Sensitive data sharing method and system based on data consanguinity
By constructing a data lineage map and real-time monitoring, the sharing of sensitive data is dynamically identified and controlled, solving the problems of rigid identification of derived data and permission policies in existing technologies, and realizing efficient and secure sharing and compliant management of sensitive data.
Patent Information
- Application Number
- CN202511099164.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-21
AI Technical Summary
Existing technologies cannot identify derived data in sensitive data sharing, static rule base updates are lagging, and permission policies are rigid and unable to adapt to dynamic data changes. This leads to the loss of control over derived sensitive data, a disconnect between rules and the data environment, high operation and maintenance costs, and difficulty in meeting real-time compliance requirements.
A sensitive data sharing system based on data lineage dynamically collects and analyzes data flow paths to construct a lineage map. Combined with a list of sensitive words and de-identification rules, it identifies and monitors sensitive data in real time, dynamically controls data access permissions, and achieves risk classification and compliance auditing of sensitive data.
It improves the accuracy and coverage of sensitive data identification, dynamically adapts to changes in the data environment, enhances data sharing efficiency, strengthens data security, meets real-time compliance requirements, and reduces operation and maintenance costs.
Smart Images

Figure CN120995497A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data management and sharing technology, and more specifically, to a method and system for sharing sensitive data based on data lineage. Background Technology
[0002] In the field of data management and sharing technology, the compliant flow of sensitive data faces severe challenges. Current mainstream technologies primarily rely on static rule matching mechanisms, such as intercepting sensitive fields through predefined keywords or regular expressions. For example, Chinese patent CN118520116A discloses a method for identifying sensitive information. However, this method has significant drawbacks: firstly, it cannot identify derived data after ETL transformation; secondly, the static rule base is outdated and struggles to adapt to dynamic data changes. On the other hand, while role-based access control (RBAC) or attribute-based access control (ABAC) schemes (such as the dynamic access control framework proposed in "Research on Data Sharing Security Models") can restrict data access, their access control policies are rigid and unable to respond to dynamic changes in lineage-related data, leading to excessive interception of legitimate data or invalidation of access control policies. Furthermore, while basic lineage tracking tools can record data flow, their batch update mechanisms cause delays in lineage updates and they are not linked to sensitive lists, making it difficult to meet GDPR and other compliance audit requirements in real-time scenarios such as finance and healthcare. The aforementioned technical deficiencies collectively lead to three core problems: loss of control over derived sensitive data (such as the inability to trace new fields after cleaning), disconnect between rules and the data environment (with both false positives and false negatives), and high operation and maintenance costs (manual maintenance is insufficient to cope with large-scale data transfer), which severely restrict the secure flow and value release of data elements. Summary of the Invention
[0003] To address the aforementioned technical problems, this invention proposes a sensitive data sharing method and system based on data lineage.
[0004] The technical solution of this invention is as follows:
[0005] This invention proposes a sensitive data sharing system based on data lineage, comprising:
[0006] The data lineage module is used to dynamically collect and analyze the entire lifecycle flow path of data from the source to the application, and construct a structured and stored lineage map.
[0007] The sensitive word list identification module is used to identify sensitive data based on the sensitive word list and lineage chart, and to perform risk classification, dynamic monitoring and compliance auditing on the sensitive data;
[0008] The data desensitization module is used to configure desensitization rules to transform or convert sensitive data.
[0009] The data sharing module performs desensitization operations on sensitive data based on a list of sensitive words and desensitization rules, approves, authorizes, and audits data sharing requests, and dynamically controls data access permissions.
[0010] Preferably, the data lineage module includes:
[0011] The bloodline collection unit tracks the data flow path automatically or manually, covering the data source, data processing logic, storage location, and downstream applications.
[0012] The lineage analysis unit identifies the dependencies and transformation logic between data entities by analyzing data processing code, system logs, and metadata, and generates a complete flow chain.
