Data file protection method and apparatus and terminal device
Abstract
The invention provides a data file protection method and apparatus and a terminal device. The method comprises: when it is detected that a data file is generated on the terminal device, determining the confidential degree of the data file; if the confidential degree indicates that the data file is a confidential file, storing the data file to a specified virtual storage region; and generating a stub file in an original storage location of the data file, wherein the stub file is used to record a consulting authority limit of the data file and a storage location of the data file in the virtual storage region. The technical solution of the present invention may make any operation on a data file stored in the virtual storage region isolated in a virtual environment, so as to prevent the data file from being leaked.
Term
8.7 yearsto projected expiry
Projected expiry 2 June 2035, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
15 claims: 7 independent, 8 dependent
- 1A method for protecting data files, which is applied to a terminal device, is characterized in that the method includes:determining the confidentiality level of the data file when it is detected that a data file is generated on the terminal device;The level indicates that the data file is a confidential file, and the data file is stored in a designated virtual storage area;a stub file is generated at the original storage location of the data file, and the stub file is used to record the access rights of the data file And the storage location of the data file in the virtual storage area. 1. 一种数据文件的保护方法,应用在终端设备上,其特征在于,所述方法包括: 在检测到所述终端设备上有数据文件生成时,确定所述数据文件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域; 在所述数据文件的原始存储位置生成存根文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
- 5The method according to any one of claims 1-4, wherein the method further comprises:when the data file is operated by the user, monitoring the data file by a client application installed on the terminal device Describe the operations performed by the user on the data file. 5. 根据权利要求1-4任一所述的方法,其特征在于,所述方法还包括: 在所述数据文件被所述用户操作时,通过安装在所述终端设备上的客户端应用程序监 控所述用户对所述数据文件所进行的操作。
- 6A method for reading a data file, applied on a terminal device, characterized in that the method includes:when a user click event on a stub file is monitored, determining the user according to the access permission recorded in the stub file Whether the user has the permission to access the data file;if the user has the permission to access the data file, start the virtual application corresponding to the data file;access the recorded data stored in the stub file through the virtual application The data file in the storage location of the virtual storage area. 6. 一种读取数据文件的方法,应用在终端设备上,其特征在于,所述方法包括: 在监听到用户关于存根文件的点击事件时,根据所述存根文件所记录的查阅权限确定 所述用户是否有访问所述数据文件的权限; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件。
- 1112. The device according to any one of claims 8-11, wherein the device further comprises:a monitoring module, configured to install the data file stored in the storage module by the user when the data file stored in the storage module is operated by the user. The client application on the terminal device monitors the operation performed by the user on the data file. 12. 根据权利要求8-11任一所述的装置,其特征在于,所述装置还包括: 监控模块,用于在所述存储模块存储的所述数据文件被所述用户操作时,通过安装在 所述终端设备上的客户端应用程序监控所述用户对所述数据文件所进行的操作。
- 1213. A device for reading a data file, which is applied to a terminal device, is characterized in that the device includes:a fourth determining module, which is used to monitor a user's click event on a stub file according to the record of the stub file To determine whether the user has the right to access the data file;13. 一种读取数据文件的装置,应用在终端设备上,其特征在于,所述装置包括: 第四确定模块,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件所 记录的查阅权限确定所述用户是否有访问所述数据文件的权限; The activation module is configured to activate the virtual application corresponding to the data file if the fourth determining module determines that the user has the authority to access the data file;the access module is configured to activate the virtual application program that is activated by the activation module The virtual application program accesses the data file stored in the storage location of the virtual storage area recorded by the stub file. 启动模块,用于如果所述第四确定模块确定所述用户有访问所述数据文件的权限,启 动所述数据文件对应的虚拟应用程序; 访问模块,用于通过所述启动模块启动的所述虚拟应用程序访问存储在所述存根文件 所记录的虚拟存储区域的存储位置的所述数据文件。
- 1415. A terminal device, characterized in that, the terminal device includes:a processor;a memory for storing executable instructions of the processor;wherein the processor is configured to detect that there is data on the terminal device When the file is generated, determine the confidentiality level of the data file;if the confidentiality level indicates that the data file is a confidential file, store the data file in the designated virtual storage area;generate at the original storage location of the data file A stub file, where the stub file is used to record the access rights of the data file and the storage location of the data file in the virtual storage area. 15. 一种终端设备,其特征在于,所述终端设备包括: 处理器;用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在检测到所述终端设备上有数据文件生成时,确定所述数据文 件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域; 在所述数据文件的原始存储位置生成存根文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
- 1516. A terminal device, characterized in that, the terminal device includes:a processor;and a memory for storing executable instructions of the processor;wherein, the processor is configured to monitor a user's click on a stub file In an event, determine whether the user has the permission to access the data file according to the access permission recorded in the stub file;if the user has the permission to access the data file, start the virtual application corresponding to the data file Accessing the data file stored in the storage location of the virtual storage area recorded in the stub file through the virtual application. 16. 一种终端设备,其特征在于,所述终端设备包括: 处理器;以及用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件 所记录的查阅权限确定所述用户是否有访问所述数据文件的权限; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件。
Independent claims7
119 paragraphs, as filed
Data file protection method, device and terminal equipment technical field
[0001] This application relates to the field of Internet technology, and in particular to a method, device and terminal device for protecting data files.
