Iterative use control method, device and equipment for data sharing, and medium
By labeling and iteratively updating data based on an initial set of strategies during the data sharing process, the problem of dynamic adjustment of control strategies in cross-domain data sharing is solved, enabling effective control and differentiated operation of data throughout its entire lifecycle in different scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
- Filing Date
- 2026-02-28
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies make it difficult to effectively control the use of original data and copies throughout their entire lifecycle during cross-domain data sharing. Furthermore, the control strategies cannot be dynamically iterated and adjusted, resulting in the inability to meet the different management and control requirements of data in different flow paths and application scenarios.
By labeling shared data based on an initial set of classification strategies and an initial set of scenario strategies, and combining operation requests and security parameters for differentiated control processing, and by iteratively updating the strategy subset, differentiated operation and full lifecycle control of data in different scenarios can be achieved.
Ensure the consistency and executability of the control strategy during data circulation and utilization within or across domains, achieve effective use control throughout the entire lifecycle of multiple propagations of the original data and multiple propagations of copies, and perform differentiated operations according to the use control strategy.
Smart Images

Figure CN121792539B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method, apparatus, device, and medium for iterative use control of data sharing. Background Technology
[0002] Cross-domain data sharing refers to a data interaction model that enables the controlled circulation, joint use, and value synergy of data resources among multiple independent management domains, under the constraints of established legal compliance, organizational strategies, and technical mechanisms, through unified or interoperable semantics, interfaces, and control rules.
[0003] Cross-domain data sharing has promoted the ubiquitous flow of data, enabling personal data to form a multi-copy distributed storage pattern in fields such as healthcare, finance, and government affairs. A single original data may be synchronized to multiple nodes such as partner institutions, cloud platforms, and research systems. The copy data will be transmitted to other nodes, and the nodes may also reprocess the copy data and circulate it again, ultimately forming a complex copy circulation network.
[0004] Traditional data classification methods can quickly achieve initial data categorization, but in scenarios involving dynamic sharing and multiple copies, semantic classification focuses only on the content characteristics of the data itself, ignoring the differences in control requirements across different data flow paths and application scenarios. Data classification groups core elements related to the same entity or event into one category, rather than grouping data elements with the same control strategies into the same category. Therefore, during data flow and utilization within or across data domains, data detaches from the original system, and the data usage control strategy cannot be dynamically adjusted according to the data flow requirements. Consequently, it is difficult to effectively control the use of original data throughout its entire lifecycle and to execute differentiated operations according to the usage control strategy during multiple propagations of original data and multiple propagations of copies. Summary of the Invention
[0005] This invention provides an iterative usage control method, apparatus, device, and medium for data sharing, addressing the shortcomings of existing technologies in controlling the multiple propagation of original data and copies when separated from the original system during data domain or cross-domain circulation and utilization. It improves data classification and scenario application based on initial classification strategy sets and initial scenario strategy sets, and supports extended data control and iterative transmission of usage control strategies by instantiating them into usage control strategies during data domain or cross-domain circulation and utilization. This ensures the consistency and executability of usage control strategies during data domain or cross-domain circulation and utilization, thereby enabling effective full-lifecycle usage control of the multiple propagation of original data and copies, even when separated from the original system, and performing differentiated operations according to the usage control strategies.
[0006] This invention provides an iterative usage control method for data sharing, comprising the following steps:
[0007] Based on the initial classification strategy set and the initial scenario strategy set, the shared data is labeled to obtain the first data;
[0008] Based on the first operation request, the set of operation algorithms, and the first scenario description, the first data is subjected to differentiated control processing to obtain the second data;
[0009] Based on the second data, the first security parameter, the second security parameter, and the second scenario description, the second data is used for iterative control.
[0010] According to an iterative usage control method for data sharing provided by the present invention, the step of annotating shared data based on an initial classification strategy set and an initial scenario strategy set to obtain first data includes: identifying information in the shared data based on a data vocabulary classification knowledge base to obtain information to be annotated; determining a first classification strategy subset and a first scenario strategy subset corresponding to the information to be annotated from the initial classification strategy set and the initial scenario strategy set based on the information to be annotated; and annotating the information to be annotated based on the first classification strategy subset and the first scenario strategy subset to obtain the first data.
[0011] According to an iterative usage control method for data sharing provided by the present invention, the step of performing differentiated control processing on the first data based on a first operation request, an operation algorithm set, and a first scenario description to obtain second data includes: determining the first operation request based on a first classification strategy subset and / or a first scenario strategy subset to obtain a determination result; if the determination result indicates that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset, selecting target data that conforms to the first classification strategy subset and / or the first scenario strategy subset from the first data based on a matching selection function; and performing differentiated control processing on the target data based on the target data, the operation algorithm set, and the first scenario description to obtain the second data.
[0012] According to the present invention, an iterative usage control method for data sharing includes iteratively controlling the use of the second data based on the second data, a first security parameter, a second security parameter, and a second scenario description. This includes: iteratively updating a first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset; and / or iteratively updating a first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario strategy subset; labeling the second data based on the second classification strategy subset and the second scenario strategy subset to obtain third data; and iteratively controlling the use of the third data based on a second operation request, the set of operation algorithms, and the second scenario description.
[0013] According to an iterative usage control method for data sharing provided by the present invention, the step of iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset includes: iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a third classification strategy subset; performing monotonicity verification on the third classification strategy subset and the first classification strategy subset to obtain a first verification result; and determining the second classification strategy subset based on the first verification result and the third classification strategy subset.
[0014] According to an iterative usage control method for data sharing provided by the present invention, determining the second classification strategy subset based on the first verification result and the third classification strategy subset includes: determining the third classification strategy subset as the second classification strategy subset when the first verification result satisfies the first iterative constraint; and iteratively updating the third classification strategy subset when the first verification result does not satisfy the first iterative constraint until the updated classification strategy subset satisfies the iterative constraint, thereby obtaining the second classification strategy subset.
[0015] According to an iterative usage control method for data sharing provided by the present invention, the step of iteratively updating a first scenario policy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario policy subset includes: iteratively updating the first scenario policy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a third scenario policy subset; performing monotonicity verification on the third scenario policy subset and the first scenario policy subset to obtain a second verification result; and determining the second scenario policy subset based on the second verification result and the third scenario policy subset.
[0016] According to an iterative usage control method for data sharing provided by the present invention, determining the second scenario strategy subset based on the second verification result and the third scenario strategy subset includes: determining the third scenario strategy subset as the second scenario strategy subset when the second verification result satisfies the second iteration constraint; iteratively updating the third scenario strategy subset when the second verification result does not satisfy the second iteration constraint until the updated scenario strategy subset satisfies the iteration constraint, thereby obtaining the second scenario strategy subset.
[0017] According to an iterative data sharing control method provided by the present invention, determining the initial classification strategy set and the initial scene strategy set includes: inputting a third security parameter into a classification strategy generation model to obtain a first classification strategy set; inputting a fourth security parameter into a scene strategy generation model to obtain a first scene strategy set; if the first classification strategy set does not meet the data sharing requirements, continuously generating a new classification strategy set based on a fifth security parameter until the number of times the new classification strategy set is generated reaches a first preset number or the new classification strategy set meets the data sharing requirements, thereby obtaining the initial classification strategy set; and / or, if the first scene strategy set does not meet the data sharing requirements, continuously generating a new scene strategy set based on a sixth security parameter until the number of times the next new scene strategy set is generated reaches a second preset number or the new scene strategy set meets the data sharing requirements, thereby obtaining the initial scene strategy set.
[0018] According to the iterative use control method for data sharing provided by the present invention, the setting forms of the first security parameter, the second security parameter, the third security parameter, the fourth security parameter, the fifth security parameter, the sixth security parameter, the first operation request, the operation algorithm set, the first scene description, the second scene description, and the second operation request include at least one of the following: rule-based, configuration file, button, circle, checkmark, mark, key, scroll wheel, menu, voice, video, eye contact, gesture, text, bioelectrical signal, and virtual reality.
