Dynamic data privacy protection evaluation method and system based on big data analysis

The dynamic data privacy protection assessment method based on big data analysis comprehensively considers multiple factors of information for dynamic evaluation and allocation of encryption methods, which solves the problems of resource waste and insufficient security in existing technologies and achieves more efficient information security protection.

CN120930170AActive Publication Date: 2025-11-11WUXI UNIV

Patent Information

Application Number
CN202511454970.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-13
Publication Date
2025-11-11
Estimated Expiration
2045-10-13

AI Technical Summary

Technical Problem

Existing information security protection methods cannot dynamically assess and allocate encryption methods based on the actual situation of the information, resulting in wasted resources and insufficient security.

Method used

Through big data analysis, considering factors such as the type of information privacy, correlation and deduction, information volume, theft situation and theft methods, dynamic evaluation is conducted and encryption methods are allocated, including information importance analysis, risk assessment and theft harm assessment.

Benefits of technology

It enables dynamic allocation of encryption methods, improves information security, optimizes resource utilization, and provides more comprehensive evaluation indicators and more accurate security decision support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930170A_ABST
    Figure CN120930170A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of privacy protection, in particular to a dynamic data privacy protection evaluation method and system based on big data analysis, and the method carries out the analysis of information importance based on the privacy type condition, the correlation derivation condition and the information amount condition of information in a corresponding scene. The corresponding information risk is evaluated through the analysis of the stealing condition of the corresponding information in the scene and the stealing means in the scene, and the information stealing hazard is evaluated through the information importance analysis result, the information risk evaluation result and the hazard condition generated by stealing. The encryption means are dynamically allocated according to the information stealing hazard assessment results of different levels, and the encryption means are dynamically allocated according to the information stealing hazard assessment results of different levels, so that waste of resources can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of privacy protection technology, and in particular to a dynamic data privacy protection assessment method and system based on big data analysis. Background Technology

[0002] Traditional information security protection methods often employ uniform encryption techniques to protect all information to the same degree. This approach has several shortcomings. On the one hand, using advanced encryption techniques for information of lower importance and less risk can lead to a waste of resources. On the other hand, simple encryption techniques may not provide sufficient security for information of high importance and greater risk. Furthermore, existing information security assessment methods often focus only on one or a few aspects of information, such as its importance or risk, without comprehensively considering multiple factors such as the type of privacy, the correlation and deduction of information, the amount of information, the theft situation, the theft methods, and the harm caused by the theft. This results in assessment results that are not comprehensive and accurate enough to provide a scientific basis for information security decisions.

[0003] Therefore, a more scientific and reasonable method for information security protection is needed, which can dynamically assess and allocate encryption methods based on the actual situation of the information. The information theft hazard assessment and encryption method proposed in this application achieves dynamic allocation of encryption methods by comprehensively analyzing and assessing multiple factors such as the privacy type of the information, the correlation derivation, the amount of information, the theft situation, the theft method, and the harm caused by the theft. This effectively improves information security and optimizes resource utilization. Summary of the Invention

[0004] To overcome the defects and shortcomings of existing technologies, this invention provides a dynamic data privacy protection assessment method and system based on big data analysis.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a dynamic data privacy protection assessment method based on big data analysis, comprising the following steps: Step S1: Obtain information on the privacy type and amount of information, and at the same time, obtain information on the theft of corresponding information in the scenario; Step S2: Analyze the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario; Step S3: Assess the risk of the corresponding information by analyzing the theft situation and the theft methods in the scenario; Step S4: Conduct a hazard assessment of information theft based on the results of information importance analysis, information risk assessment, and the harm caused by the theft. Step S5: Dynamically allocate encryption methods based on the information theft hazard assessment results of different levels.

[0006] In one implementation of the present invention, step S1 includes the following specific contents: obtaining file information that needs to be encrypted; classifying the file information into information types through a natural language extraction terminal; extracting the information types that need to be encrypted from the set encryption types, including names, IDs, transaction records, ID card numbers, and phone numbers; setting encryption types by manually setting the privacy information types that need to be encrypted in the scenario and storing them in the corresponding storage modules; simultaneously obtaining the information quantity of each information type that needs to be encrypted; the theft situation of the corresponding information is the number of times each information type that needs to be encrypted has been attacked and the means of attack in the corresponding historical scenario, obtained through historical data, wherein the means of attack are the theft paths that have occurred in the scenario in the past.

