A data governance platform for automatic identification of sensitive data

By designing a data governance platform for automatic identification of sensitive data, and utilizing preliminary comparison and segmentation of sensitive phrases, the challenge of sensitive data management has been solved, achieving efficient identification and governance of sensitive data.

CN122133179APending Publication Date: 2026-06-02YUNNAN TENGJIAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
YUNNAN TENGJIAN TECH CO LTD
Filing Date
2026-02-06
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Due to differences in organizational structure, business systems, and data platforms, sensitive data is often fragmented, not shared, duplicated, disconnected, and unevenly distributed, making effective management difficult.

Method used

Design a data governance platform for automatic identification of sensitive data, including a monitoring and display module, a transmission gateway, a sensitive data storage unit, a data receiving unit, a sensitive data comparison unit, and an operation unit. Through preliminary comparison of sensitive words, split comparison, and encryption processing, the platform can identify and manage sensitive data.

Benefits of technology

It improves the efficiency of sensitive data identification and management, reduces the amount of computation required for identification, and achieves efficient management of sensitive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133179A_ABST
    Figure CN122133179A_ABST
Patent Text Reader

Abstract

This invention discloses a data governance platform for automatic identification of sensitive data, relating to the field of sensitive data identification and governance technology. It solves the problem that due to differences in organizational structure, business systems, and data platforms, many data organizations operate independently, resulting in data non-sharing, duplicate data, disconnected information, and uneven data distribution, making sensitive data management inconvenient. The data governance platform for automatic identification of sensitive data includes a monitoring and display module, a transmission gateway, a sensitive data storage unit, a data receiving unit, a sensitive data comparison unit, and an operation unit. The monitoring and display module includes a display, a signal converter, and a signal receiver. This invention uses pre-defined sensitive word groups for preliminary analysis, identification, and classification of data. After identifying the sensitive word groups, the data is further segmented and compared, reducing the computational workload of data identification and improving the efficiency of sensitive data identification and governance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of sensitive data identification and governance technology, specifically a data governance platform for automatic identification of sensitive data. Background Technology

[0002] Sensitive data refers to data that, if leaked, may cause serious harm to society or individuals. This includes personal privacy data such as names, ID numbers, addresses, phone numbers, bank account numbers, email addresses, passwords, medical information, and educational backgrounds; it also includes data that enterprises or social organizations are not suitable to disclose, such as a company's operating information, network structure, and IP address list. There are two technical approaches to sensitive data desensitization: static desensitization and dynamic desensitization. Additionally, sensitive data can be discovered through data asset analysis, and sensitive data in the database can be transformed to prevent leakage.

[0003] Due to differences in organizational structure, business systems, and data platforms, many data organizations operate independently, with data not shared, duplicate data, disconnected information, and uneven data distribution, making it inconvenient to manage sensitive data. Therefore, this approach does not meet existing needs. To address this, we propose a data governance platform that automatically identifies sensitive data. Summary of the Invention

[0004] The purpose of this invention is to provide a data governance platform for automatic identification of sensitive data, in order to solve the problems mentioned in the background art, such as the fact that due to the differences in organizational structure, business systems, and data platforms, many data organizations are independent, data is not shared, duplicate data is generated, information is not interconnected, and data is unevenly distributed, making it inconvenient to manage sensitive data.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a data governance platform for automatic identification of sensitive data, comprising a monitoring and display module, a transmission gateway, a sensitive data storage unit, a data receiving unit, a sensitive data comparison unit, and an operation unit, wherein the monitoring and display module comprises a display, a signal converter, and a signal receiver;

[0006] The transmission gateway includes a data transmission line and a wireless router;

[0007] The operation unit includes an operation screen, a screen camera, a keyboard, and a mouse;

[0008] The sensitive data storage unit includes a storage hard disk, a storage chassis, and a chassis heat sink;

[0009] The data receiving unit includes a data receiver, a data conversion chip, a data transmission chip, and a data classification module;

[0010] The sensitive data comparison unit includes a data receiving module, a data comparison module, a database storage module, a data analysis module, and a feedback module.

[0011] Preferably, the display and the signal converter are connected via a wiring harness, and the signal converter and the signal receiver are connected to the wireless router via a data transmission cable.

[0012] Preferably, the operation unit and the data receiving unit are electrically connected, and the transmission gateway is connected to the data receiving unit, the sensitive data comparison unit, and the operation unit via transmission data lines.