[0019] The present invention also provides an iterative use control device for data sharing, comprising the following modules:
[0020] The annotation module is used to annotate the shared data based on the initial classification strategy set and the initial scenario strategy set to obtain the first data;
[0021] The differentiation processing module is used to perform differentiation control processing on the first data based on the first operation request, the set of operation algorithms, and the first scenario description to obtain the second data;
[0022] The iteration module is used to perform iterative usage control on the second data based on the second data, the first security parameter, the second security parameter, and the second scenario description.
[0023] According to a data sharing iterative usage control device provided by the present invention, the annotation module includes an identification submodule, a first determination submodule, and a first annotation submodule, wherein: the identification submodule is used to identify information in the shared data based on a data vocabulary classification knowledge base to obtain information to be annotated; the first determination submodule is used to determine, based on the information to be annotated, a first classification strategy subset and a first scenario strategy subset corresponding to the information to be annotated from the initial classification strategy set and the initial scenario strategy set; the first annotation submodule is used to annotate the information to be annotated based on the first classification strategy subset and the first scenario strategy subset to obtain the first data.
[0024] According to the iterative use control device for data sharing provided by the present invention, the differentiation processing module includes a judgment submodule, a selection submodule, and a differentiation processing submodule, wherein: the judgment submodule is used to judge the first operation request based on the first classification strategy subset and / or the first scenario strategy subset to obtain a judgment result; the selection submodule is used to select target data that conforms to the first classification strategy subset and / or the first scenario strategy subset from the first data based on a matching selection function when the judgment result indicates that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset; the differentiation processing submodule is used to perform differentiation control processing on the target data based on the target data, the operation algorithm set, and the first scenario description to obtain the second data.
[0025] According to an iterative usage control device for data sharing provided by the present invention, the iterative module includes an iterative submodule, a second annotation submodule, and a usage control submodule, wherein: the iterative submodule is used to iteratively update a first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset; and / or, to iteratively update a first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario strategy subset; the second annotation submodule is used to annotate the second data based on the second classification strategy subset and the second scenario strategy subset to obtain third data; the usage control submodule is used to iteratively control the usage of the third data based on a second operation request, the operation algorithm set, and the second scenario description.
[0026] According to an iterative data sharing control device provided by the present invention, the iterative submodule includes a first iterative unit, a first verification unit, and a first determination unit, wherein: the first iterative unit is used to iteratively update the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a third classification strategy subset; the first verification unit is used to perform monotonicity verification on the third classification strategy subset and the first classification strategy subset to obtain a first verification result; the first determination unit is used to determine the second classification strategy subset based on the first verification result and the third classification strategy subset.
[0027] According to an iterative data sharing control device provided by the present invention, the first determining unit includes a first determining subunit and a second determining subunit, wherein: the first determining subunit is used to determine the third classification strategy subset as the second classification strategy subset when the first verification result satisfies the first iterative constraint; the second determining subunit is used to iteratively update the third classification strategy subset when the first verification result does not satisfy the first iterative constraint, until the updated classification strategy subset satisfies the iterative constraint, thereby obtaining the second classification strategy subset.
[0028] According to an iterative data sharing control device provided by the present invention, the iterative submodule further includes a second iterative unit, a second verification unit, and a second determination unit, wherein: the second iterative unit is used to iteratively update the first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a third scenario strategy subset; the second verification unit is used to perform monotonicity verification on the third scenario strategy subset and the first scenario strategy subset to obtain a second verification result; and the second determination unit is used to determine the second scenario strategy subset based on the second verification result and the third scenario strategy subset.
[0029] According to an iterative data sharing control device provided by the present invention, the second determining unit includes a third determining subunit and a fourth determining subunit, wherein: the third determining subunit is used to determine the third scenario strategy subset as the second scenario strategy subset when the second verification result satisfies the second iterative constraint; the fourth determining subunit is used to iteratively update the third scenario strategy subset when the second verification result does not satisfy the second iterative constraint, until the updated scenario strategy subset satisfies the iterative constraint, thereby obtaining the second scenario strategy subset.
[0030] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements an iterative use control method for data sharing as described above.
[0031] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements an iterative use control method for data sharing as described above.
[0032] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements an iterative use control method for data sharing as described above.
[0033] The present invention provides an iterative usage control method, apparatus, device, and medium for data sharing. It involves labeling shared data based on an initial set of classification strategies and an initial set of scenario strategies to obtain first data; performing differentiated control processing on the first data based on a first operation request, a set of operation algorithms, and a first scenario description to obtain second data; and iteratively controlling the usage of the second data based on the second data, a first security parameter, a second security parameter, and a second scenario description. In this way, the initial set of classification strategies and the initial set of scenario strategies integrate data elements into a classification system according to the context, allowing the meaning of the same term to be distinguished in different scenarios. This improves the classification and scenario application of data based on the initial set of classification strategies and the initial set of scenario strategies. Furthermore, by instantiating usage control strategies during data domain or cross-domain circulation and utilization, it supports extended control of data and iterative transmission of usage control strategies, ensuring the consistency and executability of usage control strategies during data domain or cross-domain circulation and utilization. This enables effective lifecycle-wide usage control of multiple propagations of the original data and multiple propagations of copies during data domain or cross-domain circulation and utilization, even when separated from the original system, and allows for differentiated operations to be performed according to the usage control strategies. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0035] Figure 1 This is a flowchart illustrating the iterative usage control method for data sharing provided by the present invention.
[0036] Figure 2 This is one of the strategy update diagrams of the iterative use control method for data sharing provided by the present invention.
[0037] Figure 3 This is the second schematic diagram of the strategy update of the iterative use control method for data sharing provided by the present invention.
[0038] Figure 4 This is the third schematic diagram of the strategy update of the iterative use control method for data sharing provided by the present invention.
[0039] Figure 5 This is a schematic diagram of the data sharing iterative usage control device provided by the present invention.
[0040] Figure 6 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0042] Currently, in the copy circulation network, due to differences in the control capabilities and policy standards of different nodes, any loss of control over the use of any copy, incomplete desensitization, or exceeding the circulation scope may lead to the risk of data leakage or abuse across the entire chain, presenting a propagation effect where one loss affects all.
[0043] In practice, what triggers specific control obligations is often not the semantics themselves, but rather how data is handled throughout its entire lifecycle and flow: who sends it, who receives it, for what purpose, on what legal basis, and whether it crosses different data domains. Two attributes that appear completely different at the semantic level (such as an ID number and a mobile phone number) may require the same control obligations in cross-domain sharing scenarios, i.e., consistent control granularity. Conversely, two semantically similar attributes (such as an address and contact information) may require drastically different levels of protection depending on the context and whether they leave a trusted domain. Traditional semantic classification cannot adequately characterize this difference: it either imposes uniformly strong usage controls on broad categories, thereby excessively restricting data utilization; or it configures rules haphazardly for each attribute, resulting in fragmented control strategies, maintenance difficulties, and even unnoticed compliance loopholes.
[0044] Furthermore, existing multi-replica consistent data cross-domain usage control schemes mostly focus on optimizing the synchronization mechanism at the data storage layer. For example, asynchronous replication schemes based on data files reduce performance bottlenecks by changing the synchronization carrier, but they fail to solve the adaptation problem of data classification and cross-domain iterative usage control strategies. While access control technologies such as the Extensible Access Control Markup Language (XACML) provide a flexible policy description framework, the standard version has limitations in supporting dynamic policy reasoning in open scenarios and multi-scenario adaptation, making it difficult to directly apply to complex scenarios within or across multi-replica domains.
[0045] Traditional data classification methods can quickly achieve initial data categorization, but in scenarios with multiple copies and dynamic circulation, semantic classification only focuses on the content characteristics of the data itself, ignoring the differences in control requirements under different circulation paths and application scenarios. Data classification groups core related elements of the same entity or event into one category, rather than grouping data elements with the same control strategy into the same category. Therefore, during the circulation and utilization within or across data domains, data is separated from the original system, and the data use control strategy cannot be dynamically adjusted according to the data circulation needs. Consequently, it is difficult to effectively control the use of the original data throughout its entire lifecycle and to perform differentiated operations according to the usage strategy during the multiple propagation of the original data and the multiple propagation of copies.