[0013] The lineage visualization unit constructs a data lineage graph based on a graph model, using nodes to represent data and edges to represent data flow paths, thereby achieving a visual display of the entire link mapping.
[0014] Preferably, the sensitive word list identification module includes:
[0015] The rule matching unit can directly match sensitive data using keywords or regular expressions, or indirectly match derived data of sensitive data using pedigree graphs.
[0016] Risk grading unit, which combines rule weights and historical data to classify the risk level of sensitive data;
[0017] The compliance audit unit records operation logs of sensitive data identification events and the flow of sensitive data, and generates standardized audit reports.
[0018] Preferably, the data anonymization module includes:
[0019] The desensitization rule configuration unit supports custom configuration of desensitization rules, including setting desensitization strategies and algorithms;
[0020] The de-identification strategy configuration unit allows you to set the fields that need to be de-identified, the de-identification strength, and the de-identification algorithm to be applied, based on business scenarios, compliance requirements, and the risk level of sensitive data.
[0021] The desensitization algorithm management unit provides at least one of the following algorithms: rearrangement, relational mapping, offset rounding, hashing, encryption, format preservation, constant replacement, random replacement, truncation, and tagging encryption.
[0022] The log auditing unit records detailed information about the de-identification operation and generates a de-identification operation log.
[0023] Preferably, the data sharing module includes:
[0024] The data request unit receives data sharing requests submitted by users, including the purpose, scope, and duration of data use;
[0025] Shared approval units allow for automatic approval of non-sensitive data, while sensitive data is transferred to manual review.
[0026] The data authorization unit dynamically adjusts the data desensitization strategy based on the approval results to desensitize sensitive data and grant sharing permissions for approved data;
[0027] The shared audit unit monitors the entire data sharing process based on data lineage and shared approval results, intercepts unauthorized or out-of-scope data sharing violations, and generates audit logs.
[0028] On the other hand, the present invention also provides a sensitive data sharing system based on data lineage, comprising:
[0029] Real-time collection and analysis of data flow paths and transformation relationships from the source to the application, dynamically constructing data lineage maps;
[0030] Based on the sensitive word list and lineage map, sensitive data and derived data are identified, and combined with streaming monitoring and risk classification, the illegal sharing of sensitive data is intercepted in real time.
[0031] Receive data sharing requests, automatically approve or manually review them based on whether they contain sensitive data, dynamically adjust data anonymization strategies to anonymize sensitive data and grant sharing permissions for approved data based on the approval results, and dynamically authorize and audit sharing behavior.
[0032] Preferably, the step of dynamically constructing the data pedigree map includes:
[0033] Data operation logs are captured in real time using a distributed message queue, and nodes and edges are generated through parsing.
[0034] The bloodline relationship is synchronized to the graph model database for structured storage using a streaming update method.
[0035] Preferably, the sensitive data identification includes: directly matching sensitive fields using a rule engine, and tracing sensitive data and derived data related to blood relations using a graph traversal algorithm.
[0036] In another aspect, the present invention also provides an electronic device having a computer program stored thereon, which, when executed by a processor, implements a sensitive data sharing method based on data lineage as described in any embodiment of the present invention.
[0037] In another aspect, the present invention also provides a computer-readable medium for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement a sensitive data sharing method based on data lineage as described in any embodiment of the present invention.
[0038] The present invention has the following beneficial effects:
[0039] Improve the accuracy of sensitive data identification: Through kinship analysis, the coverage of sensitive data identification has been increased from 70% to 98% by traditional methods, and the false negative rate has been reduced to below 2%.
[0040] Dynamically adapting to changes in the data environment: The dynamic update mechanism can adapt to changes in the data environment in real time, promptly discover new sensitive data, and improve the flexibility of data governance and security management.
[0041] Improve data sharing efficiency: Sensitive data can be deeply identified based on kinship, improving the efficiency of data sharing approval and reducing the approval time by 60%.