[0013] Preferably, the data receiving unit is unidirectionally connected to the sensitive data comparison unit for transmission, and the sensitive data comparison unit is unidirectionally connected to the sensitive data storage unit for transmission.

[0014] Preferably, the data classification module includes an analysis chip and an analysis library, the analysis library storing sensitive word groups.

[0015] Preferably, the data comparison module includes a comparison chip, and the database storage module includes a sensitive data group and storage hardware.

[0016] Preferably, the sensitive data group is stored in storage hardware, and the sensitive data group contains sensitive word groups.

[0017] A data governance method for an automatic sensitive data identification platform includes the following steps:

[0018] S1: The operator of the operating unit transmits data over the network, and the data is transmitted to the data receiving unit via wireless signal;

[0019] S2: After receiving the data, the data receiving unit will perform a preliminary comparison between the received data and the sensitive words in the data classification module;

[0020] S3: If the content in the data does not have any identical parts with the sensitive words, the data receiving unit will send the data normally;

[0021] S4: If the content in the data has the same part as the sensitive words, the data receiving unit will transmit the data to the sensitive data comparison unit.

[0022] S5: After receiving the data, the sensitive data comparison unit retrieves the sensitive data group stored in the database storage module, splits the data in the received data, and compares it with the sensitive data group one by one;

[0023] S6: After identifying sensitive data, the portion containing the sensitive data is extracted and encrypted, and the extracted data is backed up and stored.

[0024] S7: Backup data is transmitted to the sensitive data storage unit for storage, encrypted data is transmitted normally, and a sensitive data identification alarm is sent to the monitoring display module through the transmission gateway to notify staff to handle the situation.

[0025] Compared with the prior art, the beneficial effects of the present invention are:

[0026] The invention utilizes pre-defined sensitive word groups to perform preliminary analysis, identification, and classification of data. After identifying the sensitive word groups, the data is further split and compared, which reduces the computational workload of data identification and improves the efficiency of sensitive data identification and management. Attached Figure Description

[0027] Figure 1 This is a schematic diagram of the overall structure of the present invention;

[0028] Figure 2 This is a flowchart illustrating the identification and management process for sensitive data in this invention.

[0029] In the diagram: 1. Monitoring and display module; 2. Transmission gateway; 3. Sensitive data storage unit; 4. Data receiving unit; 5. Sensitive data comparison unit; 6. Operation unit. Detailed Implementation

[0030] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0031] like Figure 1 As shown, a data governance platform for automatic identification of sensitive data includes a monitoring and display module 1, a transmission gateway 2, a sensitive data storage unit 3, a data receiving unit 4, a sensitive data comparison unit 5, and an operation unit 6. The monitoring and display module 1 includes a display, a signal converter, and a signal receiver.

[0032] The transmission gateway 2 includes a data cable and a wireless router.

[0033] The monitor and the signal converter are connected via a cable harness, while the signal converter and the signal receiver are connected to the wireless router via a data transmission cable. The signal receiver receives the data transmitted by the transmission gateway 2, converts the data through the signal converter, and finally displays the result on the monitor.

[0034] The operation unit 6 includes an operation screen, a screen camera, a keyboard, and a mouse.

[0035] The operation unit 6 is electrically connected to the data receiving unit 4, and the transmission gateway 2 is connected to the data receiving unit 4, the sensitive data comparison unit 5, and the operation unit 6 via data transmission lines.

[0036] Sensitive data storage unit 3 includes a storage hard drive, a storage chassis, and a chassis heat sink.

[0037] The data receiving unit 4 includes a data receiver, a data conversion chip, a data transmission chip, and a data classification module.

[0038] The data classification module includes an analysis chip and an analysis library, which stores sensitive word phrases.

[0039] Sensitive data comparison unit 5 includes a data receiving module, a data comparison module, a database storage module, a data analysis module, and a feedback module.

[0040] The data comparison module includes a comparison chip, and the database storage module includes a sensitive data group and storage hardware. The sensitive data group is stored in the storage hardware and contains sensitive words.

[0041] The data receiving unit 4 and the sensitive data comparison unit 5 are connected and transmitted unidirectionally. The sensitive data comparison unit 5 and the sensitive data storage unit 3 are connected and transmitted unidirectionally. The data receiving unit 4 receives data and transmits it to the sensitive data comparison unit 5. The sensitive data comparison unit 5 identifies and extracts the sensitive data in the data. The sensitive data comparison unit 5 encrypts the sensitive data and backs up and stores the sensitive data.