[0007] In one implementation of the present invention, the analysis of information importance in step S2 includes the following specific steps: S21. Obtain the data volume of various encrypted information types and the data of various encrypted file information. Obtain the probability of each encrypted information type appearing in the corresponding information type in historical encrypted files, and substitute it into the entropy calculation formula to calculate the Shannon entropy of the content of the corresponding encrypted information type. The Shannon entropy calculation formula is as follows: Where N is the number of contents of each type of encrypted information, p(xi) is the probability of the i-th content of each type of encrypted information appearing in the corresponding information type in the historical encrypted file, and log is the logarithmic function; this step can quantify the uncertainty of the contents of each type of encrypted information. By calculating Shannon entropy, we can clearly understand the degree of disorder and complexity of the contents of each type of encrypted information. The higher the entropy value, the more uncertain and difficult to predict the contents of the encrypted information type, which means that it may contain more valuable information or be more vulnerable to attack. S22. Obtain the Shannon entropy of the content of each encrypted information type. Simultaneously, combine the content of any two or more encrypted information types, and substitute the content of these two or more combined encrypted information types into the entropy calculation formula to calculate the Shannon entropy of the combined type content. By obtaining the Shannon entropy of the content of each corresponding encrypted information type separately, summing the Shannon entropy of the combined type content with one identical encrypted information type, and dividing by the sum of the Shannon entropies of all encrypted information combined type content of the corresponding combined type, the association anomaly value of the corresponding encrypted information type is obtained. The association anomaly value reflects the potential privacy leakage after combination. Individual entropy of certain fields... The value is low, but it may leak privacy when combined with other fields. The information importance of the corresponding encrypted information type is obtained by the ratio of the Shannon entropy of the corresponding encrypted information type to the set security Shannon entropy. The association importance of the corresponding encrypted information type is obtained by dividing the set association anomaly threshold by the association anomaly value of the corresponding encrypted information type. The protection importance of the corresponding encrypted information type is obtained by weighted summing of the information importance and association importance. This step not only considers the Shannon entropy of a single encrypted information type, but also deeply analyzes the Shannon entropy after the combination of any two or more encrypted information types. By calculating correlation outliers, we can identify encrypted information types that have low individual entropy values ​​but may leak privacy when combined with other fields. This is crucial for protecting user privacy and sensitive information because, in practice, attackers may combine different information to obtain valuable private data. At the same time, by calculating the importance of information and correlation, and then performing a weighted sum to obtain the protection importance, we can comprehensively consider the uncertainty of the information itself and the privacy risks brought about by information combination. This provides a more comprehensive and accurate evaluation indicator for the protection of encrypted information. This can help enterprises and organizations better allocate resources and give more attention and protection to encrypted information types with higher protection importance. S23. Divide the information content of the corresponding encrypted information type by the information content threshold to obtain the information content importance of the corresponding encrypted information type; this process evaluates the encrypted information type from the perspective of information content. S24. The importance of the information quantity of the corresponding encrypted information type is obtained by summing the importance of the protection of the information quantity of the corresponding encrypted information type. This process comprehensively considers factors such as information uncertainty, privacy risks and information quantity. Through this comprehensive evaluation, a more accurate and comprehensive indicator of the importance of encrypted information type can be obtained.

[0008] In one implementation of the present invention, the assessment of information risk in step S3 includes the following specific aspects: S31. Obtain the number of times each type of information that needs to be encrypted has been attacked and the methods of attack in the corresponding historical scenarios. Divide the average success rate of historical attack methods by the average success rate of the overall attack to obtain the degree of danger of the corresponding attack method. S32. Obtain the types of attack methods. The complexity of the attack methods is obtained by weighted summing the number of standardized attack methods and the frequency of change of standardized attack methods. The danger of a single attack method is obtained by adding the danger level of the attack method corresponding to a single attack to the complexity of the attack method. The diversity and variability of attack methods are taken into account. The more types of attack methods there are, the richer the strategies that the attacker may use. S33. Obtain the number of attacks and the risk of each individual attack within a set time period. Sum the risk of the attack methods within the set time period to obtain the information risk of the corresponding information type that needs to be encrypted. This allows for a comprehensive assessment of the security risks faced by a certain type of information that needs to be encrypted from a macro perspective. This assessment method considers the frequency of attacks and the risk of each attack, and can reflect the overall threat level of the information type under attack within a certain period of time. The number of attacks within the set time period reflects the frequency of attacks on the information type, while the risk of each individual attack method reflects the potential harm caused by each attack. By combining the two and summing the risk of the attack methods within the set time period, the overall security risk faced by the information type within that time period can be accurately measured.