[0042] Enhance data security: It can promptly identify potentially sensitive data, prevent the leakage of sensitive data and the unauthorized use of data, and enhance data security. Attached Figure Description
[0043] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is a schematic diagram of the system architecture of the present invention. Detailed Implementation
[0045] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0046] It should be understood that the step numbers used in the text are for ease of description only and are not intended to limit the order in which the steps are performed.
[0047] It should be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0048] The terms “comprising” and “including” indicate the presence of the described feature, whole, step, operation, element and / or component, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.
[0049] The term “and / or” refers to any combination of one or more of the associated listed items, as well as all possible combinations, and includes these combinations.
[0050] Example 1:
[0051] To make the objectives, technical solutions, and advantages of this invention clearer, specific embodiments of this application will be described below, with reference to the accompanying drawings. Figure 1 The technical solution of the present invention will be clearly and completely described.
[0052] To address the problems of existing technologies, this invention provides a sensitive data sharing system based on data lineage, comprising:
[0053] The data lineage module is used to dynamically collect and analyze the entire lifecycle flow path of data from the source to the application, and construct a structured and stored lineage map.
[0054] In a preferred embodiment of this invention, the data lineage module includes:
[0055] The lineage collection unit tracks the data flow path automatically or manually, covering the data source, data processing logic, storage location, and downstream applications. In this embodiment, automated event tracking technology (such as database log monitoring + API interceptor) is used to capture data operation events in real time. Table-level and field-level dependencies in ETL tasks are extracted through an SQL syntax parser. Manual supplementation of the lineage interface is also supported.
[0056] The lineage resolution unit identifies the dependencies and transformation logic between data entities by parsing data processing code, system logs, and metadata, generating a complete flow chain. In this embodiment, the lineage resolution unit parses SQL / Spark code based on an abstract syntax tree (AST) to identify field-level transformation logic in operations such as JOIN and GROUP BY; it completes entity attributes by combining with a metadata repository (Apache Atlas API); and it uses a dynamic weight algorithm to optimize dependency confidence.
[0057] The lineage visualization unit constructs a data lineage graph based on a graph model, using nodes to represent data and edges to represent data flow paths, achieving a visual display of the entire link mapping. In this embodiment, nodes (tables / fields) and edges (transformation relationships) are stored based on the Neo4j graph database; D3.js is used to dynamically render the hierarchical topology graph; and the path search algorithm (Dijkstra) is supported to locate key links.
[0058] The sensitive word list identification module is used to identify sensitive data based on the sensitive word list and lineage chart, and to perform risk classification, dynamic monitoring and compliance auditing on the sensitive data;
[0059] In a preferred embodiment of this invention, the sensitive word list identification module includes:
[0060] The rule matching unit directly matches sensitive data using keywords and regular expressions, or indirectly matches derived data of sensitive data using pedigree graphs. In this embodiment, direct matching accelerates keyword retrieval using a Trie tree; indirect matching is based on graph traversal algorithm (BFS) to trace the source and derivative relationships, and a weight decay model is used to handle multi-hop pedigrees.
[0061] The risk grading unit combines rule weights and historical data to classify the risk level of sensitive data. In this embodiment, the rule weights and the frequency of historical leakage events (the frequency of historical leakage events is extracted from the security log library, and the number of similar data leakages in the past year × 0.3 weight is included in the model) are integrated to construct a Bayesian risk model. Core data (weight ≥ 0.9) / important data (0.6 ≤ weight < 0.9) / general data (weight < 0.6) are dynamically divided.
[0062] The compliance audit unit records the operation logs of sensitive data identification events and the flow of sensitive data, and generates standardized audit reports. In this embodiment, the operation logs are collected based on Logstash to generate audit reports that comply with GDPR / CCPA standards; and the distribution of sensitive data is displayed through a risk heatmap.
[0063] The data desensitization module is used to configure desensitization rules to transform or convert sensitive data.