[0046] Based on the aforementioned problems, the iterative usage control method for data sharing provided by this invention improves the classification and scenario application of data according to the initial classification strategy set and the initial scenario strategy set. By instantiating the usage control strategy in the data circulation and utilization process, it supports the extended control of data and the iterative transmission of usage control strategies, ensuring the consistency and executability of usage control strategies in the data circulation and utilization process within or across domains. Thus, even if the data is separated from the original system during the circulation and utilization process within or across domains, it can still achieve effective usage control throughout the entire lifecycle of the multiple propagation of the original data and the multiple propagation of copies, and perform differentiated operations according to the usage strategy.
[0047] The following is combined with Figures 1 to 4 The present invention describes an iterative use control method for data sharing. The subject executing this method may be an electronic device or an iterative use control device for data sharing installed in the electronic device. The iterative use control device for data sharing may be implemented by software, hardware, or a combination of both.
[0048] Figure 1 This is a flowchart illustrating the iterative usage control method for data sharing provided by the present invention, as shown below. Figure 1 As shown, the method includes the following:
[0049] Step 101: Based on the initial classification strategy set and the initial scenario strategy set, label the shared data to obtain the first data.
[0050] Here, the initial classification strategy set is a combination rule of attributes and scenarios obtained after feature attribute instantiation, used to describe what type of data can be identified in what scenario.
[0051] The initial scenario strategy set is used to describe the requirements for controlling the use of data from which dimensions in the initial state and in a given scenario.
[0052] It should be noted that a strategy set is an ordered or unordered collection of objects, strategies, strategy combination algorithms, and iterative constraints. The combination algorithm defines the execution order of the strategies. Strategy sets can be nested, specifically described as follows: a strategy set contains one object, 0 or 1 strategy combination algorithms, several iterative constraints (which can be 0), and several strategies or strategy sets (which can be 0). The strategy set describes which object(s) a strategy is suitable for, and under the constraints of iterative constraints, which strategies(s) can be executed, as well as the iterative constraints on subsequent operations after the current strategy set has been executed. When multiple executable strategies exist for a given object, the strategy combination algorithm determines which strategies to execute and the execution order of the strategies.
[0053] It should be noted that a strategy is an ordered or unordered set composed of rules, objects, rule combination algorithms, and iterative constraints, denoted as . Specifically, a strategy can be described as follows: a strategy consists of an object, at least one set of rules, zero or one rule combination algorithm, and several iterative constraints (which can be zero). The strategy describes which rules apply to which set of objects, which rules can be executed under the constraints of the iterative constraints, and the constraints on subsequent operations after the rules are executed. When the strategy is ordered, the rules must be executed sequentially according to the specified order. When a given object has multiple executable rules, a rule combination algorithm is used to determine which rules to execute and the order in which they are executed. A strategy is a component of a strategy set.
[0054] Shared data can be any kind of data, including but not limited to resumes, medical records, student records, information management data, social data, logistics data, e-commerce data, financial data, securities data, government data, and judicial data.
[0055] Here, annotations are used to label data with classification labels, data provider shared preferences, and control strategies.
[0056] Step 102: Based on the first operation request, the set of operation algorithms, and the first scenario description, perform differentiated control processing on the first data to obtain the second data.
[0057] Here, the first operation request is the operation performed by the user on the system, which can be an operation request within the data domain or across domains.
[0058] The set of operation algorithms refers to the set of algorithms that an entity executes under specified conditions.
[0059] The scenario description refers to the context in which shared data is used, such as in human resources departments, pharmaceutical companies, and when doctors see patients.
[0060] Here, differentiated control processing refers to selecting different operation algorithms to process important information in shared data according to the control strategy used.
[0061] For example, personal health information can be categorized into different object types. Assuming the use of personal health information is limited to medical scenarios, personal identification information and address information need protection. This type of information, after de-identification, can be exchanged with pharmaceutical companies, which will store this data for no more than three years. Specifically, the protection of personal identification information (such as name, ID number, and mobile phone number) relies on personal identification information protection strategies, while the protection of address information (such as home address, work address, and location information) relies on address information protection strategies.
[0062] In the above scenario, the set of personal information protection strategies includes strategies for protecting personally identifiable information and address information. The target scenario is healthcare, and the iterative constraint is that pharmaceutical companies cannot store this data for more than three years. Different parts of personal health information have varying sensitivity when the data flows out; for example, the sensitivity of personal photos, ID cards, names, email addresses, and phone numbers decreases in that order under specific scenarios. Therefore, differentiated processing can be performed according to this order.
[0063] Step 103: Based on the second data, the first security parameter, the second security parameter, and the second scenario description, perform iterative usage control on the second data.
[0064] Here, the first security parameter and the second security parameter can include any information. For example, the first security parameter can include classification rules, attribute combination rules, etc., and the second security parameter can include scenario description, data usage description, and usage restrictions, etc.
[0065] It should be noted that iterative use control refers to iteratively updating the classification strategy and / or scenario strategy based on the first security parameter, the second security parameter, and the scenario description.
[0066] The iterative update of the classification strategy is triggered by changes in the granularity of the data content and changes in the personalized needs of scenario processing. For example, after specifying a general initial classification strategy for hospital cases, the classification strategy for sensitive personnel and sensitive diseases needs to be iteratively updated.
[0067] The iterative update of the scenario strategy is triggered by the new scenario, which requires fine-tuning of the scenario. Based on the new scenario description, the iterative update forms a new scenario strategy.
[0068] It should be noted that the first scenario description and the second scenario description can be the same or different. When the scenarios are the same, if the scenario strategy does not meet the requirements, it should be fine-tuned based on the current scenario strategy. When the scenarios are different, a new scenario strategy needs to be generated for the new scenario.
[0069] In this embodiment of the invention, the initial classification strategy set and the initial scenario strategy set integrate data elements into the classification system according to the scenario, so that the meaning of the same term can be distinguished in different scenarios. The initial classification strategy set and the initial scenario strategy set improve the classification and scenario application of data, and by instantiating them into the use control strategy in the data sharing process, it supports the extended control of data and the iterative transmission of use control strategy, ensuring the consistency and executability of use control strategy in the data sharing process. Thus, even if the original system is removed during the data domain or cross-domain circulation and utilization process, the multiple propagation of the original data and the multiple propagation of copies can be effectively controlled throughout the entire life cycle, and differentiated operations can be performed according to the use strategy.
[0070] Furthermore, the step of labeling the shared data based on the initial classification strategy set and the initial scenario strategy set to obtain the first data includes: identifying information in the shared data based on a data vocabulary classification knowledge base to obtain information to be labeled; determining a first classification strategy subset and a first scenario strategy subset corresponding to the information to be labeled from the initial classification strategy set and the initial scenario strategy set based on the information to be labeled; and labeling the information to be labeled based on the first classification strategy subset and the first scenario strategy subset to obtain the first data.
[0071] Here, data annotation functions can be used to identify information in shared data based on a data vocabulary classification knowledge base to obtain the information to be annotated. The data vocabulary classification knowledge base may be different for different shared data, but the data annotation function is unique.
[0072] Here, the first classification strategy subset can be understood as the category to which the feature attribute corresponding to the information to be labeled belongs, and the first scenario strategy subset can be understood as the scenario to which the information to be labeled is applicable, and the dimension of using and controlling the information to be labeled in that scenario.
[0073] It should be noted that after determining the first classification strategy subset and the first scenario strategy subset corresponding to the information to be labeled, the first classification strategy subset and the first scenario strategy subset can be used as labels to label the information to be labeled, thus obtaining the first data. That is, the first data is the shared data after adding labels.
