chinese (zh)
Inventor
孔祥瑞
李明
詹益峰
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2020/080051 priority Critical patent/WO2021184264A1/fr
Priority to CN202080004855.5A priority patent/CN112654989B/zh
Publication of WO2021184264A1 publication Critical patent/WO2021184264A1/fr

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices

Definitions

  • the third-party supervision device receives a supervision key request for target data sent by the data storage device, where the supervision key request is generated by the data storage device after receiving the access request sent by the access device, and the access request is used for Request to access the plaintext of the target data;
  • an embodiment of the present application also provides a data storage device, including a processor, a memory, and a communication interface.
  • the memory is used to store a program, and the processor executes the program stored in the memory.
  • the data storage device realizes any one of the methods described in the first aspect.
  • 2D is a schematic flowchart of another data storage method provided by an embodiment of the present application.
  • the third-party supervision system can not only send the supervision key used to encrypt the data A* to the data storage device, but also send it to the data storage server.
  • the time authority of the supervision key and further, only when the current time of the data storage device is within the scope allowed by the time authority, can the data A* be encrypted by the supervision key to restrict the use of the supervision key aging. Otherwise, delete the supervision key, and send to the data uploading device an indication message indicating that the data A* has failed to store.
  • S2133 Delete the supervision key, and send to the data upload device indication information for indicating storage failure of the data to be stored.
  • Implementation mode 2 The third-party monitoring device generates a digital fingerprint of the combined data of the current time and the identification of the target data to obtain the first reference fingerprint.
  • the third-party monitoring device sends the first reference fingerprint to the data storage device; the data storage device receives the first reference fingerprint.
  • the reference fingerprint, and further, the digital fingerprint of the combined data of the current time of the data storage device and the identification of the target data is generated in the same way, and the first fingerprint to be detected is obtained, and it is judged whether the first fingerprint to be detected is consistent with the first reference fingerprint, if yes If yes, perform the first decryption; otherwise, delete the supervision key, and send to the access device the indication information for indicating the failure of the target data access.
  • the receiving unit 401 is further configured to receive the supervision key sent by the third-party supervision device;
  • the key generation unit 602 is configured to generate a supervision key according to the key request
  • the receiving unit 701 is further configured to: receive the upload key
  • FIG. 13 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
  • the electronic device 1300 may be an access device for implementing the steps in the data access method executed by the access device in the foregoing embodiment.
  • the electronic device 1300 may be a mobile phone, a vehicle, a vehicle-mounted unit, a tablet computer, etc., or a server, and the electronic device 1300 may include:
  • the electronic device 1300 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
  • the internal memory 121 may be used to store computer executable program code, where the executable program code includes instructions.
  • the processor 110 executes various functional applications and data processing of the electronic device 1300 by running instructions stored in the internal memory 121.
  • the internal memory 121 may include a storage program area and a storage data area.
  • the storage program area can store an operating system, an application program (such as a sound playback function, an image playback function, etc.) required by at least one function, and the like.
  • the storage data area can store data (such as audio data, phone book, etc.) created during the use of the electronic device 1300.
  • the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), and the like.
  • UFS universal flash storage
  • the acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 1300 in various directions (generally three axes). When the electronic device 1300 is stationary, the magnitude and direction of gravity can be detected. It can also be used to identify the posture of electronic devices, and apply to applications such as horizontal and vertical screen switching, pedometers, and so on.
  • the SIM card interface 195 is used to connect to the SIM card.
  • the SIM card can be inserted into the SIM card interface 195 or pulled out from the SIM card interface 195 to achieve contact and separation with the electronic device 1300.
  • the electronic device 1300 may support 1 or N SIM card interfaces, and N is a positive integer greater than 1.
  • the SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc.
  • the same SIM card interface 195 can insert multiple cards at the same time. The types of the multiple cards can be the same or different.
  • the SIM card interface 195 can also be compatible with different types of SIM cards.
  • the SIM card interface 195 may also be compatible with external memory cards.
  • the electronic device 1300 interacts with the network through the SIM card to implement functions such as call and data communication.
  • the electronic device 1300 adopts an eSIM, that is, an embedded SIM card.
  • the eSIM card can be embedded in the electronic device 1300 and cannot be separated from the electronic device 1300.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Databases & Information Systems (AREA)
  • Automation & Control Theory (AREA)
  • Storage Device Security (AREA)