[0064] In a preferred embodiment of this invention, the data desensitization module includes:
[0065] The de-identification rule configuration unit supports custom configuration of de-identification rules, including setting de-identification strategies and algorithms; specifically including:
[0066] Graphical strategy editor: The user interface is built using the React front-end framework and supports drag-and-drop field mapping. The editor integrates a metadata catalog API to automatically retrieve the data table structure (such as field names and data types), reducing manual input errors. A pre-built template library is categorized by data type (numeric, text, date). For example, text types offer templates such as "partial masking" and "full replacement," while numeric types offer options such as "offset perturbation" and "range normalization."
[0067] Versioning Management: Based on a Git-like version control system, it supports rule snapshots, rollbacks, and audit trails. Each modification generates a unique version ID and is automatically associated with compliance policies (such as Article 25 of the GDPR) to ensure traceability.
[0068] Dynamic validation engine: Real-time validation of rule conflicts (such as contradictions between field-level rules and table-level strategies), using graph algorithms to detect dependency loops and ensure rule consistency.
[0069] The data masking strategy configuration unit allows you to set the fields to be masked, the masking strength, and the masking algorithm applied, based on business scenarios, compliance requirements, and the risk level of sensitive data. This unit is responsible for the dynamic adaptation of the strategy, including:
[0070] Risk-linked engine: Integrates the output of the sensitive word list identification module to build a weighted mapping model. Core data (risk weight ≥ 0.9) is forcibly fully anonymized (e.g., AES-256 encryption), important data (weight 0.6–0.9) is allowed partial masking, and general data (weight < 0.6) is preserved in plaintext. The policy is synchronized to the data lineage graph in real time via REST API.
[0071] Scenario-based strategy templates: Pre-set business scenario templates (such as "scientific research analysis" and "regulatory reporting"), with templates automatically associated with anonymization strength (e.g., lower anonymization strength is allowed for scientific research scenarios). Support for conditional policies (e.g., "If the user role is an internal analyst, the anonymization strength is downgraded").
[0072] Performance optimization: High-frequency storage strategy using memory caching (Redis) with response latency <10ms ensures unblocked sharing process.
[0073] The desensitization algorithm management unit provides at least one algorithm selected from rearrangement, relational mapping, offset rounding, hashing, encryption, format preservation, constant replacement, random replacement, truncation, and tagging encryption algorithms. In this embodiment, the desensitization algorithm management unit includes:
[0074] Plug-in Algorithm Engine: The engine adopts a microservice architecture and supports hot-swappable algorithm plugins. Built-in algorithms include:
[0075] Format Preservation Encryption (FPE): such as the FF3 algorithm, preserves the original format of the data (such as the phone number "+86-138**1234").
[0076] K-Anonymization: Ensures that at least K records within the same group are indistinguishable (used to prevent re-identification attacks).
[0077] Differential privacy: Adding Laplace noise, mathematically proven to satisfy (ε,δ)-privacy guarantee.
[0078] Geographical perturbation: Location offset (fixed distance or random perturbation) is achieved based on the Haversine formula.
[0079] Hardware-accelerated integration: Offloading encrypted computation through Intel QAT (QuickAssist Technology) improves AES-GPU operation throughput by 5x. Supports distributed deployment (Kubernetes clusters) and elastic resource scaling.
[0080] Algorithm selection optimizer: Based on field type, risk level, and performance requirements, it automatically recommends the optimal algorithm (e.g., FPE is preferred for highly sensitive numerical data).
[0081] The log auditing unit records detailed information about the anonymization process and generates anonymization operation logs. It records operation logs, handling results, and data flow for all identified events, generating standardized reports to meet the data traceability requirements of regulatory agencies (such as GDPR and CCPA), assisting companies in responding to audits and legal accountability.