[0074] For example, a data annotation function is used to determine the information to be annotated from the shared data based on the data vocabulary classification knowledge base. Based on the information to be standardized, the first classification strategy subset and the first scenario strategy subset corresponding to the information to be annotated are determined from the initial classification strategy set and the initial scenario strategy set. The first classification strategy subset and the first scenario strategy subset are used as labels to standardize the information to be annotated, and the first annotated data is obtained.
[0075] In this embodiment of the invention, shared information is labeled using a data vocabulary classification knowledge base, a first classification strategy subset, and a first scenario strategy subset, providing reliable data for subsequent scenario-based use.
[0076] Further, the step of performing differentiated control processing on the first data based on the first operation request, the set of operation algorithms, and the first scenario description to obtain the second data includes: determining the first operation request based on the first classification strategy subset and / or the first scenario strategy subset to obtain a determination result; if the determination result indicates that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset, selecting target data that conforms to the first classification strategy subset and / or the first scenario strategy subset from the first data based on a matching selection function; and performing differentiated control processing on the target data based on the target data, the set of operation algorithms, and the first scenario description to obtain the second data.
[0077] Here, differential control processing can only be performed if the first operation request satisfies the data using the first classification strategy subset and / or the first scenario strategy subset; otherwise, the operation request is rejected.
[0078] Here, for the same system or scenario, the matching selection function can be the same or different; for different systems or scenarios, the matching selection function can be the same or different, and its implementation can be customized according to data processing needs.
[0079] For example, when a first operation request and first data are input, it is determined whether the first operation request meets the data usage control strategy (i.e., classification strategy and scenario strategy) specified in the first data. If it does, target data that meets the usage control strategy is selected from the first data and assigned to it. and return, that is .in, This is the data from the first annotation. This is the data labeled in the previous round. Based on the target data, the set of operation algorithms and the first scene description, specific control operations are performed on the target data to obtain the second data.
[0080] In this embodiment of the invention, a determination is made based on a first operation request. When the first operation request satisfies a first classification strategy subset and / or a first scenario strategy subset, the data is differentiated, thereby improving the security and reliability of the data.
[0081] Furthermore, the iterative use control of the second data based on the second data, the first security parameter, the second security parameter, and the second scenario description includes: iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset; and / or iteratively updating the first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario strategy subset; labeling the second data based on the second classification strategy subset and the second scenario strategy subset to obtain third data; and iteratively controlling the use of the third data based on the second operation request, the operation algorithm set, and the second scenario description.
[0082] When the second scenario description differs from the first scenario description, the data obtained from the first scenario description cannot meet the requirements of the second scenario description. Therefore, it is necessary to update the first classification strategy subset and the first scenario strategy subset to obtain the second classification strategy subset and the second scenario strategy subset. Here, the iterative updates of the classification strategy and the scenario strategy are usually performed by the data user.
[0083] For example, the iterative update of the classification strategy subset: the input is a given first security parameter, a second scene description, and second data, and the output is the iteratively updated classification strategy subset. ). Can make For the first The classification strategy in the next iteration (when it is the first iteration, i.e.) When =1, (This is the initial classification strategy) For the first The classification strategy obtained after the nth iteration is also the nth... The input strategy at the next iteration. To ensure safety, it should be ensured that... .
[0084] Iterative update of scenario policies: The input is a given second security parameter, i.e., the new scenario security parameter (such as changes in scenario, receiver, receiver protection capabilities, etc.), a second scenario description, and second data. The output is the set of scenario policies after iterative update. . can make For the first The scenario strategy during the next iteration (when it was the first iteration, i.e.) When =1, (This is the initialization scenario strategy) For the first The scene strategy obtained after the nth iteration is also the nth iteration. Input strategy for the next iteration.
[0085] In this embodiment of the invention, based on the data usage context, a usage control strategy is instantiated in the process of data domain circulation and utilization, supporting the extended control of data and the iterative transmission of usage control strategies, and ensuring the consistency and executability of usage control strategies in the process of data domain circulation and utilization.
[0086] Further, the step of iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset includes: iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a third classification strategy subset; performing monotonicity verification on the third classification strategy subset and the first classification strategy subset to obtain a first verification result; and determining the second classification strategy subset based on the first verification result and the third classification strategy subset.
[0087] It should be noted that after each subset of classification strategies is generated based on the scenario description and the first security parameter, the monotonicity of the subset of classification strategies needs to be verified.
[0088] Here, monotonicity means that the range of the classification strategy subset generated each time needs to be less than or equal to the classification strategy subset of the previous round.
[0089] Here, the first validation result may or may not conform to monotonicity validation. Different first validation results lead to different methods for determining the subset of the second classification strategy.
[0090] In this embodiment of the invention, monotonicity verification is performed on the classification strategy subset after each update, which improves the reliability of the classification strategy subset.
[0091] Furthermore, determining the second classification strategy subset based on the first verification result and the third classification strategy subset includes: determining the third classification strategy subset as the second classification strategy subset when the first verification result satisfies the first iteration constraint; and iteratively updating the third classification strategy subset when the first verification result does not satisfy the first iteration constraint, until the updated classification strategy subset satisfies the iteration constraint, thereby obtaining the second classification strategy subset.
[0092] Here, the first iteration constraint can be understood as monotonicity, that is, the range of the current classification strategy subset must be less than or equal to the range of the previous scenario strategy subset. When the first verification result satisfies that the range of the third classification strategy subset is less than or equal to the range of the first classification strategy subset, the third classification strategy subset is determined as the second classification strategy subset. When the first verification result does not satisfy monotonicity, the third classification strategy subset continues to be iteratively updated until the updated classification strategy subset satisfies monotonicity. The classification strategy subset that satisfies monotonicity is then used as the second classification strategy subset.
[0093] In this embodiment of the invention, when the first verification result satisfies the first iteration constraint, the new classification strategy subset is determined as the second classification strategy subset; if it does not satisfy the constraint, the classification strategy subset is updated until the monotonicity is satisfied, thus obtaining the second classification strategy subset. This improves the reliability of the second classification strategy subset and the accuracy of data classification.
[0094] Furthermore, the step of iteratively updating the first scenario policy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario policy subset includes: iteratively updating the first scenario policy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a third scenario policy subset; performing monotonicity verification on the third scenario policy subset and the first scenario policy subset to obtain a second verification result; and determining the second scenario policy subset based on the second verification result and the third scenario policy subset.
[0095] It should be noted that after each subset of scenario policies is generated based on a new scenario description and new security parameters, the monotonicity of the subset of scenario policies needs to be verified.
[0096] Here, monotonicity means that the range of the scene policy subset generated each time needs to be less than or equal to the scene policy subset of the previous round.
[0097] Here, the second verification result may or may not conform to monotonicity verification. Different second verification results lead to different methods for determining the second scenario policy subset.
[0098] In this embodiment of the invention, monotonicity verification is performed on the scene strategy subset after each update, which improves the reliability of the scene strategy subset.
[0099] Furthermore, determining the second scenario strategy subset based on the second verification result and the third scenario strategy subset includes: determining the third scenario strategy subset as the second scenario strategy subset when the second verification result satisfies the second iteration constraint; and iteratively updating the third scenario strategy subset when the second verification result does not satisfy the second iteration constraint until the updated scenario strategy subset satisfies the iteration constraint, thereby obtaining the second scenario strategy subset.
[0100] Here, the second iteration constraint can be understood as monotonicity, meaning that the range of the current scenario policy subset must be less than or equal to the range of the previous scenario policy subset. When the second verification result shows that the range of the third scenario policy subset is less than or equal to the range of the first scenario policy subset, the third scenario policy subset is determined as the second scenario policy subset. If the second verification result does not satisfy monotonicity, the third scenario policy subset continues to be iteratively updated until the updated scenario policy subset satisfies monotonicity. The scenario policy subset that satisfies monotonicity is then used as the second scenario policy subset.