Background technique
[0002] In the free and open environment of the Internet, there is a risk of leakage in the use, storage, and transmission of data. The prior art realizes data protection through file transparent encryption and decryption methods. The specific realization process includes: when the operating system of the terminal device processes the data file at the bottom layer, the data file is encrypted, and when the user reads the data file, the operating system sends the data After the file is decrypted, it is put into the memory for the user to use. When the user needs to save the data file, the operating system encrypts the data file and finally writes it to the disk, so that the user does not feel the encryption and decryption behavior of the data file at all. The prior art achieves data leakage prevention by writing encrypted data on the disk and entering the memory to decrypt the data, but it cannot ensure that the files in the memory are not transmitted to the outside, so there is still a risk of the files being leaked.
Summary of the invention
[0003] In view of this, the present application provides a new technical solution that can solve the technical problem of anti-disclosure under the premise of not affecting the normal use of data files.
[0004] In order to achieve the above purpose, the present application provides technical solutions as follows:
[0005] According to the first aspect of this application, a data file protection method is proposed, which is applied to terminal equipment, including:
[0006] When detecting that a data file is generated on the terminal device, determine the confidentiality level of the data file;
[0007] If the confidentiality level indicates that the data file is a confidential file, store the data file in a designated virtual storage area;
[0008] A stub file is generated at the original storage location of the data file, and the stub file is used to record the access rights of the data file and the storage location of the data file in the virtual storage area.
[0009] According to the second aspect of the present application, a method for reading a data file is proposed, which is applied to a terminal device and includes:
[0010] When a user click event on the stub file is monitored, determine whether the user has the permission to access the data file according to the access permission recorded in the stub file;
[0011] If the user has the permission to access the data file, start the virtual application corresponding to the data file;
[0012] The data file stored in the storage location of the virtual storage area recorded in the stub file is accessed through the virtual application.
[0013] According to the third aspect of the present application, a data file protection device is proposed, which is applied to terminal equipment, including:
[0014] The first determining module is configured to determine the confidentiality level of the data file and the original storage location of the data file when it is detected that a data file is generated on the terminal device;
[0015] a storage module, configured to store the data file in a designated virtual storage area if the confidentiality level determined by the first determination module indicates that the data file is a confidential file;
[0016] The stub generation module is configured to generate a stub file at the original storage location determined by the first determining module, and the stub file is used to record the access rights of the data file and the data file in the virtual The storage location of the storage area.
[0017] According to a fourth aspect of the present application, a device for reading a data file is proposed, and the device for reading a data file includes:
[0018] The fourth determining module is configured to determine whether the user has access to the stub file according to the access rights recorded in the stub file when a user click event on the stub file generated by the stub generation module is monitored. Data file permissions;
[0019] The activation module is configured to activate the virtual application program corresponding to the data file if the fourth determining module determines that the user has the permission to access the data file;
[0020] The access module is configured to access the data file stored in the storage location of the virtual storage area recorded in the stub file by the virtual application program started by the startup module.