[0082] The data sharing module performs desensitization operations on sensitive data based on a list of sensitive words and desensitization rules, approves, authorizes, and audits data sharing requests, and dynamically controls data access permissions.
[0083] In a preferred embodiment of this invention, the data sharing module includes:
[0084] The data request unit receives data sharing requests submitted by users, including the purpose, scope, and duration of data use;
[0085] Shared approval units allow for automatic approval of non-sensitive data, while sensitive data is transferred to manual review.
[0086] The data authorization unit dynamically adjusts the data desensitization strategy based on the approval results to desensitize sensitive data and grant sharing permissions for approved data;
[0087] The shared audit unit monitors the entire data sharing process based on data lineage and shared approval results, intercepts unauthorized or out-of-scope data sharing violations, and generates audit logs.
[0088] In a test with a 10TB power dataset, the system achieved a sensitive data identification coverage rate of 98.2%.
[0089] Example 2:
[0090] The system collects and analyzes the flow path and transformation relationship of data from the source end to the application end in real time, and dynamically constructs a data lineage graph. In this embodiment, a distributed message queue (such as Kafka) is used to capture data operation logs (database writes, ETL tasks) in real time, analyzes and generates nodes (data entities) and edges (transformation relationships), and synchronizes them to a graph database (such as Neo4j) in a streaming update manner to ensure millisecond-level response.
[0091] Sensitive data and derived data are identified based on a list of sensitive words and a lineage graph. This is combined with streaming monitoring and risk grading to intercept unauthorized sharing of sensitive data in real time. In this embodiment, a rule engine is used to directly match sensitive fields, and a graph traversal algorithm (BFS) is used to trace derived data. By combining streaming monitoring and risk grading, unauthorized sharing is dynamically intercepted.
[0092] The system receives data sharing requests, performs automatic approval or manual review based on whether the data contains sensitive information, dynamically adjusts data anonymization strategies to anonymize sensitive data and grants sharing permissions for approved data based on the approval results, and dynamically authorizes and audits sharing behavior. In this embodiment, the system receives user requests, automatically approves non-sensitive data or transfers sensitive data for manual review; dynamically adjusts anonymization strategies (such as encrypting sensitive fields) and grants permissions based on the approval results; and audits sharing behavior based on lineage.
[0093] In a preferred embodiment of this example, the step of dynamically constructing the data lineage map includes:
[0094] Data operation logs are captured in real time using a distributed message queue, and nodes and edges are generated through parsing.
[0095] The bloodline relationship is synchronized to the graph model database for structured storage using a streaming update method.
[0096] As a preferred embodiment of this example, the sensitive data identification includes: directly matching sensitive fields using a rule engine, and tracing sensitive data and derived data related to blood relations using a graph traversal algorithm.
[0097] Example 3:
[0098] This embodiment provides an electronic device that stores a computer program, which, when executed by a processor, implements a sensitive data sharing method based on data lineage as described in any embodiment of the present invention.
[0099] Example 4:
[0100] This embodiment provides a computer-readable medium for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement a sensitive data sharing method based on data lineage as described in any embodiment of the present invention.
[0101] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent the existence of A alone, A and B simultaneously, or B alone. A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of singular or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0102] Those skilled in the art will recognize that the units and algorithm steps described in the embodiments disclosed herein can be implemented using electronic hardware, computer software, or a combination of electronic hardware and software. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0103] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0104] In the several embodiments provided in this application, any function, if implemented as a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0105] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A sensitive data sharing system based on data lineage, characterized in that, include: The data lineage module is used to dynamically collect and analyze the entire lifecycle flow path of data from the source to the application, and construct a structured and stored lineage map. The sensitive word list identification module is used to identify sensitive data based on the sensitive word list and lineage chart, and to perform risk classification, dynamic monitoring and compliance auditing on the sensitive data; The data desensitization module is used to configure desensitization rules to transform or convert sensitive data. The data sharing module performs desensitization operations on sensitive data based on a list of sensitive words and desensitization rules, approves, authorizes, and audits data sharing requests, and dynamically controls data access permissions.