[0101] In this embodiment of the invention, when the second verification result satisfies the second iteration constraint, the new scenario strategy subset is determined as the second scenario strategy subset; if it does not satisfy the constraint, the scenario strategy subset is updated until the monotonicity is satisfied, thus obtaining the second scenario strategy subset. This improves the reliability of the second scenario strategy subset, as well as the accuracy, adaptability, and confidentiality of the data application scenario.
[0102] Further, determining the initial classification strategy set and the initial scene strategy set includes: inputting a third security parameter into a classification strategy generation model to obtain a first classification strategy set; inputting a fourth security parameter into a scene strategy generation model to obtain a first scene strategy set; if the first classification strategy set does not meet the data sharing requirements, continuously generating a new classification strategy set based on a fifth security parameter until the number of times the new classification strategy set is generated reaches a first preset number or the new classification strategy set meets the data sharing requirements, thereby obtaining the initial classification strategy set; and / or, if the first scene strategy set does not meet the data sharing requirements, continuously generating a new scene strategy set based on a sixth security parameter until the number of times the new scene strategy set is generated reaches a second preset number or the new scene strategy set meets the data sharing requirements, thereby obtaining the initial scene strategy set.
[0103] Here, the third security parameter may include classification rules, attribute combination rules, etc., and the fourth security parameter may include scenario description, data usage description, and usage restrictions, etc.
[0104] It should be noted that the initial classification strategy set and the initial scenario strategy set need to meet the data sharing requirements or reach a preset number of times. If the classification strategy set and / or scenario strategy set do not meet the data sharing requirements during the generation of the classification strategy set and the scenario strategy set, the security parameters need to be changed and the classification strategy set and / or scenario strategy set regenerated until the generated classification strategy set and / or scenario strategy set meet the data sharing requirements or reach the preset number of times. The classification strategy set and / or scenario strategy set that meets the data sharing requirements will be used as the initial classification strategy set and / or initial scenario strategy set, or the last classification strategy set and / or scenario strategy set will be used as the initial classification strategy set and / or initial scenario strategy set.
[0105] It should be noted that the fifth safety parameter is different from the third safety parameter, and the sixth safety parameter is different from the fourth safety parameter.
[0106] Here, the classification strategy generation model can be a hypernym prediction model, which abstracts each data element into a feature attribute, extracts contextual elements through contextual reasoning, identifies candidate hypernym pairs based on these elements, and integrates the data elements into the classification system according to the context, so that the meaning of the same term can be distinguished in different scenarios.
[0107] In this embodiment of the invention, data elements are integrated into a classification system through a classification strategy generation model and a scenario generation model, so that the meaning of the same term in different scenarios can be distinguished. Furthermore, when the classification strategy set and the scenario strategy set do not meet the data sharing requirements, a new classification strategy set and scenario strategy set are regenerated to improve the accuracy of the classification strategy set and scenario strategy set.
[0108] It should be noted that the following implementation examples exist when iteratively controlling the use of the second data:
[0109] Example 1: Data does not leave the domain; only the scenario changes.
[0110] Figure 2 This is one of the schematic diagrams of the strategy update of the iterative use control method for data sharing provided by the present invention, such as... Figure 2As shown, it includes an initial strategy generation module, a first data annotation module, a first differentiated scenario usage control module, and a first strategy iteration update module. The initial strategy generation module includes an initial classification strategy generation unit and an initial scenario strategy generation unit. The first strategy iteration update module includes an iterative update unit for classification strategies and an iterative update unit for scenario strategies. The specific iterative data sharing control method includes: ① Inputting the third security parameter into the initial classification strategy generation unit to obtain a classification strategy set, and inputting the fourth security parameter into the initial scenario strategy generation unit to obtain a scenario strategy set. If the classification strategy set and / or scenario strategy set do not meet the data sharing requirements or have not reached the preset number of times, regenerating them until the generated classification strategy set and / or scenario strategy set meet the data sharing requirements or have reached the preset number of times, thus obtaining the initial classification strategy set and initial scenario strategy set; ② Inputting the initial classification strategy set, initial scenario strategy set, shared data, and data vocabulary classification knowledge base into the first data annotation module to obtain first data, which includes the first classification strategy subset and / or the first scenario strategy subset; ③ Inputting the initially annotated first data, operation request, operation algorithm set, and scenario description into the first differentiated scenario usage control module to obtain second data; ④ When the condition is that the scenario has changed, inputting the second data and scenario description into the first... The strategy iteration update module: ⑤ Inputs the first security parameter into the classification strategy iteration update unit and the second security parameter into the scene strategy iteration update unit. Iterates and updates the first classification strategy subset and / or the first scene strategy subset using the classification strategy iteration update unit and the scene strategy iteration update unit, respectively. If the classification strategy subset and / or scene strategy subset do not meet the iteration constraints, it continues to update until the generated classification strategy subset and scene strategy subset meet the iteration constraints. The classification strategy subset and scene strategy subset that meet the iteration constraints are determined as the second classification strategy subset and the second scene strategy subset; ⑥ When the condition is that the classification strategy subset and scene strategy subset meet the iteration constraints, the second classification strategy subset, the second scene strategy subset, and the second data are sent to the first data annotation module for re-annotation to obtain the third data; ⑦ The third data generated by the iteration annotation is sent to the first differentiated scene usage control module for new differentiated scene usage control.
[0111] Example 2: Data goes out of domain, scenario changes.
[0112] Figure 3 This is the second schematic diagram of the strategy update of the iterative use control method for data sharing provided by the present invention, as shown below. Figure 3As shown, the data user includes a second data annotation module, a second differentiated scenario usage module, and a second strategy iteration update module. The second strategy iteration update module includes a classification strategy iteration update unit and a scenario strategy iteration update unit. The data user receives first data from the data provider, which includes a first classification strategy subset and a first scenario strategy subset. The first data, operation request, operation algorithm set, and scenario description are input into the second differentiated scenario usage control module to perform differentiation processing on the first data, resulting in second data. The specific iterative usage control method for data sharing includes: ① when the scenario changes, inputting the second data and scenario description into the second strategy iteration update module; ② inputting the first security parameter into the classification strategy iteration update unit and the second security parameter into the scenario strategy iteration update unit, and iterating on the first classification strategy subset and / or the first scenario strategy subset. Update: If the classification strategy subset and / or scenario strategy subset do not meet the iteration constraints, continue updating until the generated classification strategy subset and scenario strategy subset meet the iteration constraints. The classification strategy subset and scenario strategy subset that meet the iteration constraints are determined as the second classification strategy subset and the second scenario strategy subset; ③ When the condition is that the classification strategy subset and scenario strategy subset meet the iteration constraints, send the second data, the second classification strategy subset and the second scenario strategy subset to the second data annotation module for re-annotation to obtain the third data; ④ Send the third data generated by the iterative annotation to the second differentiated scenario usage control module for differentiated scenario usage control.
[0113] It should be noted that data users can also accept multiple sets of labeled data and exercise differentiated control over the use of the merged dataset.
[0114] Example 3: Data transfer between data domains.