[0021] According to the fifth aspect of the present application, a terminal device is proposed, and the terminal device includes:
[0022] a processor; a memory for storing executable instructions of the processor;
[0023] Wherein, the processor is configured to determine the confidentiality level of the data file when it is detected that a data file is generated on the terminal device;
[0024] If the confidentiality level indicates that the data file is a confidential file, store the data file in a designated virtual storage area;
[0025] A stub file is generated at the original storage location of the data file, and the stub file is used to record the access rights of the data file and the storage location of the data file in the virtual storage area.
[0026] According to the sixth aspect of the present application, a terminal device is proposed, and the terminal device includes:
[0027] a processor; a memory for storing executable instructions of the processor;
[0028] Wherein, the processor is configured to determine whether the user has the authority to access the data file according to the access authority recorded in the stub file when the user's click event on the stub file is monitored;
[0029] If the user has the permission to access the data file, start the virtual application corresponding to the data file;
[0030] Accessing the data file stored in the storage location of the virtual storage area recorded in the stub file through the virtual application
[0031] It can be seen from the above technical solutions that when the application determines that the data file is a confidential file, the data file is stored in the designated virtual storage area, so that any operation on the data file stored in the virtual storage area can be isolated in In the virtual environment, avoid data files from being leaked; by generating stub files in the original storage location of the data files, the stub files only record the access rights of the data files and the storage location of the data files in the virtual storage area, and do not carry the data files themselves Therefore, all operations of the user on the stub file will not have any impact on the data file.
Description of the drawings
[0032] FIG. 1 shows a schematic flowchart of a data file protection method according to an exemplary embodiment of the present invention;
[0033] FIG. 2 shows a schematic flowchart of a data file protection method according to another exemplary embodiment of the present invention;
[0034] FIG. 3 shows a schematic flowchart of a method for reading a data file according to an exemplary embodiment of the present invention; [0035] FIG. 4 shows reading data according to another exemplary embodiment of the present invention Schematic diagram of the process of the document method;
[0036] FIG. 5 shows a schematic structural diagram of a terminal device according to an exemplary embodiment of the present invention;
[0037] FIG. 6 shows a schematic structural diagram of a terminal device according to another exemplary embodiment of the present invention;
[0038] FIG. 7 shows a schematic structural diagram of a data file protection device according to an exemplary embodiment of the present invention; [0039] FIG. 8 shows a data file protection according to another exemplary embodiment of the present invention Schematic diagram of the structure of the device;
[0040] FIG. 9 shows a schematic structural diagram of an apparatus for reading a data file according to an exemplary embodiment of the present invention; [0041] FIG. 10 shows a diagram of reading data according to another exemplary embodiment of the present invention Schematic diagram of the structure of the file device.
Detailed ways
[0042] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings indicate the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the application as detailed in the appended claims.
[0043] The terms used in this application are only for the purpose of describing specific embodiments, and are not intended to limit the application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and/or" as used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0044] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this application, the first information may also be referred to as second information, and similarly, the second information may also be referred to as first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "when" or "in response to determination".
[0045] When the application determines that the data file is a confidential file, the data file is stored in the designated virtual storage area, so that any operations on the data file stored in the virtual storage area can be isolated in the virtual environment to avoid data The file is leaked; the stub file is generated in the original storage location of the data file. Since the stub file only records the access rights of the recorded data file and the storage location of the data file in the virtual storage area, it does not carry any data of the data file itself, so the user All operations on the stub file will not have any impact on the data file.
[0046] To further illustrate this application, the following embodiments are provided:
[0047] FIG. 1 shows a schematic flowchart of a data file protection method according to an exemplary embodiment of the present invention; it can be applied to a terminal device, as shown in FIG. 1, including the following steps:
[0048] Step 101: When it is detected that a data file is generated on the terminal device, determine the confidentiality level of the data file. If the confidentiality level indicates that the data file is a confidential file, perform step 102. If the confidentiality level indicates that the data file is a non-confidential file, Go to step 104.