2. A sensitive data sharing system based on data lineage according to claim 1, characterized in that: The data lineage module includes: The bloodline collection unit tracks the data flow path automatically or manually, covering the data source, data processing logic, storage location, and downstream applications. The lineage analysis unit identifies the dependencies and transformation logic between data entities by analyzing data processing code, system logs, and metadata, and generates a complete flow chain. The lineage visualization unit constructs a data lineage graph based on a graph model, using nodes to represent data and edges to represent data flow paths, thereby achieving a visual display of the entire link mapping.
3. A sensitive data sharing system based on data lineage according to claim 1, characterized in that: The sensitive word list identification module includes: The rule matching unit can directly match sensitive data using keywords or regular expressions, or indirectly match derived data of sensitive data using pedigree graphs. Risk grading unit, which combines rule weights and historical data to classify the risk level of sensitive data; The compliance audit unit records operation logs of sensitive data identification events and the flow of sensitive data, and generates standardized audit reports.
4. A sensitive data sharing system based on data lineage according to claim 1, characterized in that: The data desensitization module includes: The desensitization rule configuration unit supports custom configuration of desensitization rules, including setting desensitization strategies and algorithms; The de-identification strategy configuration unit allows you to set the fields that need to be de-identified, the de-identification strength, and the de-identification algorithm to be applied, based on business scenarios, compliance requirements, and the risk level of sensitive data. The desensitization algorithm management unit provides at least one of the following algorithms: rearrangement, relational mapping, offset rounding, hashing, encryption, format preservation, constant replacement, random replacement, truncation, and tagging encryption. The log auditing unit records detailed information about the de-identification operation and generates a de-identification operation log.
5. A sensitive data sharing system based on data lineage according to claim 1, characterized in that: The data sharing module includes: The data request unit receives data sharing requests submitted by users, including the purpose, scope, and duration of data use; Shared approval units allow for automatic approval of non-sensitive data, while sensitive data is transferred to manual review. The data authorization unit dynamically adjusts the data desensitization strategy based on the approval results to desensitize sensitive data and grant sharing permissions for approved data; The shared audit unit monitors the entire data sharing process based on data lineage and shared approval results, intercepts unauthorized or out-of-scope data sharing violations, and generates audit logs.
6. A method for sharing sensitive data based on data lineage, characterized in that, Includes the following steps: Real-time collection and analysis of the flow path and transformation relationship of data from the source to the application, and dynamic construction of data lineage map; Based on the sensitive word list and lineage map, sensitive data and derived data are identified, and combined with streaming monitoring and risk classification, the illegal sharing of sensitive data is intercepted in real time. Receive data sharing requests, automatically approve or manually review them based on whether they contain sensitive data, dynamically adjust data anonymization strategies to anonymize sensitive data and grant sharing permissions for approved data based on the approval results, and dynamically authorize and audit sharing behavior.
7. A sensitive data sharing method based on data lineage according to claim 6, characterized in that: The steps for dynamically constructing a data pedigree map include: Data operation logs are captured in real time using a distributed message queue, and nodes and edges are generated through parsing. The bloodline relationship is synchronized to the graph model database for structured storage using a streaming update method.
8. A sensitive data sharing method based on data lineage according to claim 6, characterized in that: The sensitive data identification includes: using a rule engine to directly match sensitive fields, and combining a graph traversal algorithm to trace sensitive data and derived data related to blood relations.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a sensitive data sharing method based on data lineage as described in any one of claims 6-8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements a sensitive data sharing method based on data lineage as described in any one of claims 6-8.
Citation Information
Patent Citations
Sensitive information identification method and device
CN118520116A
Cited By
Data cross-platform secure transmission method and system based on industrial internet
CN121727870A
Data full life cycle privacy protection encryption management method and system
CN122197080A