[0115] Figure 4 This is the third schematic diagram of the strategy update of the iterative use control method for data sharing provided by the present invention, as shown in Figure 3. Figure 4As shown, the data provider includes a first data annotation module, a first differentiated scenario usage control module, and a first strategy iteration update module; the data user includes a second data annotation module, a second differentiated scenario usage control module, and a second strategy iteration update module. The specific iterative usage control method for data sharing includes: ① The first data annotation module annotates the shared data based on the initial classification strategy set, the initial scenario strategy set, and the data vocabulary classification knowledge base to obtain the first data. The first data includes the first classification strategy subset and the first scenario strategy subset. The initially annotated first data, operation requests, operation algorithm sets, and scenario descriptions are input into the usage control module of the first differentiated scenario to obtain the second data; ② When the scenario changes, the second data, the first security parameter, the second security parameter, and the new scenario description are input into the iterative update module of the first strategy to iteratively update the first classification strategy subset and / or the first scenario strategy subset. If the classification strategy subset and / or scenario strategy subset do not meet the iterative constraints, the updates continue until the generated classification strategy subset and scenario strategy subset meet the iterative constraints. The classification strategy subset and scenario strategy subset that meet the iterative constraints are determined as the second classification strategy subset and the second scenario strategy subset; ③ When the classification strategy subset and scenario strategy subset meet the iterative constraints, the second classification strategy subset is... The second scenario strategy subset and the second data are input into the first data annotation module to obtain the third data; ④ When the condition is to pass it to the next stage, the third data is sent to the data user, and the third data, operation request, operation algorithm set, and scenario description are input into the second differentiated scenario usage control module to perform differentiated processing on the annotated data to obtain the fourth data; ⑤ When the condition is that the scenario has changed, the fourth data, the seventh security parameter, the eighth security parameter, and the new scenario description are input into the second strategy iteration update module to iteratively update the second classification strategy subset and / or the second scenario strategy subset, and the classification strategy subset and / or scenario strategy subset that meet the iteration constraints are determined as the new classification strategy subset and / or the new scenario strategy subset; ⑥ When the condition is that the classification strategy subset and the scenario strategy subset meet the requirements, the new classification strategy subset and the new scenario strategy subset, the data vocabulary classification knowledge base, and the fourth data are sent to the second data annotation module for re-annotation to obtain the fifth data; ⑦ The fifth data generated by iterative annotation is sent to the second differentiated scenario usage control module for differentiated scenario usage control.
[0116] Furthermore, the setting forms of the first security parameter, the second security parameter, the third security parameter, the fourth security parameter, the fifth security parameter, the sixth security parameter, the first operation request, the operation algorithm set, the first scene description, the second scene description, and the second operation request include at least one of the following: rule-based, configuration file, button, circle, checkmark, mark, key, scroll wheel, menu, voice, video, eye contact, gesture, text, bioelectrical signal, and virtual reality.
[0117] In this embodiment of the invention, the first security parameter, the second security parameter, the third security parameter, the fourth security parameter, the fifth security parameter, the sixth security parameter, the first scene description, the second scene description, the first operation request, the second operation request, the set of operation algorithms, etc., are input in various forms, which provides the diversity of input.
[0118] The core difference between the semantics of a policy and a policy set is that a policy is more granular and contains rules. Here is an example containing only one rule: Only subjects with the corresponding qualifications and roles (such as attending physicians, authorized nurses, and designated medical systems) are allowed to access the corresponding health information, and other subjects are denied access by default.
[0119] Define an object. An object is a collection of resources, scenarios, and operations, denoted as [object name missing]. Specifically, an object can be described as follows: an object contains at least one resource, several application scenarios (which can be zero), and several operations (which can be zero). Objects are used to define the scope of application of rules, strategies, or sets of strategies.
[0120] For example, if the tar of a strategy or strategy set is <medical records, pharmaceutical R&D, data collection>, it means that the strategy or strategy set is applicable to medical record data collection in the context of pharmaceutical R&D.
[0121] Resources refer to a collection of objects used, which can be described by characteristic attributes, denoted as... Resources can be nested, specifically described as follows: a resource contains at least one characteristic attribute and several resources. Resources are used to describe the objects that are controlled.
[0122] Feature attributes are a collection of attribute metadata that describes a strong correlation with resource classification, denoted as A combination of instantiations of one or more characteristic attributes can characterize a class of resources.
[0123] If a medical record is considered a resource, it can be described using features such as personal identifier, address, time, and type. The consultation number and medical record number are instantiations of the personal identifier and item identifier, respectively, while the disease type and gender are instantiations of the type. Furthermore, resources possess different semantic modal attributes, such as text, audio, and video. However, these modal attributes cannot characterize the resource with fine granularity; therefore, modal information should not be annotated in the feature attributes.
[0124] An operation is a set consisting of specific operations that can be performed on a resource in a specific scenario, denoted as . An operation describes the actions that can be performed on a resource.
[0125] A scenario refers to the set of contexts in which a subject uses resources, denoted as . In different scenarios, the operations that the same entity can perform on resources differ; in other words, in a given scenario, resources and operations have a many-to-many mapping relationship, which is determined by the set elements in the scenario.
[0126] Specifically, under scenario constraints, the relationship between resources and operations is many-to-many. That is, in In this scenario, resources The operations that can be performed are ,in , , These are subsets of the scene, resources, and operations, respectively. For example, For medical, pharmacy, and pharmaceutical scenarios, For prescriptions, in a medical setting, operations such as creation, modification, and reading can be performed on the prescription. In a pharmacy setting, pharmacists can read the complete prescription, and in a pharmaceutical setting, the research team can read the anonymized prescription.
[0127] A scenario can be used to constrain the upper bound of the operations that can be performed on a resource. The upper bound of the permissions of a subject to operate on a resource under the scenario defined by S can be defined as follows: ,in Its output is a set of binary relations between resources and operations.
[0128] Define iteration constraints. Iteration constraints are the set of constraints imposed on subsequent operations after the current policy set, policy, and rule have been executed. They are denoted as... When controlling resource usage based on the current policy set, policies, and rules, a subject's operations on resources must satisfy iterative constraints passed down from the previous subject or domain. Iterative constraints include constraints imposed by subjects within a domain on resource operations by other subjects within the same domain, as well as constraints imposed by subjects between domains on resource operations after cross-domain data exchange.
[0129] For example: ① After data arrives at the user's domain from the provider, the user should delete the data immediately after use. ② After data is exchanged out of the management domain, the total number of times users in other domains read the data should not exceed 5 times.
[0130] Define a policy combination algorithm: A policy combination algorithm is a component of a policy set. It is a set of algorithms that explicitly defines the execution order of multiple policies: denoted as... ={ 1, ,… } .
[0131] Define a rule combination algorithm: A rule combination algorithm is a set of algorithms that explicitly specifies the execution order of multiple rules, denoted as . Rule combination algorithms are a component of the strategy.
[0132] A rule is defined as a set of 6-dimensional vectors consisting of an object, a subject, a condition, an operation algorithm, an expectation, and an iterative constraint, denoted as . Specifically, a rule can be described as follows: a rule contains 0 or 1 objects, at least one subject, several conditions (which can be 0), at least one operation algorithm, several expectations (which can be 0), and several iterative constraints (which can be 0). The rule describes the conditions under which a subject can execute a predetermined operation algorithm, and the expected results of the algorithm's execution. Rules are a component of a strategy.
[0133] rule This means that under the constraint of `tar`, in each rule, the subject `sub` can execute column operation algorithm `o` if condition `con` is met, and it is determined whether the execution result of operation algorithm `o` meets the expected value `e`; it also involves iterative constraints on the data during subsequent use after the rule execution is completed. Here, `sub` can be a single subject or a set of subjects. Similarly, `tar`, `con`, `o`, `e`, and `ico` can be single elements or sets of corresponding elements. To concisely describe `rul=`... Regarding the semantics, we only consider the case where each of the rules tar, sub, con, o, e, and ico contains only one element. The semantics are similar when the rules are sets. The subject, condition, operation algorithm, and expectation are defined as follows:
[0134] The subject is the set of operators that execute the algorithm, denoted as ;
[0135] A condition is a set consisting of several predicates, denoted as . Specifically, each condition It consists of a set of subconditions { The disjunctive normal form of} is used to determine whether the user subject can execute the algorithm.
[0136] Example: The user entity has the role of a doctor or nurse. The operation algorithm refers to the set of identifiers of algorithms executed by the user entity under specified conditions, denoted as . Examples: k-anonymity, l-diversity, t-proximity, differential privacy; expectation is the set of expected results of an algorithm that uses a subject to perform an operation, denoted as... If anonymization is performed on a personal photo, the personal portrait cannot be restored.
[0137] The iterative use control device for data sharing provided by the present invention will be described below. The iterative use control device for data sharing described below can be referred to in correspondence with the iterative use control method for data sharing described above.
