CN106295386A

Data file protection method and apparatus and terminal device

Abstract

The invention provides a data file protection method and apparatus and a terminal device. The method comprises: when it is detected that a data file is generated on the terminal device, determining the confidential degree of the data file; if the confidential degree indicates that the data file is a confidential file, storing the data file to a specified virtual storage region; and generating a stub file in an original storage location of the data file, wherein the stub file is used to record a consulting authority limit of the data file and a storage location of the data file in the virtual storage region. The technical solution of the present invention may make any operation on a data file stored in the virtual storage region isolated in a virtual environment, so as to prevent the data file from being leaked.

Term

8.7 yearsto projected expiry

Projected expiry 2 June 2035, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 7 independent, 8 dependent

  1. 1
    A method for protecting data files, which is applied to a terminal device, is characterized in that the method includes:determining the confidentiality level of the data file when it is detected that a data file is generated on the terminal device;The level indicates that the data file is a confidential file, and the data file is stored in a designated virtual storage area;a stub file is generated at the original storage location of the data file, and the stub file is used to record the access rights of the data file And the storage location of the data file in the virtual storage area. 1. 一种数据文件的保护方法,应用在终端设备上,其特征在于,所述方法包括: 在检测到所述终端设备上有数据文件生成时,确定所述数据文件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域; 在所述数据文件的原始存储位置生成存根文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
  2. 5
    The method according to any one of claims 1-4, wherein the method further comprises:when the data file is operated by the user, monitoring the data file by a client application installed on the terminal device Describe the operations performed by the user on the data file. 5. 根据权利要求1-4任一所述的方法,其特征在于,所述方法还包括: 在所述数据文件被所述用户操作时,通过安装在所述终端设备上的客户端应用程序监 控所述用户对所述数据文件所进行的操作。
  3. 6
    A method for reading a data file, applied on a terminal device, characterized in that the method includes:when a user click event on a stub file is monitored, determining the user according to the access permission recorded in the stub file Whether the user has the permission to access the data file;if the user has the permission to access the data file, start the virtual application corresponding to the data file;access the recorded data stored in the stub file through the virtual application The data file in the storage location of the virtual storage area. 6. 一种读取数据文件的方法,应用在终端设备上,其特征在于,所述方法包括: 在监听到用户关于存根文件的点击事件时,根据所述存根文件所记录的查阅权限确定 所述用户是否有访问所述数据文件的权限; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件。
  4. 11
    12. The device according to any one of claims 8-11, wherein the device further comprises:a monitoring module, configured to install the data file stored in the storage module by the user when the data file stored in the storage module is operated by the user. The client application on the terminal device monitors the operation performed by the user on the data file. 12. 根据权利要求8-11任一所述的装置,其特征在于,所述装置还包括: 监控模块,用于在所述存储模块存储的所述数据文件被所述用户操作时,通过安装在 所述终端设备上的客户端应用程序监控所述用户对所述数据文件所进行的操作。
  5. 12
    13. A device for reading a data file, which is applied to a terminal device, is characterized in that the device includes:a fourth determining module, which is used to monitor a user's click event on a stub file according to the record of the stub file To determine whether the user has the right to access the data file;13. 一种读取数据文件的装置,应用在终端设备上,其特征在于,所述装置包括: 第四确定模块,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件所 记录的查阅权限确定所述用户是否有访问所述数据文件的权限; The activation module is configured to activate the virtual application corresponding to the data file if the fourth determining module determines that the user has the authority to access the data file;the access module is configured to activate the virtual application program that is activated by the activation module The virtual application program accesses the data file stored in the storage location of the virtual storage area recorded by the stub file. 启动模块,用于如果所述第四确定模块确定所述用户有访问所述数据文件的权限,启 动所述数据文件对应的虚拟应用程序; 访问模块,用于通过所述启动模块启动的所述虚拟应用程序访问存储在所述存根文件 所记录的虚拟存储区域的存储位置的所述数据文件。
  6. 14
    15. A terminal device, characterized in that, the terminal device includes:a processor;a memory for storing executable instructions of the processor;wherein the processor is configured to detect that there is data on the terminal device When the file is generated, determine the confidentiality level of the data file;if the confidentiality level indicates that the data file is a confidential file, store the data file in the designated virtual storage area;generate at the original storage location of the data file A stub file, where the stub file is used to record the access rights of the data file and the storage location of the data file in the virtual storage area. 15. 一种终端设备,其特征在于,所述终端设备包括: 处理器;用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在检测到所述终端设备上有数据文件生成时,确定所述数据文 件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域; 在所述数据文件的原始存储位置生成存根文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
  7. 15
    16. A terminal device, characterized in that, the terminal device includes:a processor;and a memory for storing executable instructions of the processor;wherein, the processor is configured to monitor a user's click on a stub file In an event, determine whether the user has the permission to access the data file according to the access permission recorded in the stub file;if the user has the permission to access the data file, start the virtual application corresponding to the data file Accessing the data file stored in the storage location of the virtual storage area recorded in the stub file through the virtual application. 16. 一种终端设备,其特征在于,所述终端设备包括: 处理器;以及用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件 所记录的查阅权限确定所述用户是否有访问所述数据文件的权限; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件。