[0049] In an embodiment, the data file may be generated on the terminal device by means of copying, creating, downloading, etc. In an embodiment, the confidentiality level of the data file can be set by the user's degree of confidentiality of the data file. For example, the confidentiality level can be set to level 0, level 1, level 2, etc., and different confidentiality levels can indicate the data file For example, level 0 means that the user does not need to adopt confidentiality measures for the data file, level 1 means that the user needs to adopt confidentiality measures for the data file, or, for example, level 0 means that the user does not need to adopt confidentiality measures for the data file , Level 1 indicates that the user needs to adopt security measures for the data file on the terminal device, and Level 2 indicates that the user needs to adopt security measures for the data file on the terminal device and on the cloud server.
[0050] In an embodiment, the content information of the data file may be determined first, the content information is matched with a first preset condition, and the confidentiality level of the data file is determined according to the first result of the matching, for example, the first preset condition It can include multiple keyword groups, such as "encryption", "privacy", "non-public", etc., if it is detected that the content information of the data file contains "encryption", "privacy", etc., for example, content information Including "encryption", after matching "encryption" with the first preset condition, the confidentiality level of the data file can be determined to be level 1 according to the first result of the match. If the content information does not contain the above keyword group, then according to The first result of the matching can determine that the confidentiality level of the data file is level 0; in another embodiment, the file name of the data file can be determined first, the file name is matched with the second preset condition, and the second result of the match is Determine the confidentiality level of the data file. For example, the second preset condition may include multiple keyword groups, such as "confidential", "encrypted", etc., if it is detected that the file name of the data file contains "confidential", "encrypted" For example, if the file name includes "confidential", after matching "confidential" with the second preset condition, the confidentiality level of the data file can be determined as level 1 according to the second result of the matching. If the file name If the above keyword group is not included in, the confidentiality level of the data file can be determined to be level 0 according to the second result of the match.
[0051] Step 102, store the data file in the designated virtual storage area, and execute step 103.
[0052] In an embodiment, the virtual storage area may be a specific disk array part on the disk of the terminal device that is used to store data files that require security measures. When the user needs to access the data files stored in the virtual storage area , Virtual applications that are isolated from the operating system of the terminal device (including storage isolation, memory isolation, etc.) can be started through virtualization technology, and the data files stored in the virtual storage area can be accessed through the virtual application, so that any data file stored in the virtual storage area can be accessed. The operations of data files in the virtual storage area are all isolated in the virtual environment to prevent data files from being leaked.
[0053] In another embodiment, the virtual storage area may be a specific disk array part on the disk of the cloud server that is used to store data files that require security measures. When the user's terminal device cannot store data files or does not When data files can be kept confidential, virtual applications that are isolated from the operating system of the terminal device (including storage isolation, memory isolation, etc.) can be started through virtualization technology, and the virtual applications stored on the cloud server can be accessed through the virtual application. The data files in the storage area, so that any operation on the data files stored in the virtual storage area can be isolated in the virtual environment of the cloud server, so as to prevent the data files from being leaked.
[0054] Step 103: Generate a stub file at the original storage location of the data file. The stub file is used to record the access rights of the data file and the storage location of the data file in the virtual storage area, and the process ends.
[0055] In an embodiment, the content recorded in the stub file includes the access permission of the data file and the storage location of the data file in the virtual storage area. In an embodiment, when the user clicks on the stub file, the user can be determined first. Whether the user has access permission, the storage location of the data file in the virtual storage area can only be known when the user has the access permission, and then the data file can be accessed from the storage location of the virtual storage area; if the user does not have the access permission, the user can be rejected Lookup operation.
[0056] Step 104: Use the data file as a common file for the user to use, and the process ends.
[0057] In an embodiment, for reading a common file, reference may be made to the description of the prior art, which is not described in detail in this disclosure.
[0058] It can be seen from the above description that when the embodiment of the present invention determines that the data file is a confidential file, the data file is stored in the designated virtual storage area, so that any operation on the data file stored in the virtual storage area can be isolated. In a virtual environment, avoid data files from being leaked; by generating a stub file in the original storage location of the data file, the stub file only records the access rights of the data file and the storage location of the data file in the virtual storage area, and does not carry the data file Any data of itself, so all operations of the user on the stub file will not have any impact on the data file.