[0138] Figure 5 This is a schematic diagram of the data sharing iterative usage control device provided by the present invention, as shown below. Figure 5 As shown, the data sharing iterative use control device 500 includes the following:
[0139] The annotation module 510 is used to annotate the shared data based on the initial classification strategy set and the initial scenario strategy set to obtain the first data;
[0140] The differentiation processing module 520 is used to perform differentiation control processing on the first data based on the first operation request, the set of operation algorithms and the first scenario description to obtain the second data;
[0141] The iteration module 530 is used to perform iterative use control on the second data based on the second data, the first security parameter, the second security parameter, and the second scenario description.
[0142] In this embodiment of the invention, the annotation module includes an identification submodule, a first determination submodule, and a first annotation submodule, wherein: the identification submodule is used to identify information in the shared data based on a data vocabulary classification knowledge base to obtain information to be annotated; the first determination submodule is used to determine, based on the information to be annotated, a first classification strategy subset and a first scenario strategy subset corresponding to the information to be annotated from the initial classification strategy set and the initial scenario strategy set; the first annotation submodule is used to annotate the information to be annotated based on the first classification strategy subset and the first scenario strategy subset to obtain the first data.
[0143] In this embodiment of the invention, the differentiation processing module includes a judgment submodule, a selection submodule, and a differentiation processing submodule, wherein: the judgment submodule is used to judge the first operation request based on the first classification strategy subset and / or the first scenario strategy subset to obtain a judgment result; the selection submodule is used to select target data that conforms to the first classification strategy subset and / or the first scenario strategy subset from the first data based on a matching selection function when the judgment result indicates that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset; the differentiation processing submodule is used to perform differentiation control processing on the target data based on the target data, the operation algorithm set, and the first scenario description to obtain the second data.
[0144] In this embodiment of the invention, the iteration module includes an iteration submodule, a second annotation submodule, and a usage control submodule, wherein: the iteration submodule is used to iteratively update the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset; and / or, to iteratively update the first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a second scenario strategy subset; the second annotation submodule is used to annotate the second data based on the second classification strategy subset and the second scenario strategy subset to obtain third data; the usage control submodule is used to iteratively control the usage of the third data based on the second operation request, the operation algorithm set, and the second scenario description.
[0145] In this embodiment of the invention, the iterative submodule includes a first iterative unit, a first verification unit, and a first determination unit, wherein: the first iterative unit is used to iteratively update the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a third classification strategy subset; the first verification unit is used to perform monotonicity verification on the third classification strategy subset and the first classification strategy subset to obtain a first verification result; and the first determination unit is used to determine the second classification strategy subset based on the first verification result and the third classification strategy subset.
[0146] In this embodiment of the invention, the first determining unit includes a first determining subunit and a second determining subunit, wherein: the first determining subunit is used to determine the third classification strategy subset as the second classification strategy subset when the first verification result satisfies the first iterative constraint; the second determining subunit is used to iteratively update the third classification strategy subset when the first verification result does not satisfy the first iterative constraint, until the updated classification strategy subset satisfies the iterative constraint, thereby obtaining the second classification strategy subset.
[0147] In this embodiment of the invention, the iterative submodule further includes a second iterative unit, a second verification unit, and a second determination unit, wherein: the second iterative unit is used to iteratively update the first scenario strategy subset based on the second data, the second security parameter, and / or the second scenario description to obtain a third scenario strategy subset; the second verification unit is used to perform monotonicity verification on the third scenario strategy subset and the first scenario strategy subset to obtain a second verification result; and the second determination unit is used to determine the second scenario strategy subset based on the second verification result and the third scenario strategy subset.
[0148] In this embodiment of the invention, the second determining unit includes a third determining subunit and a fourth determining subunit, wherein: the third determining subunit is used to determine the third scenario strategy subset as the second scenario strategy subset when the second verification result satisfies the second iteration constraint; the fourth determining subunit is used to iteratively update the third scenario strategy subset when the second verification result does not satisfy the second iteration constraint, until the updated scenario strategy subset satisfies the iteration constraint, thereby obtaining the second scenario strategy subset.
[0149] In this embodiment of the invention, the iterative data sharing control device further includes an initial strategy determination module, specifically configured to: input a third security parameter into a classification strategy generation model to obtain a first classification strategy set; input a fourth security parameter into a scene strategy generation model to obtain a first scene strategy set; if the first classification strategy set does not meet the data sharing requirements, based on a fifth security parameter, continuously generate a new classification strategy set until the number of times the new classification strategy set is generated reaches a first preset number or the new classification strategy set meets the data sharing requirements, thereby obtaining the initial classification strategy set; and / or, if the first scene strategy set does not meet the data sharing requirements, based on a sixth security parameter, continuously generate a new scene strategy set until the number of times the new scene strategy set is generated reaches a second preset number or the new scene strategy set meets the data sharing requirements, thereby obtaining the initial scene strategy set.
[0150] In this embodiment of the invention, the setting forms of the first security parameter, the second security parameter, the third security parameter, the fourth security parameter, the fifth security parameter, the sixth security parameter, the first operation request, the operation algorithm set, the first scene description, the second scene description, and the second operation request include at least one of the following: based on rules, configuration files, buttons, circle, checkmark, mark, key, scroll wheel, menu, voice, video, eye contact, gesture, text, bioelectrical signals, and virtual reality.
[0151] Figure 6 A schematic diagram of the structure of the electronic device provided by the present invention is shown below. Figure 6 The electronic device may include a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, communications interface 620, and memory 630 communicate with each other via the communication bus 640. The processor 610 can invoke logical instructions in the memory 630 to execute an iterative usage control method for data sharing. This method includes: labeling shared data based on an initial classification strategy set and an initial scenario strategy set to obtain first data; performing differentiated control processing on the first data based on a first operation request, an operation algorithm set, and a first scenario description to obtain second data; and performing iterative usage control on the second data based on the second data, a first security parameter, a second security parameter, and a second scenario description.
[0152] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0153] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the iterative use control method for data sharing provided by the above methods. The method includes: labeling shared data based on an initial classification strategy set and an initial scenario strategy set to obtain first data; performing differentiated control processing on the first data based on a first operation request, an operation algorithm set, and a first scenario description to obtain second data; and performing iterative use control on the second data based on the second data, a first security parameter, a second security parameter, and a second scenario description.
[0154] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements an iterative usage control method for data sharing provided by the methods described above. The method includes: labeling shared data based on an initial classification strategy set and an initial scenario strategy set to obtain first data; performing differential control processing on the first data based on a first operation request, an operation algorithm set, and a first scenario description to obtain second data; and performing iterative usage control on the second data based on the second data, a first security parameter, a second security parameter, and a second scenario description.
[0155] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0156] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for controlling iterative use of data sharing, characterized in that, include: Based on a data vocabulary classification knowledge base, information in shared data is identified to obtain information to be labeled; Based on the information to be labeled, a first classification strategy subset and a first scenario strategy subset corresponding to the information to be labeled are determined from the initial classification strategy set and the initial scenario strategy set; Based on the first classification strategy subset and the first scenario strategy subset, the information to be labeled is labeled to obtain the first data; Based on the first operation request, the set of operation algorithms, and the first scenario description, the first data is subjected to differentiated control processing to obtain the second data; Based on the second data, the first security parameter and / or the second scenario description, the first classification strategy subset is iteratively updated to obtain the second classification strategy subset. And / or, Based on the second data, the second security parameters and / or the second scenario description, the first scenario policy subset is iteratively updated to obtain the second scenario policy subset. Based on the second classification strategy subset and the second scenario strategy subset, the second data is labeled to obtain the third data; Based on the second operation request, the set of operation algorithms, and the second scenario description, the third data is used for iterative control.
2. The iterative use control method for data sharing according to claim 1, characterized in that, The process of performing differentiated control processing on the first data based on the first operation request, the set of operation algorithms, and the first scenario description to obtain the second data includes: Based on the first classification strategy subset and / or the first scenario strategy subset, the first operation request is judged to obtain a judgment result; If the determination result is that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset, target data that conforms to the first classification strategy subset and / or the first scenario strategy subset is selected from the first data based on the matching selection function; Based on the target data, the set of operation algorithms, and the first scenario description, the target data is subjected to differentiated control processing to obtain the second data.