[0009] In one implementation of the present invention, the information theft hazard assessment in step S4 includes the following specific contents: S41. Obtain the average loss after each type of information requiring encryption is stolen per unit data volume. This can be economic loss or other losses. By comparing the average loss after the theft of the corresponding type of information requiring encryption with the loss threshold, the impact value of the loss can be obtained. This can present the consequences of information theft in a specific numerical form. Whether it is economic loss or other losses, they can be clearly measured. This helps organizations clearly understand the severity of the theft of different types of information and avoids a vague understanding of the loss. For example, for a company, the theft of customer financial information may lead to direct economic losses, while the theft of the company's R&D data may affect future market competitiveness and innovation capabilities. By quantifying the average loss, these different types of losses can be compared intuitively. S42. Obtain the loss impact value, information importance analysis results, and information risk assessment results for the corresponding information types that need to be encrypted, and then perform a weighted summation to obtain the information theft hazard assessment result. This can comprehensively consider the impact of multiple factors on information security. The loss impact value reflects the actual loss after information is stolen, the information importance analysis results reflect the core position and value of information in the organization, and the information risk assessment results consider the possibility and degree of threat of information being attacked. By integrating these factors through a weighted summation, the degree of harm caused by information theft can be assessed more comprehensively and accurately.

[0010] In one implementation of the present invention, the dynamic allocation of encryption methods in step S5 includes the following specific aspects: The information theft hazard assessment results are compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. If the assessment value is less than 0.3, it is considered low risk; between 0.3 and 0.7, it is considered medium risk; and greater than 0.7, it is considered high risk.

[0011] Secondly, the present invention also provides a dynamic data privacy protection assessment system based on big data analysis, comprising: The data acquisition module acquires information on the privacy type and amount of information, and also acquires information on the theft of corresponding information in the given scenario. The information importance analysis module analyzes the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario. The information risk assessment module assesses the risk of corresponding information by analyzing the theft situation and the theft methods in a given scenario. The theft hazard assessment module assesses the hazard of information theft based on the results of information importance analysis, information risk assessment, and the resulting harm. The dynamic allocation module dynamically allocates encryption methods based on the information theft hazard assessment results at different levels.

[0012] Thirdly, the present invention provides an electronic device comprising: a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes a dynamic data privacy protection assessment method based on big data analysis by calling the computer program stored in the memory.

[0013] Fourthly, the present invention provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform a dynamic data privacy protection assessment method based on big data analysis.

[0014] Compared with the prior art, the present invention has the following advantages and beneficial effects: Based on the privacy types, correlations, and information volume of information in the corresponding scenarios, the importance of information is analyzed. The risk of the corresponding information is assessed by analyzing the theft situation and theft methods in the scenarios. The harm of information theft is assessed by combining the results of the information importance analysis, the results of the information risk assessment, and the harm caused by the theft. Encryption methods are dynamically allocated according to the results of different levels of information theft harm assessment, which can avoid the waste of resources. In the process of analyzing the importance of information, by analyzing the degree of importance of information and the degree of importance of association, we can comprehensively consider the uncertainty of the information itself and the privacy risks brought about by the combination of information, and provide a more comprehensive and accurate assessment indicator for the protection of encrypted information. Attached Figure Description

[0015] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is a schematic diagram of the overall process of Embodiment 1 of the method of the present invention; Figure 2 This is a schematic diagram of step S2 in Embodiment 1 of the method of the present invention; Figure 3 This is a schematic diagram of step S3 in embodiment 1 of the method of the present invention; Figure 4 This is a schematic diagram of the structure of embodiment 2 of the system of the present invention. Detailed Implementation

[0016] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0017] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0018] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places throughout this specification does not necessarily refer to the same embodiment, nor is it a single embodiment or an embodiment selectively excluded from other embodiments.