[0059] FIG. 2 shows a schematic flowchart of a data file protection method according to another exemplary embodiment of the present invention. As shown in FIG. 2, the method includes the following steps:
[0060] Step 201: When the first instruction of the user to share the data file to the shared user designated by the user is monitored, the user information of the shared user is determined.
[0061] In an embodiment, when a user can share a data file with other users, he can start sharing the stub file to the designated shared user through the client application of the terminal device or the stub file sharing button. In an embodiment, the user information may include the account of the shared user in the client application, and may also include the e-mail address of the shared user that can receive the data file, that is, the user information contained in this application can receive There is no restriction on the address of the data file, as long as the shared user can receive the data file.
[0062] Step 202: Determine whether the shared user has the sharing permission based on the user information. When it is determined that the shared user has the sharing permission, perform step 203. If the shared user does not have the sharing permission, it prompts that sharing is impossible.
[0063] Step 203: Upload the data file to the cloud server for storage.
[0064] In an embodiment, the user can upload the data file to the cloud server for backup storage, and upload the stub file to the cloud server through the client application of the terminal device or the upload button of the stub file. In an implementation In an example, the client application can be control management software installed on the terminal device.
[0065] Step 204: Send a second instruction for instructing the shared user to receive the data file to the shared user according to the user information. After the shared user confirms to receive the data file through his terminal device, the shared user's terminal device The stub file of the data file is generated, and the terminal device of the shared user obtains the data file from the virtual storage area of the cloud server according to the stub file.
[0066] In this embodiment, when a data file needs to be shared, a second instruction for instructing the shared user to receive the data file is sent to the shared user according to the user information, and the shared user confirms the receipt of the data through its terminal device. After the file, the stub file of the data file is generated on the terminal device of the shared user, so the virtual sharing of the stub file realizes the sharing of the data file that needs to be kept confidential, because the real data file is not sent to the shared user , And the stub file only stores the storage location of the data file in the virtual storage area, and does not carry any data information of the data file itself. Therefore, the operation of the shared user on the stub file will not have any impact on the data file, thereby ensuring that the data file is in No secrets will be leaked during the sharing process.
[0067] FIG. 3 shows a schematic flowchart of a method for reading a data file according to an exemplary embodiment of the present invention; as shown in FIG. 3, the method includes the following steps:
[0068] Step 301, when a user click event on the stub file is monitored, determine whether the user has the permission to access the data file according to the access permission recorded in the stub file, and if the user has the permission to access the data file, execute the step
302. If the user does not have the authority to access the data file, it prompts that the user does not have the access authority, and the process ends.
[0069] In an embodiment, a client application installed on the terminal device may be used to monitor the user's click event on the stub file. The client application requires a user with login permission to log in. In an embodiment, The click event can be a double-click to open the stub file, or it can be an open event after triggering a menu. In an embodiment, the client application may record the stub file, so that it can determine whether the clicked file is a stub file or a normal data file.
[0070] Step 302, start the virtual application corresponding to the data file, and execute step 303.
[0071] Step 303: Access the data file through the virtual application program at the storage location of the virtual storage area, and the process ends.
[0072] In step 302 and step 303, in one embodiment, the virtual application program is an application program after the virtualized control management software installed on the terminal device, which can be isolated from the operating system of the terminal device. In one embodiment In the virtual application, the isolation of the virtual application and the operating system can include not only the storage isolation from the operating system, but also the memory isolation from the operating system, etc., so as to ensure that any user operations on the data file are isolated from the virtual application. In the virtual environment, illegal users are prevented from obtaining any data resources in the virtual application program through the outside of the virtual application program. In an embodiment, the user's access to the data file through the virtual application program may include normal reading, editing, using a clipboard, and so on.
[0073] In this embodiment, after it is determined that the user has the permission to access the data file, the data file is accessed through the virtual application in the storage location of the virtual storage area, thereby ensuring that any operation of the data file by the user is isolated in the virtual application. In the determined virtual environment, illegal users are prevented from obtaining any data resources in the virtual application through the outside of the virtual application.