[0042] like Figure 2 As shown, a data governance method for an automatic sensitive data identification platform includes the following steps:

[0043] S1: The operator of the operation unit 6 transmits data over the network, and the data is transmitted to the data receiving unit 4 via wireless signal;

[0044] S2: After receiving the data, the data receiving unit 4 will perform a preliminary comparison between the received data and the sensitive word groups in the data classification module;

[0045] S3: If the content in the data does not have any identical parts with the sensitive words, the data receiving unit 4 will send the data normally.

[0046] S4: If the content in the data has the same part as the sensitive words, the data receiving unit 4 will transmit the data to the sensitive data comparison unit 5.

[0047] S5: After receiving the data, the sensitive data comparison unit 5 retrieves the sensitive data group stored in the database storage module, and splits the data in the received data and compares it with the sensitive data group one by one;

[0048] S6: After identifying sensitive data, the portion containing the sensitive data is extracted and encrypted, and the extracted data is backed up and stored.

[0049] S7: Backup data is transmitted to sensitive data storage unit 3 for storage, encrypted data is transmitted normally, and a sensitive data identification alarm is sent to monitoring display module 1 through transmission gateway 2 to notify staff to handle the situation.

[0050] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A data governance platform for automatic identification of sensitive data, comprising a monitoring and display module (1), a transmission gateway (2), a sensitive data storage unit (3), a data receiving unit (4), a sensitive data comparison unit (5), and an operation unit (6), characterized in that: The monitoring display module (1) includes a display, a signal converter, and a signal receiver; The transmission gateway (2) includes a data transmission line and a wireless router; The operation unit (6) includes an operation screen, a screen camera, a keyboard, and a mouse; The sensitive data storage unit (3) includes a storage hard disk, a storage chassis, and a chassis heat sink; The data receiving unit (4) includes a data receiver, a data conversion chip, a data transmission chip, and a data classification module; The sensitive data comparison unit (5) includes a data receiving module, a data comparison module, a database storage module, a data analysis module, and a feedback module.

2. The data governance platform for automatic identification of sensitive data according to claim 1, characterized in that: The display and the signal converter are connected via a wiring harness, while the signal converter and the signal receiver are connected to the wireless router via a data transmission cable.

3. The data governance platform for automatic identification of sensitive data according to claim 2, characterized in that: The operation unit (6) is electrically connected to the data receiving unit (4), and the transmission gateway (2) is connected to the data receiving unit (4), the sensitive data comparison unit (5), and the operation unit (6) via a data transmission line.

4. The data governance platform for automatic identification of sensitive data according to claim 3, characterized in that: The data receiving unit (4) is unidirectionally connected to the sensitive data comparison unit (5) for transmission, and the sensitive data comparison unit (5) is unidirectionally connected to the sensitive data storage unit (3) for transmission.

5. The data governance platform for automatic identification of sensitive data according to claim 4, characterized in that: The data classification module includes an analysis chip and an analysis library, which stores sensitive word groups.

6. The data governance platform for automatic identification of sensitive data according to claim 5, characterized in that: The data comparison module includes a comparison chip, and the database storage module includes sensitive data groups and storage hardware.

7. The data governance platform for automatic identification of sensitive data according to claim 6, characterized in that: The sensitive data group is stored in storage hardware, and the sensitive data group contains sensitive word groups.

8. The governance method of a data governance platform for automatic identification of sensitive data according to claim 7, characterized in that: Includes the following steps: S1: The operator of the operation unit (6) transmits data in the network, and the data is transmitted to the data receiving unit (4) via wireless signal. S2: After receiving the data, the data receiving unit (4) will perform a preliminary comparison between the received data and the sensitive word groups in the data classification module; S3: If the content in the data does not have the same part as the sensitive words, the data receiving unit (4) will send the data normally; S4: If the content in the data has the same part as the sensitive words, the data receiving unit (4) will transmit the data to the sensitive data comparison unit (5); S5: Sensitive data comparison unit (5) receives data and retrieves the sensitive data group stored in the database storage module, and splits the data in the received data and compares it with the sensitive data group one by one; S6: After identifying sensitive data, the portion containing the sensitive data is extracted and encrypted, and the extracted data is backed up and stored. S7: The backup data is transmitted to the sensitive data storage unit (3) for storage, the encrypted data is transmitted normally, and a sensitive data identification alarm is sent to the monitoring display module (1) through the transmission gateway (2) to notify the staff to handle it.