[0019] Example 1

[0020] like Figures 1 to 3As shown, this embodiment provides a dynamic data privacy protection assessment method based on big data analysis, which specifically includes the following steps: Step S1: Obtain information on the privacy type and amount of information, and at the same time, obtain information on the theft of corresponding information in the scenario; In this embodiment, step S1 includes the following specific content: obtaining the file information to be encrypted, classifying the file information into information types using a natural language extraction terminal, and extracting the information types to be encrypted from the set encryption types, including names, IDs, transaction records, ID card numbers, and phone numbers, etc. The encryption types are obtained by manually setting the privacy information types to be encrypted in the scenario. The specific steps of the natural language extraction terminal classifying the file information into information types are as follows: the terminal first parses unstructured files such as images and PDFs using OCR, or directly reads the text content in structured documents such as Word and Excel to ensure complete extraction of the original information; then, it denoises the extracted text (e.g., removing noise). The system performs several steps: encoding (garbled text, special characters), word segmentation (Chinese and English word segmentation), and stop word filtering, and standardizes the encoding format (e.g., UTF-8) to provide standardized input for subsequent analysis. Finally, it combines rules (regular expression matching of ID cards, phone numbers, etc.) and deep learning models (e.g., BERT-NER) to identify entities such as names, organizations, dates, and amounts in the text, label their types, and store them in corresponding storage modules. Simultaneously, it acquires the amount of information for each type of information requiring encryption, and the theft status of the corresponding information is obtained by analyzing the number of attacks and attack methods for each type of information requiring encryption in historical scenarios. The attack methods are identified by the historical theft paths that occurred in the scenario (e.g., SQL injection, man-in-the-middle attacks, etc.). Step S2: Analyze the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario; In this embodiment, the analysis of information importance in step S2 includes the following specific steps: S21. Obtain the data volume of various encrypted information types and the data of various encrypted file information. Obtain the probability of each encrypted information type appearing in the corresponding information type in historical encrypted files, and substitute it into the entropy calculation formula to calculate the Shannon entropy of the content of the corresponding encrypted information type. The Shannon entropy calculation formula is as follows: In this formula, N represents the number of encrypted information types, p(xi) represents the probability of the i-th content of an encrypted information type appearing in the corresponding information type in a historical encrypted file, and log is the logarithmic function. This step quantifies the uncertainty of the content of encrypted information types. By calculating Shannon entropy, the degree of disorder and complexity of each encrypted information type can be clearly understood. The higher the entropy value, the more uncertain and unpredictable the content of that encrypted information type is, which means that it may contain more valuable information or be more vulnerable to attack. This helps to adopt different protection strategies for encrypted information types with different entropy values ​​during the information protection process, thereby improving the targeting and effectiveness of information protection. It should be noted that Shannon entropy theory is an important concept in information theory. It measures the uncertainty of information based on probabilistic statistics. In the context of encrypted information, the probability of each encrypted information type appearing in a historical encrypted file is different. These probabilities reflect the frequency of the content's appearance. Substituting these probabilities into the Shannon entropy calculation formula can accurately calculate the entropy value of the encrypted information type. This calculation method has a solid mathematical theoretical foundation and can objectively reflect the essential characteristics of information. S22. Obtain the Shannon entropy of the content of each encrypted information type. Simultaneously, combine the content of any two or more encrypted information types, and substitute the content of these two or more combined encrypted information types into the entropy calculation formula to calculate the Shannon entropy of the combined content. By obtaining the Shannon entropy of the content of each corresponding encrypted information type separately, summing the Shannon entropy of the combined content of any one of the same encrypted information type, and dividing by the sum of the Shannon entropies of all encrypted information combinations of the corresponding combined content, the association anomaly value of the corresponding encrypted information type is obtained. The association anomaly value reflects the possibility of privacy leakage after combination. Some fields may have low entropy values ​​individually, but may have low entropy values ​​when combined with other fields. The combination may leak privacy (e.g., low entropy value on its own, but can identify an individual). The information importance of the corresponding encrypted information type is obtained by the ratio of the Shannon entropy of the corresponding encrypted information type to the set security Shannon entropy. The association importance of the corresponding encrypted information type is obtained by dividing the association anomaly threshold of the set association anomaly by the association anomaly value of the corresponding encrypted information type. The protection importance of the corresponding encrypted information type is obtained by weighted summation of the information importance and association importance. This step not only considers the Shannon entropy of a single encrypted information type, but also deeply analyzes the Shannon entropy of any combination of two or more encrypted information types. By calculating correlation outliers, we can identify encrypted information types that have low individual entropy values ​​but may leak privacy when combined with other fields. This is crucial for protecting user privacy and sensitive information because, in practice, attackers may combine different pieces of information to obtain valuable private data. Furthermore, by calculating the importance of information and its correlation, and then performing a weighted sum to obtain the protection importance, we can comprehensively consider the uncertainty of the information itself and the privacy risks brought about by information combinations. This provides a more comprehensive and accurate assessment indicator for the protection of encrypted information. This helps enterprises and organizations better allocate resources to encrypted information types with higher