3. The iterative use control method for data sharing according to claim 1, characterized in that, The step of iteratively updating the first classification strategy subset based on the second data, the first security parameter, and / or the second scenario description to obtain a second classification strategy subset includes: Based on the second data, the first security parameter and / or the second scenario description, the first classification strategy subset is iteratively updated to obtain the third classification strategy subset. Monotonicity verification is performed on the third classification strategy subset and the first classification strategy subset to obtain the first verification result; Based on the first verification result and the third classification strategy subset, the second classification strategy subset is determined.
4. The iterative use control method for data sharing according to claim 3, characterized in that, The step of determining the second classification strategy subset based on the first verification result and the third classification strategy subset includes: If the first verification result satisfies the first iteration constraint, the third classification strategy subset is determined as the second classification strategy subset; If the first verification result does not satisfy the first iterative constraint, the third classification strategy subset is iteratively updated until the updated classification strategy subset satisfies the iterative constraint, thus obtaining the second classification strategy subset.
5. The iterative use control method for data sharing according to claim 1, characterized in that, The step of iteratively updating the first scenario policy subset based on the second data, the second security parameters, and / or the second scenario description to obtain a second scenario policy subset includes: Based on the second data, the second security parameters and / or the second scenario description, the first scenario policy subset is iteratively updated to obtain the third scenario policy subset. Monotonicity verification is performed on the third scenario strategy subset and the first scenario strategy subset to obtain a second verification result; Based on the second verification result and the third scenario strategy subset, the second scenario strategy subset is determined.
6. The iterative use control method for data sharing according to claim 5, characterized in that, The step of determining the second scenario strategy subset based on the second verification result and the third scenario strategy subset includes: If the second verification result satisfies the second iteration constraint, the third scenario strategy subset is determined as the second scenario strategy subset; If the second verification result does not satisfy the second iteration constraint, the third scenario strategy subset is iteratively updated until the updated scenario strategy subset satisfies the iteration constraint, thus obtaining the second scenario strategy subset.
7. The iterative use control method for data sharing according to claim 1, characterized in that, Determining the initial classification strategy set and the initial scenario strategy set includes: The third security parameter is input into the classification strategy generation model to obtain the first set of classification strategies. The fourth security parameter is input into the scenario policy generation model to obtain the first scenario policy set; If the first set of classification strategies does not meet the data sharing requirements, a new set of classification strategies is continuously generated based on the fifth security parameter until the number of times the new set of classification strategies is generated reaches the first preset number or the new set of classification strategies meets the data sharing requirements, thus obtaining the initial set of classification strategies. And / or, If the first set of scenario strategies does not meet the data sharing requirements, a new set of scenario strategies is continuously generated based on the sixth security parameter until the number of times the new set of scenario strategies is generated reaches the second preset number or the new set of scenario strategies meets the data sharing requirements, thus obtaining the initial set of scenario strategies.
8. The iterative use control method for data sharing according to claim 7, characterized in that, The first security parameter, the second security parameter, the third security parameter, the fourth security parameter, the fifth security parameter, the sixth security parameter, the first operation request, the operation algorithm set, the first scene description, the second scene description, and the second operation request are set in the following ways: based on rules, configuration files, buttons, circle, checkmark, mark, key, scroll wheel, menu, voice, video, eye contact, gesture, text, bioelectrical signals, and virtual reality.
9. A data-sharing iterative usage control device, characterized in that, include: The annotation module is used to annotate the shared data based on the initial classification strategy set and the initial scenario strategy set to obtain the first data; The differentiation processing module is used to perform differentiation control processing on the first data based on the first operation request, the set of operation algorithms, and the first scenario description to obtain the second data; The iteration module is used to perform iterative usage control on the second data based on the second data, the first security parameter, the second security parameter, and the second scenario description. The annotation module includes an identification submodule, a first determination submodule, and a first annotation submodule, wherein: The identification submodule is used to identify information in the shared data based on the data vocabulary classification knowledge base to obtain the information to be labeled; The first determining submodule is used to determine, based on the information to be labeled, a first classification strategy subset and a first scene strategy subset corresponding to the information to be labeled from the initial classification strategy set and the initial scene strategy set; The first annotation submodule is used to annotate the information to be annotated based on the first classification strategy subset and the first scenario strategy subset to obtain the first data; The iteration module includes an iteration submodule, a second annotation submodule, and a usage control submodule, wherein: The iterative submodule is used to iteratively update the first classification strategy subset based on the second data, the first security parameter and / or the second scenario description, to obtain the second classification strategy subset. And / or, Based on the second data, the second security parameters, and / or the second scenario description, the first scenario policy subset is iteratively updated to obtain the second scenario policy subset. The second annotation submodule is used to annotate the second data based on the second classification strategy subset and the second scenario strategy subset to obtain the third data; The usage control submodule is used to perform iterative usage control on the third data based on the second operation request, the set of operation algorithms, and the second scenario description.
10. The data sharing iterative usage control device according to claim 9, characterized in that, The differentiation processing module includes a judgment submodule, a selection submodule, and a differentiation processing submodule, wherein: The judgment submodule is used to judge the first operation request based on the first classification strategy subset and / or the first scenario strategy subset, and obtain a judgment result; The selection submodule is used to select target data that conforms to the first classification strategy subset and / or the first scenario strategy subset from the first data based on a matching selection function when the determination result is that the first operation request satisfies the first classification strategy subset and / or the first scenario strategy subset. The differentiation processing submodule is used to perform differentiation control processing on the target data based on the target data, the set of operation algorithms, and the first scenario description to obtain the second data.
11. The data sharing iterative usage control device according to claim 9, characterized in that, The iterative submodule includes a first iterative unit, a first verification unit, and a first determination unit, wherein: The first iteration unit is used to iteratively update the first classification strategy subset based on the second data, the first security parameter and / or the second scenario description to obtain a third classification strategy subset; The first verification unit is used to perform monotonicity verification on the third classification strategy subset and the first classification strategy subset to obtain a first verification result; The first determining unit is configured to determine the second classification strategy subset based on the first verification result and the third classification strategy subset.
12. The data sharing iterative usage control device according to claim 11, characterized in that, The first determining unit includes a first determining subunit and a second determining subunit, wherein: The first determining subunit is used to determine the third classification strategy subset as the second classification strategy subset when the first verification result satisfies the first iteration constraint; The second determining subunit is used to iteratively update the third classification strategy subset when the first verification result does not satisfy the first iterative constraint, until the updated classification strategy subset satisfies the iterative constraint, thus obtaining the second classification strategy subset.
13. The data sharing iterative usage control device according to claim 9, characterized in that, The iterative submodule further includes a second iterative unit, a second verification unit, and a second determination unit, wherein: The second iteration unit is used to iteratively update the first scenario policy subset based on the second data, the second security parameters and / or the second scenario description, to obtain a third scenario policy subset; The second verification unit is used to perform monotonicity verification on the third scenario strategy subset and the first scenario strategy subset to obtain a second verification result; The second determining unit is used to determine the second scenario strategy subset based on the second verification result and the third scenario strategy subset.
14. The data sharing iterative usage control device according to claim 13, characterized in that, The second determining unit includes a third determining subunit and a fourth determining subunit, wherein: The third determining subunit is used to determine the third scenario strategy subset as the second scenario strategy subset when the second verification result satisfies the second iteration constraint; The fourth determining subunit is used to iteratively update the third scenario strategy subset when the second verification result does not meet the second iterative constraint, until the updated scenario strategy subset meets the iterative constraint, and then obtain the second scenario strategy subset.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the iterative use control method for data sharing as described in any one of claims 1 to 8.
16. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the iterative use control method for data sharing as described in any one of claims 1 to 8.
17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the iterative use control method for data sharing as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Data sharing method and device
CN117725611A
Power grid data epitaxial access control method and system
CN120729575A