Abstract

Un procédé de sauvegarde de données, un procédé d'accès à des données, et un appareil et un dispositif associés sont divulgués. Le procédé de sauvegarde de données fait appel aux étapes suivantes : lorsqu'un dispositif de stockage de données sauvegarde des données à stocker, la demande d'une clé de supervision à partir d'un dispositif de supervision tiers, le chiffrement, au moyen de la clé de supervision, des données à stocker, et le stockage de données chiffrées des données à stocker; puis, lorsque les données stockées de données cibles dans le dispositif de stockage de données sont accessibles, la demande de la clé de supervision à partir du dispositif de supervision tiers, et le déchiffrement des données chiffrées des données cibles au moyen de la clé de supervision afin d'obtenir les données cibles. Par conséquent, au moyen du procédé de sauvegarde de données, il peut être garanti que le processus d'un dispositif de stockage de données stockant des données est supervisé par un dispositif de supervision tiers, et lorsque le dispositif de stockage de données ne possède pas de clé de supervision, le dispositif de stockage de données ne peut pas déchiffrer les données stockées dans celui-ci, de sorte que la surveillance de données soit réalisée, et que la sécurité des données soit protégée.
PCT/CN2020/080051 2020-03-18 2020-03-18 Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés WO2021184264A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2020/080051 WO2021184264A1 (fr) 2020-03-18 2020-03-18 Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés
CN202080004855.5A CN112654989B (zh) 2020-03-18 2020-03-18 数据保存方法、数据访问方法及相关装置、设备

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/080051 WO2021184264A1 (fr) 2020-03-18 2020-03-18 Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés

Publications (1)

Publication Number Publication Date
WO2021184264A1 true WO2021184264A1 (fr) 2021-09-23

Family

ID=75368403

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/080051 WO2021184264A1 (fr) 2020-03-18 2020-03-18 Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés

Country Status (2)

Country Link
CN (1) CN112654989B (fr)
WO (1) WO2021184264A1 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116049826A (zh) * 2022-06-09 2023-05-02 荣耀终端有限公司 基于tpm的数据保护方法、电子设备及存储介质
WO2024113865A1 (fr) * 2022-11-29 2024-06-06 华为技术有限公司 Procédé et appareil de transmission sécurisée pour un flux vidéo
CN118246080A (zh) * 2024-05-28 2024-06-25 山东云海国创云计算装备产业创新中心有限公司 一种数据处理方法、电子设备、存储介质及产品

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113127912A (zh) * 2021-05-07 2021-07-16 杭州天谷信息科技有限公司 一种数据保密以及公布的方法和系统

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103856321A (zh) * 2012-12-07 2014-06-11 观致汽车有限公司 一种数据加密解密方法及其系统
US9875374B2 (en) * 2015-07-01 2018-01-23 Michael L. Brownewell System and method for collecting, storing, and securing data
CN110011959A (zh) * 2019-01-07 2019-07-12 诚镌科技有限公司 数据存储方法、数据查询方法和系统

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101340436B (zh) * 2008-08-14 2011-05-11 普天信息技术研究院有限公司 基于便携式存储设备实现远程访问控制的方法及装置
CN102821096B (zh) * 2012-07-17 2014-10-29 华中科技大学 一种分布式存储系统及其文件共享方法
CN104009842A (zh) * 2014-05-15 2014-08-27 华南理工大学 基于des、rsa加密算法及脆弱数字水印的通信数据加解密方法
CN105991563B (zh) * 2015-02-05 2020-07-03 阿里巴巴集团控股有限公司 一种保护敏感数据安全的方法、装置及三方服务系统
CN105915338B (zh) * 2016-05-27 2018-12-28 北京中油瑞飞信息技术有限责任公司 生成密钥的方法和系统
CN108270739B (zh) * 2016-12-30 2021-01-29 华为技术有限公司 一种管理加密信息的方法及装置
CN109428900B (zh) * 2017-08-21 2022-05-13 创新先进技术有限公司 一种数据处理的方法及装置
CN107566357B (zh) * 2017-08-25 2018-11-16 厦门益协作网络科技有限公司 一种基于分区认证技术的互联网交易信息数据存储方法
CN107682367A (zh) * 2017-11-14 2018-02-09 北京酷我科技有限公司 一种pc端网页登录方法和系统
CN107749862A (zh) * 2017-11-23 2018-03-02 爱国者安全科技(北京)有限公司 一种数据加密集中存储方法、服务器、用户终端及系统
CN109361704A (zh) * 2018-12-12 2019-02-19 深圳市网心科技有限公司 云存储数据加密传输方法、系统、设备及存储介质
CN110619237B (zh) * 2019-08-14 2022-08-26 江苏芯盛智能科技有限公司 数据存储方法、装置、计算机设备以及存储介质