protection importance. In the field of information security, privacy breaches depend not only on the characteristics of individual pieces of information but also on the relationships between them. Some information may not be of high value when viewed alone, but when combined with other information, they may pose unexpected privacy breach risks. Therefore, by calculating the Shannon entropy and correlation outliers of the combined types of content, these potential privacy risks can be effectively identified. The calculation of information importance and correlation importance is based on a quantitative assessment of information uncertainty and privacy risks. Combining the two through a weighted summation can more reasonably reflect the importance of protecting encrypted information types. It should be noted that the weights here need to be determined based on the degree of importance attached to the uncertainty of the information itself and the privacy risks of information combination in the actual scenario. For example, if the enterprise is more concerned about the uncertainty of the information itself, then the weight of the importance of the information can be set to 0.7, and the weight of the importance of association can be set to 0.3; conversely, if the enterprise is more concerned about the privacy risks brought about by information combination, the weight of the importance of association can be set to 0.6, and the weight of the importance of the information can be set to 0.4. S23. Divide the information content of the corresponding encrypted information type by the information content threshold to obtain the information content importance of the corresponding encrypted information type. This process evaluates the encrypted information type from the perspective of information content. Information content is an important indicator for measuring information value. By calculating the information content importance, we can intuitively understand the relative importance of each encrypted information type in terms of information content. This helps to sort and prioritize different encrypted information types according to the size of information content during the information protection process. Security Shannon entropy is a pre-set standard value used to measure the security level of encrypted information type content. By analyzing a large number of historical encrypted files, we can statistically determine the Shannon entropy distribution of different encrypted information types and take a suitable quantile as the security Shannon entropy. For example, sort the Shannon entropy of all encrypted information types from smallest to largest and take the 20th quantile as the security Shannon entropy. Suppose that after analysis, the security Shannon entropy of a certain type of encrypted information is set to 2.5. S24. The information importance of a given type of encrypted information is obtained by summing the importance of its quantity and the importance of its protection. This process comprehensively considers factors such as information uncertainty, privacy risks, and information quantity. Through this comprehensive assessment, a more accurate and comprehensive indicator of the importance of encrypted information types can be obtained. This helps enterprises and organizations allocate resources more scientifically in the information protection process and take stricter protection measures for encrypted information types with higher information importance. Step S3: Assess the risk of the corresponding information by analyzing the theft situation and the theft methods in the scenario; In this embodiment, the assessment of information risk in step S3 includes the following specific aspects: S31. Obtain the number of attacks and attack methods for each type of information requiring encryption in the corresponding historical scenarios. Divide the average success rate of historical attack methods by the average success rate of the overall attack to obtain the danger level of the corresponding attack method. This can assign a specific quantitative indicator to each attack method, which helps security personnel to intuitively understand the potential threat of different attack methods and thus carry out targeted prevention of key attack methods. For example, for attack methods with a high degree of danger, more resources can be invested in monitoring and defense to improve the security of information systems. The historical scenarios in this application are within two months or recently, without considering the improvement of defense measures or the iteration of attack techniques, rather than long-term history, so as to reflect the current dynamic balance between attack and defense. S32. The complexity of attack methods is determined by weighting and summing the standardized number of attack methods and the frequency of change of these methods. The severity of a single attack method is obtained by adding its severity to the overall complexity. This comprehensive assessment considers the diversity and variability of attack methods. A greater variety of attack methods indicates a wider range of possible attacker strategies; a higher frequency of change in attack methods suggests that the attacker is constantly adjusting their attack methods, increasing the difficulty of defense. This comprehensive evaluation more fully reflects the complexity of attack methods. The standardization process involves dividing the corresponding parameter by the standard value of the corresponding parameter type. In step S32, the complexity of the attack method is obtained by weighted summing the number of types of attack methods after standardization and the frequency of change of the attack methods after standardization. The weights can be determined based on the degree of influence of the type and frequency of change of the attack methods on the complexity of the attack. If it is believed that the type of attack method has a greater impact on the complexity, then the weight of the number of types can be set to 0.6 and the weight of the frequency of change can be set to 0.4; conversely, if more attention is paid to the frequency of change of the attack methods, the weight of the frequency of change can be set to 0.7 and the weight of the number of types can be set to 0.3. S33. Obtain the number of attacks and the risk of each individual attack within a set time period. Sum the risk of the attack methods within the set time period to obtain the information risk of the corresponding information type that needs to be encrypted. This allows for a comprehensive assessment of the security risks faced by a certain type of information that needs to be encrypted from a macro perspective. This assessment method considers the frequency of attacks and the risk of each attack, reflecting the overall threat level of the information type under attack over a period of time. The number of attacks within the set time period reflects the frequency of attacks on the information type, while the risk of each individual attack reflects the potential harm caused by each attack. By combining the two and summing the risk of the attack methods within the set time period, the overall security risk faced by the information type during that time period can be accurately measured. The