[0074] FIG. 4 shows a schematic flowchart of a method for reading a data file according to another exemplary embodiment of the present invention; in this embodiment, the stub file is stored on the terminal device, and the data file is stored on the virtual server of the cloud server. The storage area is illustrated by how the terminal device obtains the data file from the cloud server through the stub file, as shown in Figure 4, including the following steps:
[0075] Step 401: After detecting that the user clicks on the stub file and opens the stub file, the terminal device starts the Remote Desktop Protocol (RDP) component according to the information recorded in the stub file, and connects to the cloud server through the RDP component .
[0076] Step 402, the terminal device transmits the information recorded in the stub file to the cloud server through the RDP component.
[0077] In an embodiment, the data information recorded in the stub file has been encrypted by the client application, and the encrypted data information records the data file corresponding to the stub file, the user authority to view the data file, and data file sharing Circulation process, open and use the relevant history of the data file.
[0078] Step 403: After the cloud server verifies the transmitted information, the cloud server starts the remote virtualization program on the terminal device, and opens the data file stored on the cloud server according to the virtual storage location recorded in the stub file.
[0079] In an embodiment, the transmitted information may include the user authority of the client application, the information that the user needs to be authenticated, and the virtual storage path of the data file requested to be opened on the cloud server.
[0080] Step 404, the cloud server maps the document editor to the terminal device.
[0081] In an embodiment, the cloud server can create a new editable file through a document editor (for example, word), and transmit the entire visual form of the editable file to the local terminal device, so that the A remote document editor is mapped on the terminal device.
[0082] Step 405, the terminal device uses a document editor to operate the data file stored on the cloud server.
[0083] In an embodiment, the operations on the data file may include viewing and editing the content of the data file, and copying the data file, etc. The present disclosure does not limit the specific operations on the data file.
[0084] In an exemplary scenario, after the shared user receives the stub file through the embodiment shown in FIG. 2, when the shared user needs to obtain the data file from the cloud server according to the stub file, In this embodiment, the data file is obtained from the virtual storage area of the cloud server. In another exemplary scenario, if the disk of the terminal device is limited by storage space or the disk of the terminal device is not provided with a virtual storage area, the data file is stored in the virtual storage area of the cloud server. In this case, when the terminal When the user of the device needs to obtain the data file from the remote server according to the stub file, the data file can also be obtained from the virtual storage area of the cloud server through this embodiment. In another exemplary scenario, when a user needs to operate a data file from a cloud server through a different terminal device, the above method can also be used to remotely read the data file. For example, the user generates a data file on the terminal device A. The stub file is stored in the virtual storage area of the terminal device A. When the user sends the stub file from the terminal device A to the terminal device B, and the terminal device A uploads the data file to the cloud server, if the user needs If the data file is read from the terminal device B, the data file can be operated from the cloud server through this embodiment.
[0085] Through the above embodiments, due to the high cost of implementation of application virtualization such as Citrix XenApp in the prior art, this application adopts an application virtualization solution based on the RDP protocol, and any Windows operating system can be used, and the remote desktop RDP protocol can be used. , RDP control components, message hooks, and window tailoring technology to realize remote application virtualization technology, avoid dependence on the operating system, so that the cloud server can use any Windows operating system, so it has more flexibility.
[0086] On the basis of the above-mentioned embodiments shown in FIG. 1 to FIG. 4, when the data file is operated by the user, it is also possible to monitor the user's operation on the data file through the client application installed on the terminal device; In one embodiment, the user's operation on the data file can be either the user's operation on the data file on the terminal device, or the user's operation on the data file by the cloud server mapped to the document editor on the terminal device. Therefore, all data file-oriented behaviors such as the opening, operation, and circulation of data files can be effectively monitored and managed.
[0087] Corresponding to the above-mentioned data file protection method, the present application also proposes a schematic structural diagram of the terminal device according to an exemplary embodiment of the present application shown in FIG. 5. Please refer to Figure 5. At the hardware level, the terminal device includes a processor, internal bus, network interface, memory, and non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs, forming a protection device for the data file on the logical level. Of course, in addition to software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and may also be Hardware or logic device.
