Nova Patents
CN106295386B

Protecting data files

Abstract

This application provides a data file protection method, device, and terminal device. The method includes: determining the confidentiality level of the data file when it is detected that the data file is generated on the terminal device; The data file is a confidential file, and the data file is stored in a designated virtual storage area; a stub file is generated in the original storage location of the data file, and the stub file is used to record the access rights of the data file and the The storage location of the data file in the virtual storage area. In the technical solution of the present invention, any operation on the data file stored in the virtual storage area can be isolated in the virtual environment, so as to prevent the data file from being leaked.

CN106295386B, drawing sheet 1
Sheet 1 of 1

Term

8.7 yearsleft in the term

Expires 2 June 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

16 claims: 8 independent, 8 dependent

  1. 1
    1 A method for protecting data files, applied to a terminal device, characterized in that, the method includes:determining the confidentiality level of the data file when it is detected that a data file is generated on the terminal device;if said The confidentiality level indicates that the data file is a confidential file, and the data file is stored in a designated virtual storage area. The data file stored in the virtual storage area is accessed through a virtual application program, so that the data file stored in the virtual storage area can be accessed by a virtual application. The operations of the data files are all isolated in a virtual environment, the virtual application is a virtual application isolated from the operating system of the terminal device;a stub file that does not carry the data of the data file itself is generated, and the stub file is stored The original storage location of the data file is used to monitor whether a user accesses the data file, and the stub file is used to record the access permission of the data file and the storage location of the data file in the virtual storage area. 1 .一种数据文件的保护方法,应用在终端设备上,其特征在于,所述方法包括: 在检测到所述终端设备上有数据文件生成时,确定所述数据文件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域,其中,存储在虚拟存储区域内的数据文件通过虚拟应用程序访问,以使对存储在 虚拟存储区域的数据文件的操作都被隔离在虚拟环境中,所述虚拟应用程序是与终端设备 的操作系统相隔离的虚拟应用程序; 生成未携带所述数据文件本身数据的存根文件,将所述存根文件存储在所述数据文件 的原始存储位置以监听用户是否访问所述数据文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
  2. 5
    5 The method according to any one of claims 1-4, wherein the method further comprises:when the data file is operated by the user, monitoring through a client application installed on the terminal device The operation performed by the user on the data file. 5 .根据权利要求1-4任一所述的方法,其特征在于,所述方法还包括: 在所述数据文件被所述用户操作时,通过安装在所述终端设备上的客户端应用程序监 控所述用户对所述数据文件所进行的操作。
  3. 6
    6 A data file protection method, applied to a terminal device, characterized in that the method comprises:when a user click event on a stub file is monitored, determining the user according to the access rights recorded in the stub file Whether there is permission to access the data file;wherein, the stub file is stored in the original storage location of the data file;the stub file does not carry the data of the data file itself;if the user has access to the data File permissions, start the virtual application program corresponding to the data file, where the virtual application program is a virtual application program isolated from the operating system of the terminal device;access the records stored in the stub file through the virtual application program The data files in the storage location of the virtual storage area are isolated in the virtual environment so that operations on the data files stored in the virtual storage area are all isolated. 6 .一种数据文件的保护方法,应用在终端设备上,其特征在于,所述方法包括: 在监听到用户关于存根文件的点击事件时,根据所述存根文件所记录的查阅权限确定 所述用户是否有访问所述数据文件的权限;其中,所述存根文件存储在所述数据文件的原 始存储位置;所述存根文件未携带所述数据文件本身的数据; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序, 所述虚拟应用程序是与终端设备的操作系统相隔离的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件,以使对存储在虚拟存储区域的数据文件的操作都被隔离在虚拟环境中。
  4. 8
    8 A device for protecting data files, applied to a terminal device, characterized in that the device includes:a first determining module, configured to determine the data file when it is detected that a data file is generated on the terminal device The confidentiality level of the data file and the original storage location of the data file;a storage module for storing the data file in the terminal if the confidentiality level determined by the first determining module indicates that the data file is a confidential file A virtual storage area on the device, where data files stored in the virtual storage area are accessed through a virtual application program, so that operations on the data files stored in the virtual storage area are all isolated in the virtual environment. The virtual application program It is a virtual application program isolated from the operating system of the terminal device;a stub generation module is used to generate a stub file that does not carry the data of the data file itself, and store the stub file in the original storage location of the data file to monitor Whether the user accesses the data file, the stub file is used to record the access permission of the data file and the storage location of the data file in the virtual storage area. 8 .一种数据文件的保护装置,应用在终端设备上,其特征在于,所述装置包括: 第一确定模块,用于在检测到所述终端设备上有数据文件生成时,确定所述数据文件 的机密等级以及所述数据文件的原始存储位置; 存储模块,用于如果所述第一确定模块确定的所述机密等级表示所述数据文件为机密 文件,将所述数据文件存储到所述终端设备上的虚拟存储区域,其中,存储在虚拟存储区域 内的数据文件通过虚拟应用程序访问,以使对存储在虚拟存储区域的数据文件的操作都被 隔离在虚拟环境中,所述虚拟应用程序是与终端设备的操作系统相隔离的虚拟应用程序; 存根生成模块,用于生成未携带所述数据文件本身数据的存根文件,将所述存根文件 存储在所述数据文件的原始存储位置以监听用户是否访问所述数据文件,所述存根文件用 于记录所述数据文件的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