average overall attack success rate is the standard value used to calculate the risk level of the corresponding attack method. This can be achieved by collecting a large amount of historical attack data, statistically analyzing the success rate of all attack methods, and then calculating the average. For example, if 1000 attack data points are collected, the overall attack success rate is calculated to be an average of 30%. Standard values ​​for the types and frequency of attack methods: These two standard values ​​are used in the standardization process. Based on the statistical results of historical data, the average or median of the corresponding parameters can be taken as the standard value. For example, if the statistics show that the average number of attack methods is 5, then the standard value for the number of methods can be set to 5; if the median frequency of attack method changes is 2 times per hour, then the standard value for the frequency of change can be set to 2 times per hour. Step S4: Conduct a hazard assessment of information theft based on the results of information importance analysis, information risk assessment, and the harm caused by the theft. In this embodiment, the information theft hazard assessment in step S4 includes the following specific contents: S41. Obtain the average loss after each type of information requiring encryption is stolen per unit data volume. This can be economic loss or other losses. By comparing the average loss after the theft of the corresponding type of information requiring encryption with the loss threshold, the impact value of the loss can be obtained. This can present the consequences of information theft in a specific numerical form. Whether it is economic loss or other losses, they can be clearly measured. This helps organizations clearly understand the severity of the theft of different types of information and avoids a vague understanding of the loss. For example, for a company, the theft of customer financial information may lead to direct economic losses, while the theft of the company's R&D data may affect future market competitiveness and innovation capabilities. By quantifying the average loss, these different types of losses can be compared intuitively. S42. Obtain the loss impact value, information importance analysis result, and information risk assessment result for the corresponding type of information to be encrypted, and then perform a weighted summation to obtain the information theft hazard assessment result. This method can comprehensively consider the impact of multiple factors on information security. The loss impact value reflects the actual loss after information is stolen, the information importance analysis result reflects the core position and value of information in the organization, and the information risk assessment result considers the possibility and degree of threat of information being attacked. By integrating these factors through weighted summation, the degree of harm of information theft can be assessed more comprehensively and accurately. In step S42, the loss impact value, information importance analysis result, and information risk assessment result for the corresponding type of information to be encrypted are obtained and then weighted summation to obtain the information theft hazard assessment result. The determination of the weights needs to comprehensively consider the actual loss after information is stolen, the core value of the information, and the possibility and degree of threat of being attacked. For example, if the enterprise considers the actual loss after information is stolen to be the most important, then the weight of the loss impact value can be set to 0.5, the weight of the information importance analysis result can be set to 0.3, and the weight of the information risk assessment result can be set to 0.2. The loss threshold is a standard value used to calculate the loss impact value. The threshold can be determined based on the company's risk tolerance and historical loss data. For example, a company can set the loss threshold at 100,000 yuan based on its own financial situation and risk tolerance. Step S5: Dynamically allocate encryption methods based on the information theft hazard assessment results of different levels; In this embodiment, the dynamic allocation of encryption methods in step S5 includes the following specific details: The information theft hazard assessment results are compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. If the assessment value is less than 0.3, it is considered low risk; between 0.3 and 0.7, it is considered medium risk; and greater than 0.7, it is considered high risk. The information theft hazard assessment results are compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. The threshold can be determined based on the enterprise's tolerance for information security risks. For low-risk information: basic security measures can be taken, such as regular backups and setting simple access permissions. Specifically: take basic security measures, such as regularly backing up forum data to prevent data loss; set simple access permissions so that only registered users can access the forum to avoid malicious attacks from outsiders. For medium-risk information: security protection needs to be strengthened, such as using encryption technology, strengthening access control, and conducting regular security audits. Specifically, encryption technology should be used to encrypt and store training materials to prevent them from being stolen during transmission and storage; access control should be strengthened so that only authorized employees can access training materials; and regular security audits should be conducted to check for any abnormal access behavior. For high-risk information: the strictest security measures should be taken, such as using advanced encryption algorithms, establishing a multi-layered protection system, and real-time monitoring and early warning. At the same time, contingency plans should be developed to deal with potential information theft incidents. Specifically, advanced encryption algorithms should be used to encrypt the code during storage and transmission to ensure code security; a multi-layered protection system should be established, including firewalls and intrusion detection systems, to prevent attacks from external hackers; real-time monitoring and early warning should be implemented to promptly detect abnormal access behavior and attack signs; and contingency plans should be developed so that measures can be taken quickly once the code is stolen, such as freezing relevant accounts and notifying the police. In this embodiment, it should be noted that it has the following advantages: Information importance is analyzed based on the privacy type, association, and amount of information in the corresponding scenario; the risk of the corresponding information is assessed through analysis of the theft situation and theft methods in the scenario; the harm of information theft is assessed based on the information importance analysis results, information risk assessment results, and the harm caused by theft; and encryption methods are dynamically allocated according to different levels of information theft harm assessment results, thus avoiding resource waste.