[0088] Corresponding to the foregoing method for reading data files, the present application also proposes a schematic structural diagram of a terminal device according to another exemplary embodiment of the present application shown in FIG. 6. Please refer to Figure 6. At the hardware level, the terminal device includes a processor, internal bus, network interface, memory, and non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs, forming a device for reading data files on a logical level. Of course, in addition to the software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and can also be Hardware or logic device.
[0089] FIG. 7 is a schematic structural diagram of a data file protection device according to an exemplary embodiment of the present invention; as shown in FIG. 7, in a software implementation, the data file protection device may include: a first determination module 71. The storage module 72 and the stub generation module 73. among them:
[0090] The first determining module 71 is configured to determine the confidentiality level of the data file and the original storage location of the data file when it is detected that a data file is generated on the terminal device;
[0091] The storage module 72 is configured to store the data file in a designated virtual storage area if the confidentiality level determined by the first determination module 71 indicates that the data file is a confidential file;
[0092] The stub generation module 73 is configured to generate a stub file at the original storage location determined by the first determination module 71, and the stub file is used to record the access permission of the data file and the storage location of the data file in the virtual storage area.
[0093] FIG. 8 shows a schematic structural diagram of a data file protection device according to another exemplary embodiment of the present invention. Based on the above-mentioned embodiment shown in FIG. 7, the first determining module 71 may include:
[0094] The first determining unit 711 is configured to determine the content information of the data file;
[0095] The first matching unit 712 is configured to match the content information determined by the first determining unit 711 with a first preset condition, and determine the confidentiality level of the data file according to the first result of the matching; and/or,
[0096] The second determining unit 713 is used to determine the file name of the data file;
[0097] The second matching unit 714 is configured to match the file name determined by the second determining unit 713 with a second preset condition, and determine the confidentiality level of the data file according to the second result of the matching.
[0098] In an embodiment, the device may further include:
[0099] The second determining module 74 is configured to determine the user information of the shared user when the user needs to share the data file stored in the storage module 72 with the first instruction of the user designated by the user to be shared;
[0100] The sending module 75 is configured to send a second instruction for instructing the shared user to receive the data file to the shared user according to the user information determined by the second determining module 74, and the shared user confirms to receive the data through the corresponding terminal device After the file, a stub file of the data file is generated on the terminal device of the shared user.
[0101] In an embodiment, the device may further include:
[0102] The third determining module 76 uses the user information determined according to the second determining module 74 to determine whether the shared user has the sharing authority;
[0103] The uploading module 77 is used to upload the data file to the cloud server for storage when the third determining module 76 determines that the shared user has the sharing authority, so that the shared user obtains it from the virtual storage area of the cloud server according to the stub file To the data file.
[0104] In an embodiment, the device may further include:
[0105] The monitoring module 78, when the data file stored in the storage module 72 is operated by the user, monitors the user's operation on the data file through a client application installed on the terminal device.
[0106] FIG. 9 shows a schematic structural diagram of an apparatus for reading a data file according to an exemplary embodiment of the present invention; in a software implementation, as shown in FIG. 9, the apparatus for reading a data file may include: Four determining module 91, starting module 92, and accessing module 93; among them:
[0107] The fourth determining module 91 is configured to determine whether the user has the authority to access the data file according to the access authority recorded in the stub file when the user's click event on the stub file is monitored;
[0108] The activation module 92 is configured to activate the virtual application corresponding to the data file if the fourth determining module 91 determines that the user has the permission to access the data file;
[0109] The access module 93 is used to access the data file stored in the storage location of the virtual storage area recorded in the stub file through the virtual application program started by the startup module 92.
[0110] FIG. 10 shows a schematic structural diagram of an apparatus for reading a data file according to another exemplary embodiment of the present invention; on the basis of the embodiment shown in FIG. 9, the access module 93 may include:
[0111] The network connection unit 931 is configured to connect to the cloud server through the remote desktop protocol component according to the information recorded in the stub file;
[0112] The transmission unit 932 is used to transmit the information recorded in the stub file to the cloud server through the remote desktop protocol component, so that the cloud server can start the remote virtualization program on the terminal device after passing the verification of the information recorded in the storage file, according to The virtual storage location recorded in the stub file maps the document editor of the data file stored on the cloud server to the terminal device;
[0113] The operating unit 933 is configured to operate the data file stored on the cloud server through the document editor. [0114] It can be seen from the above embodiment that when the application determines that the data file is a confidential file, the data file is stored in the designated virtual storage area, so that any operation on the data file stored in the virtual storage area can be isolated in the virtual storage area. In the environment, avoid data files from being leaked; by generating a stub file in the original storage location of the data file, the stub file only records the access rights of the data file and the storage location of the data file in the virtual storage area, and does not carry the data file itself. Any data, so all operations of the user on the stub file will not have any impact on the data file.