  5. 12
    12 The device according to any one of claims 8-11, wherein the device further comprises:a monitoring module, configured to install the data file stored in the storage module by the user when the data file is operated by the user. The client application on the terminal device monitors the operation performed by the user on the data file. 12 .根据权利要求8-11任一所述的装置,其特征在于,所述装置还包括: 监控模块,用于在所述存储模块存储的所述数据文件被所述用户操作时,通过安装在 所述终端设备上的客户端应用程序监控所述用户对所述数据文件所进行的操作。
  6. 13
    13 A device for protecting data files, applied to a terminal device, characterized in that the device comprises:a fourth determining module, which is used to monitor the users click event on the stub file according to the record of the stub file The access authority determines whether the user has the authority to access the data file;wherein the stub file is stored in the original storage location of the data file;the stub file does not carry the data of the data file itself;the startup module is used If the fourth determining module determines that the user has the right to access the data file, start the virtual application program corresponding to the data file, and the virtual application program is a virtual application program isolated from the operating system of the terminal device Access module, configured to access the data file stored in the storage location of the virtual storage area recorded in the stub file by the virtual application program started by the startup module, so that the data stored in the virtual storage area File operations are isolated in the virtual environment. 13 .一种数据文件的保护装置,应用在终端设备上,其特征在于,所述装置包括: 第四确定模块,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件所 记录的查阅权限确定所述用户是否有访问数据文件的权限;其中,所述存根文件存储在所 述数据文件的原始存储位置;所述存根文件未携带所述数据文件本身的数据; 启动模块,用于如果所述第四确定模块确定所述用户有访问所述数据文件的权限,启 动所述数据文件对应的虚拟应用程序,所述虚拟应用程序是与终端设备的操作系统相隔离 的虚拟应用程序; 访问模块,用于通过所述启动模块启动的所述虚拟应用程序访问存储在所述存根文件 所记录的虚拟存储区域的存储位置的所述数据文件,以使对存储在虚拟存储区域的数据文 件的操作都被隔离在虚拟环境中。
  7. 15
    15 A terminal device, characterized in that the terminal device includes:a processor;a memory for storing executable instructions of the processor;wherein the processor is configured to detect that the terminal device has When the data file is generated, the confidentiality level of the data file is determined;if the confidentiality level indicates that the data file is a confidential file, store the data file in a designated virtual storage area, where the data file stored in the virtual storage area The data file is accessed through a virtual application program, so that operations on the data file stored in the virtual storage area are isolated in the virtual environment. The virtual application program is a virtual application program isolated from the operating system of the terminal device;A stub file carrying the data of the data file itself, the stub file is stored in the original storage location of the data file to monitor whether a user accesses the data file, and the stub file is used to record the access rights of the data file And the storage location of the data file in the virtual storage area. 15 .一种终端设备,其特征在于,所述终端设备包括: 处理器;用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在检测到所述终端设备上有数据文件生成时,确定所述数据文 件的机密等级; 如果所述机密等级表示所述数据文件为机密文件,将所述数据文件存储到指定的虚拟 存储区域,其中,存储在虚拟存储区域内的数据文件通过虚拟应用程序访问,以使对存储在 虚拟存储区域的数据文件的操作都被隔离在虚拟环境中,所述虚拟应用程序是与终端设备 的操作系统相隔离的虚拟应用程序; 生成未携带所述数据文件本身数据的存根文件,将所述存根文件存储在所述数据文件 的原始存储位置以监听用户是否访问所述数据文件,所述存根文件用于记录所述数据文件 的查阅权限和所述数据文件在所述虚拟存储区域的存储位置。
  8. 16
    16 A terminal device, characterized in that, the terminal device includes:a processor;and a memory for storing executable instructions of the processor;wherein, the processor is used to monitor the user's information about the stub file When the event is clicked, it is determined whether the user has the permission to access the data file according to the access permission recorded in the stub file;wherein the stub file is stored in the original storage location of the data file;the stub file does not carry all the data files. The data of the data file itself;if the user has the permission to access the data file, start the virtual application corresponding to the data file, 16 . 一种终端设备,其特征在于,所述终端设备包括: 处理器;以及用于存储所述处理器可执行指令的存储器; 其中,所述处理器,用于在监听到用户关于存根文件的点击事件时,根据所述存根文件 所记录的查阅权限确定所述用户是否有访问数据文件的权限;其中,所述存根文件存储在 所述数据文件的原始存储位置;所述存根文件未携带所述数据文件本身的数据; 如果所述用户有访问所述数据文件的权限,启动所述数据文件对应的虚拟应用程序, The virtual application program is a virtual application program isolated from the operating system of the terminal device;the data file stored in the storage location of the virtual storage area recorded by the stub file is accessed through the virtual application program, so that the The operations of data files stored in the virtual storage area are all isolated in the virtual environment. 所述虚拟应用程序是与终端设备的操作系统相隔离的虚拟应用程序; 通过所述虚拟应用程序访问存储在所述存根文件所记录的虚拟存储区域的存储位置 的所述数据文件,以使对存储在虚拟存储区域的数据文件的操作都被隔离在虚拟环境中。