[0021] Example 2

[0022] like Figure 4 As shown, this embodiment provides a dynamic data privacy protection assessment system based on big data analysis, which is implemented based on the dynamic data privacy protection assessment method based on big data analysis in Embodiment 1. It includes: a data acquisition module, which acquires the privacy type and amount of information, and at the same time acquires the theft of corresponding information in the scenario; The information importance analysis module analyzes the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario. The information risk assessment module assesses the risk of corresponding information by analyzing the theft situation and the theft methods in a given scenario. The theft hazard assessment module assesses the hazard of information theft based on the results of information importance analysis, information risk assessment, and the resulting harm. The dynamic allocation module dynamically allocates encryption methods based on the information theft hazard assessment results of different levels. The specific steps of each module in this embodiment are the same as those in the method embodiment of embodiment 1, and will not be repeated here.

[0023] Example 3

[0024] An electronic device according to an embodiment of the present invention includes a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes a dynamic data privacy protection assessment method based on big data analysis by calling the computer program stored in the memory. It should be noted that all computer programs for the dynamic data privacy protection assessment method based on big data analysis are implemented using the C language.

[0025] Example 4

[0026] This embodiment proposes a computer-readable storage medium on which an erasable and rewritable computer program is stored. When a computer program runs on a computer device, it causes the computer device to perform the aforementioned dynamic data privacy protection assessment method based on big data analysis.

[0027] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired network and / or wireless network. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives (SSDs).

[0028] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0029] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0030] In the several embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only one method, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0031] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0032] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0033] In the description of this specification, references to terms such as "an embodiment," "example," and "specific example" indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0034] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A dynamic data privacy protection assessment method based on big data analysis, characterized in that, Includes the following steps: The privacy types and amount of information obtained, as well as the theft of corresponding information in the relevant scenarios; The importance of information is analyzed based on the privacy type, correlation, and information volume of the information in the corresponding scenario; The risk level of the information is assessed by analyzing the theft situation and the theft methods in the scenario. The harm assessment of information theft is conducted based on the results of information importance analysis, information risk assessment, and the harm caused by the theft. The encryption methods are dynamically allocated based on the risk assessment results of information theft at different levels; the analysis of the importance of the information includes the following specific steps: S21. Obtain the data volume of various types of encrypted information and the data of various encrypted file information. Obtain the probability of the content of each type of encrypted information appearing in the corresponding information type in the historical encrypted files. Substitute it into the entropy calculation formula to calculate the Shannon entropy of the content of the corresponding type of encrypted information. S22. Perform correlation analysis on the Shannon entropy of the content of the encrypted information type to obtain the correlation anomaly value of the corresponding encrypted information type. Obtain the information importance of the corresponding encrypted information type by the ratio of the Shannon entropy of the corresponding encrypted information type to the set security Shannon entropy. Obtain the correlation importance of the corresponding encrypted information type by dividing the set correlation anomaly threshold by the correlation anomaly value of the corresponding encrypted information type. Obtain the protection importance of the corresponding encrypted information type by weighted summing of the information importance and correlation importance. S23. Divide the information content of the corresponding encrypted information type by the information content threshold to obtain the information content importance of the corresponding encrypted information type. S24. Summing the information importance and protection importance of the corresponding encrypted information type yields the information importance of the corresponding encrypted information type. The assessment of the information's risk includes the following specific aspects: S31. Obtain the number of times each type of information that needs to be encrypted has been attacked and the methods of attack in the corresponding historical scenarios. Divide the average success rate of historical attack methods by the average success rate of the overall attack to obtain the degree of danger of the corresponding attack method. S32. Obtain the types of attack methods. The complexity of the attack method is obtained by weighted summing the number of types of attack methods after standardization and the frequency of change of the attack methods after standardization. The danger of a single attack method is obtained by adding the danger level of the attack method corresponding to a single attack to the complexity of the attack method. S33. Obtain the number of attacks within a set time period and the risk of each attack method; sum the risks of the attack methods within the set time period to obtain the information risk of the corresponding type of information that needs to be encrypted; The information theft hazard assessment includes the following specific contents: S41. Obtain the average loss after each type of information requiring encryption is stolen per unit data volume, and obtain the loss impact value by the ratio of the average loss after the corresponding type of information requiring encryption is stolen to the loss threshold. S42. Obtain the loss impact value, information importance analysis results and information risk assessment results of the corresponding information types that need to be encrypted, and then perform a weighted summation to obtain the information theft hazard assessment result.