[0115] After considering and practicing the invention disclosed herein, those skilled in the art will easily think of other embodiments of the present application. This application is intended to cover any variations, uses, or adaptive changes of this application. These variations, uses, or adaptive changes follow the general principles of this application and include common knowledge or customary technical means in the technical field that are not disclosed in this application. . And the embodiments are only regarded as exemplary, and the true scope and spirit of the application are pointed out by the following claims.
[0116] It should also be noted that the terms "including", "including" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, It also includes other elements that are not explicitly listed, or elements inherent to the process, method, commodity, or equipment. If there are no more restrictions, the element defined by the sentence "including a..." does not exclude the existence of other identical elements in the process, method, commodity, or equipment that includes the element.
[0117] The above descriptions are only preferred embodiments of this application, and are not intended to limit this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall include Within the scope of protection of this application.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN115086308A | Cited by | China | – | Search report | – |
| CN109726041A | Cited by | China | – | Search report | – |
| CN101187994A | Cites | China | Y | Search report | 2?9 |
| CN102004886A | Cites | China | Y | Search report | 1-3,5-6,8-10,12-13,15-16 |
| CN102882923A | Cites | China | Y | Search report | 4?6-7?11?13-14?16 |
| CN103262024A | Cites | China | Y | Search report | 1-16 |
| CN103620606A | Cites | China | A | Search report | 1-16 |
| WO2008095237A1 | Cites | World Intellectual Property Organization (WIPO) | Y | Search report | 1-3,5-6,8-10,12-13,15-16 |
| US2012290926A1 | Cites | United States of America | A | Search report | 1-16 |
| US2013024424A1 | Cites | United States of America | YX | Search report | 2?4?6-7?9?11?13-14?16 |
| US2014157363A1 | Cites | United States of America | Y | Search report | 1-3,5-6,8-10,12-13,15-16 |
15 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510295401 | China | A | |
| CN201510295401 | – | – | – |
| CN20151295401 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| US2016357978A1 | United States of America | A1 | |
| WO2016196030A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN106295386AThis record | China | A | |
| TW201702925A | Taiwan Province of China | A | |
| KR20170133485A | Republic of Korea | A | |
| EP3304275A1 | European Patent Office (EPO) | A1 | |
| JP2018522320A | Japan | A | |
| US10114962B2 | United States of America | B2 | |
| EP3304275A4 | European Patent Office (EPO) | A4 | |
| US2019087596A1 | United States of America | A1 | |
| JP6511161B2 | Japan | B2 | |
| KR102037656B1 | Republic of Korea | B1 | |
| TWI690821B | Taiwan Province of China | B | |
| EP3304275B1 | European Patent Office (EPO) | B1 | |
| CN106295386B | China | B |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent grantGrantedGR01 | GR01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 106295386
- Publication, DOCDB
- 106295386
- Publication, EPODOC
- CN106295386
- Application
- 102954019
- Application, DOCDB
- 201510295401
- Application, EPODOC
- CN201510295401
Titles3
- Chinese
- 数据文件的保护方法、装置及终端设备
- English
- Data file protection method, device and terminal equipment
- English
- Data file protection method and apparatus and terminal device
Classification
- CPC, 16
- G06F21/6209
- G06F21/6218
- G06F21/74
- G06F2221/2141
- G06F21/53
- G06F21/6272
- H04L63/101
- H04L63/102
- H04L63/105
- H04L67/10
- G06F16/00
- G06F16/122
- H04L69/00
- G06F3/06
- G06F21/604
- H04L63/10
- IPC, 2
- G06F21 62
- G06F21 74