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103856321A (zh) * 2012-12-07 2014-06-11 观致汽车有限公司 一种数据加密解密方法及其系统
US9875374B2 (en) * 2015-07-01 2018-01-23 Michael L. Brownewell System and method for collecting, storing, and securing data
CN110011959A (zh) * 2019-01-07 2019-07-12 诚镌科技有限公司 数据存储方法、数据查询方法和系统

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116049826A (zh) * 2022-06-09 2023-05-02 荣耀终端有限公司 基于tpm的数据保护方法、电子设备及存储介质
CN116049826B (zh) * 2022-06-09 2023-10-13 荣耀终端有限公司 基于tpm的数据保护方法、电子设备及存储介质
WO2024113865A1 (fr) * 2022-11-29 2024-06-06 华为技术有限公司 Procédé et appareil de transmission sécurisée pour un flux vidéo
CN118246080A (zh) * 2024-05-28 2024-06-25 山东云海国创云计算装备产业创新中心有限公司 一种数据处理方法、电子设备、存储介质及产品

Also Published As

Publication number Publication date
CN112654989A (zh) 2021-04-13
CN112654989B (zh) 2022-01-28

Similar Documents

Publication Publication Date Title
WO2021184264A1 (fr) Procédé de sauvegrade de données, procédé d'accès à des données, et appareil et dispositif associés
WO2023011376A1 (fr) Procédé de mise à jour de clé dans un système de communication beidou, et système et appareil associé
CN113408016B (zh) 保存密文的方法和装置
WO2021175266A1 (fr) Procédé et appareil de vérification d'identité, et dispositifs électroniques
WO2021057982A1 (fr) Procédé de traitement d'application et produit associé
CN115696237A (zh) 一种北斗通信系统中加密方法、系统及相关装置
WO2022143156A1 (fr) Procédé et appareil d'appel chiffré, terminal et support de stockage
CN113892103A (zh) 用于执行加解密处理的装置及方法
CN116669020B (zh) 一种密码管理方法、系统和电子设备
CN118118739A (zh) 视频流的安全传输方法和装置
US20230214532A1 (en) Permission negotiation method and apparatus during communication, and electronic device
WO2022037405A1 (fr) Procédé de vérification d'informations, dispositif électronique et support d'enregistrement lisible par ordinateur
CN113950048B (zh) 连接建立方法、电子设备及存储介质
CN113676440B (zh) 通信过程中的权限协商方法、装置和电子设备
CN117332398A (zh) 签发设备证书的方法、设备和系统
US20240233933A1 (en) Contact tracing method and related device
WO2024037040A1 (fr) Procédé de traitement de données, et dispositif électronique
WO2022042273A1 (fr) Procédé d'utilisation de clé et produit associé
CN116049826B (zh) 基于tpm的数据保护方法、电子设备及存储介质
CN115599596B (zh) 数据处理方法、电子设备、系统及存储介质
WO2024037500A1 (fr) Procédé de communication et appareil associé
US20230024222A1 (en) Method and apparatus for pushing vehicle information, user account server, and user equipment
CN115550919A (zh) 设备配对认证方法、装置、发送方设备及接收方设备
CN114866243A (zh) 证书吊销列表管理方法、装置及电子设备
CN115701016A (zh) 一种北斗通信系统中鉴权校验方法、系统及相关装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20925207

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20925207

Country of ref document: EP

Kind code of ref document: A1