2. The dynamic data privacy protection assessment method based on big data analysis according to claim 1, characterized in that, The association analysis includes the following specific contents: Obtain the Shannon entropy of the content of the encrypted information type. At the same time, combine the content of any two or more encrypted information types and substitute the content of these two or more encrypted information types into the entropy value calculation formula to calculate the Shannon entropy of the combined content. By obtaining the Shannon entropy of the content of the corresponding encrypted information type separately, summing the Shannon entropy of the combined content of one of the same encrypted information type and dividing it by the sum of the Shannon entropy of all encrypted information combination types of the corresponding combined content, the associated anomaly value of the corresponding encrypted information type is obtained.

3. The dynamic data privacy protection assessment method based on big data analysis according to claim 2, characterized in that, The dynamic allocation of the encryption method includes the following specific details: The information theft hazard assessment results are compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. If the assessment value is less than 0.3, it is low risk; between 0.3 and 0.7, it is medium risk; and greater than 0.7, it is high risk. For low-risk information: Take basic security precautions; For medium-risk information: enhanced security measures are needed; For high-risk information: Take the strictest security measures.

4. The dynamic data privacy protection assessment method based on big data analysis according to claim 1, characterized in that, The information obtained includes the privacy type and amount of information, as well as the theft situation of the corresponding information in the scenario. This includes the following specific content: obtaining file information that needs to be encrypted, classifying the file information into information types through a natural language extraction terminal, extracting the information types that need to be encrypted from the set encryption types, and the theft situation of the corresponding information is the number of times each type of information that needs to be encrypted has been attacked and the means of attack in the historical corresponding scenario, which is obtained through historical data. The means of attack are the theft paths that have occurred in the scenario in the past.

5. A dynamic data privacy protection assessment system based on big data analysis, used to implement the dynamic data privacy protection assessment method based on big data analysis as described in any one of claims 1-4, characterized in that, in, The system includes: The data acquisition module acquires information on the privacy type and amount of information, and also acquires information on the theft of corresponding information in the given scenario. The information importance analysis module analyzes the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario. The information risk assessment module assesses the risk of corresponding information by analyzing the theft situation and the theft methods in a given scenario. The theft hazard assessment module assesses the hazard of information theft based on the results of information importance analysis, information risk assessment, and the resulting harm. The dynamic allocation module dynamically allocates encryption methods based on the information theft hazard assessment results at different levels.

6. An electronic device, comprising: A processor and a memory, wherein the memory stores a computer program that can be called by the processor; characterized in that the processor executes the dynamic data privacy protection assessment method based on big data analysis as described in any one of claims 1-4 by calling the computer program stored in the memory.

Citation Information

Patent Citations

  • Data security risk assessment method and system

    CN116720194A

  • Privacy evaluation method and system

    CN119026171A

  • Multi-application environment encryption communication method and system for user privacy protection

    CN119382995A

  • Integrated data management method and system based on cloud native

    CN120011343A

  • Network and information security encryption system and method

    CN120546908A

Cited By

  • Virtual power plant digital resource protection method and system based on privacy computing

    CN121923932A